codejunkie Posted September 16, 2004 Posted September 16, 2004 (edited) I have been getting this message about every 5 mins its driving my crazy "[181.1] Inbound DCE BIND to potentially vulnerable RPC DCOM interface attempt detected"Is there a new virus/backdoor that is using these ports, I am running SP2!the app that is svchost.exe that its coming into. The port is 135Port 1026 is open when I ran the sercurity check on symantecand svchost.exe is listing on ports135, 1029, 1030, 67, 68, 53, 1032, 1089, 4001, 4002, 4003, 4004, 2440, 2441I have blocked everthing that it can do at the momentOther ports that have been detected as open are80, 135, 443, 1723I am running a webserver from this PC so that 80 and 443. then theres the VPN 1723so why is 135 open? Edited September 16, 2004 by codejunkie
CoffeeFiend Posted September 16, 2004 Posted September 16, 2004 There is no reason that I can think of why you would want that port to be open to the outside world. Your firewall should be blocking that, if not, perhaps it's time to look for another one?
The Unicorn Posted September 16, 2004 Posted September 16, 2004 Info about port 135 can be found on http://www.grc.com/port_135.htm.Not sure when this was updated though. Could be preSP2.
codejunkie Posted September 16, 2004 Author Posted September 16, 2004 theres no problem with the Firewall I just want to know why I am getting so meny hits, but seem there is more out going trafic thats beening blocked then incoming, thats why I think I have a virus but Nortons online checker didnt find anything nore did NOD32.And its like I said I have SP2 the only think I have used lately is the JPEG fix for Visual Studio 2003 and Office 2000, Windows didnt need it. other than nothing has changed
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now