Solved

Unknown ports

Posted on 2008-09-30
3
671 Views
Last Modified: 2012-05-05
I have been monitoring traffic on my WAN and I can see some traffic that I cant identify.

From a server running Windows 2003 R2 SP1 and Exchange 2003 I am seeing traffic on tcp port 1245. My analyzer is identifying the application as "isbconference2"

A separate server again running Win2k3 R2 SP1 and Exchange 2003 is pushing out traffic on tcp port 1230 and the analyzer is identifying this as application "periscope"

Please can you help me determine what this traffic is?
0
Comment
Question by:dgjlee
3 Comments
 
LVL 23

Expert Comment

by:Justin Durrant
ID: 22606591
0
 
LVL 1

Author Comment

by:dgjlee
ID: 22606905
Sorry... This answer is not applicable.
0
 
LVL 32

Accepted Solution

by:
harbor235 earned 500 total points
ID: 22613533
Periscope Presentation software displays the screen of a Pocket PC onto a nearby desktop or laptop PC for projection, and remotely controls PowerPoint presentations, runs on port 1230

For port 1245 i found this
http://www.symantec.com/business/security_response/attacksignatures/detail.jsp?asid=20256
However,  isbconference2 run on this port as well, could be conferencing software, i would ask around and see if anyone is running these apps. Go to the server in question and list the software that is installed and see if any of the above software is installed . If not i would look at this from a potential security threat and runs some virus/malware program on this system.

harbor235 ;}

0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question