OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: P2P Networking and port 3531

From: Brian Eckman (eckmanumn.edu)
Date: Wed Jul 09 2003 - 12:59:41 CDT


James Lay wrote:
> Hey all!
>
> Real quick...saw this today on my network:
>
> P2PNetworking.exe had udp and tcp port 3531 open. Packet caps of tcp
(only
> in ascii though :() show:
> KK
> CDN0/0
>
> Googling didn't bring up much, so I thought I'd see if anyone has
seen this
> kind of activity before. Thanks!
>
> James

3531/tcp and 3531/udp are used by PeerEnabler, a Joltid product (as you
mentioned, the application name is P2PNetworking.exe). This product is
bundled with KaZaA Media Desktop 2.5 Beta.

Googling 3531/tcp will lead you to Joltid if you check a few links.

Brian
--
Brian Eckman
Security Analyst
OIT Security and Assurance
University of Minnesota

"There are 10 types of people in this world. Those who
understand binary and those who don't."

----------------------------------------------------------------------------
Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
world's premier technical IT security event! 10 tracks, 15 training sessions,
1,800 delegates from 30 nations including all of the top experts, from CSO's to
"underground" security specialists. See for yourself what the buzz is about!
Early-bird registration ends July 3. This event will sell out. www.blackhat.com
----------------------------------------------------------------------------