Security Basics mailing list archives
Re: How to find a process
From: Ansgar -59cobalt- Wiechers <bugtraq () planetcobalt net>
Date: Thu, 14 Jun 2007 13:57:37 +0200
On 2007-06-13 Francisco Rodrigo Cortinas Maseda wrote:
My problem is that we have some strange traffic on the firewalls, going from a server on a DMZ to public client pools. 10:09:10.511978 00:0e:0c:71:7f:cd > 10:00:00:00:26:01, ethertype IPv4 (0x0800), length 61: IP XXXXX.44267 > XXXXXX.3072: UDP, length 19 The problem is: with netstat i only see the ports daemons are listening on. I want to know the process that is using the outgoing port, that is, 44267. Is there a way to know this?
Of course there is. However, the way differs from operating system to operating system so you should've mentioned what OS the server is running. On Windows Server 2003 you'd use "netstat -anob", on earlier Windows versions you'd have to resort to TCPView [1]. On Linux servers the command would be "netstat -antp", on Mac OS X Server "lsof -i -P". [1] http://www.microsoft.com/technet/sysinternals/Networking/TcpView.mspx Regards Ansgar Wiechers -- "All vulnerabilities deserve a public fear period prior to patches becoming available." --Jason Coombs on Bugtraq
Current thread:
- RE: How to find a process, (continued)
- RE: How to find a process Shortz, Alan (Jun 14)
- Re: How to find a process Nikhil Wagholikar (Jun 14)
- Re: How to find a process Ansgar -59cobalt- Wiechers (Jun 14)
- Re: How to find a process Matthias Merk (Jun 14)
- Re: How to find a process Pingu (Jun 14)
- Re: How to find a process Pranay Kanwar (Jun 14)
- RE: How to find a process Nichol.Deaddis (Jun 14)
- Re: How to find a process Tsu (Jun 14)
- RE: How to find a process M. Waseem Sindhu (Jun 14)
- Re: How to find a process Roman Shirokov (Jun 14)
- Re: How to find a process Ansgar -59cobalt- Wiechers (Jun 14)
- Re: How to find a process Manuel GarcĂa (Jun 14)
- Re: How to find a process Alcides (Jun 14)
- Re: How to find a process Justin Lintz (Jun 14)
- Re: How to find a process Joshua M. Miller (Jun 14)
- Re: How to find a process rmyster (Jun 15)
- Re: How to find a process levinson_k (Jun 14)
- RE: How to find a process Gressick, Michael (Jun 14)
- RE: How to find a process Dan Denton (Jun 14)
- RE: How to find a process Dan Denton (Jun 14)
- Re: How to find a process Ansgar -59cobalt- Wiechers (Jun 14)
(Thread continues...)