funny firewall behaviour

Apr 7, 2005
35
0
0
for the past 12 hours, i've been getting alot of hits from various sources on port 6346, which is supposed to be from the gnutella network, but as far as i know, i dont have any apps that access that. how can i pin down which program is actually using that port?
 

gaidin123

Senior member
May 5, 2000
962
1
0
If this is a host based firewall you should be able to get a mapping of ports to processes in WinXP and 2003 by running netstat -ano at a command prompt. Then open up the task manager, add the PID column to the viewable columns and do a little cross referencing.

If this is a linux box netstat -lnp will show you the port, pid, and process name in one line.

If this is an OS X box you can run lsof -something that I can't remember to get similar output.

If this is a network firewall with multiple machines behind it, figure out the internal IP these probes are directed at and run the above tools on it or do an nmap -sV <ip> to grab whatever info it can from the listening port.

Gaidin

Edit: Of course if you aren't actually running anything on those ports you could just be getting probes on that port for some service you aren't running. You weren't very clear on whether your machine was responding to this traffic...
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |