<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Port 3158 in Security</title>
<link>http://www.dslreports.com/forum/r18408506</link>
<description></description>
<language>en</language>
<pubDate>Thu, 04 Dec 2008 13:12:56 EDT</pubDate>
<lastBuildDate>Thu, 04 Dec 2008 13:12:56 EDT</lastBuildDate>

<item>
<title>Re: Port 3158</title>
<link>http://www.dslreports.com/forum/remark,18409375</link>
<description><![CDATA[<A HREF="/useremail/u/1459613"><b>The Snowman</b></A> : <br><br>    At this point I am not totally convinced the Trojan has been completely removed.....an would suggest you do a Hijack This .....<br><br>   will drop back here later.....to see what you post back]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18409375</guid>
<pubDate>Mon, 28 May 2007 15:20:53 EDT</pubDate>
</item>

<item>
<title>Re: Port 3158</title>
<link>http://www.dslreports.com/forum/remark,18409305</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : <br><br>    DEFINITELY YOU SHOULD READ THIS   <br><br>   &raquo;<A HREF="http://www.securityfocus.com/infocus/1605" >www.securityfocus.com/infocus/1605</A><br><br>>Detecting and Containing IRC-Controlled Trojans: When Firewalls, AV, and IDS Are Not Enough>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18409305</guid>
<pubDate>Mon, 28 May 2007 15:09:27 EDT</pubDate>
</item>

<item>
<title>Re: Port 3158</title>
<link>http://www.dslreports.com/forum/remark,18409231</link>
<description><![CDATA[<A HREF="/useremail/u/1459613"><b>The Snowman</b></A> : <br><br>   If in fact you do have Trillian.....and you have used it for File Transfer...then perhaps thats were the Trojan came from,  but no matter....there appears NO REASON for that particular Port to be doing anything....unless someone else here can offer a reason.......<br>  My suggestion would be to remove Trillian if in fact you do have it installed....if its the Agent in all this then removing it should shut down that port....<br>   Are you ABSOLUTELY SURE you removed that Trojan ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18409231</guid>
<pubDate>Mon, 28 May 2007 14:56:41 EDT</pubDate>
</item>

<item>
<title>Re: Port 3158</title>
<link>http://www.dslreports.com/forum/remark,18409168</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : <br><br>Cerulean Studios, LLC<br><br>Trillian  (instant messenger)<br><br>&raquo;<A HREF="http://www.ceruleanstudios.com/" >www.ceruleanstudios.com/</A><br><br>============================================================<br>Here are the ports that Trillian uses by default: <br><br>MSN<br>Connection: 1863<br>File Transfer: 6891<br><br>ICQ<br>Connection: 5190<br>File Transfer: Dynamic unless specified<br><br>AIM<br>Connection: 5190<br>File Transfer: 5190<br>Direct Connect: 4443<br><br>Yahoo<br>Connection: 5050<br>File Transfer: 80<br>Webcam: 5100<br><br>&raquo;<A HREF="http://www.ceruleanstudios.com/support/index.php?s=T_PORTS&p=CONTACT_ROOT/C_T" >www.ceruleanstudios.com/support/&middot;&middot;&middot;ROOT/C_T</A><br><br>------------------------------------------------------------<br><br>Here are the default ports that Trillian uses:<br><br>MSN<br>Connection: 1863<br>File Transfer: 6891<br><br>ICQ<br>Connection: 5190<br>File Transfer: Dynamic unless specified<br><br>AIM<br>Connection: 5190<br>File Transfer: 5190<br><br>Yahoo<br>Connection: 5050<br>File Transfer: 80<br>Webcam: 5100<br><br>Jabber:<br>Connection: 5222<br>File Transfer: (automatic by default)<br><br>&raquo;<A HREF="http://forums.ceruleanstudios.com/showthread.php?threadid=35182" >forums.ceruleanstudios.com/showt&middot;&middot;&middot;id=35182</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18409168</guid>
<pubDate>Mon, 28 May 2007 14:44:30 EDT</pubDate>
</item>

<item>
<title>Re: Port 3158</title>
<link>http://www.dslreports.com/forum/remark,18408506</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Port 3158 = "SmashTV Protocol", whatever that is.<br><br>But it could be a trojan as well.  Is the connection inbound or outbound?  Can you post the output of netstat -ano?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18408506</guid>
<pubDate>Mon, 28 May 2007 12:45:52 EDT</pubDate>
</item>

<item>
<title>Re: Port 3158</title>
<link>http://www.dslreports.com/forum/remark,18408253</link>
<description><![CDATA[<A HREF="/useremail/u/744566"><b>dannyboy 950</b></A> : The next thing to consider is do these people have any buisness connecting to you or you to them? Do they even know they are trying to connect to you?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18408253</guid>
<pubDate>Mon, 28 May 2007 11:52:34 EDT</pubDate>
</item>

<item>
<title>Re: IP address connection</title>
<link>http://www.dslreports.com/forum/remark,18407968</link>
<description><![CDATA[<A HREF="/useremail/u/620986"><b>DR_JAY</b></A> : Thanks Amy<br><br>boy do I feel like an idiot  :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18407968</guid>
<pubDate>Mon, 28 May 2007 10:51:42 EDT</pubDate>
</item>

<item>
<title>Re: IP address connection</title>
<link>http://www.dslreports.com/forum/remark,18407917</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : WhoIs info:  &raquo;<A HREF="/whois/70.42.52.11">/whois/70.42.52.11</A><br>CustName:   Cerulean Studios, LLC<br>Address:    475 Federal Road<br>Address:    Unit F<br>City:       Brookfield<br>StateProv:  CT<br>PostalCode: 06804<br>Country:    US<br>RegDate:    2006-03-09<br>Updated:    2006-03-09<br><br>-amy-<br><SMALL>--<br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18407917</guid>
<pubDate>Mon, 28 May 2007 10:35:28 EDT</pubDate>
</item>

<item>
<title>Port 3158</title>
<link>http://www.dslreports.com/forum/remark,18407904</link>
<description><![CDATA[<A HREF="/useremail/u/620986"><b>DR_JAY</b></A> : Hi All,<br><br>Over the weekend I was using my laptop and unfortunately I found a virus/trojan named "dna.exe" which was slowing down my computer.  I did a "netstat" in the Windows XP command prompt and my laptop was trying to connect to over 100 computers.  I removed this virus and the laptop is running fine.<br><br>However...<br><br>I noticed that there is a connection to port: 3158 and the IP address is 70.42.52.11 .  I tried doing a trace route and unfortunately it didn't give me much information as to where is the location of this IP address is coming from.  Even after I do a clean reboot, my laptop keeps connecting to that IP address and the same port.<br><br>The question I ask is port: 3158 a potential security hole or is it a safe service program that I am unaware that my laptop keeps executing?<br><br>If need anymore details, I am more than happy to provide it if there is any good Samaritan willing to assist me.<br><br>Thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18407904</guid>
<pubDate>Mon, 28 May 2007 10:31:57 EDT</pubDate>
</item>

</channel>
</rss>
