Re: Port Zero
| Newsgroups | gmane.comp.security.incidents |
|---|---|
| Message-ID | <[email protected]> |
I had in incident yesterday (18 June 2005), where a client's Windows box listed almost every possible port as open, listening in the same way described above. Similiar netstat -an output as above. From my experience this isn't normal. A few hours later the machine rapidly starting sending packets to random addresses on port 443. What could this possibly be? Is it a virus/backdoor/something malicious? Baba, is that your whole netstat output?