Home page logo
/

basics logo Security Basics mailing list archives

RE: irc port open on 6668/tcp and 6667/tcp
From: "Wolf, Glenn" <glenn.wolf () we-inc com>
Date: Wed, 12 Feb 2003 09:41:52 -0800

APC PowerChute uses these ports.  It is an UPS-monitoring program that is
typically installed on servers.

On a similar note, TrendMicro's Office scan listens on port 12345.  So does
the NetBus trojan.

Hope this helps,
Glenn


-----Original Message-----
From: Nelson, Ernie [mailto:Ernie.Nelson () wizards com] 
Sent: Tuesday, February 11, 2003 9:24 AM
To: Harish Gondavale; security-basics () securityfocus com
Subject: RE: irc port open on 6668/tcp and 6667/tcp


I'd grab the fport utility from http://www.foundstone.com/ and run it on the
PDC to see what process is using those open ports.

Now my question is, why these port are open on PDC? Is
there something suspicious? What should I do to find
the exact reason?   


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]