Port Details - Port 135

Jan 10 7,234 Jan 11 6,754 Jan 12 6,661 Jan 13 6,480 Jan 14 6,505 Jan 15 6,555 Jan 16 6,356 Jan 17 6,713 Jan 18 6,710 Jan 19 6,657 Jan 20 6,527 Jan 21 6,782 Jan 22 6,729 Jan 23 6,812 Jan 24 7,216 Jan 25 7,017 Jan 26 6,716 Jan 27 6,976 Jan 28 6,901 Jan 29 6,226 Jan 30 2,349 Jan 31 3,637 Feb 01 6,793 Feb 02 6,595 Feb 03 6,567 Feb 04 6,465 Feb 05 6,456 Feb 06 7,249 Feb 07 8,050 Feb 08 7,208 Feb 09 5,601 Jan 10 75,055 Jan 11 75,389 Jan 12 75,206 Jan 13 75,647 Jan 14 75,202 Jan 15 75,006 Jan 16 75,126 Jan 17 74,874 Jan 18 75,407 Jan 19 74,628 Jan 20 75,026 Jan 21 10,258 Jan 22 74,885 Jan 23 74,405 Jan 24 74,275 Jan 25 74,209 Jan 26 74,981 Jan 27 72,036 Jan 28 9,917 Jan 29 57,755 Jan 30 73,258 Jan 31 70,376 Feb 01 74,357 Feb 02 73,636 Feb 03 9,850 Feb 04 9,626 Feb 05 41,784 Feb 06 13,946 Feb 07 15,535 Feb 08 74,755 Feb 09 72,009
[show ascii data]
  • Start Date:
  • End Date:
  • Port:
  • Left Graph:
  • Right Graph:
  • Show Range:Yes No

Port Information

ProtocolServiceName
tcpepmapDCE endpoint resolution
tcploc-srvNCS local location broker
udpepmapDCE endpoint resolution
udploc-srvLocation Service
[get complete service list]

User Comment

Submitted ByDate
Comment
Richard Akerman2009-10-04 18:45:22
It appears this port is being used as the starting point of Windows "NET SEND" spam messages that use the Messenger service. A connection is made to port 135 to determine what high-numbered port the Messenger service is running on.
xentheon2009-10-04 18:45:22
Looks like msblast is on it's way... If you manage to sniff any of the packets you will see one of these messages: "billy gates why do you make this possible?" "Stop making money and fix your software!!" Mblast can be found in c:\windows\system32\ as well as: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ And the 'patch' from windows at: http://microsoft.com/downloads/details.aspx?FamilyId=2354406C-C5B6-44AC-9532-3DE40F69C074&displaylang=en
a1fa2009-10-04 18:45:22
Hi, Today (9-17-2003), I have noticed several computers scanning external IP addresses on UDP:135. The computers are doing ascending IP scan, similar to Blaster. This is the payload : "CKAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA!" More on this can be found at : http://www.securityfocus.com/news/6975 Does anybody else have similar problems? Do you know what worm is this? join #inSecurity @ FreeNode a1fa
VIPER X2005-06-12 05:22:59
Some well known Root kits also use this port to transmit data back to home base and download more malware. I also suspect may be an entry point for some root kit /malware for un patched systems or systems that did not patch correctly.
Phil Brammer2003-12-17 17:41:44
Please see http://www.nipc.gov/warnings/advisories/2003/Potential7302003.htm for the latest on an RPC exploit against Microsoft operating systems. Also, from the vendor: http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp Please ensure that all unnecessary TCP/UDP ports are blocked and particularly TCP 135, TCP 139, TCP 445, or any other specifically configured RPC port. Unapproved CVE #: CAN-2003-0352 (As of July 31st, 2003)
Marcus H. Sachs, SANS Institute2003-10-09 22:32:52
SANS Top-20 Entry: W5 Windows Remote Access Services http://www.sans.org/top20/index1.php#w5 Remote Procedure Calls Many versions of Microsoft operating systems (Windows NT 4.0, 2000, XP, and 2003) provide an inter-process communication mechanism that allows programs running on one host to execute code on remote hosts. Three vulnerabilities have been published that would allow an attacker to run arbitrary code on susceptible hosts with Local System privileges. One of these vulnerabilities was exploited by Blaster/MSblast/LovSAN and Nachi/Welchia worms. There are also other vulnerabilities that would allow attackers to mount Denial of Service attacks against RPC components.
Jolly2003-10-09 22:32:20
Port of entry for RPC bug exploiting Worms like lovSan, msblaster on unfixed Windows 32bit systems. Potentialy very dangerous.
2003-10-09 22:32:06
port used by Blaster32 worm for propogation
oog2003-08-26 23:35:00
Port 135 is essential to the functionality of Active Directory and Microsoft Exchange mail servers, among other things.
Faiz Ahmad Shuja2003-08-13 20:00:45
http://www.cert.org/advisories/CA-2003-20.html W32/Blaster worm The W32/Blaster worm exploits a vulnerability in Microsoft's DCOM RPC interface as described in VU#568148 and CA-2003-16. Upon successful execution, the worm attempts to retrieve a copy of the file msblast.exe from the compromising host. Once this file is retrieved, the compromised system then runs it and begins scanning for other vulnerable systems to compromise in the same manner. In the course of propagation, a TCP session to port 135 is used to execute the attack. However, access to TCP ports 139 and 445 may also provide attack vectors and should be considered when applying mitigation strategies. Microsoft has published information about this vulnerability in Microsoft Security Bulletin MS03-026. http://microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp
Brian Porter2003-08-10 00:30:30
CVE: CAN-2003-0352 Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message. http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0352
Johannes Ullrich2003-01-24 18:42:15
This port is used for Windows RPC. Windows RPC allows for the display of popup messages.
Add a comment

CVE Links

CVE #Description
CVE-2003-352 "Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0
CVE-2003-528 "Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter
CVE-2003-533 "Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a
CVE-2003-717 "The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message
CVE-2003-813 "A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request