DS3 interfaces on a Cisco 7000 series router.

DS3 interfaces on a Cisco 7000 series router.

Network Security Auditing Tools

Modified 20 August 2009

Topics on this page:


Startling statistics about distributed denial of service and spam


A list of TCP ports used by common attacks. Use this to make sense of all those entries in your firewall logs. See the latest package of the Snort package for far more details. See http://www.dshield.org/ for reports on current scanning patterns.

Legitimate TCP Ports Commonly Probed For Exploits

21 FTP
22 SSH
23 TELNET
25 SMTP
53 DNS
79 FINGER
80 HTTP
109 POPv2
110 POPv3
111 portmap
113 AUTH/identd
119 NNTP
139 SMB (Windows NT and later)
143 IMAP
445 SMB (Windows 2000 and later)
513 rsh
514 rlogin
515 LPD (print spooler)
1433 Microsoft SQL Server
3128 squid (web/ftp proxy/cache)
3389 Terminal Server (Windows 2000 and later)
5632 PCAnywhere
5555 Napster
6000 X11
6666 Napster
6699 Napster
7777 Napster
8875 Napster
8080 Common web proxy port
8888 Napster

TCP and UDP ports used for remote system control.

Port on target
Port Protocol Software
22TCPpcAnywhere
22UDPpcAnywhere
407TCPTimbuktu
407UDPTimbuktu
799TCPRemotely Possibly / ControlIT
800TCPRemotely Possibly / ControlIT
800UDPRemotely Possibly / ControlIT
1494TCPCitrix ICA
1494UDPCitrix ICA
2000TCPRemotely Anywhere
2001TCPRemotely Anywhere
3127-3198TCPMydoom
3389TCPWindows Terminal Server
4899TCPRAdmin
5800TCPVNC (and 5801, ...)
5900TCPVNC (and 5901, ...)
5631TCPpcAnywhere
5632TCPpcAnywhere
5632UDPpcAnywhere
43188TCPReachOut
65301TCPpcAnywhere

Suspicious TCP and UDP Ports. Most of these are used for Windows worms and Trojans, a few are used for denial-of-service (DOS) and distributed denial-of-service (DDOS) attacks.

Port on target
Port Protocol Attack
21TCP ADMw0rm
23TCP w00w00
23TCP r00t
23TCP rewt
23TCP sm4ck
23TCP HidePak
23TCP HideSource
79TCP CDK
80TCP BackOriface
139TCP QAZ Worm
139TCP WinNuke DOS
146TCP Infector
445TCP Various Windows worms
555TCP PhaseZero
617TCP arkiea DOS
666TCP SatansBackdoor
666TCP BackConstruction
1054TCP ACKcmdC
2140UDP DeepThroat
2773TCP Sub7 trojan keystroke logger
3150UDP DeepThroat
3344TCP Matrix
3345TCP Matrix
4120UDP DeepThroat
2589TCP Dagger
5401TCP BackConstruction
5402TCP BackConstruction
5714TCP WinCrash
6789TCP Doly
6838UDP mstream DDOS
6969TCP GateCrasher
7215TCP Sub7 trojan remote terminal (aka "The Matrix")
7597TCP QAZ Worm
10498UDP mstream DDOS
12345TCP netbus
12346TCP netbus
12754TCP mstream DDOS
15104TCP mstream DDOS
18753UDP shaft DDOS
20034TCP netbus
20432TCP shaft DDOS
20433TCP shaft DDOS
21554TCP GirlFriendaccess
23476TCP DonaldDick
27374TCP Sub7 trojan
27444UDP Trin00
27665TCP Trin00
30100TCP NetSphere
30101TCP NetSphere
30102TCP NetSphere
31335UDP Trin00
31337UDP Back Oriface
31785UDP HackAttack
54238TCP Sub7 trojan remote application eavesdropper
54320UDP Back Oriface 2000 (aka BO2k)
54321UDP Back Oriface 2000 (aka BO2k)
Port on attacker
Port Protocol Attack
80TCP ACKcmdC
110TCP QAZ Worm
1000-1300TCP Infector
1024TCP SatansBackdoor
2589TCP Dagger
3344TCP Matrix
3345TCP Matrix
5031TCP NetMetro
5032TCP NetMetro
16959TCP Subseven trojan
27374TCP Subseven trojan
60000UDP DeepThroat

Analysis Tools

Analysis tools fit into major categories. Executive summary: use Nmap for port scanning and version detection, use OpenVAS or Nessus for vulnerability scanning.

Port Scanners

Vulnerability Scanners

Vulnerability scanners can also provide warnings about apparent risks due to buggy network server software. Note that some just make assumptions based on banner details, while others may attempt an exploit to see if it works. Also, some of the commercial Windows-specific ones may give false-negative errors if run without remote administrative privileges:

Lists of links to many network scanners in various categories: http://www.networkintrusion.co.uk/

Host-based analysis. So port 80 is open, and the banner says it's Apache 2.0.45, but now you must answer further question: What binary program has that port open, what shared libraries is it using, and what other files, sockets, and pipes does that process have open? And should I have complete confidence in all of this?

Other network scanners are found at:


The top 100 network security tools — short descriptions and links to get them: http://sectools.org/index.html

Use Snort to detect scans and other network attacks: http://www.snort.org/

hping2 lets you send craft and send customized ICMP packets: http://www.kyuzz.org/antirez/hping/

icmpenum — distributed ICMP-based host enumerator and network census-taker. http://linux.softpedia.com/get/System/Networking/Icmpenun-25545.shtml

Gibson Research Corporation has an interesting site — it will scan your host for you and report the results: http://www.grc.com/

More tool FTP sites:

Other tools:


DNS Authentication

Earlier versions of DNS are susceptible to DNS spoofing and other abuses. To fix your DNS, make sure you're running the latest version of BIND, available at http://www.isc.org.

Then make sure you configure it correctly: http://www.team-cymru.org/ReadingRoom/Documents/secure-bind-template.html


Automatic Teller Machine (ATM) Security

The ATM Marketplace site has a "buyer's guide" that lets you compare features, and in some cases it reveals some details of network interface, CPU, and even OS. http://www.atmmarketplace.com/


Back to the main Security Page


Home Unix/Linux Networking Infosec Travel Technical Radio Site Map Contact
Use /bin/vi! Manipulate images with ImageMagick! Hosted on OpenBSD
Hosted on Apache Valid XHTML 1.1! Valid CSS!
© Bob Cromwell Mar 2010. Created with /bin/vi and ImageMagick, hosted on OpenBSD with Apache.    Root password available here, privacy policy here.