Port Details - Port 3389

Aug 07 946 Aug 08 853 Aug 09 1,172 Aug 10 1,121 Aug 11 1,094 Aug 12 1,113 Aug 13 1,059 Aug 14 947 Aug 15 843 Aug 16 1,104 Aug 17 1,088 Aug 18 1,099 Aug 19 1,023 Aug 20 1,036 Aug 21 871 Aug 22 813 Aug 23 1,047 Aug 24 1,039 Aug 25 996 Aug 26 1,023 Aug 27 1,012 Aug 28 912 Aug 29 952 Aug 30 1,023 Aug 31 983 Sep 01 1,021 Sep 02 972 Sep 03 958 Sep 04 861 Sep 05 802 Sep 06 858 Aug 07 19,785 Aug 08 84,915 Aug 09 18,214 Aug 10 80,471 Aug 11 28,587 Aug 12 49,351 Aug 13 27,168 Aug 14 16,835 Aug 15 60,059 Aug 16 15,848 Aug 17 39,439 Aug 18 18,553 Aug 19 76,189 Aug 20 29,028 Aug 21 17,109 Aug 22 22,580 Aug 23 30,652 Aug 24 55,135 Aug 25 91,643 Aug 26 91,709 Aug 27 54,303 Aug 28 50,588 Aug 29 90,070 Aug 30 66,395 Aug 31 36,358 Sep 01 27,913 Sep 02 81,533 Sep 03 98,965 Sep 04 72,677 Sep 05 77,913 Sep 06 84,472
[show ascii data]
  • Start Date:
  • End Date:
  • Port:
  • Left Graph:
  • Right Graph:
  • Show Range:Yes No

Port Information

ProtocolServiceName
tcpms-term-servicesMS Terminal Services
udpms-term-servicesMS Terminal Services
[get complete service list]

User Comment

Submitted ByDate
Comment
Scott Fendley2005-07-17 03:13:54
Potential exploit of Remote Desktop Protocol on Windows Systems. Please see http://isc.sans.org/diary.php?date=2005-07-15 and http://isc.sans.org/diary.php?date=2005-07-16 for more information.
jeff bryner2002-11-09 21:16:59
See http://www.xato.net/reference/xato-112001-01.txt for a discussion on how terminal services source ip address can be easily spoofed; so don't trust event log entries of connection attempts. Jeff.
Add a comment

CVE Links

CVE #Description
CVE-2001-540 "Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389."