Page 1 of 2

Netsatat

Posted: Wed Oct 12, 2005 6:26 pm
by Eamonn
Just wondering if anybody knew why I seem to have an open connection to click-network.com (which seems to be a random cable TV company!)???


Image


Can body think of a way of closing the connection?


Ta :)

Posted: Wed Oct 12, 2005 6:57 pm
by fac51
would have thought it would be to do with some running process you have going in the background

Posted: Wed Oct 12, 2005 7:00 pm
by 117
prolly a route to whatever website you were browsing at the time, I just ran Netstat with firefox open and it came up with loads of stuff all related to the sites i had open at the time or the route to get there
Displays active TCP connections, ports on which the computer is listening, Ethernet statistics, the IP routing table, IPv4 statistics (for the IP, ICMP, TCP, and UDP protocols), and IPv6 statistics (for the IPv6, ICMPv6, TCP over IPv6, and UDP over IPv6 protocols). Used without parameters, netstat displays active TCP connections.
[url=http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/netstat.mspx[/url]

Posted: Wed Oct 12, 2005 7:26 pm
by fac51
but could be something else running in the background with an open connection rather than a website being browsed.

Posted: Wed Oct 12, 2005 8:09 pm
by Eamonn
have closed all internet related apps and the bastid's still coming up! it looks like some sort of adware imo

Posted: Wed Oct 12, 2005 8:37 pm
by fac51
agreed

Posted: Thu Oct 13, 2005 7:57 am
by vinnieza
i thought if it was a site you just visited it says http as the port or 8080 while that says port 4931. Also, if you're nopt on it anymore it says time_wait or closed?

I think it's what edd said, a background program, unless it's somthing to do with NTL if you have NTL?

But i no nothing about these things so i maybe wrong

Posted: Thu Oct 13, 2005 8:24 am
by Vlammetje
i wasn't aware NTL operated in UAE as well?? :para:

does adaware nto pick ity up? can you close the port at all?

Posted: Thu Oct 13, 2005 9:15 am
by Eamonn
nope NTL does indeed not operate in the UAE! :lol:


Have done an ad-aware scan, and also a spybot scan but no luck! :deize:

Posted: Thu Oct 13, 2005 9:23 am
by Eamonn
now its changed into 01060011091acf47.cg.shawcable.net:2581, which seems to be another cable/telephone company!

Posted: Thu Oct 13, 2005 1:03 pm
by fac51
i would burn your pc ;)

wonder if its a connection incoming from an attacker using different hacked pc's? paranoia maybe

could try using ethereal to monitor the connection and see what packets of dtaa are being exchanged. its a bit tricky to use but it may help.

http://www.ethereal.com/

its a great proggy and can easily scare you as you see all your plain text passwords whizz by.

Posted: Thu Oct 13, 2005 2:52 pm
by Eamonn
downloading it now...

Posted: Thu Oct 13, 2005 3:39 pm
by Eamonn
:o rittte wtf is one supposed to do with this proggy!

Posted: Thu Oct 13, 2005 5:49 pm
by fac51
read the helpfile mate, its complicated to say the least but you set it to monitor your ethernet port and it will show all data packets incoming and outgoing.

you can open those packets and see all the data that gets transfered over the net, this is the reason its so frightenening when you see your passwords whizz by and realise how easy they would be to intercept and read :/

anyway maybe you would be able to see the packets of data that are heading to the ip address your concerned about?

Posted: Fri Oct 14, 2005 7:57 am
by vinnieza
You could always also try asking the people at hackthissite.org as they're pretty good with comp. stuff.