본문 바로가기

Coding

[PHP] 오픈 포트 확인

$trojans = array ("1" => "(UDP) - Sockets des Troie",
"2" => "Death",
"15" => "B2",
"20" => "Senna Spy FTP server",
"21" => "Back Construction, Blade Runner, Cattivik FTP Server, CC Invader, Dark FTP, Doly Trojan, Fore, FreddyK, Invisible FTP, Juggernaut 42, Larva, MotIv FTP, Net Administrator, Ramen, RTB 666, Senna Spy FTP server, The Flu, Traitor 21, WebEx, WinCrash",
"22" => "Adore sshd, Shaft",
"23" => "ADM worm, Fire HacKer, My Very Own trojan, RTB 666, Telnet Pro, Tiny Telnet Server - TTS, Truva Atl",
"25" => "Ajan, Antigen, Barok, BSE, Email Password Sender - EPS, EPS II, Gip, Gris, Happy99, Hpteam mail, Hybris, I love you, Kuang2, Magic Horse, MBT (Mail Bombing Trojan), Moscow Email trojan, Naebi, NewApt worm, ProMail trojan, Shtirlitz, Stealth, Stukach, Tapiras, Terminator, WinPC, WinSpy",
"30" => "Agent 40421",
"31" => "Agent 31, Hackers Paradise, Masters Paradise",
"39" => "SubSARI",
"41" => "Deep Throat, Foreplay",
"44" => "Arctic",
"48" => "DRAT",
"50" => "DRAT",
"53" => "ADM worm, Lion",
"58" => "DMSetup",
"59" => "DMSetup",
"69" => "BackGate",
"79" => "CDK, Firehotcker",
"80" => "711 trojan (Seven Eleven), AckCmd, Back End, Back Orifice 2000 Plug-Ins, Cafeini, CGI Backdoor, Executor, God Message, God Message 4 Creator, Hooker, IISworm, MTX, NCX, Noob, Ramen, Reverse WWW Tunnel Backdoor, RingZero, RTB 666, Seeker, WAN Remote, Web Server CT, WebDownloader",
"81" => "RemoConChubo",
"99" => "Hidden Port, Mandragore, NCX",
"110" => "ProMail trojan",
"113" => "Invisible Identd Deamon, Kazimas",
"119" => "Happy99",
"121" => "Attack Bot, God Message, JammerKillah",
"123" => "Net Controller",
"133" => "Farnaz",
"137" => "Chode",
"137" => "(UDP) - Msinit, Qaz",
"138" => "Chode",
"139" => "Chode, God Message worm, Msinit, Netlog, Network, Qaz, Sadmind, SMB Relay",
"142" => "NetTaxi",
"146" => "Infector",
"146" => "(UDP) - Infector",
"166" => "NokNok",
"170" => "A-trojan",
"334" => "Backage",
"411" => "Backage",
"420" => "Breach, Incognito",
"421" => "TCP Wrappers trojan",
"455" => "Fatal Connections",
"456" => "Hackers Paradise",
"511" => "T0rn Rootkit",
"513" => "Grlogin",
"514" => "RPC Backdoor",
"515" => "lpdw0rm, Ramen",
"531" => "Net666, Rasmin",
"555" => "711 trojan (Seven Eleven), Ini-Killer, Net Administrator, Phase Zero, Phase-0, Stealth Spy",
"600" => "Sadmind",
"605" => "Secret Service",
"661" => "NokNok",
"666" => "Attack FTP, Back Construction, BLA trojan, Cain & Abel, lpdw0rm, NokNok, Satans Back Door - SBD, ServU, Shadow Phyre, th3r1pp3rz (= Therippers)",
"667" => "SniperNet",
"668" => "th3r1pp3rz (= Therippers)",
"669" => "DP trojan",
"692" => "GayOL",
"777" => "AimSpy, Undetected",
"808" => "WinHole",
"911" => "Dark Shadow, Dark Shadow",
