Previous Thread
Next Thread
Print Thread
Rate Thread
#97 09/30/03 04:33 AM
Joined: Sep 2003
Posts: 7
Junior Member
Junior Member
Joined: Sep 2003
Posts: 7
From what I have been able to gather on the matter is that a port is a connection to and from a computer system. This is a way for a "hacker" to gain entry into a system by exploiting it and using the port as a back door. I have a few questions concerning the matter that hopefully can be answered as I try to obsorb the knowledge that is being handed to me:

1. Is there a list of common ports and what they are used for somewhere?
2. Why are some ports more vulnerable than others? Port 445 opposed to port 1080?
3. How exactly does one gain entry by using an open port? (If this question is considered illegal, forgive me, for security purposes only, i assure you.)

I think that's it. Any info would be most welcome.


Seek the knowledge, not the answer.
Sponsored Links
▼ Sponsored Links ▼ ▲ Sponsored Links ▲
#98 09/30/03 05:54 AM
Joined: Mar 2002
Posts: 1,041
I
UGN Elite Poster
UGN Elite Poster
I Offline
Joined: Mar 2002
Posts: 1,041
First thing, we were just talking about this in IRC the other day. Here's how I explained what a port is:

Quote:
[19:08] <%Infinite> instead of calling em ports, call em 'application numbers'. So now telnet is app number 23, and ssh is 22, smtp is 25, etc. When you receive a packet your nic looks at it and sees a '22' in the port field, so it gives the data portion to the ssh program
So... To answer your question,

1. http://www.google.ca/search?q=commo...p;hl=en&btnG=Google+Search&meta=

2. The only thing that makes a port more vulnerable than another is what program is listening on it. Telnet's default port is 23. You can run a telnet server on any port you so choose to run it on. Said telnet server is no more vulnerable if it is listening on port 69 than on 23.

3. Entry is gained by manipulating the program that is listening on the other side, whether that is a telnet server, smtp server, dns server, irc server, etc.

Infinite

#99 09/30/03 03:00 PM
Joined: Sep 2003
Posts: 7
Junior Member
Junior Member
Joined: Sep 2003
Posts: 7
Thanks for the info Infinite. Just after I posted I found a couple good sites on port numbers that gave me quite a bit of information. I'm still just curious as to how someone would manipulate the program listening? I found that port 135, 139, and 445 are very open NetBios ports. What would someone do to manipulate that? I'm concerned cause a lot of these ports are still open on many of the computers on my network. Not sure if I should shut them down or what.


Seek the knowledge, not the answer.
#100 09/30/03 05:54 PM
Joined: Oct 2002
Posts: 955
UGN Super Poster
UGN Super Poster
Joined: Oct 2002
Posts: 955
Check out this old school text, but very relevant still b/c many people still running these versions of Windows. Also, it explains how to do a lot with commands available on any windows box.

NTWARDOC

#101 10/02/03 06:23 PM
Joined: Sep 2003
Posts: 7
Junior Member
Junior Member
Joined: Sep 2003
Posts: 7
I will do that, thank you jon.


Seek the knowledge, not the answer.
#102 11/09/03 05:38 AM
Joined: Nov 2003
Posts: 33
Junior Member
Junior Member
Joined: Nov 2003
Posts: 33
port 21 is almost always open, as is 5169 cuz AIM using it and millions of people use aim if theyre online


Link Copied to Clipboard
Member Spotlight
None yet
Forum Statistics
Forums41
Topics33,840
Posts68,858
Members2,176
Most Online3,253
Jan 13th, 2020
Latest Postings
Top Posters
UGN Security 41,392
Gremelin 7,203
§intå× 3,255
SilentRage 1,273
Ice 1,146
pergesu 1,136
Infinite 1,041
jonconley 955
Girlie 908
unreal 860
Top Likes Received
Ghost 2
Ice 1
Dartur 1
Cyrez 1
Girlie 1
unreal 1
Powered by UBB.threads™ PHP Forum Software 8.0.0