Solved

How can I determine which port a program is running on?

Posted on 2007-04-06
6
250 Views
Last Modified: 2010-04-18
How can I determine which port a program is running on?  I did a vulnerability scan on one of my servers and port 5250 is open.  This is a port used by various trojans.  I would like to see what program or service is using this port...........
0
Comment
Question by:gopher_49
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 
LVL 30

Accepted Solution

by:
LauraEHunterMVP earned 125 total points
ID: 18863777
On a 2003 server, run the following command: netstat -ano.  This will give you the port# and the Process ID of the .exe or service that is using it.  You can then look in Task Manager to determine which process corresponds to that Process ID.
0
 
LVL 18

Assisted Solution

by:John Gates, CISSP
John Gates, CISSP earned 125 total points
ID: 18863778
You can use utilities here:

http://www.microsoft.com/technet/sysinternals/default.mspx

You will find all kinds of useful utilities here for troubleshooting.

-D-
0
 
LVL 18

Expert Comment

by:John Gates, CISSP
ID: 18863791
0
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

 
LVL 18

Expert Comment

by:John Gates, CISSP
ID: 18863808
netstat -ano will do that as well but the sysinternals utilities give you a graphical view if you are not a "Command Line" kind of person ;-)

-D-
0
 
LVL 18

Expert Comment

by:John Gates, CISSP
ID: 18863821
And i guess when you find a rouge process you could use:

TASKKILL /PID <program ID>
0
 

Author Comment

by:gopher_49
ID: 18863926
Thanks for both of your suggestions.  I used the 'netstat -ano' commmand some time ago, however, I forgot the syntax.  Also, I used the Sysinternals utilities in the past, however, it's been awhile.  This refreshed my memory and I'm now back on track.

Thanks!
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
In this video, viewers will be given step by step instructions on adjusting mouse, pointer and cursor visibility in Microsoft Windows 10. The video seeks to educate those who are struggling with the new Windows 10 Graphical User Interface. Change Cu…
In this video, viewers are given an introduction to using the Windows 10 Snipping Tool, how to quickly locate it when it's needed and also how make it always available with a single click of a mouse button, by pinning it to the Desktop Task Bar. Int…

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question