New User? Click here to register! Feel free to read this for beginners help.

Computer Cops
image image image image image image image image
Prime Choice
· Head Lines
· Dnld of the Week!
· Find a Cure!

· Ian T's (Article 12)
· Marcia's (Op8)
· Paul's (Article 3)

· Ian T's Archive
· Marcia's Archive
· Paul's Archive
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Security Central
· Home
· Wireless
· Bookmarks
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· Recommend Us
· RegChat
· Reviews
· Search
· Sections
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
Donations
image
Search

image
Survey
Which Anti-Virus product do you use?

Computer Associates
Eset (NOD32)
F-Secure
Frisk (F-Prot)
Grisoft (AVG)
Kaspersky
Network Associates (McAfee)
Panda
Sophos
Symantec (NAV)
Trend Micro
Other



Results
Polls

Votes: 8614
Comments: 80
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Paul...another newbie. Help?
Goto page 1, 2  Next
 
Post new topic   Reply to topic       Computer Cops Forum Index -> Site Toolkit
View previous topic :: View next topic  
Author Message
deleonj10
Trooper
Trooper



Joined: Feb 27, 2004
Posts: 12
Location: Uk

PostPosted: Fri Feb 27, 2004 4:44 pm    Post subject: Paul...another newbie. Help? Reply with quote

Hi there, I know you've gotten this many times...but Im new here and I dont exactly know how to read the TCP Port Scanner. I have 4 possible services connected...is that a bad thing? Should I shut them...and how?
Thanks so much! Justin



Starting Common Services TCP Port Scan ...
Connection Refused: Port 21 used by FTP.
ESTABLISHED CONNECTION: Possible SSH / secure shell service found on port 22.
Connection Refused: Port 23 used by Telnet.
ESTABLISHED CONNECTION: Possible SMTP / send mail / outgoing mail service found on port 25.
Connection Refused: Port 53 used by DNS.
Connection Refused: Port 69 used by TFTP / Trivial file transfer.
Connection Refused: Port 70 used by GOPHER.
Connection Refused: Port 79 used by FINGER.
Connection Refused: Port 80 used by HTTP / web servers.
Connection Refused: Port 110 used by POP3 / incoming mail.
ESTABLISHED CONNECTION: Possible SUNRPC / Sun portmapper service found on port 111.
Connection Refused: Port 135 used by EPMAP / Microsoft RPC - SMB file/print sharing.
Connection Refused: Port 137 used by NETBIOS-NS / NETBIOS Name Service.
Connection Refused: Port 138 used by NETBIOS-DGM / NETBIOS Datagram Service.
Connection Refused: Port 139 used by NETBIOS-SSN / NETBIOS Session Service.
Connection Refused: Port 143 used by IMAP / incoming mail.
Connection Refused: Port 194 used by IRC / Internet relay chat.
Connection Refused: Port 389 used by LDAP / lightweight directory access protocol.
Connection Refused: Port 407 used by TIMBUKTU.
Connection Refused: Port 443 used by HTTPS / secure HTTP (SSL).
Connection Refused: Port 445 used by MICROSOFT-DS / directory service, found on Win2k.
ESTABLISHED CONNECTION: Possible PRINTER / print spooler service found on port 515.
Connection Refused: Port 525 used by TIMED / time server.
Connection Refused: Port 546 used by DHCP Client.
Connection Refused: Port 547 used by DHCP Server.
Connection Refused: Port 554 used by RTSP / real time streaming (music).
Connection Refused: Port 1080 used by SOCKS / Internet proxy.
Connection Refused: Port 1214 used by Kazaa.
Connection Refused: Port 1433 used by MS-SQL / MSDE and SQL Server.
Connection Refused: Port 1723 used by PPTP / virtual private network (VPN).
Connection Refused: Port 1863 used by MSN Messenger.
Connection Refused: Port 5000 used by Microsoft UPnP.
Connection Refused: Port 5190 used by AOL Instant Messenger.
Connection Refused: Port 5631 used by pcAnywhere.
Connection Refused: Port 5678 used by Linksys Remote Administration 1.42.7 Vulnerability.
Connection Refused: Port 6346 used by Gnutella.
Connection Refused: Port 6347 used by Gnutella.
Connection Refused: Port 6665 used by IRCU / common IRC.
Connection Refused: Port 6666 used by IRCU / common IRC.
Connection Refused: Port 6667 used by IRCU / common IRC.
Connection Refused: Port 6668 used by IRCU / common IRC.
Connection Refused: Port 6669 used by IRCU / common IRC.
Connection Refused: Port 8080 used by HTTP-ALT / alternate HTTP (see port 80).
4 possible services were detected on your system.

