Thursday, December 09, 2004

How do I identify unknown open ports and their associated applications.?

You can go to http://www.foundstone.com
and download Fport. It will show you something like this


FPort v2.0 - TCP/IP Process to Port Mapper

Copyright 2000 by Foundstone, Inc.

http://www.foundstone.com


Pid Process Port Proto Path

1764 inetinfo -> 25 TCP C:\WINDOWS\System32\inetsrv\inetinfo.exe

1764 inetinfo -> 80 TCP C:\WINDOWS\System32\inetsrv\inetinfo.exe

1620 Apache -> 81 TCP C:\Apache\Apache2\bin\Apache.exe

988 -> 135 TCP

4 System -> 139 TCP

1764 inetinfo -> 443 TCP C:\WINDOWS\System32\inetsrv\inetinfo.exe

4 System -> 445 TCP

1764 inetinfo -> 1038 TCP C:\WINDOWS\System32\inetsrv\inetinfo.exe

2536 mqsvc -> 1047 TCP C:\WINDOWS\System32\mqsvc.exe

5632 msnmsgr -> 1056 TCP C:\Program Files\MSN Messenger\msnmsgr.exe

5632 msnmsgr -> 1057 TCP C:\Program Files\MSN Messenger\msnmsgr.exe

5632 msnmsgr -> 1058 TCP C:\Program Files\MSN Messenger\msnmsgr.exe

5632 msnmsgr -> 1059 TCP C:\Program Files\MSN Messenger\msnmsgr.exe

5632 msnmsgr -> 1060 TCP C:\Program Files\MSN Messenger\msnmsgr.exe

3076 -> 1062 TCP

1736 FlashComAdmin -> 1111 TCP C:\Program Files\Macromedia\Flash Communica

tion Server MX\FlashComAdmin.exe

3796 OSDK62http -> 1422 TCP C:\Program Files\Openwave\SDK 6.2.2\program

\http\OSDK62http.exe

5480 firefox -> 1668 TCP C:\Program Files\Mozilla Firefox\firefox.ex

e

5480 firefox -> 1669 TCP C:\Program Files\Mozilla Firefox\firefox.ex

e

2536 mqsvc -> 1801 TCP C:\WINDOWS\System32\mqsvc.exe

2492 FlashCom -> 1935 TCP C:\Program Files\Macromedia\Flash Communica

tion Server MX\FlashCom.exe

2184 omtsreco -> 2030 TCP c:\oracle\ora92\bin\omtsreco.exe

2536 mqsvc -> 2103 TCP C:\WINDOWS\System32\mqsvc.exe

2536 mqsvc -> 2105 TCP C:\WINDOWS\System32\mqsvc.exe

2536 mqsvc -> 2107 TCP C:\WINDOWS\System32\mqsvc.exe

No comments: