Thinking...
[get complete service list]
Port Information
Protocol Service Name
tcp squid-http Proxy Server
tcp ndl-aas Active API Server Port
udp ndl-aas Active API Server Port
tcp ReverseWWWTunnel [trojan] Reverse WWW Tunnel Backdoor
tcp RingZero [trojan] RingZero
Top IPs Scanning
Today Yesterday
152.42.184.125 (718)87.120.191.37 (1190)
188.166.234.70 (590)185.200.116.36 (428)
178.128.212.131 (554)185.200.116.58 (410)
87.120.191.37 (457)185.91.127.107 (406)
185.200.116.35 (294)87.121.84.14 (396)
185.200.116.72 (245)204.76.203.28 (341)
176.97.210.9 (220)176.97.210.9 (331)
204.76.203.28 (207)172.105.0.111 (230)
185.91.127.107 (176)159.65.233.219 (228)
160.191.35.153 (159)192.159.99.162 (186)
User Comments
Submitted By Date
Comment
2012-08-25 16:07:47
Planet Lab uses this port as well
Ronnie 2010-05-25 20:52:09
This port is also used by WinProxy
Brian Porter 2004-02-11 00:46:11
MyDoom.C / Doomjuice http://www.lurhq.com/mydoom-c.html http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.doomjuice.html http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DOOMJUICE.A http://us.mcafee.com/virusInfo/default.asp?id=description&;;;virus_k=101002 http://www.sophos.com/virusinfo/analyses/w32doomjuicea.html http://www.f-secure.com/v-descs/doomjuice.shtml http://www.viruslist.com/eng/alert.html?id=930701
2004-02-06 22:18:45
The Win32.Mydoom computer-virus opens and listens to the TCP port 3127, (if this port is already in use, the worm tries the next one free from the range 3128- 3199). The backdoor appears to have two main functions: execution of remotely-supplied code, and port forwarding. Reference: http://www3.ca.com/virusinfo/virus.aspx?ID=38102
Johannes Ullrich 2002-10-12 08:57:51
scans on port 3128 usually look for badly configured proxy servers in order to use them to hide further intrusion attempts or to bypass company (or country wide) firewall rules restricting access to certain web sites. These scans usually come in sets that scan several ports frequently used by proxies (80,8080...) Port 3128 is usually used by 'squid', a very popular web proxy server that is also able to proxy other protocols (e.g. ftp). If you run a proxy server, make sure it only proxies request from the inside. The two most common configuration problems are to permit strangers to use the proxy server to attack other web sites, or even worse to allow strangers to use the proxy server to access web site ('intranet') sites on the inside.
CVE Links
CVE # Description