防火牆埠(上)(轉載)

anttyhuang發表於2007-06-28

--- 轉載---:

(其他相關資訊可以見:)

網路埠及其詳解------需要分析防火牆日誌的朋友可以參考一下按埠號可分為3大類:1)公認埠(Well Known Ports):從01023,它們緊密繫結(binding)於一些服務。通常這些埠的通訊明確表明了某種服務的協議。例如:80埠實際上總是HTTP通訊。2)註冊埠(Registered Ports):從102449151。它們鬆散地繫結於一些服務。也就是說有許多服務繫結於這些埠,這些埠同樣用於許多其它目的。例如:許多系統處理動態埠從1024左右開始。3)動態和/或私有埠(Dynamic and/or Private Ports):從4915265535。理論上,不應為服務分配這些埠。實際上,機器通常從1024起分配動態埠。但也有例外:SUNRPC埠從32768開始。
0
通常用於分析作業系統。這一方法能夠工作是因為在一些系統中“0”是無效埠,當你試圖使用一種通常的閉合埠連線它時將產生不同的結果。一種典型的掃描:使用IP地址為0.0.0.0,設定ACK位並在乙太網層廣播。

[@more@]1 tcpmux TCP Port Service Multiplexer 傳輸控制協議埠服務多路開關選擇器
2
 compressnet Management Utility   compressnet 管理實用程式
3
 compressnet Compression Process   壓縮排程
5
 rje Remote Job Entry     遠端作業登入
7
 echo Echo       回顯
9
 discard Discard     丟棄
11
 systat Active Users     線上使用者
13
 daytime Daytime      時間
17
 qotd Quote of the Day    每日引用
18
 msp Message Send Protocol    訊息傳送協議
19
 chargen Character Generator   字元發生器
20
 ftp-data File Transfer[Default Data]  檔案傳輸協議(預設資料口) 
21
 ftp File Transfer[Control]    檔案傳輸協議(控制)
22
 ssh SSH Remote Login Protocol   SSH遠端登入協議
23
 telnet Telnet     終端模擬協議
24
 any private mail system    預留給個人用郵件系統
25
 smtp Simple Mail Transfer    簡單郵件傳送協議
27
 nsw-fe NSW User System FE    NSW 使用者系統現場工程師
29
 msg-icp MSG ICP      MSG ICP
31
 msg-auth MSG Authentication   MSG驗證
33
 dsp Display Support Protocol   顯示支援協議
35
 any private printer server   預留給個人印表機服務
37
 time Time       時間
38
 rap Route Access Protocol    路由訪問協議
39
 rlp Resource Location Protocol   資源定位協議
41
 graphics Graphics     圖形
42
 nameserver WINS Host Name Server   WINS 主機名服務
43
 nicname Who Is     "綽號" who is服務
44
 mpm-flags MPM FLAGS Protocol   MPM(訊息處理模組)標誌協議
45
 mpm Message Processing Module [recv]  訊息處理模組 
46
 mpm-snd MPM [default send]    訊息處理模組(預設傳送口)
47
 ni-ftp NI FTP     NI FTP
48
 auditd Digital Audit Daemon   數碼音訊後臺服務49 tacacs Login Host Protocol (TACACS)  TACACS登入主機協議50 re-mail-ck Remote Mail Checking Protocol 遠端郵件檢查協議[未結束]
51
 la-maint IMP Logical Address Maintenance  IMP(介面資訊處理機)邏輯地址維護
52
 xns-time XNS Time Protocol    施樂網路服務系統時間協議
53
 domain Domain Name Server    域名伺服器
54
 xns-ch XNS Clearinghouse     施樂網路服務系統票據交換 55 isi-gl ISI Graphics Language   ISI圖形語言
56
 xns-auth XNS Authentication   施樂網路服務系統驗證
57
 ? any private terminal access   預留個人用終端訪問
58
 xns-mail XNS Mail     施樂網路服務系統郵件
59
 any private file service    預留個人檔案服務
60
 Unassigned      未定義
61
 ni-mail NI MAIL      NI郵件?
62
 acas ACA Services     非同步通訊介面卡服務
63
 whois+ whois+      WHOIS+
64
 covia Communications Integrator (CI)  通訊介面 
65
 tacacs-ds TACACS-Database Service   TACACS資料庫服務
66
 sql*net Oracle SQL*NET    Oracle SQL*NET
67
 bootps Bootstrap Protocol Server   載入程式協議服務端
68
 bootpc Bootstrap Protocol Client   載入程式協議客戶端
69
 tftp Trivial File Transfer    小型檔案傳輸協議
70
 gopher Gopher     資訊檢索協議
71
 netrjs-1 Remote Job Service   遠端作業服務
72
 netrjs-2 Remote Job Service   遠端作業服務
73
 netrjs-3 Remote Job Service   遠端作業服務
74
 netrjs-4 Remote Job Service   遠端作業服務
75
 any private dial out service   預留給個人撥出服務