"999" => "Chat power, Deep Throat, Foreplay, WinSatan",
"1000" => "Connecter, Der Sp?er / Der Spaeher, Direct Connection",
"1001" => "Der Sp?er / Der Spaeher, Le Guardien, Silencer, Theef, WebEx",
"1005" => "Theef",
"1008" => "Lion",
"1010" => "Doly Trojan",
"1011" => "Doly Trojan",
"1012" => "Doly Trojan",
"1015" => "Doly Trojan",
"1016" => "Doly Trojan",
"1020" => "Vampire",
"1024" => "Jade, Latinus, NetSpy, Remote Administration Tool - RAT [no 2]",
"1025" => "Fraggle Rock, md5 Backdoor, NetSpy, Remote Storm",
"1025" => "(UDP) - Remote Storm",
"1031" => "Xanadu",
"1035" => "Multidropper",
"1042" => "BLA trojan",
"1042" => "(UDP) - BLA trojan",
"1045" => "Rasmin",
"1049" => "/sbin/initd",
"1050" => "MiniCommand",
"1053" => "The Thief",
"1054" => "AckCmd",
"1080" => "SubSeven 2.2, WinHole",
"1081" => "WinHole",
"1082" => "WinHole",
"1083" => "WinHole",
"1090" => "Xtreme",
"1095" => "Remote Administration Tool - RAT",
"1097" => "Remote Administration Tool - RAT",
"1098" => "Remote Administration Tool - RAT",
"1099" => "Blood Fest Evolution, Remote Administration Tool - RAT",
"1104" => "(UDP) - RexxRave",
"1150" => "Orion",
"1151" => "Orion",
"1170" => "Psyber Stream Server - PSS, Streaming Audio Server, Voice",
"1174" => "DaCryptic",
"1180" => "Unin68",
"1200" => "(UDP) - NoBackO",
"1201" => "(UDP) - NoBackO",
"1207" => "SoftWAR",
"1208" => "Infector",
"1212" => "Kaos",
"1234" => "SubSeven Java client, Ultors Trojan",
"1243" => "BackDoor-G, SubSeven, SubSeven Apocalypse, Tiles",
"1245" => "VooDoo Doll",
"1255" => "Scarab",
"1256" => "Project nEXT, RexxRave",
"1269" => "Matrix",
"1272" => "The Matrix",
"1313" => "NETrojan",
"1337" => "Shadyshell",
"1338" => "Millennium Worm",
"1349" => "Bo dll",
"1386" => "Dagger",
"1394" => "GoFriller",
"1441" => "Remote Storm",
"1492" => "FTP99CMP",
"1524" => "Trinoo",
"1568" => "Remote Hack",
"1600" => "Direct Connection, Shivka-Burka",
"1703" => "Exploiter",
"1777" => "Scarab",
"1807" => "SpySender",
"1826" => "Glacier",
"1966" => "Fake FTP",
"1967" => "For Your Eyes Only - FYEO, WM FTP Server",
"1969" => "OpC BO",
"1981" => "Bowl, Shockrave",
"1991" => "PitFall",
"1999" => "Back Door, SubSeven, TransScout",
"2000" => "Der Spaer / Der Spaeher, Insane Network, Last 2000, Remote Explorer 2000, Senna Spy Trojan Generator",
"2001" => "Der Spaer / Der Spaeher, Trojan Cow",
"2023" => "Ripper Pro",
"2080" => "WinHole",
"2115" => "Bugs",
"2130" => "(UDP) - Mini Backlash",
"2140" => "The Invasor",
"2140" => "(UDP) - Deep Throat, Foreplay",
"2155" => "Illusion Mailer",
"2255" => "Nirvana",
"2283" => "Hvl RAT",
"2300" => "Xplorer",
"2311" => "Studio 54",
"2330" => "IRC Contact",
"2331" => "IRC Contact",
"2332" => "IRC Contact",
"2333" => "IRC Contact",
