×

Loading...

The different between netstat command and netstat port.

Netstat command is useful command in Win98 and NT (2k, XP). Use different parameter, you can find many information. It can provide TCP and UDP connection, open port and such things.
Netstat port is a NetBIOS protocol's port. NEtBios is a Microsoft Protocol for LAN; Netbios is base on Broadcasting rather than TCP/IP. Netbios most time use UDP to listen port and creat a connection. If you want to know Netbios protocol's status, you can use NBtstat.exe to check it. This command is very useful in check a IP confliction because you can use it find computers with the different "computer name" but use the same IP address.
Sign in and Reply Report

Replies, comments and Discussions:

  • 枫下家园 / 电脑用户 / 常用端口表
    本文发表在 rolia.net 枫下论坛1 tcpmux TCP Port Service Multiplexer 传输控制协议端口服务多路开关选择器
    2 compressnet Management Utility     compressnet 管理实用程序
    3 compressnet Compression Process    压缩进程
    5 rje Remote Job Entry          远程作业登录
    7 echo Echo               回显
    9 discard Discard            丢弃
    11 systat Active Users          在线用户
    13 daytime Daytime            时间
    17 qotd Quote of the Day         每日引用
    18 msp Message Send Protocol       消息发送协议
    19 chargen Character Generator      字符发生器
    20 ftp-data File Transfer [Default Data] 文件传输协议(默认数据口) 
    21 ftp File Transfer [Control]      文件传输协议(控制)
    22 ssh SSH Remote Login Protocol     SSH远程登录协议
    23 telnet Telnet             终端仿真协议
    24 ? any private mail system       预留给个人用邮件系统
    25 smtp Simple Mail Transfer       简单邮件发送协议
    27 nsw-fe NSW User System FE       NSW 用户系统现场工程师
    29 msg-icp MSG ICP            MSG ICP
    31 msg-auth MSG Authentication      MSG验证
    33 dsp Display Support Protocol     显示支持协议
    35 ? any private printer server     预留给个人打印机服务
    37 time Time               时间
    38 rap Route Access Protocol       路由访问协议
    39 rlp Resource Location Protocol    资源定位协议
    41 graphics Graphics           图形
    42 nameserver WINS Host Name Server   WINS 主机名服务
    43 nicname Who Is            "绰号" who is服务
    44 mpm-flags MPM FLAGS Protocol     MPM(消息处理模块)标志协议
    45 mpm Message Processing Module [recv] 消息处理模块 
    46 mpm-snd MPM [default send]      消息处理模块(默认发送口)
    47 ni-ftp NI FTP             NI FTP
    48 auditd Digital Audit Daemon      数码音频后台服务 
    49 tacacs Login Host Protocol (TACACS)  TACACS登录主机协议
    50 re-mail-ck Remote Mail Checking Protocol 远程邮件检查协议
    51 la-maint IMP Logical Address Maintenance IMP(接口信息处理机)逻辑地址维护
    52 xns-time XNS Time Protocol      施乐网络服务系统时间协议  
    53 domain Domain Name Server       域名服务器
    54 xns-ch XNS Clearinghouse       施乐网络服务系统票据交换
    55 isi-gl ISI Graphics Language     ISI图形语言
    56 xns-auth XNS Authentication      施乐网络服务系统验证
    57 ? any private terminal access     预留个人用终端访问
    58 xns-mail XNS Mail           施乐网络服务系统邮件
    59 ? any private file service      预留个人文件服务
    60 ? Unassigned             未定义
    61 ni-mail NI MAIL            NI邮件?
    62 acas ACA Services           异步通讯适配器服务
    63 whois+ whois+              WHOIS+
    64 covia Communications Integrator (CI) 通讯接口 
    65 tacacs-ds TACACS-Database Service   TACACS数据库服务
    66 sql*net Oracle SQL*NET        Oracle SQL*NET
    67 bootps Bootstrap Protocol Server   引导程序协议服务端
    68 bootpc Bootstrap Protocol Client   引导程序协议客户端
    69 tftp Trivial File Transfer      小型文件传输协议
    70 gopher Gopher             信息检索协议
    71 netrjs-1 Remote Job Service      远程作业服务
    72 netrjs-2 Remote Job Service      远程作业服务
    73 netrjs-3 Remote Job Service      远程作业服务
    74 netrjs-4 Remote Job Service      远程作业服务
    75 ? any private dial out service    预留给个人拨出服务
