- Port 80 OPEN!!!!!
- Posted by Richard H on August 14th, 2003
Hi all security experts!
I have a Win98SE machine running Kerio Personal Firewall 2.1.5 and blackICE
IDS. I am behind a Belkin Gateway Router with NAT and firewall enabled.
When I run a Shields UP 'common ports scan', port 80 is found to be open!
A few months ago, when I last checked, all ports were stealthed.
A virus/trojan scan with AVP 3.5, Sophos AV 3.72, Inoculate IT 4.5, eSafe
AV, F-Prot for DOS, TDS-3, The Cleaner and Trend Housecall all show
negative results.
Inspection of all running processes, msconfig startup, and autoexec.bat
contents show nothing suspicious.
I have uninstalled personal web server.
The Kerio Firewall Status and ‘netstat –an’ show no suspicious connections.
(see below)
Active Connections
Proto Local Address Foreign Address State
TCP 0.0.0.0:44334 0.0.0.0:0 LISTENING
TCP 0.0.0.0:44334 0.0.0.0:0 LISTENING
TCP 127.0.0.1:8080 0.0.0.0:0 LISTENING
TCP 169.254.246.190:137 0.0.0.0:0 LISTENING
TCP 169.254.246.190:138 0.0.0.0:0 LISTENING
TCP 169.254.246.190:139 0.0.0.0:0 LISTENING
TCP 192.168.2.2:137 0.0.0.0:0 LISTENING
TCP 192.168.2.2:138 0.0.0.0:0 LISTENING
TCP 192.168.2.2:139 0.0.0.0:0 LISTENING
UDP 0.0.0.0:44334 *:*
UDP 169.254.246.190:137 *:*
UDP 169.254.246.190:138 *:*
UDP 192.168.2.2:137 *:*
UDP 192.168.2.2:138 *:*
Remote administration and DMZ is disabled on my router.
A spyware check with AdAware and SpyBot S&D (all updated) shows no spyware
infestation.
What could be causing port 80 to be open, and how could I stealth it?
Thanks in advance.
Richard
- Posted by Lord Shaolin on August 14th, 2003
Richard H <me@me.com> randomly produced:
:: Hi all security experts!
:: I have a Win98SE machine running Kerio Personal Firewall 2.1.5 and
:: blackICE IDS. I am behind a Belkin Gateway Router with NAT and
:: firewall enabled. When I run a Shields UP 'common ports scan', port
It's probably port 80 on your router (remote admin).
When you run external scans against yourself you are running them against
your router (Your public IP address)
Not against your actual PC.
I can confirm your port 80 is showing as open but I'm unable to connect to
it.
Cheers
ST
--
..: http://www.security-forums.com :.
Share your knowledge
It's a way to achieve
Immortality.
- Posted by Richard H on August 15th, 2003
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
"Jim Watt" <jimwatt@aol.no.way> wrote in message
news:j2injv8c4opto7vac9v0sd3ik1lapqujd4@4ax.com...
What worrys me is that last time when i ran Shields UP (a few months ago)
all ports were stealthed.
Remote/web administration is disabled on my router, and Shields UP still
reports port80 as open.
Could someone have hacked into my router and changed the settings so it
looks to me that remote admin is disabled, but really it is enabled?
The router settings are protected by a non-default password, and i have
never enabled remote administation before.
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0
iQA/AwUBPzzD0iYncAS5ivfOEQK6VgCfR3D8Hw0q7ZZbLLRj87MN3Y 8vp+IAnRP6
RQodoAGJDzEh2hmWR+4yMA6+
=XFUi
-----END PGP SIGNATURE-----
- how do I open port 445 (Help and Support) by maltinator
- open port (Microsoft Windows) by djj
- Re: port 80 open? (Security & Administration) by Christian- Vzla
- Port already open (Computers & Technology) by Larry
- Tosiba Tecra S1: Com Port will not open (Laptops/Notebooks) by Carmen

