|
-
December 5th, 2003, 01:29 PM
#1
Member
interesting ports on a win2k box
root@0[knoppix]# nmap -vv -sS -p 1-65535 -O -P0 x.x.x.x
Starting nmap 3.48 ( http://www.insecure.org/nmap/ ) at 2000-04-13 05:54 CEST
Host server.comp-utec.local (x.x.x.x) appears to be up ... good.
Initiating SYN Stealth Scan against server.comp-utec.local (x.x.x.x) at 05:
54
Adding open port 40019/tcp
Adding open port 47624/tcp
Adding open port 135/tcp
Adding open port 1002/tcp
Adding open port 1720/tcp
Adding open port 1025/tcp
The SYN Stealth Scan took 7 seconds to scan 65535 ports.
For OSScan assuming that port 135 is open and port 1 is closed and neither are f
irewalled
Interesting ports on server.comp-utec.local (x.x.x.x):
(The 65529 ports scanned but not shown below are in state: closed)
PORT STATE SERVICE
135/tcp open msrpc
1002/tcp open unknown
1025/tcp open NFS-or-IIS
1720/tcp open H.323/Q.931
40019/tcp open unknown
47624/tcp open unknown
Device type: general purpose
Running: Microsoft Windows 95/98/ME|NT/2K/XP
OS details: Microsoft Windows Millennium Edition (Me), Windows 2000 Professional
or Advanced Server, or Windows XP
OS Fingerprint:
TSeq(Class=RI%gcd=1%SI=2818%IPID=I%TS=0)
T1(Resp=Y%DF=Y%W=FFFF%ACK=S++%Flags=AS%Ops=MNWNNT)
T2(Resp=Y%DF=N%W=0%ACK=S%Flags=AR%Ops=)
T3(Resp=Y%DF=Y%W=FFFF%ACK=S++%Flags=AS%Ops=MNWNNT)
T4(Resp=Y%DF=N%W=0%ACK=O%Flags=R%Ops=)
T5(Resp=Y%DF=N%W=0%ACK=S++%Flags=AR%Ops=)
T6(Resp=Y%DF=N%W=0%ACK=O%Flags=R%Ops=)
T7(Resp=Y%DF=N%W=0%ACK=S++%Flags=AR%Ops=)
PU(Resp=Y%DF=N%TOS=0%IPLEN=38%RIPTL=148%RID=E%RIPCK=E%UCK=E%ULEN=134%DAT=E)
TCP Sequence Prediction: Class=random positive increments
Difficulty=10264 (Worthy challenge)
TCP ISN Seq. Numbers: 5FEFBAE8 5FF0D551 5FF1D081 5FF2EF5E 5FF405B4 5FF577B1
IPID Sequence Generation: Incremental
Nmap run completed -- 1 IP address (1 host up) scanned in 10.137 seconds
root@0[knoppix]#
thats a recent nmap on myself. i have found some of these ports very interesting and i did not see these ports open before. the thing is i have found these ports open on my scanning fro poxies that have proxy flooded an irc server. does anyone know anything about the following ports?
1002/tcp open unknown
1025/tcp open NFS-or-IIS
1720/tcp open H.323/Q.931
40019/tcp open unknown
47624/tcp open unknown
box is win2k sp4 with all security patches enabled. running serv u ftp server as well but its not on now. i am also running DU Update to update my dyndns.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|