    76 deos Distributed External Object Store 分布式外部对象存储 
    77 ? any private RJE service      预留给个人远程作业输入服务
    78 vettcp vettcp             修正TCP?
    79 finger Finger             FINGER(查询远程主机在线用户等信息)
    80 http World Wide Web HTTP       全球信息网超文本传输协议
    81 hosts2-ns HOSTS2 Name Server     HOST2名称服务
    82 xfer XFER Utility           传输实用程序
    83 mit-ml-dev MIT ML Device       模块化智能终端ML设备
    84 ctf Common Trace Facility       公用追踪设备
    85 mit-ml-dev MIT ML Device       模块化智能终端ML设备
    86 mfcobol Micro Focus Cobol       Micro Focus Cobol编程语言
    87 ? any private terminal link      预留给个人终端连接
    88 kerberos Kerberos           Kerberros安全认证系统
    89 su-mit-tg SU/MIT Telnet Gateway    SU/MIT终端仿真网关
    90 dnsix DNSIX Securit Attribute Token Map DNSIX 安全属性标记图 
    91 mit-dov MIT Dover Spooler       MIT Dover假脱机
    92 npp Network Printing Protocol     网络打印协议
    93 dcp Device Control Protocol      设备控制协议
    94 objcall Tivoli Object Dispatcher   Tivoli对象调度
    95 supdup SUPDUP            
    96 dixie DIXIE Protocol Specification  DIXIE协议规范
    97 swift-rvf Swift Remote Virtural File Protocol 快速远程虚拟文件协议 
    98 tacnews TAC News           TAC(东京大学自动计算机?)新闻协议
    99 metagram Metagram Relay       
    101/tcp hostname NIC Host Name Server
    102/tcp iso-tsap ISO-TSAP Class 0
    103/tcp gppitnp Genesis Point-to-Point Trans Net
    104/tcp acr-nema ACR-NEMA Digital Imag. & Comm. 300
    105/tcp cso CCSO name server protocol
    105/tcp csnet-ns Mailbox Name Nameserver
    106/tcp 3com-tsmux 3COM-TSMUX
    107/tcp rtelnet Remote Telnet Service
    108/tcp snagas SNA Gateway Access Server
    109/tcp pop2 Post Office Protocol - Version 2
    110/tcp pop3 Post Office Protocol - Version 3
    111/tcp sunrpc SUN Remote Procedure Call
    112/tcp mcidas McIDAS Data Transmission Protocol
    113/tcp ident
    114/tcp audionews Audio News Multicast
    115/tcp sftp Simple File Transfer Protocol
    116/tcp ansanotify ANSA REX Notify
    117/tcp uucp-path UUCP Path Service
    118/tcp sqlserv SQL Services
    119/tcp nntp Network News Transfer Protocol
    120/tcp cfdptkt CFDPTKT
    121/tcp erpc Encore Expedited Remote Pro.Call
    122/tcp smakynet SMAKYNET
    123/tcp ntp Network Time Protocol
    124/tcp ansatrader ANSA REX Trader
    125/tcp locus-map Locus PC-Interface Net Map Ser
    126/tcp unitary Unisys Unitary Login
    127/tcp locus-con Locus PC-Interface Conn Server
    128/tcp gss-xlicen GSS X License Verification
    129/tcp pwdgen Password Generator Protocol
    130/tcp cisco-fna cisco FNATIVE
    131/tcp cisco-tna cisco TNATIVE
    132/tcp cisco-sys cisco SYSMAINT
    133/tcp statsrv Statistics Service
    134/tcp ingres-net INGRES-NET Service
    135/tcp epmap DCE endpoint resolution
    136/tcp profile PROFILE Naming System
    137/tcp netbios-ns NETBIOS Name Service
    138/tcp netbios-dgm NETBIOS Datagram Service
    139/tcp netbios-ssn NETBIOS Session Service
    140/tcp emfis-data EMFIS Data Service
    141/tcp emfis-cntl EMFIS Control Service
    142/tcp bl-idm Britton-Lee IDM
    143/tcp imap Internet Message Access Protocol
    144/tcp uma Universal Management Architecture
    145/tcp uaac UAAC Protocol
    146/tcp iso-tp0 ISO-IP0
    147/tcp iso-ip ISO-IP
    148/tcp jargon Jargon
    149/tcp aed-512 AED 512 Emulation Service
    150/tcp sql-net SQL-NET
    151/tcp hems HEMS
    152/tcp bftp Background File Transfer Program
    153/tcp sgmp SGMP
    154/tcp netsc-prod NETSC
    155/tcp netsc-dev NETSC
    156/tcp sqlsrv SQL Service
    157/tcp knet-cmp KNET/VM Command/Message Protocol
    158/tcp pcmail-srv PCMail Server
    159/tcp nss-routing NSS-Routing
    160/tcp sgmp-traps SGMP-TRAPS
    161/tcp snmp SNMP
