
Security Basics mailing list archives
RE: Hidden windows ports, files and services.
From: Alex Yan <drcyyan () yahoo com>
Date: Tue, 15 Feb 2005 08:19:46 -0800 (PST)
Paul, I have Verizon DSL with a Linksys router (BEFS41 ?). I didn't configure it right till last weekend. The firewall and port blocking were not working properly before. I did try the XP ftp server and SERV-U ftp. But I already removed these components. Under IIS, there are no services running now. As you suggested, I can try remove IIS component. Thanks Alex --- Paul Marsh <pmarsh () nmefdn org> wrote:
Alex: Are you running IIS on the system in question? Are you running FTP along with IIS? If you don't need them add/remove programs, add/remove Windows Components uncheck IIS and click next, reboot and do a netstat -bano and see what's listening now. What kind of a internet connection do you have, broadband maybe? Thanx, Paul -----Original Message----- From: Alex Yan [mailto:drcyyan () yahoo com] Sent: Tuesday, February 15, 2005 10:17 AM To: Paul Marsh; security-basics () securityfocus com Subject: RE: Hidden windows ports, files and services. Hi Paul, I did run TASKLIST before without "/SVC" The processes are invisible to this command. Last night, I checked Recycler, system32, system, etc, but didn't get much. I run TCPVIEW and got two set of interesting entries with non-existent: <non-existent>:348 local:ftp LISTENING <non-existent>:348 local:https LISTENING <non-existent>:348 local:6101 LISTENING <non-existent>:1740 local:ftp LISTENING <non-existent>:1740 local:https LISTENING <non-existent>:1740 local:6101 LISTENING These can be seen from "netstat" too. But I can't kill these processes using TCPVIEW. I tried to kill other regular processes, it's OK. Using "msconfig", I disabled sys.ini and win.ini, stopped to load startup programs and disabled all services loading except those from Microsoft for a clean boot. But these processes are still there. I also disabled some MS services like IIS, Plug/Play. Web Client, etc. No luck. After I disabled "DHCP", processes are gone. But after "DHCP" was disabled, almost all other processes are gone too. Next step, maybe I should do something on registry. Thanks Alex --- Paul Marsh <pmarsh () nmefdn org> wrote:Alex: This is very interesting and hopefully you can doa little moreinvestigation before you nuke and rebuild. Youdid an netstat -banoand found two processes running listening on port21.Try a TASKLIST /SVC at a command prompt to see if you can identify theexecutable. I'd doa complete port scan on the system to see whatelse is happening tryNMAP http://www.insecure.org/nmap/ against yoursystem on all 65Kports TCP and UDP. I'd also run Etherealhttp://www.ethereal.com/ onthe system to see if anything is trying to callhome or if anything istrying to get in. I'm hoping with the list oflistening ports andcapturing some traffic we can identify what'scook'in. Another goodsource of info can be found at
http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_an
d_Rootkit_Tools_in_a_Windows_Environment.html Please keep us up to date as to what you find. Thanx -----Original Message----- From: Alex Yan [mailto:drcyyan () yahoo com] Sent: Monday, February 14, 2005 2:39 PM To: H Carvey; security-basics () securityfocus com Subject: Re: Hidden windows ports, files andservices.Hi all, Thanks a lot for your help. On weekend I tried some suggested options, butstill didn't get muchyet. Scanned the system using the latest Norton AV andStinger in the safemode. Nothing came out. Run "netstat -baon". It gives process IDs andprogram names for otherprocesses. For the processes related to port 21,it says "No ownershipinformation can be found". Tried fport, cport, process explorer, etc, but noluck."telnet 127.0.0.1 21" gives prompt "220 ." andthen times out in 15seconds. No telnet service was found in Windowsservice list.Tonight I will follow the Mark's suggestions stepby step and see if Ican get something. I will also try other options.If anything cameout, I will let you know. I am a software developer, more on Unix, not sofamiliar with Windowsregistry and all kinds of services and processeson XP. If I can notfind the problem and fix it, I have to reformatthe system. But evenafter reformating, there is still a chance thatthe system could notbe totally clean, because I have to restore somecritical data fromthe backup. Thanks again. Alex__________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com
__________________________________ Do you Yahoo!? Yahoo! Mail - now with 250MB free storage. Learn more. http://info.mail.yahoo.com/mail_250
Current thread:
- Re: Hidden windows ports, files and services., (continued)
- Re: Hidden windows ports, files and services. Security (Feb 11)
- Re: Hidden windows ports, files and services. Varun Pitale (Feb 14)
- Re: Hidden windows ports, files and services. Security (Feb 11)
- RE: Hidden windows ports, files and services. Doug . Janelle (Feb 11)
- Re: Hidden windows ports, files and services. H Carvey (Feb 14)
- Re: Hidden windows ports, files and services. Alex Yan (Feb 14)
- Re: Hidden windows ports, files and services. Mario Pascucci (Feb 15)
- Re: Hidden windows ports, files and services. Security (Feb 17)
- Re: Hidden windows ports, files and services. Alex Yan (Feb 14)
- RE: Hidden windows ports, files and services. Paul Marsh (Feb 15)
- RE: Hidden windows ports, files and services. Alex Yan (Feb 15)
- RE: Hidden windows ports, files and services. Paul Marsh (Feb 15)
- RE: Hidden windows ports, files and services. Alex Yan (Feb 15)
- RE: Hidden windows ports, files and services. Alex Yan (Feb 15)
- RE: Hidden windows ports, files and services. Paul Marsh (Feb 15)
- Re: Hidden windows ports, files and services. H Carvey (Feb 17)