|
Security Incidents
mailing list archives
Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028
From: Salomao Barguil <barguil () yahoo com>
Date: Thu, 27 Feb 2003 16:40:23 -0800 (PST)
Hi,
Running netstat -a , I found a foreign address
"GirlNextDoor_" listening to ports TCP 1025/1028.
Can someone explain me what is going on this desktop ?
It's a Win2k/SP2 workstation with Mcafee antivirus and
ZoneAlarm.
Also, can you explain me the second set of
connections, foreign address "*:*" ?
Thanks for your help,
Sal.
-------------------------------------------------------
Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.
C:\>netstat -a
Active Connections
Proto Local Address Foreign Address
State
TCP p4win2k:epmap Girlnextdoor_:0
LISTENING
TCP p4win2k:microsoft-ds Girlnextdoor_:0
LISTENING
TCP p4win2k:1025 Girlnextdoor_:0
LISTENING
TCP p4win2k:1028 Girlnextdoor_:0
LISTENING
TCP p4win2k:netbios-ssn Girlnextdoor_:0
LISTENING
UDP p4win2k:epmap *:*
UDP p4win2k:microsoft-ds *:*
UDP p4win2k:1027 *:*
UDP p4win2k:1030 *:*
UDP p4win2k:netbios-ns *:*
UDP p4win2k:netbios-dgm *:*
UDP p4win2k:isakmp *:*
C:\>
-------------------------------------------------------
__________________________________________________
Do you Yahoo!?
Yahoo! Tax Center - forms, calculators, tips, more
http://taxes.yahoo.com/
----------------------------------------------------------------------------
<Pre>Lose another weekend managing your IDS?
Take back your personal time.
15-day free trial of StillSecure Border Guard.</Pre>
<A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A>
By Date
By Thread
Current thread:
- Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028 Salomao Barguil (Mar 04)
|