Should I be worried ? [Archive] - SpeedGuide.net Broadband Community

View Full Version : Should I be worried ?


whitestar
04-24-05, 02:11 AM
:rtfm:

HI,
I am just starting out in the world of server admin and have read so ooo many books and did sooo many courses my head is starting to explode

what i do waht to know is should I be worried about traffic like this


Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\******>netstat

Active Connections

Proto Local Address Foreign Address State
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:1399 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:1573 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:2122 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:2127 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:2340 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:2353 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:2964 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:3130 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:3132 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:3186 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:3710 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:3953 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:4333 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:4351 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:4545 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:4775 ESTABLISHED
TCP whitestar:epmap cnh195149217182.surfer.cnh.at:4790 ESTABLISHED


C:\Documents and Settings\*******>

whitestar
04-26-05, 02:43 PM
It seems they are still trying to connect ?
any ideas ? :irate:

Respice
05-08-05, 11:49 AM
do a netstat -an. This will give you IP Addresses and allow you to track the traffic better. As an admin your should be worried that there are numerous connections established to your server that you don't recognize on several random high ports.

Do you have access to a firewall? Is this for your company or home?