Rvsmon does not close socket

Discussion in 'Returnil releases' started by Adric, Jul 22, 2011.

Thread Status:
Not open for further replies.
  1. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    795
    I noticed that after Returnil checks for updates, rsvmon does not close the socket and is always in Close_Wait status and sometimes there is more than one entry. Why is rvsmon holding the connection(s) open?

    Al
     
  2. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
    what are using to monitor state of sockets?
     
  3. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    795
    TCPView from Sysinternals and Current Ports from Nirsoft.

    Al
     
  4. Coldmoon

    Coldmoon Returnil Moderator

    Joined:
    Sep 18, 2006
    Posts:
    2,981
    Location:
    USA
    Hi Adric,
    The service is simply waiting for a command (remote management in a network), a message (Ex; updated build available for download, new license assigned, etc), or could be sending potential malware file and/or suspicious file activity reports to the AI analysis server.

    Mike
     
  5. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    795
    Yes, but Returnil is always holding the connection(s) open. My understanding of CLOSE_WAIT was that the local side received a FIN from the other side and the OS is waiting for the program at the local end to actually close its connection which it is not doing. Would it not be better to close the socket rather than leaving the socket open for infrequent data?

    Al
     
    Last edited: Jul 22, 2011
  6. Coldmoon

    Coldmoon Returnil Moderator

    Joined:
    Sep 18, 2006
    Posts:
    2,981
    Location:
    USA
    Good question. Let me check with the development team to get a more detailed reply on this.

    Mike
     
  7. Coldmoon

    Coldmoon Returnil Moderator

    Joined:
    Sep 18, 2006
    Posts:
    2,981
    Location:
    USA
    Hi Adric,
    I have a reply from the engineering team on this:

    Mike
     
Thread Status:
Not open for further replies.