    162/tcp snmptrap SNMPTRAP
    163/tcp cmip-man CMIP/TCP Manager
    164/tcp cmip-agent CMIP/TCP Agent
    165/tcp xns-courier Xerox
    166/tcp s-net Sirius Systems
    167/tcp namp NAMP
    168/tcp rsvd RSVD
    169/tcp send SEND
    170/tcp print-srv Network PostScript
    171/tcp multiplex Network Innovations Multiplex
    172/tcp cl/1 Network Innovations CL/1
    173/tcp xyplex-mux Xyplex
    174/tcp mailq MAILQ
    175/tcp vmnet VMNET
    176/tcp genrad-mux GENRAD-MUX
    177/tcp xdmcp X Display Manager Control Protocol
    178/tcp nextstep NextStep Window Server
    179/tcp bgp Border Gateway Protocol
    180/tcp ris Intergraph
    181/tcp unify Unify
    182/tcp audit Unisys Audit SITP
    183/tcp ocbinder OCBinder
    184/tcp ocserver OCServer
    185/tcp remote-kis Remote-KIS
    186/tcp kis KIS Protocol
    187/tcp aci Application Communication Interface
    188/tcp mumps Plus Five's MUMPS
    189/tcp qft Queued File Transport
    190/tcp gacp Gateway Access Control Protocol
    191/tcp prospero Prospero Directory Service
    192/tcp osu-nms OSU Network Monitoring System
    193/tcp srmp Spider Remote Monitoring Protocol
    194/tcp irc Internet Relay Chat Protocol
    195/tcp dn6-nlm-aud DNSIX Network Level Module Audit
    196/tcp dn6-smm-red DNSIX Session Mgt Module Audit Redir
    197/tcp dls Directory Location Service
    198/tcp dls-mon Directory Location Service Monitor
    199/tcp smux SMUX
    200/tcp src IBM System Resource Controller
    201/tcp at-rtmp AppleTalk Routing Maintenance
    202/tcp at-nbp AppleTalk Name Binding
    203/tcp at-3 AppleTalk Unused
    204/tcp at-echo AppleTalk Echo
    205/tcp at-5 AppleTalk Unused
    206/tcp at-zis AppleTalk Zone Information
    207/tcp at-7 AppleTalk Unused
    208/tcp at-8 AppleTalk Unused
    209/tcp qmtp The Quick Mail Transfer Protocol
    210/tcp z39.50 ANSI Z39.50
    211/tcp 914c/g Texas Instruments 914C/G Terminal
    212/tcp anet ATEXSSTR
    214/tcp vmpwscs VM PWSCS
    215/tcp softpc Insignia Solutions
    216/tcp CAIlic Computer Associates Int'l License Server
    217/tcp dbase dBASE Unix
    218/tcp mpp Netix Message Posting Protocol
    219/tcp uarps Unisys ARPs
    220/tcp imap3 Interactive Mail Access Protocol v3
    221/tcp fln-spx Berkeley rlogind with SPX auth
    222/tcp rsh-spx Berkeley rshd with SPX auth
    223/tcp cdc Certificate Distribution Center
    242/tcp direct Direct
    243/tcp sur-meas Survey Measurement
    244/tcp dayna Dayna
    245/tcp link LINK
    246/tcp dsp3270 Display Systems Protocol
    247/tcp subntbcst_tftp SUBNTBCST_TFTP
    248/tcp bhfhs bhfhs
    256/tcp rap RAP
    257/tcp set Secure Electronic Transaction
    258/tcp yak-chat Yak Winsock Personal Chat
    259/tcp esro-gen Efficient Short Remote Operations
    260/tcp openport Openport
    263/tcp hdap HDAP
    264/tcp bgmp BGMP
    280/tcp http-mgmt http-mgmt
    309/tcp entrusttime EntrustTime
    310/tcp bhmds bhmds
    312/tcp vslmp VSLMP
    315/tcp dpsi DPSI
    316/tcp decauth decAuth
    317/tcp zannet Zannet
    321/tcp pip PIP
    344/tcp pdap Prospero Data Access Protocol
    345/tcp pawserv Perf Analysis Workbench
    346/tcp zserv Zebra server
    347/tcp fatserv Fatmen Server
    348/tcp csi-sgwp Cabletron Management Protocol
    349/tcp mftp mftp
    351/tcp matip-type-b MATIP Type B
    351/tcp bhoetty bhoetty (added 5/21/97)
    353/tcp ndsauth NDSAUTH
    354/tcp bh611 bh611
    357/tcp bhevent bhevent
    362/tcp srssend SRS Send
    365/tcp dtk DTK
    366/tcp odmr ODMR
    368/tcp qbikgdp QbikGDP
    371/tcp clearcase Clearcase
    372/tcp ulistproc ListProcessor
    373/tcp legent-1 Legent Corporation
    374/tcp legent-2

