hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Port 3003
isaiah
I been Getting latly a lot of scans on my network for port 3003 does any one know a vuln that goes with that port
liquidSilver
No idea, but it seems like its a TCP port... svhost.exe?

A few links:

http://www.seifried.org/security/ports/3000/3003.html

http://www.securityfocus.com/archive/75/34...30/2003-12-06/0


...dunno if its something usefull..
sysadmin
I only found this (google)

3003 - tcp, udp - cgms - tiscom.uscg.mil
SirSmokealot
jeah that google stuff is also i know about it ... but i found a scan.txt with port 3003 scans on my machine.. was already some days old , and they lost connection cause of my dynamic ip(they got in via dameware-and i fixxed it now...)

but i am really interested what they tried to scan for... cause never saw anything with port 3003 before..... (was a irc script kiddy i think ...)
nolimit
It's possible it's the hackers backdoor port.
usanet21
is it svhost.exe that is running maybe
svhost.exe runs on 3003
Viporizer
My svhost doesn't run under port 3003...
320X
isaiahi got the same port open in XP 3003, use the tcpview to see that conection
Icarus
svchost.exe its a services, svhost.exe maybe its a backdoor look pid if = to port 135
Nightdemon
TCP 3003 CGMS
don't have any idea what that could be blink.gif
silos
like nolimit says it might be a port created by the hacker [netcat port perhaps].
Nexcess
'svhost'

isnt a standard windows process

'svchost' is

if you have something called 'svhost' on your machine its something you or someone else has installed.

Planquadrat
maby this can help you to find mor aboute port 3003 and Vul.

http://www.network-intelligence.com/suppor...xpsig_3003.html
anole
On my network, where 3003 is listening, there is a Serv-U installed listening on 43958.
Nostremato
QUOTE (anole @ Feb 1 2004, 08:46 AM)
On my network, where 3003 is listening, there is a Serv-U installed listening on 43958.

maybe it is only a backdoor which the hackers installed blink.gif
esorone
QUOTE (Nostremato @ Feb 1 2004, 09:09 AM)
QUOTE (anole @ Feb 1 2004, 08:46 AM)
On my network, where 3003 is listening, there is a Serv-U installed listening on 43958.

maybe it is only a backdoor which the hackers installed blink.gif

But if the hacker installed this backdoor he is scanning hier own hacks???

Don't think so.

Greetz esorone
Erra
Unless of course he lost his list of his hacks.... and now he is trying to find them again wink.gif

Of course, that would be really funny. Scanning for his Serv-U port.... biggrin.gif
TedOb1
Again more speculation. Could be two warring warez gangs. One trying to take over the others sites.
Double-=V=-
Well he could have some kinda autohacker which doesn't log the ip's it hacked.
x0x
In situations like this searching through web pages which although may appear to be relevant can sometimes lead you into the complete opposite direction.

Instead simply capture what is in the payload using tcpdump as below :

tcpdump -X port 3003 > gotcha.txt

Now you have the payload and can analyse the capture and search based on the contents and thus giving you more chance of identifying the scan.

Greetings.

x0x

Reckless
Yeah , theres a very good possiblity the person is searching for his own hacks .. on the port .. coz i did it once too tongue.gif .. Mighta lost Ips .. So is prolly scanning for Ftp ports .
FakoLy
if you have servu on your machine that means you have a stro on your box smile.gif
maybe port 3003 is used by the backdoor that the pirate installed and the othter port is the port used by servu..
look in your task manager for "servudaemon.exe" process but it could have been renamed, most hackers that make stros on other computers rename their servu process into "svchost.exe" because you can have more than one svchost.exe proces at the same time...
i think the port scan on port 3003 is just another warezer that is trying to scan for vulns.. maybe to own the stro smile.gif
just try to find the servu home directory there are surely interesting things in it smile.gif and look in system32 for the .ini file (to install you have to upp servudaemon.exe and servudaemon.ini to the remote-box and then, rename the exe and execute it.. i think you can't rename the ini)
anole
Yep FakoLy, you're absolutely right, There were lots (many gigs) of interesting files available (but not now) for download, as well as the server files themselves!
mdk
FakoLy: wrong.
You can rename the service name, the exe and ini filename...
Search the forum for "mod servu" or something like this. Heres a tutorial.
nubela
QUOTE (FakoLy @ Feb 8 2004, 12:16 AM)
if you have servu on your machine that means you have a stro on your box smile.gif
maybe port 3003 is used by the backdoor that the pirate installed and the othter port is the port used by servu..
look in your task manager for "servudaemon.exe" process but it could have been renamed, most hackers that make stros on other computers rename their servu process into "svchost.exe" because you can have more than one svchost.exe proces at the same time...
i think the port scan on port 3003 is just another warezer that is trying to scan for vulns.. maybe to own the stro smile.gif
just try to find the servu home directory there are surely interesting things in it smile.gif and look in system32 for the .ini file (to install you have to upp servudaemon.exe and servudaemon.ini to the remote-box and then, rename the exe and execute it.. i think you can't rename the ini)

yea u can rename the .ini by hex editting it.
barty32
I'm rather sure it's only a backd00r of another hacker
securitydood
yeah servu listening on port 43958 is the default remote administrator that runs as part of servu.

as u already commented u had been hacked and abused sad.gif

make sure you lock your box down a little better. get a firewall installed etc etc smile.gif

as no one else mentioned 43958 I thought I'd post this reply smile.gif sorry if its of no use to anyone.
DvilleStoner
QUOTE (Nostremato @ Feb 1 2004, 09:09 AM)
QUOTE (anole @ Feb 1 2004, 08:46 AM)
On my network, where 3003 is listening, there is a Serv-U installed listening on 43958.

maybe it is only a backdoor which the hackers installed blink.gif

like 8 times ditto
DvilleStoner
QUOTE (Double-=V=- @ Feb 3 2004, 09:48 AM)
Well he could have some kinda autohacker which doesn't log the ip's it hacked.

that would be kinda dumb ehh?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.