Netsatat

Hacking, cracking and bluejacking. Discussions on how to keep your stuff secure and private here.

Moderators: Andy, fac51, 117

Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Netsatat

Post by Eamonn »

Just wondering if anybody knew why I seem to have an open connection to click-network.com (which seems to be a random cable TV company!)???


Image


Can body think of a way of closing the connection?


Ta :)
Eamonn

Image
User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

Post by fac51 »

would have thought it would be to do with some running process you have going in the background
Image
117
Lowly Janitor Guru
Posts: 12548
Joined: Sat Jun 14, 2003 12:23 pm
Location: a destination a little up the road

Post by 117 »

prolly a route to whatever website you were browsing at the time, I just ran Netstat with firefox open and it came up with loads of stuff all related to the sites i had open at the time or the route to get there
Displays active TCP connections, ports on which the computer is listening, Ethernet statistics, the IP routing table, IPv4 statistics (for the IP, ICMP, TCP, and UDP protocols), and IPv6 statistics (for the IPv6, ICMPv6, TCP over IPv6, and UDP over IPv6 protocols). Used without parameters, netstat displays active TCP connections.
[url=http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/netstat.mspx[/url]
Image
Image
User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

Post by fac51 »

but could be something else running in the background with an open connection rather than a website being browsed.
Image
Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Post by Eamonn »

have closed all internet related apps and the bastid's still coming up! it looks like some sort of adware imo
Eamonn

Image
User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

Post by fac51 »

agreed
Image
vinnieza
Allowed to Drink!!!!
Posts: 3258
Joined: Sun Mar 07, 2004 12:09 pm
Location: Pluto
Contact:

Post by vinnieza »

i thought if it was a site you just visited it says http as the port or 8080 while that says port 4931. Also, if you're nopt on it anymore it says time_wait or closed?

I think it's what edd said, a background program, unless it's somthing to do with NTL if you have NTL?

But i no nothing about these things so i maybe wrong
Image
....................My site: www.vthemes.co.uk
.........................* no questions asked *

Image
User avatar
Vlammetje
Sexy Guru
Posts: 6569
Joined: Sat Jun 21, 2003 12:52 pm
Location: Den Haag
Contact:

Post by Vlammetje »

i wasn't aware NTL operated in UAE as well?? :para:

does adaware nto pick ity up? can you close the port at all?
www.vlammetje.com
Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Post by Eamonn »

nope NTL does indeed not operate in the UAE! :lol:


Have done an ad-aware scan, and also a spybot scan but no luck! :deize:
Eamonn

Image
Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Post by Eamonn »

now its changed into 01060011091acf47.cg.shawcable.net:2581, which seems to be another cable/telephone company!
Eamonn

Image
User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

Post by fac51 »

i would burn your pc ;)

wonder if its a connection incoming from an attacker using different hacked pc's? paranoia maybe

could try using ethereal to monitor the connection and see what packets of dtaa are being exchanged. its a bit tricky to use but it may help.

http://www.ethereal.com/

its a great proggy and can easily scare you as you see all your plain text passwords whizz by.
Image
Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Post by Eamonn »

downloading it now...
Eamonn

Image
Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Post by Eamonn »

:o rittte wtf is one supposed to do with this proggy!
Eamonn

Image
User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

Post by fac51 »

read the helpfile mate, its complicated to say the least but you set it to monitor your ethernet port and it will show all data packets incoming and outgoing.

you can open those packets and see all the data that gets transfered over the net, this is the reason its so frightenening when you see your passwords whizz by and realise how easy they would be to intercept and read :/

anyway maybe you would be able to see the packets of data that are heading to the ip address your concerned about?
Image
vinnieza
Allowed to Drink!!!!
Posts: 3258
Joined: Sun Mar 07, 2004 12:09 pm
Location: Pluto
Contact:

Post by vinnieza »

You could always also try asking the people at hackthissite.org as they're pretty good with comp. stuff.
Image
....................My site: www.vthemes.co.uk
.........................* no questions asked *

Image
Post Reply