Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Interpreting Netstat Reports

Posted on 2001-07-13
12
Medium Priority
?
684 Views
Last Modified: 2013-12-28
I've been told that the below indicates "OPEN PORTS".
that is what i'm trying to get away from.

Can someone tell me if this is true, Open Ports, and if it's the
UDP that specifies an open port or the *:*

D:\WINNT>netstat -a
UDP    my machine3cj:epmap  *:*
UDP    my machine3cj:microsoft-ds  *:*
UDP    my machine3cj:1025   *:*
UDP    my machine3cj:1027   *:*
UDP    my machine3cj:netbios-ns  *:*
UDP    my machine3cj:netbios-dgm  *:*
UDP    my machine3cj:isakmp  *:*
UDP    my machine3cj:2278   *:*
UDP    my machine3cj:2288   *:*

I'm using Zonealarm at present.
If I'm in the wrong area of experts-exchange please let me know.

Regards, Bud
http://www.wintrouble.net
0
Comment
Question by:smeebud
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
  • 3
12 Comments
 
LVL 63

Expert Comment

by:SysExpert
ID: 6281602
As long as these are on a LAN, then you have no problem.

I would use.

Test firewall ports  and port blocking
http://grc.com/

To see if you have any real problems
or use NMAP or similar to do intrusion testing.

I hope this helps !
0
 
LVL 14

Author Comment

by:smeebud
ID: 6282214
I was hoping for moremthan that.
i need to know how tom interprete these
thinks,
For instance, can you tell me which ports are open?
What does *:* mean, and so forth.

I'm not on a Lan.

Regards, Bud
http://www.wintrouble.net
0
 
LVL 63

Expert Comment

by:SysExpert
ID: 6282549

List of TCp/IP ports ports list, port list TCP ports list              
 http://www.joemagee.com/filez/port-numbers.txt

Most of the ports are ports that MS listens on, Netbios, DHCP, WINS, DNS
etc.

I hope the list I quoted will help.


0
Supports up to 4K resolution!

The VS192 2-Port 4K DisplayPort Splitter is perfect for anyone who needs to send one source of DisplayPort high definition video to two or four DisplayPort displays. The VS192 can split and also expand DisplayPort audio/video signal on two or four DisplayPort monitors.

 
LVL 1

Expert Comment

by:l8knight
ID: 6282675
Hi smeebud,

basically what it is telling you is the

protocol -> TCP/UDP

hostname/computername -> my machine3cj

service/portnumber -> epmap or 80

connection status -> *:* or bab5:1046

*:* means that it is waiting for packets... you will only find this with UDP because it is a connectionless protocol i.e. you do not need to establish a connection before sending it data.

bab5:1046 means that it has a connection to a machine called bab5 on port 1046.
 

Hope this helps

l8knight
0
 
LVL 14

Author Comment

by:smeebud
ID: 6282689
|8knight,
 
You've hit on it.

*:* means that it is waiting for packets... you will only find this with UDP because it is a connectionless
protocol i.e. you do not need to establish a connection before sending it data.

What I want to know is, (Does *:*) mean an open port that port sniffers can access.

Regards, Bud
http://www.wintrouble.net
0
 
LVL 1

Expert Comment

by:l8knight
ID: 6282702
Yes, a port sniffer can tell that you have that port open... whether they can access it or not depends on what is using that port. If it is a backdoor program like "backoriface" then yes they could... if it is a DNS server then they could only use it for doing a DNS query.

l8knight
0
 
LVL 1

Expert Comment

by:l8knight
ID: 6282734
A port sniffer will only show what ports are active on machine...

You would then need to either to use a security vulnerability in the legitimate software e.g. running an executable via script directory in a Web Server or access illegimate software such back oriface.

there is no magic way of hackers gaining access to your machine.

keep adding security updates to your machine and use a virus checker (most of these will detect a trojan) and you should be fairly safe.

hope this explains it a little better

regards

l8knight
0
 
LVL 14

Author Comment

by:smeebud
ID: 6283713
it explains it very well.

I just like to know how to close these ports.
For instance I'm using ZoneAlarm.

There are sections in it where I can specify ports to lock.
But a port with the # 1025 is used for instance when I FTP.

So if I lock it, the FTP will just look for the next highr number.
I can't lock them all.

Reason I'm paraniod is last week as I was working my screen went black, locked tight.
When I shut down and tried to re-boot, the system didn't see any drives. it took two days to rebuild my boot loader,
but when I Restored Drive D:, where I have and was working on windows 2000 when system crashed, I saw that drive had been named "John".....

I never label my drives so I'm sure someone came in and did this.

Regards, Bud
http://www.wintrouble.net

0
 
LVL 63

Expert Comment

by:SysExpert
ID: 6283914
Zone Alarm - if kept updated is not easy to bypass.
It could have been a random label caused when you crashed.

Just use 2  updated virus scanners and keep your OS security patches updated also.

Turn off all sharing.

I hope this helps !
0
 
LVL 1

Expert Comment

by:l8knight
ID: 6285748
hi bud,

Sorry I have no experience whatsoever with ZoneAlarm so I can't tell you how to block/close ports with it. :-(

I wouldn't worry about outgoing ports that get opened while you are using internet software like ftp. Your software needs to open these to communicate with the internet.

Worry about the incoming ports that are always open.

A quick check is to close all you internet apps, then do a netstat -a and check the ports with a known port list like the one SysExpert provided a link to above. This way you can work out which services are using the ports. If the ports/services seem suspect or you can't match up the port number with a known service then I would think about blocking it.

Another thing you could do is get a list of ports that trojans are known to use... you should be able to find such a list at any good security orientated website.

cheers and good hunting

l8knight
0
 
LVL 1

Accepted Solution

by:
l8knight earned 800 total points
ID: 6285822
here's a trojan port list for you courtesy of TL Security

http://www.tlsecurity.net/trojanh.htm

l8knight
0
 
LVL 14

Author Comment

by:smeebud
ID: 6286228
Thanks you both sysexpert
and |8knight.

I'm going to have to give this port subject some serious study.

Regards, Bud
http://www.wintrouble.net
0

Featured Post

Optimum High-Definition Video Viewing and Control

The ATEN VM0404HA 4x4 4K HDMI Matrix Switch supports 4K resolutions of UHD (3840 x 2160) and DCI (4096 x 2160) with refresh rates of 30 Hz (4:4:4) and 60 Hz (4:2:0). It is ideal for applications where the routing of 4K digital signals is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article helps those who get the 0xc004d307 error when trying to rearm (reset the license) Office 2013 in a Virtual Desktop Infrastructure (VDI) and/or those trying to prep the master image for Microsoft Key Management (KMS) activation. (i.e.- C…
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question