Re: Strange echo requests from 127.0.0.1 apparentlyto root nameservers
"RolandGreen" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Well as stated by other people if you are using a new version of windows (ie Windows 2003 or XP) you can use netstat -aon Terje Trane wrote: >>Roland wrote: >>There is a shareware utility developed by Foundstone, Inc. >>http://www.foundstone.com called fport.exe which is able link >>the port >>and pid in one command line program. >> >> > >Thanks, but I already have this. It shows open ans listening TCP and UDP >ports, but not ICMP. > > > >>In addition there is another utility called handle developed by >>Sysinternals @ >>http://www.sysinternals.com/ntw2k/freeware/handle.shtml. >>This utility links process IDs to ports and program names, >> >> > >Thanks, I downloaded this and immediatly made it a part of my toolbox. I'm >not shure how this will help. I'am not near the machine we are researching >now, but I tested on my laptop. I started a ping and ran handle. Searching >for ping.exe in the result I find: > >ping.exe pid: 2304 SYSTEK-NETBIOS\trane > c: File C:\Documents and Settings\trane > 778: File >C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0 >.2600.2180_x-ww_a84f1ff9 > >Nothing here tells me that this process was sending ICMP packets anywhere. > > >_______________________________________________ >Intrusions mailing list >[email protected] >http://www.dshield.org/mailman/listinfo/intrusions > > > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions