Click here to get back home

responses on port 41523

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
responses on port 41523 nutso fasst 04-04-2006
Posted by nutso fasst on April 4, 2006, 4:16 pm
Please log in for more thread options
Hello.

For a while I inadvertently had ports open in a firewall on an NT box
connected to the Internet. There were no services on the ports.

Firewall logs showed unblocked connection attempts with no
responses...except for one port: 41523. An occasional probe of 41523 would
typically consist of a connection attempt, one response, then another
connection attempt with no response. Sometimes there would be a third
connection attempt with no response.

Netstat showed nothing listening on 41523, and I don't see any indication
the system was compromised. But why a response only on that port, and only
to the first attempt to connect?

Is this just the TCP/IP stack replying with RST, then ignoring subsequent
connection attempts? Could the reply be due to the type of scan, which I
suspect has to do with the ARCserve Backup port 41523 vulnerability?

thanx,
nf





Posted by Steven L Umbach on April 5, 2006, 12:20 am
Please log in for more thread options
Hard to say what is going on if you initially have found no listening
process. What you could do is use portqry from another computer on your
network to see what is found and install the port reporter service on the
computer to log port activity and review the logs to see if that port has
been used and if so by what process [if using Windows 2003 as Windows 2000
only reports port use]. Of course a routine scan for malware and spyware
would be a good idea if it has not been done in a while. --- Steve

http://support.microsoft.com/default.aspx?kbid=832919 -- Portqry command
line port scanner.
http://www.microsoft.com/downloads/details.aspx?FamilyID=69BA779B-BAE9-4243-B9D6-63E62B4BCD2E&displaylang=en

--- Port Reporter

> Hello.
>
> For a while I inadvertently had ports open in a firewall on an NT box
> connected to the Internet. There were no services on the ports.
>
> Firewall logs showed unblocked connection attempts with no
> responses...except for one port: 41523. An occasional probe of 41523 would
> typically consist of a connection attempt, one response, then another
> connection attempt with no response. Sometimes there would be a third
> connection attempt with no response.
>
> Netstat showed nothing listening on 41523, and I don't see any indication
> the system was compromised. But why a response only on that port, and only
> to the first attempt to connect?
>
> Is this just the TCP/IP stack replying with RST, then ignoring subsequent
> connection attempts? Could the reply be due to the type of scan, which I
> suspect has to do with the ARCserve Backup port 41523 vulnerability?
>
> thanx,
> nf
>
>
>
>



Posted by nutso fasst on April 5, 2006, 6:47 pm
Please log in for more thread options

> Hard to say what is going on if you initially have found no listening
> process. What you could do is use portqry

I tried portqry after opening the ports in the firewall. It reported 'not
listening' and I saw the same response in the log as before. I closed the
port in the FW again and will just keep monitoring. According to MS, the
Port Reporter service doesn't run on NT.

Thanks much for the suggestions.

nf



Similar ThreadsPosted
Windows Service runs batch file requiring user responses on WS2003 August 12, 2005, 9:40 pm
port lockouts March 11, 2006, 1:13 pm
close 135 port two NIC October 5, 2006, 5:00 am
Authenticate USB PORT October 18, 2006, 6:49 am
Functions of Port 445? November 2, 2006, 11:35 pm
Port Disable January 2, 2007, 11:20 pm
telnet using port 443 February 28, 2007, 6:55 pm
PCAnywhere port forwarding ? September 23, 2005, 12:37 am
TCP/UDP Port Security Troubleshooting October 20, 2005, 12:46 pm
Which port to open on firewall? November 1, 2005, 1:44 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap