一台经常用的电脑,最近发现安全疑点。
早上起床,然后就在Windows运行下面CMD,然后在命令行Netstat -ano >d:\1.txt 获得一个文本文件,具体内容如下:
Active Connections
Proto Local Address Foreign Address State PID
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1052
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:8080 0.0.0.0:0 LISTENING 160
TCP 0.0.0.0:8442 0.0.0.0:0 LISTENING 160
TCP 0.0.0.0:8443 0.0.0.0:0 LISTENING 160
TCP 0.0.0.0:10243 0.0.0.0:0 LISTENING 1220
TCP 127.0.0.1:1026 127.0.0.1:32000 ESTABLISHED 160
TCP 127.0.0.1:1044 127.0.0.1:5152 FIN_WAIT_2 3084
TCP 127.0.0.1:5152 0.0.0.0:0 LISTENING 120
TCP 127.0.0.1:5152 127.0.0.1:1044 CLOSE_WAIT 120
TCP 127.0.0.1:8005 0.0.0.0:0 LISTENING 160
TCP 127.0.0.1:32000 0.0.0.0:0 LISTENING 2012
TCP 127.0.0.1:32000 127.0.0.1:1026 ESTABLISHED 2012
TCP 192.168.1.243:139 0.0.0.0:0 LISTENING 4
TCP 192.168.1.243:1038 222.69.93.105:80 CLOSE_WAIT 160
TCP 192.168.1.243:1039 222.69.93.105:80 CLOSE_WAIT 160
TCP 192.168.1.243:1040 192.168.1.245:139 TIME_WAIT 0
TCP 192.168.1.243:1054 60.186.134.120:8090 TIME_WAIT 0
TCP 192.168.1.243:1061 114.89.161.27:8090 TIME_WAIT 0
TCP 192.168.1.243:1066 114.82.74.194:8090 FIN_WAIT_2 1220
TCP 192.168.1.243:1067 114.95.53.93:8090 FIN_WAIT_2 1220
TCP 192.168.1.243:1068 61.170.209.139:8090 SYN_SENT 1220
TCP 192.168.1.243:1069 114.91.202.98:8090 FIN_WAIT_2 1220
TCP 192.168.1.243:1070 218.82.153.6:8090 FIN_WAIT_2 1220
TCP 192.168.1.243:1072 59.54.100.240:8090 TIME_WAIT 0
TCP 192.168.1.243:1076 120.34.72.110:8090 TIME_WAIT 0
TCP 192.168.1.243:1077 122.232.165.65:8090 TIME_WAIT 0
TCP 192.168.1.243:1079 180.152.25.103:8090 TIME_WAIT 0
TCP 192.168.1.243:1082 59.174.107.11:8090 TIME_WAIT 0
TCP 192.168.1.243:1085 60.180.104.97:8090 TIME_WAIT 0
TCP 192.168.1.243:1087 123.170.207.91:8090 TIME_WAIT 0
TCP 192.168.1.243:1088 125.107.77.171:8090 TIME_WAIT 0
TCP 192.168.1.243:1090 27.188.18.134:8090 TIME_WAIT 0
TCP 192.168.1.243:1092 222.70.166.6:8090 TIME_WAIT 0
TCP 192.168.1.243:1093 114.89.84.102:8090 TIME_WAIT 0
TCP 192.168.1.243:1095 222.72.107.75:8090 SYN_SENT 1220
TCP 192.168.1.243:1097 222.214.129.68:8090 TIME_WAIT 0
TCP 192.168.1.243:1098 113.71.215.53:8090 TIME_WAIT 0
TCP 192.168.1.243:1102 222.65.51.218:8090 FIN_WAIT_2 1220
TCP 192.168.1.243:1103 58.41.32.36:8090 SYN_SENT 1220
TCP 192.168.1.243:1104 116.235.162.242:8090 FIN_WAIT_2 1220
TCP 192.168.1.243:1110 60.166.162.118:8090 SYN_SENT 1220
TCP 192.168.1.243:1113 222.89.35.110:8090 ESTABLISHED 1220
UDP 0.0.0.0:445 *:* 4
UDP 0.0.0.0:1028 *:* 1532
UDP 0.0.0.0:1043 *:* 3084
UDP 0.0.0.0:3600 *:* 1532
UDP 0.0.0.0:3601 *:* 1220
UDP 0.0.0.0:9200 *:* 1220
UDP 0.0.0.0:10243 *:* 1220
UDP 0.0.0.0:18050 *:* 160
UDP 127.0.0.1:123 *:* 1196
UDP 127.0.0.1:1025 *:* 1532
UDP 127.0.0.1:1047 *:* 3084
UDP 127.0.0.1:1900 *:* 2092
UDP 192.168.1.243:123 *:* 1196
UDP 192.168.1.243:137 *:* 4
UDP 192.168.1.243:138 *:* 4
UDP 192.168.1.243:1900 *:* 2092
能者上~
需要得到的结果是:
1..这种系统,对老手是否可以裸机使用是否存在重大的危险(如果有,请提出方案)
2.需要做哪些方面的防范
3.是否存在重大的危险(如果有,请提出方案)
个人目标是裸机
~
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; znwb6600; .NET CLR 1.1.4322)