Thanks again...
Back to top
View users profile Send private message AIM Address
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Fri Feb 27, 2004 5:39 pm    Post subject: Reply with quote

Hi and welcome Jason. What is your OS?
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
deleonj10
Trooper
Trooper



Joined: Feb 27, 2004
Posts: 12
Location: Uk

PostPosted: Fri Feb 27, 2004 5:44 pm    Post subject: Reply with quote

Hi Paul...Windows. Windows XP and MSIE browser. Hope it helps, thanks...Justin
Back to top
View users profile Send private message AIM Address
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Fri Feb 27, 2004 6:08 pm    Post subject: Reply with quote

Try the same scan again. I made some code changes just now.
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
deleonj10
Trooper
Trooper



Joined: Feb 27, 2004
Posts: 12
Location: Uk

PostPosted: Fri Feb 27, 2004 6:46 pm    Post subject: Reply with quote

This is what I get

Starting Common Services TCP Port Scan ...
Connection Refused: Port 21 used by FTP.
ESTABLISHED CONNECTION: Possible SSH / secure shell service found on port 22.
Connection Refused: Port 23 used by Telnet.
ESTABLISHED CONNECTION: Possible SMTP / send mail / outgoing mail service found on port 25.
Connection Refused: Port 53 used by DNS.
Connection Refused: Port 69 used by TFTP / Trivial file transfer.
Connection Refused: Port 70 used by GOPHER.
Connection Refused: Port 79 used by FINGER.
Connection Refused: Port 80 used by HTTP / web servers.
Connection Refused: Port 110 used by POP3 / incoming mail.
ESTABLISHED CONNECTION: Possible SUNRPC / Sun portmapper service found on port 111.
Connection Refused: Port 135 used by EPMAP / Microsoft RPC - SMB file/print sharing.
Connection Refused: Port 137 used by NETBIOS-NS / NETBIOS Name Service.
Connection Refused: Port 138 used by NETBIOS-DGM / NETBIOS Datagram Service.
Connection Refused: Port 139 used by NETBIOS-SSN / NETBIOS Session Service.
Connection Refused: Port 143 used by IMAP / incoming mail.
Connection Refused: Port 194 used by IRC / Internet relay chat.
Connection Refused: Port 389 used by LDAP / lightweight directory access protocol.
Connection Refused: Port 407 used by TIMBUKTU.
Connection Refused: Port 443 used by HTTPS / secure HTTP (SSL).
Connection Refused: Port 445 used by MICROSOFT-DS / directory service, found on Win2k.
ESTABLISHED CONNECTION: Possible PRINTER / print spooler service found on port 515.
Connection Refused: Port 525 used by TIMED / time server.
Connection Refused: Port 546 used by DHCP Client.
Connection Refused: Port 547 used by DHCP Server.
Connection Refused: Port 554 used by RTSP / real time streaming (music).
Connection Refused: Port 1080 used by SOCKS / Internet proxy.
Connection Refused: Port 1214 used by Kazaa.
Connection Refused: Port 1433 used by MS-SQL / MSDE and SQL Server.
Connection Refused: Port 1723 used by PPTP / virtual private network (VPN).
Connection Refused: Port 1863 used by MSN Messenger.
Connection Refused: Port 5000 used by Microsoft UPnP.
Connection Refused: Port 5190 used by AOL Instant Messenger.
Connection Refused: Port 5631 used by pcAnywhere.
Connection Refused: Port 5678 used by Linksys Remote Administration 1.42.7 Vulnerability.
Connection Refused: Port 6346 used by Gnutella.
Connection Refused: Port 6347 used by Gnutella.
Connection Refused: Port 6665 used by IRCU / common IRC.
Connection Refused: Port 6666 used by IRCU / common IRC.
Connection Refused: Port 6667 used by IRCU / common IRC.
Connection Refused: Port 6668 used by IRCU / common IRC.
Connection Refused: Port 6669 used by IRCU / common IRC.
Connection Refused: Port 8080 used by HTTP-ALT / alternate HTTP (see port 80).
4 possible services were detected on your system. For further help, please visit the CCSP Toolkit Forum
Back to top
View users profile Send private message AIM Address
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Fri Feb 27, 2004 7:38 pm    Post subject: Reply with quote

Ok, I don't think your system is being scanned. What is the IP address the page says its scanning? Is that your IP Address?
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
deleonj10
Trooper
Trooper



