Security Incidents mailing list archives

Re: Port Zero


From: nony101 () last za net
Date: 19 Jul 2005 08:59:10 -0000

I had in incident yesterday (18 June 2005), where a client's Windows box listed almost every possible port as open, 
listening in the same way described above. Similiar netstat -an output as above. From my experience this isn't normal.

A few hours later the machine rapidly starting sending packets to random addresses on port 443.

What could this possibly be? Is it a virus/backdoor/something malicious?

Baba, is that your whole netstat output?


Current thread: