| View previous topic :: View next topic | 
	
	
		| Author | Message | 
	
		| pkSML -
 
 
 Joined: 29 May 2006
 Posts: 959
 Location: Michigan, USA
 
 | 
			
				|  Posted: Fri Sep 22, 2006 9:20 pm    Post subject: Ports 1026-1030 - What for? |   |  
				| 
 |  
				| Hello. 
 I have Linksys' Logviewer that keeps track of all outgoing and incoming traffic to the router. I consistently receive requests for ports 1026, 1027, and other ports near that range. I have Googled for an explanation of these ports, but can't find a satisfactory one.
 
 These requests make up most in the list of incoming activity and occur within every five minutes it seems. Oddly enough, dnsstuff.com reports these requests coming from IP addresses in China.
 
 Has anyone else seen this occurring?
 Do you have an explanation of why it happens? (I'm assuming it's for some type of vulnerability check by hackers.)
 
 Thanks in advance.
 _________________
 Stephen
 Need a LitlURL?
 
   http://CodeBin.yi.org
 |  | 
	
		| Back to top |       | 
	
		|  | 
	
		| cmxflash -
 
 
 Joined: 11 Dec 2004
 Posts: 872
 
 
 | 
			
				|  Posted: Fri Sep 22, 2006 10:30 pm    Post subject: |   |  
				| 
 |  
				| This is what my portscanner says: 
 
  	  | Quote: |  	  | Port  >  Used by 
 1025 > ICQ
 1026 > ICQ
 1027 > ICQ
 1028 > ICQ
 1029 > ICQ and InCommand.Backdoor
 1030 > BBN IAD
 1031 > BBN IAD
 
 | 
 |  | 
	
		| Back to top |     | 
	
		|  | 
	
		| pkSML -
 
 
 Joined: 29 May 2006
 Posts: 959
 Location: Michigan, USA
 
 | 
			
				|  Posted: Fri Sep 22, 2006 11:20 pm    Post subject: |   |  
				| 
 |  
				| Thanks cmxflash. I'm finding more information about this! 
 Is there any way to monitor what packets are being delivered to these ports? In other words, can anyone tell me of some freeware that will capture packets on a specific port? I'd like to see the contents of these packets.
 _________________
 Stephen
 Need a LitlURL?
 
   http://CodeBin.yi.org
 |  | 
	
		| Back to top |       | 
	
		|  | 
	
		| cmxflash -
 
 
 Joined: 11 Dec 2004
 Posts: 872
 
 
 | 
			
				|  Posted: Fri Sep 22, 2006 11:56 pm    Post subject: |   |  
				| 
 |  
				| Ethereal is a good program for sniffing traffic. Link. |  | 
	
		| Back to top |     | 
	
		|  | 
	
		| pkSML -
 
 
 Joined: 29 May 2006
 Posts: 959
 Location: Michigan, USA
 
 | 
			
				|  Posted: Sat Sep 23, 2006 10:23 pm    Post subject: |   |  
				| 
 |  
				| Awesome program, cmxflash! 
 I found the results I was looking for. I have successfully captured some traffic from ports 1026 and 1027.
 
 Ethereal Results --> Port 1026 ~ Port 1027 (Note: These .cap files are openable with Ethereal to get all the gory details, but you can still see the contents in notepad.)
 
 PortPeeker Results: --> Port 1026 ~ Port 1027
 _________________
 Stephen
 Need a LitlURL?
 
   http://CodeBin.yi.org
 |  | 
	
		| Back to top |       | 
	
		|  | 
	
		| cmxflash -
 
 
 Joined: 11 Dec 2004
 Posts: 872
 
 
 | 
			
				|  Posted: Sat Sep 23, 2006 10:42 pm    Post subject: |   |  
				| 
 |  
				| Looks like traffic from the old messenger service in Windows. This service is disabled by default in SP2. 
 This traffic was used to send annoying messages containing ads that tell you to download a program from a website (most likly spyware/malware).
 
 This is what the packages contains:
 
 
 Do not download anything from the URLs listed below
 
  	  | Quote: |  	  | Ôò¡ 
 Your windows registry is corrupted and slowing down your computer.
 Microsoft recommends a complete system scan.
 Microsoft recommends:
 
 http://www.msrepair.net
 
 To download a free registry repair program
 
 
 Windows has found 55 Critical System Errors.
 
 To fix the errors please do the following:
 
 1. Download Registry Update from: www.helpfixpc.com
 2. Install Registry Update
 3. Run Registry Update
 4. Reboot your computer
 
 FAILURE TO ACT NOW MAY LEAD TO SYSTEM FAILURE!
 
 
 Registry Cleaner Recommended
 
 To fix the errors please do the following:
 1. Download Registry Repair from: http://www.regpro32.com
 2. Install Registry Repair
 3. Run Registry Repair
 4. Reboot your computer
 FAILURE TO ACT NOW MAY LEAD TO DATA LOSS AND CORRUPTION!
 
 | 
  	  | Quote: |  	  | Ôò¡ 
 
 Windows has found 55 Critical System Errors.
 
 To fix the errors please do the following:
 
 1. Download Registry Update from: www.regfixit.com
 2. Install Registry Update
 3. Run Registry Update
 4. Reboot your computer
 
 FAILURE TO ACT NOW MAY LEAD TO SYSTEM FAILURE!
 
 
 Windows has found 55 Critical System Errors.
 
 To fix the errors please do the following:
 
 1. Download Registry Update from: www.helpfixpc.com
 2. Install Registry Update
 3. Run Registry Update
 4. Reboot your computer
 
 FAILURE TO ACT NOW MAY LEAD TO SYSTEM FAILURE!
 
 
 Windows has found 55 Critical System Errors.
 
 To fix the errors please do the following:
 
 1. Download Registry Update from: www.regfixit.com
 2. Install Registry Update
 3. Run Registry Update
 4. Reboot your computer
 
 FAILURE TO ACT NOW MAY LEAD TO SYSTEM FAILURE!
 
 | 
 |  | 
	
		| Back to top |     | 
	
		|  | 
	
		|  |