Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [unisog] Re: Port 109 Mystery

From: Buck Buchanan <lbuchana(at)csc.com>
Date: Thu Mar 13 2003 - 09:01:20 EST

Hi,

Loki <loki@fatelabs.com> writes:

>This may have been something you tried, but looking at that path, it
...
>>On Wed, 2003-03-12 at 11:54, Douglas Brown wrote:
...
>> 220 winlogon -> 109 TCP \??\C:\WINNT\system32\winlogon.exe

According to "Developing Windows NT Device Drivers - A Programmer's Handbook", by Dekker and Newcomer: \??\ is "the directory of all named devices available for CreateFile". When a program tries to open C: \WINNT\system32\winlogon.exe, "C:" is translated to "\??\C:" by the Win32 subsystem.

Since fport normally does not display the "\??\" prefix, I am wondering if this might be a clue to how winlogon.exe was run.

B Cing U

Buck


Do you need help?X

<Pre>Lose another weekend managing your IDS? Take back your personal time.
15-day free trial of StillSecure Border Guard.</Pre> <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A> Received on Thu Mar 13 11:23:54 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:00 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library