It might be worth noting that the reason a lot of trojans use 1025 is because it's the first port that ANY user can bind to. Binding to the restricted ports (1-1024) in *nix/*BSD requires special privileges -- it may even be root access, not 100% sure on that. At any rate, I think that NT/2K/XP require administrator or system level access to do the same.