"2334" => "IRC Contact",
"2335" => "IRC Contact",
"2336" => "IRC Contact",
"2337" => "IRC Contact",
"2338" => "IRC Contact",
"2339" => "IRC Contact, Voice Spy",
"2339" => "(UDP) - Voice Spy",
"2345" => "Doly Trojan",
"2400" => "Portd",
"2555" => "Lion, T0rn Rootkit",
"2565" => "Striker trojan",
"2583" => "WinCrash",
"2589" => "Dagger",
"2600" => "Digital RootBeer",
"2702" => "Black Diver",
"2716" => "The Prayer",
"2773" => "SubSeven, SubSeven 2.1 Gold",
"2774" => "SubSeven, SubSeven 2.1 Gold",
"2801" => "Phineas Phucker",
"2929" => "Konik",
"2989" => "(UDP) - Remote Administration Tool - RAT",
"3000" => "InetSpy, Remote Shut",
"3024" => "WinCrash",
"3031" => "Microspy",
"3128" => "Reverse WWW Tunnel Backdoor, RingZero",
"3129" => "Masters Paradise",
"3131" => "SubSARI",
"3150" => "The Invasor",
"3150" => "(UDP) - Deep Throat, Foreplay, Mini Backlash",
"3456" => "Terror trojan",
"3459" => "Eclipse 2000, Sanctuary",
"3700" => "Portal of Doom",
"3777" => "PsychWard",
"3791" => "Total Solar Eclypse",
"3801" => "Total Solar Eclypse",
"4000" => "Connect-Back Backdoor, SkyDance",
"4092" => "WinCrash",
"4201" => "War trojan",
"4242" => "Virtual Hacking Machine - VHM",
"4321" => "BoBo",
"4444" => "CrackDown, Prosiak, Swift Remote",
"4488" => "Event Horizon",
"4523" => "Celine",
"4545" => "Internal Revise",
"4567" => "File Nail",
"4590" => "ICQ Trojan",
"4653" => "Cero",
"4666" => "Mneah",
"4950" => "ICQ Trogen (Lm)",
"5000" => "Back Door Setup, BioNet Lite, Blazer5, Bubbel, ICKiller, Ra1d, Sockets des Troie",
"5001" => "Back Door Setup, Sockets des Troie",
"5002" => "cd00r, Linux Rootkit IV (4), Shaft",
"5005" => "Aladino",
"5010" => "Solo",
"5011" => "One of the Last Trojans - OOTLT, One of the Last Trojans - OOTLT, modified",
"5025" => "WM Remote KeyLogger",
"5031" => "Net Metropolitan",
"5032" => "Net Metropolitan",
"5321" => "Firehotcker",
"5333" => "Backage, NetDemon",
"5343" => "WC Remote Administration Tool - wCrat",
"5400" => "Back Construction, Blade Runner",
"5401" => "Back Construction, Blade Runner, Mneah",
"5402" => "Back Construction, Blade Runner, Mneah",
"5512" => "Illusion Mailer",
"5534" => "The Flu",
"5550" => "Xtcp",
"5555" => "ServeMe",
"5556" => "BO Facil",
"5557" => "BO Facil",
"5569" => "Robo-Hack",
"5637" => "PC Crasher",
"5638" => "PC Crasher",
"5742" => "WinCrash",
"5760" => "Portmap Remote Root Linux Exploit",
"5802" => "Y3K RAT",
"5873" => "SubSeven 2.2",
"5880" => "Y3K RAT",
"5882" => "Y3K RAT",
"5882" => "(UDP) - Y3K RAT",
"5888" => "Y3K RAT",
"5888" => "(UDP) - Y3K RAT",
"5889" => "Y3K RAT",
"6000" => "The Thing",
"6006" => "Bad Blood",
"6272" => "Secret Service",
"6400" => "The Thing",
"6661" => "TEMan, Weia-Meia",
"6666" => "Dark Connection Inside, NetBus worm",