76 deos
 Distributed External Object Store 分散式外部物件儲存 
77
 any private RJE service     預留給個人遠端作業輸入服務
78
 vettcp vettcp     修正TCP?
79
 finger Finger     查詢遠端主機線上使用者等資訊
80
 http World Wide Web HTTP     全球資訊網超文字傳輸協議 81 hosts2-ns HOSTS2 Name Server   HOST2名稱服務
82
 xfer XFER Utility     傳輸實用程式
83
 mit-ml-dev MIT ML Device     模組化智慧終端ML裝置
84
 ctf Common Trace Facility    公用追蹤裝置
85
 mit-ml-dev MIT ML Device     模組化智慧終端ML裝置
86
 mfcobol Micro Focus Cobol    Micro Focus Cobol程式語言
87
 any private terminal link   預留給個人終端連線
88
 kerberos Kerberos     Kerberros安全認證系統
89
 su-mit-tg SU/MIT Telnet Gateway   SU/MIT終端模擬閘道器
90
 dnsix DNSIX Securit Attribute Token Map  DNSIX 安全屬性標記圖91 mit-dov MIT Dover Spooler    MIT Dover假離線
92
 npp Network Printing Protocol   網路列印協議
93
 dcp Device Control Protocol   裝置控制協議
94
 objcall Tivoli Object Dispatcher   Tivoli物件排程
95
 supdup  SUPDUP    
96
 dixie DIXIE Protocol Specification   DIXIE協議規範
97
 swift-rvfSwift Remote Virtural File Protocol)快速遠端虛擬檔案協議98 tacnews TAC News      TAC新聞協議
99
 metagram Metagram Relay    
100
 newacct [unauthorized use]
101=NIC Host Name Server
102=ISO-TSAP
103=Genesis Point-to-Point Trans Net
104=ACR-NEMA Digital Imag. & Comm. 300
105=Mailbox Name Nameserver
106=3COM-TSMUX3com-tsmux
107=Remote Telnet Service
108=SNA Gateway Access Server
109=Post Office Protocol - Version 2
110=Post Office Protocol - Version 3
111=SUN RPC
112=McIDAS Data Transmission Protocol
113=Authentication Service
114=Audio News Multicast
115=Simple File Transfer Protocol
116=ANSA REX Notify
117=UUCP Path Service
118=SQL Servicessqlserv
119=Network News Transfer Protocol
120=CFDPTKTcfdptkt
121=Encore Expedited Remote Pro.Call
122=SMAKYNETsmakynet
123=Network Time Protocol
124=ANSA REX Trader
125=Locus PC-Interface Net Map Ser
126=Unisys Unitary Login
127=Locus PC-Interface Conn Server
128=GSS X License Verification
129=Password Generator Protocol
130=cisco FNATIVE
131=cisco TNATIVE
132=cisco SYSMAINT
133=Statistics Service
134=INGRES-NET Service
135=Location Service
136=PROFILE Naming System
137=NETBIOS Name Service
138=NETBIOS Datagram Service
139=NETBIOS Session Service
140=EMFIS Data Service
141=EMFIS Control Service
142=Britton-Lee IDM
143=Interim Mail Access Protocol v2
144=NewSnews
145=UAAC Protocoluaac
146=ISO-IP0iso-tp0
147=ISO-IPiso-ip
148=CRONUS-SUPPORT
149=AED 512 Emulation Service
150=SQL-NETsql-net
151=HEMShems
152=Background File Transfer Program
153=SGMPsgmp
154=NETSCnetsc-prod
155=NETSCnetsc-dev
156=SQL Service
157=KNET/VM Command/Message Protocol
158=PCMail Serverpcmail-srv
159=NSS-Routingnss-routing
160=SGMP-TRAPSsgmp-traps
161=SNMP
162=SNMP TRAP
163=CMIP/TCP Manager
164=CMIP/TCP Agent
165=Xeroxxns-courier
166=Sirius Systems
167=NAMPnamp
168=RSVDrsvd
169=Send
170=Network PostScript
170=Network PostScript
171=Network Innovations Multiplex
172=Network Innovations CL/1
173=Xyplexxyplex-mux
174=MAILQ
175=VMNET
176=GENRAD-MUXgenrad-mux
177=X Display Manager Control Protocol
178=NextStep Window Server
179=Border Gateway Protocol
