OVH Cloud OVH Cloud

Windows 2003 server portscan!

1 réponse
Avatar
Angelus86
Hello,

First, excuse my English...

I have a personal firewall (Sygate) installed on my PC and I always receive
portscan attack from my DC server (Windows 2003 server)and also from other
2000 and 2003 servers. I have also a Hardware firewall between my PC and this
servers and I have the same message so I think the problem does not come from
my firewall.
I checked the server and the antivirus (server protect Trend) is uptodate
and after a scan nothing detected!
I made a netstat -an on the server and for me there are to many UDP and TCP
ports opened for a windows 2003 server.
Here a part of the result of the netstat -an

TCP 0.0.0.0:42 0.0.0.0:0 LISTENING
TCP 0.0.0.0:53 0.0.0.0:0 LISTENING
TCP 0.0.0.0:88 0.0.0.0:0 LISTENING
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:389 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:464 0.0.0.0:0 LISTENING
TCP 0.0.0.0:593 0.0.0.0:0 LISTENING
TCP 0.0.0.0:636 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1025 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1026 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1028 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1057 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1058 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1076 0.0.0.0:0 LISTENING
TCP 0.0.0.0:2301 0.0.0.0:0 LISTENING
TCP 0.0.0.0:2381 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING
TCP 0.0.0.0:5168 0.0.0.0:0 LISTENING
TCP 0.0.0.0:5169 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49400 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49401 0.0.0.0:0 LISTENING
UDP 0.0.0.0:42 *:*
UDP 0.0.0.0:161 *:*
UDP 0.0.0.0:445 *:*
UDP 0.0.0.0:500 *:*
UDP 0.0.0.0:1030 *:*
UDP 0.0.0.0:1042 *:*
UDP 0.0.0.0:1047 *:*
UDP 0.0.0.0:1048 *:*
UDP 0.0.0.0:1054 *:*
UDP 0.0.0.0:1056 *:*
UDP 0.0.0.0:1059 *:*
UDP 0.0.0.0:1070 *:*
UDP 0.0.0.0:1071 *:*
UDP 0.0.0.0:1074 *:*
UDP 0.0.0.0:1075 *:*
UDP 0.0.0.0:1223 *:*
UDP 0.0.0.0:1302 *:*
UDP 0.0.0.0:1469 *:*
UDP 0.0.0.0:1481 *:*
UDP 0.0.0.0:2240 *:*
UDP 0.0.0.0:4092 *:*
UDP 0.0.0.0:4500 *:*
UDP 0.0.0.0:4656 *:*
UDP 127.0.0.1:53 *:*
UDP 127.0.0.1:123 *:*
UDP 127.0.0.1:1046 *:*
UDP 159.217.119.12:464 *:*

if anybody has an idea...

Thank you for your help

Guillaume

1 réponse

Avatar
GG [MVP]
First, excuse my English...


Bin alors cause la France comme dirait ma fille :-)
fr veut dire forum de langue française.
--
Cordialement.
GG. [MVP]
http://gilisa.assysm.com