What Windows process initiate connection to other Port 139?

What Windows process initiate connection to other Port 139?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
What Windows process initiate connection to other Port 139? ys 07-27-2004
Posted by ys on July 27, 2004, 3:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am not sure whether my machine got hacked. It keeps trying to make
TCP connection to port 139 on the other machine[s]. However, I found
no process based on its initiating port. It seems to me it was
spawned by other running process, but I am running out of idea to
track that down.

One thing I don't really understand is that how does my machine know
these IP addresses for connection; therefore, I suspect it has been
hacked.

Not sure whether it is related. There are a lot of machines trying to
make connections to my machine at port 135 and 445. Most initiating
IP are near. If this is normal, how do they know my IP? I just hope
my machine didn't boardcast its address for invitations! :(

I am using Windows 2000 Server with limited ports open to the net. I
captured these IP log from my hardware router.

ys


Posted by jayjwa on August 4, 2004, 6:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


> I am not sure whether my machine got hacked. It keeps trying to make
> TCP connection to port 139 on the other machine[s]. However, I found
> no process based on its initiating port. It seems to me it was
> spawned by other running process, but I am running out of idea to
> track that down.

Try a web-search about SMB and Windows "File Sharing"/Network
Neighborhood, and netbios. It's a big topic.


> One thing I don't really understand is that how does my machine know
> these IP addresses for connection; therefore, I suspect it has been
> hacked
>

Broadcasts. They look for who is the domain master, have "elections",
create Browse-lists. My ISP's network is buzzing with activity from
Windows machines. I too wondered why all these machines seemed to probe
mine on certain ports, namely 137-138/udp, and 139,445/tcp. If you
have a sniffer, watch the traffic sometime and see what they send.
Have a look at http://www.samba.org/ They're better at explaining
stuff and you can see source code, unlike whatever MS has on it (if
you can find what you're looking for on their site...)


> Not sure whether it is related. There are a lot of machines trying to
> make connections to my machine at port 135 and 445. Most initiating
> IP are near. If this is normal, how do they know my IP? I just hope
> my machine didn't boardcast its address for invitations! :(

They're probably all on your ISP's subnet, right? Visible, browsable
machines should make up the Windows Network Neighborhood (don't quote
me on this, I never checked it from a Windows machine myself). On
Linux, I can see a shares listing with something like this-

smbclient -U guest -N -L <the netbios machine's name>


> I am using Windows 2000 Server with limited ports open to the net. I
> captured these IP log from my hardware router.

Be careful what you're serving up ;) I few people have their C:\
shared with the rest of the subnet here. I'm not sure how secure MS
Windows 2000 server is, but there's been issues in the past regarding
this area; like anything else, keep patched, keep current, and do your
homework.


--
--- SIGSEGV (Segmentation fault) @ 0 (0) ---
+++ killed by SIGSEGV +++


Similar ThreadsPosted
Generic Host Process for Win32 Services, Port 32729 September 26, 2005, 12:41 pm
remote process viewer... February 20, 2006, 5:10 pm
Anybody ran into a process which doesn't appear in task manager? December 5, 2006, 3:15 pm
Secure RDP connection from outside the network July 12, 2006, 6:23 pm
Credit card authorization process July 1, 2004, 1:37 pm
knowing which process accesses which ports March 25, 2005, 10:19 pm
Extremely slow "broadband" connection January 2, 2005, 3:06 pm
connection logger advice needed February 2, 2005, 5:42 pm
ADSL connection dropping randomly April 18, 2005, 2:49 pm
ftp to ibiblio results in connection to Google as well August 22, 2007, 11:00 am

The site map in XML format XML site map

Contact Us | Privacy Policy