    木马的:
    15=NETSTAT PORT
    21=Blade Runner, Doly Trojan, Fore, FTP trojan, Invisible FTP, Larva, ebEx, WinCrash
    22=SSH PORT
    23=Tiny Telnet Server
    25=Shtrilitz Stealth, Terminator, WinPC, WinSpy, Kuang2 0.17A-0.30, Antigen, Email Password Sender, Haebu Coceda, Kuang2, ProMail trojan, Tapiras
    31=Agent 31, Hackers Paradise, Masters Paradise
    41=DeepThroat
    53=DOMAIN PORT
    58=DMSetup
    63=WHOIS PORT
    79=Firehotcker
    80=Executor 110=ProMail trojan
    90=DNS PORT
    101=HOSTNAME PORT
    110=POP3 PORT
    121=JammerKillah
    137=NETBIOS Name Service PORT
    138=NETBIOS Datagram Service PORT
    139=NETBIOS Session Service PORT
    194=IRC PORT
    406=IMSP PORT
    421=TCP Wrappers
    456=Hackers Paradise
    531=Rasmin
    555=Ini-Killer, Phase Zero, Stealth Spy
    666=Attack FTP, Satanz Backdoor
    911=Dark Shadow
    999=DeepThroat
    1001=Silencer, WebEx
    1011=Doly Trojan
    1012=Doly Trojan
    1024=NetSpy
    1045=Rasmin
    1090=Xtreme
    1095=Rat
    1097=Rat
    1098=Rat
    1099=Rat
    1170=Psyber Stream Server
    1170=Voice
    1234=Ultors Trojan
    1243=BackDoor-G, SubSeven
    1245=VooDoo Doll
    1349=BO DLL
    1492=FTP99CMP
    1600=Shivka-Burka
    1807=SpySender
    1080=SOCKS PORT
    1981=Shockrave
    1999=BackDoor 1.00-1.03
    2001=Trojan Cow
    2023=Ripper
    2115=Bugs
    2140=Deep Throat
    2140=The Invasor
    2565=Striker
    2583=WinCrash
    2801=Phineas Phucker
    3024=WinCrash
    3129=Masters Paradise
    3150=Deep Throat, The Invasor
    3700=Portal of Doom
    4092=WinCrash
    4567=File Nail
    4590=ICQTrojan
    5000=Bubbel, Back Door Setup, Sockets de Troie
    5001=Back Door Setup, Sockets de Troie
    5321=Firehotcker
    5400=Blade Runner
    5401=Blade Runner
    5402=Blade Runner
    5550=JAPAN Trojan-xtcp
    5555=ServeMe
    5556=BO Facil
    5557=BO Facil
    5569=Robo-Hack
    5742=WinCrash
    6400=The Thing
    6666=IRC SERVER PORT
    6667=IRC CHAT PORT
    6670=DeepThroat
    6711=SubSeven
    6771=DeepThroat
    6776=BackDoor-G, SubSeven
    6939=Indoctrination
    6969=GateCrasher
    6969=Priority
    7000=Remote Grab
    7300=NetMonitor
    7301=NetMonitor
    7306=NetMonitor
    7307=NetMonitor
    7308=NetMonitor
    7626=G_Client(冰河)
    7789=Back Door Setup, ICKiller
    9872=Portal of Doom
    9873=Portal of Doom
    9874=Portal of Doom
    9875=Portal of Doom
    9989=iNi-Killer
    10067=Portal of Doom
    10167=Portal of Doom
    10520=Acid Shivers
    10607=Coma
    11000=Senna Spy
    11223=Progenic trojan
    12223=Hack?9 KeyLogger
    12345=GabanBus, NetBus, Pie Bill Gates, X-bill
    12346=GabanBus, NetBus, X-bill
    12361=Whack-a-mole
    12362=Whack-a-mole
    12631=WhackJob
    13000=Senna Spy
    16969=Priority
    20001=Millennium
    20034=NetBus 2 Pro
    21544=GirlFriend
    22222=Prosiak
    23456=Evil FTP, Ugly FTP
    26274=Delta Source
    29891=The Unexplained
