Check Port Status Windows

Windows 7 Forums is the largest help and support community, providing friendly help and advice for Microsoft Windows 7 Computers such as Dell, HP, Acer, Asus or a custom build. Hi All I would like to know if there is a way I can test if a specific port is open on an IP address and if my PC can connect to that port?

Check Port Status Windows

Checks that Port 80 is available for use.

Autodesk Vault Server needs port 80 to be free for successful installation and operation. If this check fails, another application is using port 80.
  1. From the Windows Start menu, select Run.
  2. In the Run dialog box, enter: cmd.
  3. Click OK.
  4. In the command window, enter: netstat -ano
  5. A list of active connections is displayed. Locate the active connection that is using local address 0.0.0.0:80 and note the process ID (PID) number. For example:
    Proto Local Address Foreign Address State PID
    TCP
    1. 0.0.0:80
    1. 0.0.0:0
    LISTENING 1924
  6. Start Windows Task Manager and select the Processes tab.
  7. If the PID column is not displayed, from the View menu, select Select Columns. In the Select Columns dialog, turn on the PID (Process Identifier) check box and then click OK.
  8. Locate the process matching the PID that is using 0.0.0.0:80.
  9. Make sure that it is safe to shut down the process and then shut it down.
Windows

For more information, see Microsoft Knowledge Base Article 281336: 'How to determine which program uses or blocks specific transmission control protocol ports in Windows':

Netstat, the TCP/IP networking utility, has a simple set of options and identifies a computer’s listening ports, along with incoming and outgoing network connections. This data can be very helpful if you’re trying to resolve a malware issue or diagnose a security problem.

I have to admit, I much prefer graphical user interfaces when it comes to working on a computer. I’ve never been a big fan of command line tools, but occasionally some, such as Netstat, do come into their own.

Another reason I find Netstat such a useful tool is that it can be found on almost any computer by default, from Unix and Linux machines through to Windows and Macs. The fact you don’t have to install and run a separate diagnostic tool can be a life saver when dealing with a client’s PC or a quarantined machine.

Every open port on your computer is an entry point that can be exploited to gain covert access. So if you need to know what connections a machine has to the internet and what services may be open and running, Netstat can quickly tell you.

Let me explain how to Netstat command in Windows. First, just open a command prompt window and type:

netstat -an

The -a parameter lists all the computer’s connections and listening ports, while the -n parameter displays addresses and port numbers in numerical format. A typical (truncated) result from Netstat -an looks like this:

Active Connections

Proto Local AddressForeign AddressState
TCP 0.0.0.0:210.0.0.0:0LISTENING
TCP 0.0.0.0:250.0.0.0:0LISTENING
TCP 0.0.0.0:800.0.0.0:0LISTENING
TCP 0.0.0.0:1350.0.0.0:0LISTENING
TCP 0.0.0.0:4430.0.0.0:0LISTENING
TCP 0.0.0.0:4450.0.0.0:0LISTENING
TCP 0.0.0.0:10350.0.0.0:0LISTENING
TCP 0.0.0.0:33510.0.0.0:0LISTENING
TCP 127.0.0.1:10400.0.0.0:0LISTENING
TCP 127.0.0.1:10490.0.0.0:0LISTENING
TCP 127.0.0.1:1059127.0.0.1:27015ESTABLISHED
TCP 127.0.0.1:10850.0.0.0:0LISTENING
TCP 127.0.0.1:14340.0.0.0:0LISTENING
TCP 127.0.0.1:51520.0.0.0:0LISTENING
TCP 127.0.0.1:5152127.0.0.1:3414CLOSE_WAIT

The first column (proto stands for protocol) lists all of the transmission control protocol (TCP) and user datagram protocol (UDP) connections on the machine running Netstat. The second column is the machine’s local IP address and port number, while the third is the remote or foreign address and port number. The final column is called State, which is the state that the connection, or potential connection, is in.

