Ports 1026-1030 - What for?

 
Post new topic   Reply to topic    Aprelium Forum Index -> General Questions
View previous topic :: View next topic  
Author Message
pkSML
-


Joined: 29 May 2006
Posts: 955
Location: Michigan, USA

PostPosted: Fri Sep 22, 2006 9:20 pm    Post subject: Ports 1026-1030 - What for? Reply with quote

Hello.

I have Linksys' Logviewer that keeps track of all outgoing and incoming traffic to the router. I consistently receive requests for ports 1026, 1027, and other ports near that range. I have Googled for an explanation of these ports, but can't find a satisfactory one.

These requests make up most in the list of incoming activity and occur within every five minutes it seems. Oddly enough, dnsstuff.com reports these requests coming from IP addresses in China.

Has anyone else seen this occurring?
Do you have an explanation of why it happens? (I'm assuming it's for some type of vulnerability check by hackers.)

Thanks in advance.
_________________
Stephen
Need a LitlURL?


http://CodeBin.yi.org
Back to top View user's profile Send private message Visit poster's website
cmxflash
-


Joined: 11 Dec 2004
Posts: 872

PostPosted: Fri Sep 22, 2006 10:30 pm    Post subject: Reply with quote

This is what my portscanner says:

Quote:
Port > Used by

1025 > ICQ
1026 > ICQ
1027 > ICQ
1028 > ICQ
1029 > ICQ and InCommand.Backdoor
1030 > BBN IAD
1031 > BBN IAD
Back to top View user's profile Send private message
pkSML
-


Joined: 29 May 2006
Posts: 955
Location: Michigan, USA

PostPosted: Fri Sep 22, 2006 11:20 pm    Post subject: Reply with quote

Thanks cmxflash. I'm finding more information about this!

Is there any way to monitor what packets are being delivered to these ports? In other words, can anyone tell me of some freeware that will capture packets on a specific port? I'd like to see the contents of these packets.
_________________
Stephen
Need a LitlURL?


http://CodeBin.yi.org
Back to top View user's profile Send private message Visit poster's website
cmxflash
-


Joined: 11 Dec 2004
Posts: 872

PostPosted: Fri Sep 22, 2006 11:56 pm    Post subject: Reply with quote

Ethereal is a good program for sniffing traffic. Link.
Back to top View user's profile Send private message
pkSML
-


Joined: 29 May 2006
Posts: 955
Location: Michigan, USA

PostPosted: Sat Sep 23, 2006 10:23 pm    Post subject: Reply with quote

Awesome program, cmxflash!

I found the results I was looking for. I have successfully captured some traffic from ports 1026 and 1027.

Ethereal Results --> Port 1026 ~ Port 1027 (Note: These .cap files are openable with Ethereal to get all the gory details, but you can still see the contents in notepad.)

PortPeeker Results: --> Port 1026 ~ Port 1027
_________________
Stephen
Need a LitlURL?


http://CodeBin.yi.org
Back to top View user's profile Send private message Visit poster's website
cmxflash
-


Joined: 11 Dec 2004
Posts: 872

PostPosted: Sat Sep 23, 2006 10:42 pm    Post subject: Reply with quote

Looks like traffic from the old messenger service in Windows. This service is disabled by default in SP2.

This traffic was used to send annoying messages containing ads that tell you to download a program from a website (most likly spyware/malware).

This is what the packages contains:


Do not download anything from the URLs listed below
Quote:
Ôò¡

Your windows registry is corrupted and slowing down your computer.
Microsoft recommends a complete system scan.
Microsoft recommends:

http://www.msrepair.net

To download a free registry repair program


Windows has found 55 Critical System Errors.

To fix the errors please do the following:

1. Download Registry Update from: www.helpfixpc.com
2. Install Registry Update
3. Run Registry Update
4. Reboot your computer

FAILURE TO ACT NOW MAY LEAD TO SYSTEM FAILURE!


Registry Cleaner Recommended

To fix the errors please do the following:
1. Download Registry Repair from: http://www.regpro32.com
2. Install Registry Repair
3. Run Registry Repair
4. Reboot your computer
FAILURE TO ACT NOW MAY LEAD TO DATA LOSS AND CORRUPTION!
Quote:
Ôò¡


Windows has found 55 Critical System Errors.

To fix the errors please do the following:

1. Download Registry Update from: www.regfixit.com
2. Install Registry Update
3. Run Registry Update
4. Reboot your computer

FAILURE TO ACT NOW MAY LEAD TO SYSTEM FAILURE!


Windows has found 55 Critical System Errors.

To fix the errors please do the following:

1. Download Registry Update from: www.helpfixpc.com
2. Install Registry Update
3. Run Registry Update
4. Reboot your computer

FAILURE TO ACT NOW MAY LEAD TO SYSTEM FAILURE!


Windows has found 55 Critical System Errors.

To fix the errors please do the following:

1. Download Registry Update from: www.regfixit.com
2. Install Registry Update
3. Run Registry Update
4. Reboot your computer

FAILURE TO ACT NOW MAY LEAD TO SYSTEM FAILURE!
Back to top View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Aprelium Forum Index -> General Questions All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB phpBB Group