"6667" => "Dark FTP, EGO, Maniac rootkit, Moses, ScheduleAgent, SubSeven, Subseven 2.1.4 DefCon 8, The Thing (modified), Trinity, WinSatan",
"6669" => "Host Control, Vampire",
"6670" => "BackWeb Server, Deep Throat, Foreplay, WinNuke eXtreame",
"6711" => "BackDoor-G, SubSARI, SubSeven, VP Killer",
"6712" => "Funny trojan, SubSeven",
"6713" => "SubSeven",
"6723" => "Mstream",
"6767" => "UandMe",
"6771" => "Deep Throat, Foreplay",
"6776" => "2000 Cracks, BackDoor-G, SubSeven, VP Killer",
"6838" => "(UDP) - Mstream",
"6883" => "Delta Source DarkStar (??)",
"6912" => "Shit Heep",
"6939" => "Indoctrination",
"6969" => "2000 Cracks, Danton, GateCrasher, IRC 3, Net Controller, Priority",
"6970" => "GateCrasher",
"7000" => "Exploit Translation Server, Kazimas, Remote Grab, SubSeven, SubSeven 2.1 Gold",
"7001" => "Freak88, Freak2k, NetSnooper Gold",
"7158" => "Lohoboyshik",
"7215" => "SubSeven, SubSeven 2.1 Gold",
"7300" => "NetMonitor",
"7301" => "NetMonitor",
"7306" => "NetMonitor",
"7307" => "NetMonitor, Remote Process Monitor",
"7308" => "NetMonitor, X Spy",
"7424" => "Host Control",
"7424" => "(UDP) - Host Control",
"7597" => "Qaz",
"7626" => "Binghe, Glacier, Hyne",
"7718" => "Glacier",
"7777" => "God Message, The Thing (modified), Tini",
"7789" => "Back Door Setup, ICKiller, Mozilla",
"7826" => "Oblivion",
"7891" => "The ReVeNgEr",
"7983" => "Mstream",
"8080" => "Brown Orifice, Generic backdoor, RemoConChubo, Reverse WWW Tunnel Backdoor, RingZero",
"8685" => "Unin68",
"8787" => "Back Orifice 2000",
"8812" => "FraggleRock Lite",
"8988" => "BacHack",
"8989" => "Rcon, Recon, Xcon",
"9000" => "Netministrator",
"9325" => "(UDP) - Mstream",
"9400" => "InCommand",
"9870" => "Remote Computer Control Center",
"9872" => "Portal of Doom",
"9873" => "Portal of Doom",
"9874" => "Portal of Doom",
"9875" => "Portal of Doom",
"9876" => "Cyber Attacker, Rux",
"9878" => "TransScout",
"9989" => "Ini-Killer",
"9999" => "The Prayer",
"10000" => "OpwinTRojan",
"10005" => "OpwinTRojan",
"10008" => "Cheese worm, Lion",
"10067" => "(UDP) - Portal of Doom",
"10085" => "Syphillis",
"10086" => "Syphillis",
"10100" => "Control Total, GiFt trojan",
"10101" => "BrainSpy, Silencer",
"10167" => "(UDP) - Portal of Doom",
"10520" => "Acid Shivers",
"10528" => "Host Control",
"10607" => "Coma",
"10666" => "(UDP) - Ambush",
"11000" => "Senna Spy Trojan Generator",
"11050" => "Host Control",
"11051" => "Host Control",
"11223" => "Progenic trojan, Secret Agent",
"11831" => "Latinus",
"12076" => "Gjamer",
"12223" => "Hack'99 KeyLogger",
"12310" => "PreCursor",
"12345" => "Adore sshd, Ashley, cron / crontab, Fat Bitch trojan, GabanBus, icmp_client.c, icmp_pipe.c, Mypic, NetBus, NetBus Toy, NetBus worm, Pie Bill Gates, ValvNet, Whack Job, X-bill",