Built-in Windows commands that can find hack attempts

“LISTENING” shows a classic open port listening for inbound connections. “ESTABLISHED” means there’s an actual connection between your machine and the remote IP and port that is able to exchange traffic. Occasionally, you’ll see “CLOSE_WAIT” in this column, which is a state TCP goes into while ending an established connection.

As you can see, there are plenty of entries with a local address of 0.0.0.0 plus a port. This designation means the port is listening on all network interfaces and will accept any incoming connection on that port number.

How To Check Port Status Windows 10

The local address entries beginning 127.0.0.1 are processes listening for connections from the PC itself, not from the Internet or network. If the IP address in this column is your local network IP, then the port is only listening for connections from your local network. The port is listening for connections from the Internet if it displays your online IP address.

A quick glance through Netstat’s output can alert you to many potential problems. For example, if your security policy bans the use of internet relay chat (IRC), but there are numerous connections to port 6667 (the default IRC port) on a remote machine, then there's a chance that the PC has a Trojan connected to a remote IRC server waiting to receive commands. Although Netstat only takes a snapshot, you can use the interval option to refresh the output every so many seconds. Use the Netstat command below, for example:

netstat –an 1 | find “3333”

The command will check every second and print the results if a process starts listening on TCP port 3333.

If you want to find out which process on a machine is sending out packets to a particular machine you can run:

netstat –ano 1 | find “Dest_IP_Addr”

The -o parameter outputs the process ID (PID) responsible for the connection. You can then find the program associated with a PID by typing “tasklist” at the Netstat command prompt. You can also use netstat’s -b flag, which outputs the EXE and its associated DLLs that are using the TCP and UDP ports. Finally, if you want to know when another system, such as a bot controller, connects to a machine listening on a particular TCP port, such as port 4444, you can run:

netstat –an 1 | find “4444” | find “ESTABLISHED”

Check Port Status Windows 10

In this example, Netstat will not display an output until it finds an established connection on port 4444, and it will include the source IP address connected to the port, a helpful bit of information in an investigation.

You can, of course, achieve more accurate and detailed results using a port scanner such as Nmap.

However, Netstat is already built in and the commands are quick and easy to use. You may also be interested in Microsoft’s Sysinternals Process Monitor tool, an advanced monitoring utility for Windows that shows real-time file system, Registry and process/thread activity.

*Note: The –b and –o options are not available on Windows 2000 and be aware that running them with the interval option would be a drain on a system’s resources.

About the author:Michael Cobb, CISSP-ISSAP is the founder and managing director of Cobweb Applications Ltd., a consultancy that offers IT training and support in data security and analysis. He co-authored the book IIS Security and has written numerous technical articles for leading IT publications.

Download this free guide

Hear that screaming? A network security fail strikes again

From allegations of nation state-level interference in crucial elections, to massive botnet attacks that brought down critical online services for millions, network security dominated mainstream news cycles for weeks on end. In this guide we will explore some of the key themes driving enterprise network security initiatives, from how to protect and monitor day-to-day activity on the network, to tips on how to defend it from malicious external attackers.

Read more on Network security management

Download Computer Weekly
  • In The Current Issue:
    • Unpicking the datacentre industry’s complicated relationship with climate change
    • IT leaders need to speak up about the voice channel
    • Ecuador citizens’ data breach holds lessons for enterprises

Check Port Status Windows Cmd

  • SIBOS audience applauds Boris Johnson’s loss in the Supreme Court– Fintech makes the world go around
  • Getting cloud under control: A how-to guide for CIOs– Ahead in the Clouds

Check Port Status Windows Server

Related Content

Check Port Status Windows Server 2008

  • Focus Windows port scanning with the netscan command– SearchNetworking
  • Using Netsh with Windows Firewall– SearchNetworking
  • Using NetStat commands and Microsoft Port Reporter ...– SearchMidmarketSecurity