why those suspect port 443 connections?

why those suspect port 443 connections?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
why those suspect port 443 connections? cpc 01-10-2007
Posted by cpc on January 10, 2007, 6:26 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi everybody!

Sometime ago I started the windows firewall log(c:\windows\pfirewall.log
by default). Itīs amusing to have a look to this file because we can see
the huge amount of noise out there.

I'm worry about some outgoing connections from my computer to port 443
(https) of unknown ip's address.
Thereīs a repetitive address which I cannot locate, it happens randomly
so I can track it with netstat -b, the address is 213.199.161.250.
Can someone of you tell me whose is that address?
In the other hand I also see normal https connections like msn
messenger, windows update and so on.

I'm running WXP SP2
Windows Defender installed (I donīt find that address in "currently
connected programs)
Itīs a new computer and I have no extra software installed like p2p (I
swear it), even I donīt have an antivirus installed

Thank you very much

Posted by Tom Willett on January 11, 2007, 7:56 am
If you were  Registered and logged in, you could reply and use other advanced thread options
The IP address belongs to Microsoft. See:
http://www.dnsstuff.com/tools/whois.ch?ip=213.199.161.250

> Hi everybody!
>
> Sometime ago I started the windows firewall log(c:\windows\pfirewall.log
> by default). Itīs amusing to have a look to this file because we can see
> the huge amount of noise out there.
>
> I'm worry about some outgoing connections from my computer to port 443
> (https) of unknown ip's address.
> Thereīs a repetitive address which I cannot locate, it happens randomly so
> I can track it with netstat -b, the address is 213.199.161.250.
> Can someone of you tell me whose is that address?
> In the other hand I also see normal https connections like msn messenger,
> windows update and so on.
>
> I'm running WXP SP2
> Windows Defender installed (I donīt find that address in "currently
> connected programs)
> Itīs a new computer and I have no extra software installed like p2p (I
> swear it), even I donīt have an antivirus installed
>
> Thank you very much



Posted by cpc on January 12, 2007, 9:46 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thank you very much for your replay Tom

Tom Willett escribió:
> The IP address belongs to Microsoft. See:
> http://www.dnsstuff.com/tools/whois.ch?ip=213.199.161.250
>
>> Hi everybody!
>>
>> Sometime ago I started the windows firewall log(c:\windows\pfirewall.log
>> by default). Itīs amusing to have a look to this file because we can see
>> the huge amount of noise out there.
>>
>> I'm worry about some outgoing connections from my computer to port 443
>> (https) of unknown ip's address.
>> Thereīs a repetitive address which I cannot locate, it happens randomly so
>> I can track it with netstat -b, the address is 213.199.161.250.
>> Can someone of you tell me whose is that address?
>> In the other hand I also see normal https connections like msn messenger,
>> windows update and so on.
>>
>> I'm running WXP SP2
>> Windows Defender installed (I donīt find that address in "currently
>> connected programs)
>> Itīs a new computer and I have no extra software installed like p2p (I
>> swear it), even I donīt have an antivirus installed
>>
>> Thank you very much
>
>

Similar ThreadsPosted
direct 3d suspect file October 7, 2007, 11:55 am
Port scan says port 21 is open June 21, 2007, 12:51 pm
puzzling connections July 9, 2005, 8:49 pm
Are my Network Connections Encrypted November 26, 2007, 3:27 pm
Connections from subnets to shares are rejected October 27, 2005, 2:31 pm
Unknown Connections On SMTP Relay November 25, 2005, 11:11 am
Detect what software is blocking connections January 26, 2006, 11:49 am
spyware tcp connections from spoolsv.exe to internet!!! February 7, 2006, 8:01 am
netstat showing too many connections LISTENING May 15, 2006, 1:36 pm
DMO & ADO connections fail even with valid credentials when using LOGON32_LOGON_NEW_CREDENTIALS flag with 'LogonUser' April 17, 2006, 9:19 am

The site map in XML format XML site map

Contact Us | Privacy Policy