看板NetSecurity
標 題Re: 真的被駭了
發信站台大電機 Maxwell BBS (Thu Jul 29 18:18:43 2004)
轉信站ptt!ctu-reader!ctu-peer!news.nctu!netnews.csie.nctu!news.ee.ttu!news.n
4359那個port很可疑。你有telent出去嗎。沒有的話,就是真的被駭了。
※ 引述《[email protected] (007)》之銘言:
: Active Connections
: Proto Local Address Foreign Address State
: TCP administ-5wlmc4:epmap administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:microsoft-ds administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:1025 administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:1026 administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:1103 administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:4359 administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:4817 administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:4886 administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:netbios-ssn administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:4359 210.59.145.177:telnet ESTABLISHED
: TCP administ-5wlmc4:1053 administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:4356 administ-5wlmc4:0 LISTENING
: TCP administ-5wlmc4:netbios-ssn administ-5wlmc4:0 LISTENING
: UDP administ-5wlmc4:microsoft-ds *:*
: UDP administ-5wlmc4:netbios-ns *:*
: UDP administ-5wlmc4:netbios-dgm *:*
: UDP administ-5wlmc4:isakmp *:*
: UDP administ-5wlmc4:4500 *:*
: UDP administ-5wlmc4:1062 *:*
: UDP administ-5wlmc4:4329 *:*
: UDP administ-5wlmc4:netbios-ns *:*
: UDP administ-5wlmc4:netbios-dgm *:*
: UDP administ-5wlmc4:isakmp *:*
: UDP administ-5wlmc4:4500 *:*
: 那這樣算正常嗎?我只是把及時通關掉。
--
※ Origin: 臺大電機 Maxwell 站 ◆ From: adsl-68-77-151-97.dsl.emhril.ameritech.