Forums: What Is Going On In Port 1214? - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

What Is Going On In Port 1214? raising port scanning

#1 User is offline   net_runner 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 113
  • Joined: 10-August 03

Posted 07 February 2004 - 09:09 AM

Im not sure what are scannig this boys, maybe it a worms, a virus, a new secret vuln... whatever, mi router catch a lot of scanning in this port... any suggestion?


thankz
0

#2 User is offline   xlulux 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 139
  • Joined: 25-January 04

Posted 07 February 2004 - 09:43 AM

port 1214 is kazaA i think, capture the packets sent to your router and post, and keep looking for new worms, that is probibly it cause hackers dont just scan one port , that is mostly unknown
0

#3 User is offline   net_runner 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 113
  • Joined: 10-August 03

Posted 07 February 2004 - 09:58 AM

i dont know how to capture packet, maybe you can teach me.
about 1214, yes is this network, kazaa/morpheus... (and i dont use this lame p2p)
0

#4 User is offline   Kenny 

  • Commander In Chief
  • Icon
  • Group: Admin
  • Posts: 6,446
  • Joined: 18-August 06

Posted 07 February 2004 - 10:30 AM

yeah kazaa port

if your new to sniffing then you might want to try this program for free

packetmon

http://www.analogx.c...etwork/pmon.htm

should help you

also i made a program in the programmers section called TROY .. might help you identify trojans and open ports

http://www.governmen...?showtopic=6248
Kenny aka ComSec

Please read the Forum Rules !!!

Blog

" http://kaltech.blogspot.com/ "

______________________
0

#5 User is offline   TedOb1 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 120
  • Joined: 05-October 03

Posted 07 February 2004 - 12:30 PM

xlulux is right 1214 is the default port for morphous/kazaa. you find this allot if your using dial-up. someone signs off that was sharing some popular files and your assigned that ip address when you sign on. to see for yourself scan a ip range for computers listening on 1214. fire-up telnet or netcat. telnet xx.xxx.xx.xxx 1214. enter "GET http/1.0 \n\n" some like to put another '/' between get and http but this works.

C:\>echo GET http/1.0 \n\n |nc -vv 172.147.xxx.62 1214
AC00000E.ipt.aol.com [172.147.xxx.62] 1214 (?) open
HTTP/1.0 501 Not Implemented
X-Kazaa-Username: lazygirl
X-Kazaa-Network: KaZaA
X-Kazaa-IP: 172.147.xxx.62:1530
X-Kazaa-SupernodeIP: 172.128.xxx.108:2030

sent 20, rcvd 158: NOTSOCK

packetmon is great. but a word of advise, if your are using a modem to connect there's not a packet scanner on the market that will capture outgoing packets from your machine. you have to set up a gateway that dials up to connect and then set your computer to use a network connection to the gateway for internet access to use an outbound sniffer.

easy answer...set your firewall not to warn you of these connection attempts unless your running kazaa.
0

#6 User is offline   eXist 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 110
  • Joined: 30-December 03

Posted 07 February 2004 - 10:37 PM

Check out fport, to see if it is actually infact Kazaa that's running. Someone may have other stuff installed on your computer and use this port as a simple "disguise". Also, if packetmon isn't to your liking, try getting snort, another open source packet sniffer.
0

#7 User is offline   net_runner 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 113
  • Joined: 10-August 03

Posted 08 February 2004 - 08:04 AM

First, i wanna say thankz to xlulux, ComSec, TedOb1, eXist
second, packetmon rulz
third: im drunk :)


exist: is not necesary to run fport(great tool) the connection attemp is catched by the router and the router's real time logs is what im looking.
0

#8 User is offline   net_runner 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 113
  • Joined: 10-August 03

Posted 08 February 2004 - 08:48 AM

packetmon catch this packet..

Quote

HEADER:
45 00 00 30 1B 02 40 00 6D 06 00 DC 52 D5 DD 6A  E..0..@.m...R..j
C0 A8 01 02 04 54 04 BE 00 03 1A A0 00 00 00 00  .....T..........
70 02 FF FF 6D E4 00 00                          p...m...       

DATA:
02 04 05 50 01 01 04 02                          ...P....       


how it can be interpreted?
what could it looking for?

pd: i started this topic becouse i detect a raising activity in port 1214...
0

#9 User is offline   kenshin_efx 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 94
  • Joined: 08-September 03

Posted 08 February 2004 - 06:25 PM

try snort, is a sniffer.
www.google.cl ---> snort
0

#10 User is offline   Kenny 

  • Commander In Chief
  • Icon
  • Group: Admin
  • Posts: 6,446
  • Joined: 18-August 06

Posted 08 February 2004 - 08:24 PM

kenshin_efx, on Feb 9 2004, 02:25 AM, said:

try snort, is a sniffer.
www.google.cl ---> snort

i think from the reaction to his post :

Quote

dont know how to capture packet, maybe you can teach me


snort might just be a bit to advanced for a newbie...hence the easy starter with packetmon

jmo ;)
Kenny aka ComSec

Please read the Forum Rules !!!

Blog

" http://kaltech.blogspot.com/ "

______________________
0

#11 User is offline   kenshin_efx 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 94
  • Joined: 08-September 03

Posted 09 February 2004 - 09:29 AM

i will try packetmon, 10x for the tip ComSec.
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting