What's up with port 445?
Looking at the DSHIELD data for the port 445 Shows an interesting little trend. Reports showing 445 as the target port is down. Something that is also observed by some readers in their various darknets.
Ports showing 445 as the source however is way up. If you are seeing this or have some packets, please send them through. For the packets, I'm interested especially in the source port 445 traffic.
Mark H
Update
Quite number of people have reported a similar drop in their stats for 445 as the target port, but no real explanations just yet. Likely to be confiker related, but that's speculation at the moment.
Keywords: 445 tcp
5 comment(s)
×
Diary Archives
Comments
TCPView is a Windows program that will show you detailed listings of all TCP and UDP endpoints on your system.
Useful Links:
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx
http://download.sysinternals.com/Files/TcpView.zip
c[a]rlito
Mar 6th 2009
1 decade ago
rjmx
Mar 6th 2009
1 decade ago
Mark
Mar 6th 2009
1 decade ago
Looking at it again, and playing around with the dates a bit more, the ramp disappears. Probably an artifact of the sample rate. Sorry for the false alarm.
rjmx
Mar 7th 2009
1 decade ago
alterself
Mar 10th 2009
1 decade ago