What are these ports open and listening for? Any ideas.

CromNogger

Senior member
Jan 26, 2001
849
0
0
135, 445, 1025, 1027, 1029, 1035, 1039, 1043, 15876 and 44334. Status is listening for all of these when I type netstat -an. The IP address is listed as 0.0.0.0:0. I do not understand. Someone clarify?
 

Pretender

Banned
Mar 14, 2000
7,192
0
0
0.0.0.0 means no one is connected but the socket is listening waiting for inbound connections. Damn I don't have a reference in front of me, search on google for port lists.
 

PCResources

Banned
Oct 4, 2000
2,499
0
0
In Linux, all ports are enabled as default, shut all of them then enable the ones you need...

In Win the standard is that all ports are disabled (locked) and are only enabled if you choose to do so...

Your computer is wide open, close it up before someone decides that he wants to mess with you...

Patrick
 

PCResources

Banned
Oct 4, 2000
2,499
0
0
e-tech, that trojan does not run under linux...

But trippy should still close those ports, there are no need to keep them open...

My recommendation is that you use the personal firewall and keep all ports that you do not need closed, in Linux, this is easily done, in win, it is done by default (the ports, not the firewall...

Patrick
 

CromNogger

Senior member
Jan 26, 2001
849
0
0
Thanks for all the help, guys. I saw one suspicious looking open port while scanning with Anti-Trojan (probably a trojan in itself haha). This confirms my suspicion.
 

CromNogger

Senior member
Jan 26, 2001
849
0
0
What can I do?
I have NIS 2K, NAV 2K (realtime thingy enabled), Anti-Trojan 5.5 and Anti-Trojan Watch, ZoneAlarm Pro, and Tiny Personal Firewall. I'm only running Tiny right now. Let me know if there's anything else I should know or do.

if I'm running the firewall, are the ports closed? Cuz netstat thinks they're open .. what can I do?
 

CromNogger

Senior member
Jan 26, 2001
849
0
0
A whole bunch more are listening now, in the 2-thousands

BTW, why are u talkin about Linux? I'm running Win2K
 

Pretender

Banned
Mar 14, 2000
7,192
0
0
uh, a few things

1) IE may be opening new sockets and not closing them properly, hence they still exist in closed form. I don't know why they'd be listed as listening, but try rebooting and see if the same ports are open BEFORE going to any websites.

2) Press control-alt-delete and note any strange or unusual apps. If you are unsure which apps don't belong, post all of them up here.
 

CromNogger

Senior member
Jan 26, 2001
849
0
0
No unusual apps.

There were listen ports open before the last reboot, too. I can reboot and double check.
 

Pretender

Banned
Mar 14, 2000
7,192
0
0
The established connections: 5190 is AIM, 1863 is probably AIM or some feature of it (direct connect?), the 21 is ftp.

Everything else: damned if I know.

Ah, you might wanna go to System Info and see if anything suspicious is loading, I forgot that you're on 2k and it's easy for a program to hide itself as a process where most people don't have the patience to check (me included).
 

Pretender

Banned
Mar 14, 2000
7,192
0
0
ah I was wrong, 1863 is for MSN Messenger. BTW, you can find info about most ports by just doing a search for "port xxxx" on google, where xxxx is the number.