jeah that google stuff is also i know about it ... but i found a scan.txt with port 3003 scans on my machine.. was already some days old , and they lost connection cause of my dynamic ip(they got in via dameware-and i fixxed it now...)
but i am really interested what they tried to scan for... cause never saw anything with port 3003 before..... (was a irc script kiddy i think ...)
nolimit
Jan 29 2004, 11:09 AM
It's possible it's the hackers backdoor port.
usanet21
Jan 29 2004, 02:15 PM
is it svhost.exe that is running maybe svhost.exe runs on 3003
Viporizer
Jan 29 2004, 03:21 PM
My svhost doesn't run under port 3003...
320X
Jan 29 2004, 04:05 PM
isaiahi got the same port open in XP 3003, use the tcpview to see that conection
Icarus
Jan 29 2004, 04:29 PM
svchost.exe its a services, svhost.exe maybe its a backdoor look pid if = to port 135
Nightdemon
Jan 29 2004, 04:39 PM
TCP 3003 CGMS don't have any idea what that could be
silos
Jan 29 2004, 06:58 PM
like nolimit says it might be a port created by the hacker [netcat port perhaps].
Nexcess
Jan 29 2004, 07:10 PM
'svhost'
isnt a standard windows process
'svchost' is
if you have something called 'svhost' on your machine its something you or someone else has installed.
Planquadrat
Jan 29 2004, 07:40 PM
maby this can help you to find mor aboute port 3003 and Vul.
On my network, where 3003 is listening, there is a Serv-U installed listening on 43958.
Nostremato
Feb 1 2004, 09:09 AM
QUOTE (anole @ Feb 1 2004, 08:46 AM)
On my network, where 3003 is listening, there is a Serv-U installed listening on 43958.
maybe it is only a backdoor which the hackers installed
esorone
Feb 1 2004, 12:25 PM
QUOTE (Nostremato @ Feb 1 2004, 09:09 AM)
QUOTE (anole @ Feb 1 2004, 08:46 AM)
On my network, where 3003 is listening, there is a Serv-U installed listening on 43958.
maybe it is only a backdoor which the hackers installed
But if the hacker installed this backdoor he is scanning hier own hacks???
Don't think so.
Greetz esorone
Erra
Feb 2 2004, 07:58 PM
Unless of course he lost his list of his hacks.... and now he is trying to find them again
Of course, that would be really funny. Scanning for his Serv-U port....
TedOb1
Feb 3 2004, 04:40 AM
Again more speculation. Could be two warring warez gangs. One trying to take over the others sites.
Double-=V=-
Feb 3 2004, 09:48 AM
Well he could have some kinda autohacker which doesn't log the ip's it hacked.
x0x
Feb 3 2004, 03:24 PM
In situations like this searching through web pages which although may appear to be relevant can sometimes lead you into the complete opposite direction.
Instead simply capture what is in the payload using tcpdump as below :
tcpdump -X port 3003 > gotcha.txt
Now you have the payload and can analyse the capture and search based on the contents and thus giving you more chance of identifying the scan.
Greetings.
x0x
Reckless
Feb 7 2004, 05:04 PM
Yeah , theres a very good possiblity the person is searching for his own hacks .. on the port .. coz i did it once too .. Mighta lost Ips .. So is prolly scanning for Ftp ports .
FakoLy
Feb 8 2004, 12:16 AM
if you have servu on your machine that means you have a stro on your box maybe port 3003 is used by the backdoor that the pirate installed and the othter port is the port used by servu.. look in your task manager for "servudaemon.exe" process but it could have been renamed, most hackers that make stros on other computers rename their servu process into "svchost.exe" because you can have more than one svchost.exe proces at the same time... i think the port scan on port 3003 is just another warezer that is trying to scan for vulns.. maybe to own the stro just try to find the servu home directory there are surely interesting things in it and look in system32 for the .ini file (to install you have to upp servudaemon.exe and servudaemon.ini to the remote-box and then, rename the exe and execute it.. i think you can't rename the ini)
anole
Feb 11 2004, 05:17 AM
Yep FakoLy, you're absolutely right, There were lots (many gigs) of interesting files available (but not now) for download, as well as the server files themselves!
mdk
Feb 11 2004, 12:59 PM
FakoLy: wrong. You can rename the service name, the exe and ini filename... Search the forum for "mod servu" or something like this. Heres a tutorial.
nubela
Feb 11 2004, 01:42 PM
QUOTE (FakoLy @ Feb 8 2004, 12:16 AM)
if you have servu on your machine that means you have a stro on your box maybe port 3003 is used by the backdoor that the pirate installed and the othter port is the port used by servu.. look in your task manager for "servudaemon.exe" process but it could have been renamed, most hackers that make stros on other computers rename their servu process into "svchost.exe" because you can have more than one svchost.exe proces at the same time... i think the port scan on port 3003 is just another warezer that is trying to scan for vulns.. maybe to own the stro just try to find the servu home directory there are surely interesting things in it and look in system32 for the .ini file (to install you have to upp servudaemon.exe and servudaemon.ini to the remote-box and then, rename the exe and execute it.. i think you can't rename the ini)
yea u can rename the .ini by hex editting it.
barty32
Feb 12 2004, 01:45 PM
I'm rather sure it's only a backd00r of another hacker
securitydood
Feb 16 2004, 07:01 PM
yeah servu listening on port 43958 is the default remote administrator that runs as part of servu.
as u already commented u had been hacked and abused
make sure you lock your box down a little better. get a firewall installed etc etc
as no one else mentioned 43958 I thought I'd post this reply sorry if its of no use to anyone.
DvilleStoner
Feb 26 2004, 10:20 AM
QUOTE (Nostremato @ Feb 1 2004, 09:09 AM)
QUOTE (anole @ Feb 1 2004, 08:46 AM)
On my network, where 3003 is listening, there is a Serv-U installed listening on 43958.
maybe it is only a backdoor which the hackers installed
like 8 times ditto
DvilleStoner
Feb 26 2004, 10:21 AM
QUOTE (Double-=V=- @ Feb 3 2004, 09:48 AM)
Well he could have some kinda autohacker which doesn't log the ip's it hacked.
that would be kinda dumb ehh?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.