Couple of strange entries in netstat

Discussion in 'Computer Security' started by Donald Jacobsen, Sep 20, 2003.

  1. Hello all,

    Started seeing some weird disk activity on my computer, so I decided to
    check my system out, looking for backdoors, etc. Antivirus and Adaware
    didn't pick up anything, but when I ran netstat, I got this:

    Active Connections

    Proto Local Address Foreign Address State
    (snipped)
    TCP balrog:2416 localhost:43958 ESTABLISHED
    TCP balrog:43958 localhost:2416 ESTABLISHED

    No clue what these port numbers are. Why would my system be connecting to
    itself on these 2 ports?

    Thanks,
    --Donald
     
    Donald Jacobsen, Sep 20, 2003
    #1
    1. Advertisements

  2. Donald Jacobsen

    Chuck Guest

    You need to know what process has attached those ports. A good, free
    port mapper is Active Ports.
    http://www.ntutility.com/freeware.html

    Much more useful than netstat.

    Cheers,

    Chuck


    Chuck

    Spam sucks - PLEASE get rid of the spam before emailing me!
     
    Chuck, Sep 20, 2003
    #2
    1. Advertisements

  3. Some personal firewalls do this. You can see what runs on what ports
    with a number of utilities, one is fport from foundstone.com, but these
    days almost everyone offers a util to do this.

    /steve
    --
    No one gives you more control of your e-mail than we do!
    http://www.cotse.net/servicedetails.html
    E-Mail, Anon Proxies, Remailers, Usenet, Web Hosting, More.
    The Internet's Full Service Privacy Website, Your Shield From The
    Internet.
     
    Stephen K. Gielda, Sep 22, 2003
    #3
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.