    Roger A. Grimes (author of the famous book "Malicious Mobile Code: Virus Protection for Windows") has just released a new article which is the main story in this month's Security Administrator magazine. Possibly the first article of its kind to approach this subject matter, it looks into port-to-process mapping/port enumeration, and compares 11 programs that achieve this (including Port Explorer, OpenPorts, TCPView, FPort and more).

    Roger's conclusion: "The strongest contender in this comparative review is DiamondCS, with its GUI utility Port Explorer and its command-line tool OpenPorts. Sysinternals' TCPView is a good backup choice, if you can avoid the stability problems I experienced on NT. Foundstone's Fport is a good alternative to OpenPorts in the command-line port-enumerator field. But if you perform network security or administration for a living, you should have a copy of Port Explorer."

    Full Article:

    i notice that he says "if" you can avoid "stability" problems.. the program(s) need to be safe..
  9. Bowserman

    Bowserman Infrequent Poster

    He is referring to Sysinternals TCPView:

  10. redwolfe_98

    redwolfe_98 Registered Member

    should i delete my post? :) sorry, i don't know how i got confused, there.. i was on my way out, and was rushing.
    Hi all,

    Keep in mind the difference between a portmapper, i.e. port-to-process mapper and a portscanner. Those you mentioned are all portscanners (except for netcat which still isn't a port-to-process mapper either).
    A port scanner will allow you to connect to a machine (remote or local one) and possibly get or provoque a reaction when it encounters a listening service. In some cases, that reaction will reveal what service is running and this will reveal to the administrator of the examined PC what application is running there.
    However, for a long time the question "a scan of my system (eith er with such a portscanner or with an AT scanner that examines open ports) revealed port xy listening. Do I have to worry?" has been asked very very frequently. Probably it wasn't possible to solicit a telling answer from the service by connecting directly to the port - after all, nothing about the protocol in use is known.
    That is where Port-To-process mappers come in. You launch them and they tell you "your port xy is being held open by your application yz.exe" - and then you can scan that with a malware scanner, google for info on it, kill and delete it or whatever.

    i was impressed with "openports", and i am interested in port explorer, but i read another thread where someone said uninstalling the trial version messed up their system so that they could no longer connect to the internet.. is it safe to install (and uninstall) port explorer?
    i hadn't any pb doing it before installing my purchased version ;)
    Hi redwolfe_98

    The beta testers have installed and uninstalled many many times without any issues and many many users have installed it have uninstalled (for instance for upgrades) without any issue.

    That being said, there is always a chance during any install/uninstall of any program that there may be issues but these would likely arise from very strange and unique circumstances due to a problematic registry or something similar.

    If you like openports you will love PE :D
    That problem is due to the corruption of Winsock in windows, and although it doesn't happen very can sometimes.

    Definately give the trial a go, but if you want to be safe you could download the appropriate Winsock repair utility for your OS from here just to play it safe (scroll to the bottom of the page).

    Jade :).
    Yes with that utility you can fix Winsock corruption issues easily.

    Unless you have other LSP software installed (unlikely but possible) you won't run into any issues, and even if something else is installed that uses the LSP unless something major goes wrong everything will still work fine when you uninstall Port Explorer.