Magueta
09-25-2003, 11:57 PM
Hey all,
What I'm about to tell you is happening on a Windows 2K machine but I don't belong to a Windows group so I'm giving it a try here. I'm sure the problem isn't specific to Windows but it might have something to do with it. I do "netstat -a" on my system and everything makes sense except for the following connections
TCP amd1800x2:3095 free-gallery-hosting.dickworshipperz.com:http ESTABLISHED
TCP amd1800x2:3966 amd1800x2:0 LISTENING
TCP amd1800x2:4855 free-gallery-hosting.dickworshipperz.com:http ESTABLISHED
TCP amd1800x2:5000 free-gallery-hosting.dickworshipperz.com:http ESTABLISHED
I don't know why they're connected to my system and I've never visited that site, in fact if I type it into the browser nothing gets served up except for an error message saying I'm not authorized to access anything. A port scan reveals a server with the following ports listening: 21, 22, 25, 80, 110, 135, 137, 138, 139, 445, 587. The 13x ports suggest it's a Windows machine but the ssh and smtp suggest otherwise. Anyway, I suppose that's not really important, what is important is why the connection remains established even when I sever all internet access from the Windows machine, is that normal? Could there be something wrong with Zonealarm? Why is there a connection to me from this place anyway? I've found Google had 2 or 3 connections to me from their port 80 and it had been over 3 or 4 hours since I had last visited their site. I was running Kazaa and Gnucleus which are filesharing programs so there were plenty of other connections but they all disappeared when I shut down the software and stopped all internet activity. Also, I look at the lights on my cable modem and there's no traffic either way and when I do a netstat the connection is still there. Anyone have any suggestions as to why this connection might persist? Should I be worried?
Joe
What I'm about to tell you is happening on a Windows 2K machine but I don't belong to a Windows group so I'm giving it a try here. I'm sure the problem isn't specific to Windows but it might have something to do with it. I do "netstat -a" on my system and everything makes sense except for the following connections
TCP amd1800x2:3095 free-gallery-hosting.dickworshipperz.com:http ESTABLISHED
TCP amd1800x2:3966 amd1800x2:0 LISTENING
TCP amd1800x2:4855 free-gallery-hosting.dickworshipperz.com:http ESTABLISHED
TCP amd1800x2:5000 free-gallery-hosting.dickworshipperz.com:http ESTABLISHED
I don't know why they're connected to my system and I've never visited that site, in fact if I type it into the browser nothing gets served up except for an error message saying I'm not authorized to access anything. A port scan reveals a server with the following ports listening: 21, 22, 25, 80, 110, 135, 137, 138, 139, 445, 587. The 13x ports suggest it's a Windows machine but the ssh and smtp suggest otherwise. Anyway, I suppose that's not really important, what is important is why the connection remains established even when I sever all internet access from the Windows machine, is that normal? Could there be something wrong with Zonealarm? Why is there a connection to me from this place anyway? I've found Google had 2 or 3 connections to me from their port 80 and it had been over 3 or 4 hours since I had last visited their site. I was running Kazaa and Gnucleus which are filesharing programs so there were plenty of other connections but they all disappeared when I shut down the software and stopped all internet activity. Also, I look at the lights on my cable modem and there's no traffic either way and when I do a netstat the connection is still there. Anyone have any suggestions as to why this connection might persist? Should I be worried?
Joe