Firewall Wizards mailing list archives
Re: OT? New compromise.
From: "St John, Richard" <Richard.StJohn () gbe com>
Date: Wed, 28 Mar 2007 12:33:36 -0500
Probably way off base, but port 1720, isn't that part of H323? And isn't 1863 part of MSN Messenger? First thing I do when any "new" traffic pops up is do a sniff or TCPDump {use the -s 1500 and -w filename options} of the traffic to see what is actually there {usually I use our firewalls, but I also use wireshark at the workstation, or I will mirror a port on the switch and use another machine to do the actual capture. A sniff will also give you the traffics "IP destination". Once this is done, at your leisure, you can either block the destination or block the port. Once you determine there might be an issue, I think there used to be a program called openports which would run on the machine and relate any LISTENING or ESTABLISHED ports to the actual file that has the port open. This would then give you the service/process/program waiting for traffic on that port. _______________________________________________ firewall-wizards mailing list firewall-wizards () listserv icsalabs com https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- FW: OT? New compromise. Jim Seymour (Mar 28)
- Re: FW: OT? New compromise. Victor Williams (Mar 28)
- Re: FW: OT? New compromise. Jim Seymour (Mar 28)
- Re: FW: OT? New compromise. Mitko Stoyanov (Mar 29)
- Re: FW: OT? New compromise. Jim Seymour (Mar 28)
- <Possible follow-ups>
- Re: OT? New compromise. St John, Richard (Mar 28)
- Re: OT? New compromise. J. Oquendo (Mar 28)
- Re: OT? New compromise. Stian Øvrevåge (Mar 28)
- Re: OT? New compromise. Jim Seymour (Mar 29)
- Re: OT? New compromise. Paul D. Robertson (Mar 29)
- Re: OT? New compromise. J. Oquendo (Mar 29)
- Re: OT? New compromise. Paul D. Robertson (Mar 29)
- Re: OT? New compromise. J. Oquendo (Mar 28)
- Re: OT? New compromise. Victor Williams (Mar 29)
- Re: FW: OT? New compromise. Victor Williams (Mar 28)
- Re: OT? New compromise. Mattias Ahnberg (Mar 29)
- Re: OT? New compromise. Mark (Mar 29)
- Re: OT? New compromise. Richard Golodner (Mar 29)