PDA

View Full Version : Portref.txt updates


Rainwalker
January 31st, 2004, 01:20 PM
Greetings all is http://www.tds.diamonds.com.au/portref.txt down because it is no longer needed? One of the notices that pops up in the tds box is telling us to check every few weeks for portref. txt updates :-\

TIA

Jooske
January 31st, 2004, 01:32 PM
In the site rebuild must have changed the link, we'll hear it soon i guess, thanks for mentioning it

Rainwalker
February 4th, 2004, 11:17 AM
Greetings all,
Does anyone have anymore information on this :-\

TIA

FanJ
February 4th, 2004, 09:39 PM
Question for Wayne:

Sorry Wayne,
Could you please jump in here to answer the question?

Gavin - DiamondCS
February 4th, 2004, 10:11 PM
http://tds.diamondcs.com.au/portref.txt

This is the correct link ! there is no WWW in it ;)

I will upload a newer portref.txt, should be there now :) And PE users can check for new port/domain databases too..

Jooske
February 5th, 2004, 12:00 AM
Thanks Gavin, the portref page can be copied and put to place, the PE check keeps telling i'm already up to date so either your message was PE users can TRY or it is not uploaded yet there or updating is not working via PE or i was already uptodate but last time i tried via PE was over a week or two ago and also then was told i was uptodate.

Pilli
February 5th, 2004, 03:28 AM
PE reports "Already up to date" here also

Rainwalker
February 5th, 2004, 11:57 AM
Thanks Gavin

me three on "Already up to date"

FanJ
February 6th, 2004, 12:31 AM
Thanks Gavin !!!

I've just got the new PortExplorer port and domain database ;D

FanJ
February 6th, 2004, 01:25 AM
How to install portref.txt

1) I downloaded the new portref.txt file.

2) I opened the file with WordPad then used: Save As type "Text - MS DOS Format".

3) I closed and then restarted TDS-3, and then it worked.

Note: the file has to be in your main TDS-3 directory.


How to work with the Portref-list:

Utilities > Port Reference
Then you can type a port-number (for example: 23) and click OK.
In the console you will get all the info about that port with respect to Trojans etc. that use that port.

07:20:41 [PortRef] 23: Telnet Protocol (RFC 854), WinGate, RAT: Fire HacKer, Tiny Telnet Server - TTS, Truva Atl, RTB666, TelnetPro 1.0, Swarm, Baron Night, AlphaDog, MMX, Net Coach, PEST, Manipulator Lite, Mind Control

You can also use it the other way around:

Utilities > Reverse Port Reference
Then you can type a name, for example: telnet
Click OK.
In the console you will get now all the info about ports with respect to telnet.

07:22:14 [Rev PortRef] 23 = Telnet Protocol (RFC 854), WinGate, RAT: Fire HacKer, Tiny Telnet Server - TTS, Truva Atl, RTB666, TelnetPro 1.0, Swarm, Baron Night, AlphaDog, MMX, Net Coach, PEST, Manipulator Lite, Mind Control
07:22:14 [Rev PortRef] 89 = SU-MIT-TG - SU/MIT Telnet Gateway
07:22:14 [Rev PortRef] 107 = RTELNET - Remote Telnet Service
07:22:14 [Rev PortRef] 513 = LOGIN - Remote Login via Telnet, RAT: Grlogin
07:22:14 [Rev PortRef] 992 = TELNETS - telnet Protocol over TLS/SSL, RAT: Snape
07:22:14 [Rev PortRef] 1342 = VMOTELNET - VMODEM telnet redirect
07:22:14 [Rev PortRef] 1618 = SKYTELNET - skyt
07:22:14 [Rev PortRef] 2564 = HP-3000-TELNET - HP 3000 NS/VT block mode telnet
07:22:14 [Rev PortRef] 11666 = RAT: H04x3r Telnet
07:22:14 [Rev PortRef] 34324 = RAT: Tiny Telnet Server, BigGluck, TN
07:22:14 [Rev PortRef] 65535 = HIPORT: up port telnet, RAT: RC1 trojan, **** Heep, Peeper, Iddono

Jooske
February 6th, 2004, 02:40 AM
Hope in future such databases are shared over the various DCS tools!

Rainwalker
February 6th, 2004, 03:49 PM
:)