    30029=AOL Trojan 30100=NetSphere 1.27a, NetSphere 1.31
    30101=NetSphere 1.31, NetSphere 1.27a
    30102=NetSphere 1.27a, NetSphere 1.31
    30103=NetSphere 1.31
    30303=Sockets de Troie
    31337=Baron Night, BO client, BO2, Bo Facil, BackFire, Back Orifice, DeepBO
    31338=NetSpy DK 31338=Back Orifice, DeepBO
    31339=NetSpy DK
    31666=BOWhack
    31785=Hack Attack
    31787=Hack Attack
    31789=Hack Attack
    31791=Hack Attack
    33333=Prosiak
    34324=BigGluck, TN
    40412=The Spy
    40421=Agent 40421, Masters Paradise
    40422=Masters Paradise
    40423=Masters Paradise
    40426=Masters Paradise
    47262=Delta Source
    50505=Sockets de Troie
    50766=Fore
    53001=Remote Windows Shutdown
    54321=School Bus .69-1.11
    60000=Deep Throat
    61466=Telecommando
    65000=Devil
    69123=ShitHeep  更多精彩文章及讨论,请光临枫下论坛 rolia.net
    • Good, thanks
    • 极好!已收下!谢谢!
    • 时间口不是13吗?怎么改37了?daytime和time有什么不一样吗
      • daytime protocol: RFC867; time protocol: RFC868
        • thank you!
    • 15端口的NETSTAT怎么是木马端口,我常在DOS下用这个命令查机器的连接情况,请专家解惑!谢谢!
      • 谁能帮我说说这个不懂的问题?非常感谢!!
      • Please Check which type Protocol?TCP or UDP. Other, there are many Trojan program occur the same port to comunication.
        • 谢谢你!我不是说看到NETSTAT的通信,这个应该是WIN98下自带的一个网络状态查询程序,是不是跟这文章里讲的在15端口上运行的NETSTAT是两回事?
          • The different between netstat command and netstat port.
            Netstat command is useful command in Win98 and NT (2k, XP). Use different parameter, you can find many information. It can provide TCP and UDP connection, open port and such things.
            Netstat port is a NetBIOS protocol's port. NEtBios is a Microsoft Protocol for LAN; Netbios is base on Broadcasting rather than TCP/IP. Netbios most time use UDP to listen port and creat a connection. If you want to know Netbios protocol's status, you can use NBtstat.exe to check it. This command is very useful in check a IP confliction because you can use it find computers with the different "computer name" but use the same IP address.
            • Eh, no. Netstat port (tcp/15) has nothing to do with NETBIOS. It's a standard service that is listenning on tcp/15. When a connection to tcp/15 occurs,
              the service will output the result of netstat command.

              To make the service work, edit /etc/inetd.conf and add the following line:

              netstat stream tcp nowait nobody /usr/bin/netstat /usr/bin/netstat -f inet

              on your unix machine, then do a 'kill -HUP `cat /var/run/inetd.pid`'. Then from another machine, telnet to the unix host on tcp port 15. You'll get an output of 'netstat -f inet'.

              As simple as that.
              • 谢谢二位的解释,那么,上面那篇转的文章怎么把15 port 归于木马端口呢?
                • 不知道。那篇转的文章还把21, 22, 23, 25, 53, etc. 都当作木马端口呢。
                  • 哦,您这么说我就明白了,谢谢:)
                    • 很正常啊,伪装成标准段口,如25,表面上你是看不出来的,一切工作正常,但是所有向外的邮件都被截获了。
    • 好东东
    • 谢谢!