180=Intergraphris
181=Unifyunify
182=Unisys Audit SITP
183=OCBinderocbinder
184=OCServerocserver
185=Remote-KIS
186=KIS Protocolkis
187=Application Communication Interface
188=Plus Five
401=Uninterruptible Power Supply
402=Genie Protocol
403=decapdecap
404=ncednced
405=ncldncld
406=Interactive Mail Support Protocol
407=Timbuktutimbuktu
408=Prospero Resource Manager Sys. Man.
409=Prospero Resource Manager Node Man.
410=DECLadebug Remote Debug Protocol
411=Remote MT Protocol
412=Trap Convention Port
413=SMSPsmsp
414=InfoSeekinfoseek
415=BNetbnet
416=Silverplattersilverplatter
417=Onmuxonmux
418=Hyper-Ghyper-g
419=Arielariel1
420=SMPTEsmpte
421=Arielariel2
422=Arielariel3
423=IBM Operations Planning and Control Start
424=IBM Operations Planning and Control Track
425=ICADicad-el
426=smartsdpsmartsdp
427=Server Location
429=OCS_AMU
430=UTMPSDutmpsd
431=UTMPCDutmpcd
432=IASDiasd
433=NNSPnnsp
434=MobileIP-Agent
435=MobilIP-MN
436=DNA-CMLdna-cml
437=comscmcomscm
439=dasp, Thomas Obermair
440=sgcpsgcp
441=decvms-sysmgtdecvms-sysmgt
442=cvc_hostdcvc_hostd
443=https
444=Simple Network Paging Protocol
445=Microsoft-DS
446=DDM-RDBddm-rdb
447=DDM-RFMddm-dfm
448=DDM-BYTEddm-byte
449=AS Server Mapper
450=TServertserver
512=exec, Remote process execution
513=login, remote login
514=cmd, exec with auto auth.
514=syslog
515=Printer spooler
516=Unassigned
517=talk
519=unixtime
520=extended file name server
521=Unassigned
522=Unassigned
523=Unassigned
524=Unassigned
526=newdate
530=rpc courier
531=chatconference
532=readnewsnetnews
533=for emergency broadcasts
539=Apertus Technologies Load Determination
540=uucp
541=uucp-rlogin
542=Unassigned
543=klogin
544=kshell
545=Unassigned
546=Unassigned
547=Unassigned
548=Unassigned
549=Unassigned
550=new-who
551=Unassigned
552=Unassigned
553=Unassigned
554=Unassigned
555=dsf
556=remotefs
557-559=rmonitor
560=rmonitord
561=dmonitor
562=chcmd
563=Unassigned
564=plan 9 file service
565=whoami
566-569 Unassigned
570=demonmeter
571=udemonmeter
572-599 Unassigned ipc server
600=Sun IPC server
607=nqs
606=Cray Unified Resource Manager
608=Sender-Initiated/Unsolicited File Transfer
609=npmp-trapnpmp-trap
610=npmp-localnpmp-local
611=npmp-guinpmp-gui
634=ginadginad
666=Doom Id Software
704=errlog copy/server daemon
709=EntrustManager
729=IBM NetView DM/6000 Server/Client
730=IBM NetView DM/6000 send/tcp
731=IBM NetView DM/6000 receive/tcp
741=netGWnetgw
742=Network based Rev. Cont. Sys.
744=Flexible License Manager
747=Fujitsu Device Control
748=Russell Info Sci Calendar Manager
749=kerberos administration
751=pump
752=qrh
754=send
758=nlogin
759=con
760=ns
762=quotad
763=cycleserv
765=webster
767=phonephonebook
769=vid
771=rtip
772=cycleserv2
774=acmaint_dbd
775=acmaint_transd
780=wpgs
786=Concertconcert
800=mdbs_daemon
996=Central Point Software
997=maitrd
999=puprouter
1023=Reserved
1024=Reserved
1025=network blackjack
1030=BBN IAD
1031=BBN IAD

來自 “ ITPUB部落格 ” ,連結:http://blog.itpub.net/10292431/viewspace-921822/,如需轉載,請註明出處,否則將追究法律責任。

相關文章