Joined: Feb 27, 2004
Posts: 12
Location: Uk

PostPosted: Fri Feb 27, 2004 7:51 pm    Post subject: Reply with quote

the IP addresses are the same, in the "reveal your IP" and "TCP Port Scanner." Is there something that is going wrong? Ill have to resume this later tomorrow, thanks again for the help. Justin
Back to top
View users profile Send private message AIM Address
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Sat Feb 28, 2004 8:37 am    Post subject: Reply with quote

Hi Justin, ok, its good they are the same. Can you check if that matches what your computer's IP address is?
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
deleonj10
Trooper
Trooper



Joined: Feb 27, 2004
Posts: 12
Location: Uk

PostPosted: Sat Feb 28, 2004 8:59 am    Post subject: Reply with quote

yeah, Ive checked a few times...all the IP's match up! Now what?
Back to top
View users profile Send private message AIM Address
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Sat Feb 28, 2004 9:29 am    Post subject: Reply with quote

Interesting that you get those ports open on a WinXP box... that is not common. That is typically more indicative of a solaris OS than any MS OS.

Run a 'netstat -an' for me in your DOS window and paste the results.

_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
deleonj10
Trooper
Trooper



Joined: Feb 27, 2004
Posts: 12
Location: Uk

PostPosted: Sat Feb 28, 2004 9:36 am    Post subject: Reply with quote

everytime I run a netstat -an, it flashes as if it completes the task then immediately closes...I cant even view the results. ???
Back to top
View users profile Send private message AIM Address
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Sat Feb 28, 2004 9:40 am    Post subject: Reply with quote

Hi, you have to go to DOS first by typing in 'cmd'. Then at the window, type in the other command.
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
deleonj10
Trooper
Trooper



Joined: Feb 27, 2004
Posts: 12
Location: Uk

PostPosted: Sat Feb 28, 2004 9:43 am    Post subject: Reply with quote

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\Justin deLeon>netstat -an

Active Connections

Proto Local Address Foreign Address State
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1025 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1026 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3757 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3856 0.0.0.0:0 LISTENING
TCP 0.0.0.0:5000 0.0.0.0:0 LISTENING
TCP 0.0.0.0:5101 0.0.0.0:0 LISTENING
TCP 10.1.22.5:139 0.0.0.0:0 LISTENING
TCP 10.1.22.5:3757 216.155.193.176:80 ESTABLISHED
TCP 10.1.22.5:3856 141.195.134.84:5101 ESTABLISHED
TCP 127.0.0.1:3001 0.0.0.0:0 LISTENING
TCP 127.0.0.1:3002 0.0.0.0:0 LISTENING
TCP 127.0.0.1:3003 0.0.0.0:0 LISTENING
UDP 0.0.0.0:445 *:*
UDP 0.0.0.0:500 *:*
UDP 0.0.0.0:3008 *:*
UDP 0.0.0.0:3013 *:*
UDP 0.0.0.0:3282 *:*
UDP 10.1.22.5:123 *:*
UDP 10.1.22.5:137 *:*
UDP 10.1.22.5:138 *:*
UDP 10.1.22.5:1900 *:*
UDP 127.0.0.1:123 *:*
UDP 127.0.0.1:1900 *:*
UDP 127.0.0.1:3018 *:*
UDP 127.0.0.1:3251 *:*
UDP 127.0.0.1:3367 *:*
UDP 127.0.0.1:3492 *:*
UDP 127.0.0.1:3502 *:*
UDP 127.0.0.1:3673 *:*
UDP 127.0.0.1:3763 *:*
UDP 127.0.0.1:3772 *:*

C:\Documents and Settings\Justin deLeon>


alright, thanks...
Back to top
View users profile Send private message AIM Address
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Sat Feb 28, 2004 11:23 am    Post subject: Reply with quote

5101 eh? Check this out:

http://computercops.biz/postt11302.html

Lets step thru the others one at a time starting with a couple:

smtp and ssh, do you have an email server running and a secure shell server on that PC?

_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
deleonj10
Trooper
Trooper



Joined: Feb 27, 2004
Posts: 12
Location: Uk

PostPosted: Sat Feb 28, 2004 12:03 pm    Post subject: Reply with quote

ok Paul, right about the 5101, yahoo messenger. email server running and a secure shell server on my PC, I use yahoo mail and Im not sure what a secure shell server would be. Thanks for your patience Paul.
Back to top
View users profile Send private message AIM Address
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Site Toolkit All times are GMT - 5 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8 © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops