Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > Port Explorer
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 10th, 2006, 08:36 AM
twomile twomile is offline
Infrequent Poster
 
Join Date: Mar 2006
Posts: 2
Default pe, ports, tasks and my little brain

Dear Brainy Ones,

First, thanks for any help, in advance, and excuse my ignorance. I’m getting a VERY small idea of what I’m doing, but I’ve still got a LONG LONG way to go …. so many things to learn, so little time! System is XP home SP2.

First an easy one ….. are “sockets” and “ports” identical?

Now to the fun bit ... I got PE up and running OK, that wasn't too hard. Then I re-booted to see what my pc "at rest” looked like, but I noticed some strange things like......

1. PE listed lsass twice as pid 624, once on UDP 500 and once on UDP 4500. So why 2 ports for one process? … I thought one process = one port.

2. But …. when I right clicked onto “What is lsass 624?” it said it had FOUR sockets open, not just the two listed on the screenshot. Why?

3. Svchost appeared 4 times (PID 880 TCP 135 - PID 940 UDP 123 - PID 940 UDP 1029 - PID 1100 UDP 1900)... OK, this is probably not unusual, but same deal as above ......... right clicking on svchost pid 880 TCP 135 it says it had two sockets open, but only one was listed on the screenshot.

4. Tried to get more info on the svchosts by typing tasklist in “run … start” but it doesn’t work .. it can’t find the tasklist file. Maybe because the operating system isn’t in English?

5. Then I noticed Task manager showed not 4 but SIX svchosts running … seems a lot. Why don’t they show on PE (maybe because they aren’t using ports?), and why is one of them 19meg and the others around 3-4 meg?

Hope someone can help me with these (probably dumb) questions. Oh, and I got plenty more where they came from!!!!!

cheers

twomile
  #2  
Old March 10th, 2006, 09:50 AM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re: pe, ports, tasks and my little brain

Hi there Twomiles and welcome to the forum!

You probably noticed only the ports with outside internet access are displayed?
svchost can be anything, scanners, other applications, etc.
A socket is shown when using a port, a process can have several sockets open. UDP and TCP. You'll notice lots of times if you have the netstat sockets showing a TCP port has an UDP port of the same numer.
(netstat might show as *system)
Which tasklist file you mean? The file log?
Which language is your system?

If you want to see what is happening on a socket of process you could enable the socket spy and see what data traffic goes there. Don't leave it on very long time as that thing can grow fast with a busy socket or process!

I think you'll find lots of additional info in the helpfile, which gives lots of interesting background info!
__________________
Jooske
"o_o"
  #3  
Old March 11th, 2006, 02:50 AM
CrazyM's Avatar
CrazyM CrazyM is offline
Firewall Moderator
 
Join Date: Feb 2002
Location: BC, Canada
Posts: 2,433
Default Re: pe, ports, tasks and my little brain

Hi twomile

... and welcome to Wilders

Quote:
Originally Posted by twomile
1. PE listed lsass twice as pid 624, once on UDP 500 and once on UDP 4500. So why 2 ports for one process? … I thought one process = one port.
one port = one process would probably be more accurate. A port can only have one process bound to it, but a process can use multiple ports.

Quote:
4. Tried to get more info on the svchosts by typing tasklist in “run … start” but it doesn’t work .. it can’t find the tasklist file. Maybe because the operating system isn’t in English?
Did you try tasklist /svc at the commond prompt?
ie. run > cmd > (then in commond promt) > tasklist /svc

Quote:
5. Then I noticed Task manager showed not 4 but SIX svchosts running … seems a lot. Why don’t they show on PE (maybe because they aren’t using ports?), and why is one of them 19meg and the others around 3-4 meg?
It is not unusual to have many instances of svchost, it is sort of a catchall for a number of processes. Running the above tasklist /svc in the command prompt will show what is running under the various instances. If you cannot get that to work you could try something like Process Explorer from Sysinternals which will show you that and alot more.

Regards,

CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks."
- Bruce Schneier

Last edited by CrazyM : March 11th, 2006 at 04:35 AM.
  #4  
Old March 15th, 2006, 12:57 PM
twomile twomile is offline
Infrequent Poster
 
Join Date: Mar 2006
Posts: 2
Default Re: pe, ports, tasks and my little brain

Thanks Jooske, thanks CrazyM !!!!!

Probably you go crazy hearing the same dumb questions again and again but believe me, having some help is REALLY appreciated.

By tasklist I meant .......... c:\tasklist /svc > ........... but this gives me something like the following message (it's Italian, Jooske) ......... "tasklist" is not recognised as an internal or external command, executable programme or batch file.

But anyway I downloaded Process Explorer instead... wow, works really well .... that's a lot of info there... it'll take me a few minutes to learn it

Already I have learned from Process Explorer why one svchost is so big .... it's got about 20 services running from it!

I'm still not clear what the difference between a port and a socket is!!!!! Does "socket" just mean "port being used"? So in general a file can spawn several processes, each process (pid) can have several ports, and ............. each port can have several sockets open ? ? ?
thanks very much for your help

twomile
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > Port Explorer « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:25 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums