Server 2003 - Upnp problem.

Associate
Joined
12 Mar 2006
Posts
376
Hello all,

I have server 2003 setup on a box at home with apache, ssh, and other various things running.

Lately I’ve noticed that I can not access the web server from the net.

I’ve looked at the logs in the router (Linksys WAG354G) and found under the 'upnp' bit that something from the server is mapping ext port:42193 to the internal port:80 directed at the web server.

Then 15 seconds later the mapping is deleted. This then leaves the original ext port:80 to int port:80 unmapped and no longer accessible from the outside world :confused:

The router log says the request came from the server's IP. I have no idea what software is asking for this port and it seems a tad suspicious.

Currently I’ve had to disable upnp on the router, which is causing msn and outlook on other computers to lose connectivity.

Any idea's how to stop this getting mapped?

Regards Laser402
 
Care to tell me how?

Thats kind of the problem, all it has is apache, ssh, nod32, webui on it.

Cant find anything in the logs on the server and have turned off upnp on all the apps I know.
 
Last edited:
Yes it is suspicious.

Have turned upnp off on the router now so it can’t access it. But is an issue for a few other computers with ports etc.

Had Nod32 do full scans 3 times with every filter on and 100% clean.

Does ZoneAlarm run as a service? just as it’s a server it isn’t usually logged on.

Many thanks

Laser402
 
Changed Apache's listening port and still gets unmapped.

It seems to be following what ever port apache is on.

Apache is using php 5. Could be someone hacking? (wasted effort nothing of any value except to me)
 
Back
Top Bottom