"12346" => "Fat Bitch trojan, GabanBus, NetBus, X-bill",
"12348" => "BioNet",
"12349" => "BioNet, Webhead",
"12361" => "Whack-a-mole",
"12362" => "Whack-a-mole",
"12363" => "Whack-a-mole",
"12623" => "(UDP) - DUN Control",
"12624" => "ButtMan",
"12631" => "Whack Job",
"12754" => "Mstream",
"13000" => "Senna Spy Trojan Generator, Senna Spy Trojan Generator",
"13010" => "BitchController, Hacker Brasil - HBR",
"13013" => "PsychWard",
"13014" => "PsychWard",
"13223" => "Hack?9 KeyLogger",
"13473" => "Chupacabra",
"14500" => "PC Invader",
"14501" => "PC Invader",
"14502" => "PC Invader",
"14503" => "PC Invader",
"15000" => "NetDemon",
"15092" => "Host Control",
"15104" => "Mstream",
"15382" => "SubZero",
"15858" => "CDK",
"16484" => "Mosucker",
"16660" => "Stacheldraht",
"16772" => "ICQ Revenge",
"16959" => "SubSeven, Subseven 2.1.4 DefCon 8",
"16969" => "Priority",
"17166" => "Mosaic",
"17300" => "Kuang2 the virus",
"17449" => "Kid Terror",
"17499" => "CrazzyNet",
"17500" => "CrazzyNet",
"17569" => "Infector",
"17593" => "AudioDoor",
"17777" => "Nephron",
"18667" => "Knark",
"18753" => "(UDP) - Shaft",
"19864" => "ICQ Revenge",
"20000" => "Millenium",
"20001" => "Insect, Millenium, Millenium (Lm)",
"20002" => "AcidkoR",
"20005" => "Mosucker",
"20023" => "VP Killer",
"20034" => "NetBus 2.0 Pro, NetBus 2.0 Pro Hidden, NetRex, Whack Job",
"20203" => "Chupacabra",
"20331" => "BLA trojan",
"20432" => "Shaft",
"20433" => "(UDP) - Shaft",
"21544" => "GirlFriend, Kid Terror, Matrix",
"21554" => "Exploiter, FreddyK, Kid Terror, Schwindler, Winsp00fer",
"21579" => "Breach",
"21957" => "Latinus",
"22222" => "Donald Dick, Prosiak, Ruler, RUX The TIc.K",
"23005" => "NetTrash, Olive, Oxon",
"23006" => "NetTrash",
"23023" => "Logged",
"23032" => "Amanda",
"23321" => "Konik",
"23432" => "Asylum",
"23456" => "Evil FTP, Ugly FTP, Whack Job",
"23476" => "Donald Dick",
"23476" => "(UDP) - Donald Dick",
"23477" => "Donald Dick",
"23777" => "InetSpy",
"24000" => "Infector",
"24289" => "Latinus",
"25123" => "Goy'Z TroJan",
"25555" => "FreddyK",
"25685" => "MoonPie",
"25686" => "MoonPie",
"25982" => "MoonPie",
"26274" => "(UDP) - Delta Source",
"26681" => "Voice Spy",
"27160" => "MoonPie",
"27374" => "Bad Blood, EGO, Fake SubSeven, Lion, Ramen, Seeker, SubSeven, SubSeven 2.1 Gold, Subseven 2.1.4 DefCon 8, SubSeven 2.2, SubSeven Muie, The Saint, Ttfloader, Webhead",
"27444" => "(UDP) - Trinoo",
"27573" => "SubSeven",
"27665" => "Trinoo",
"28431" => "Hack'ack",
"28678" => "Exploiter",
"29104" => "NetTrojan",
"29292" => "BackGate",
"29369" => "ovasOn",
"29559" => "Latinus",
"29891" => "The Unexplained",
"30000" => "Infector",
"30001" => "ErrOr32",
"30003" => "Lamers Death",
"30005" => "Backdoor JZ",
"30029" => "AOL trojan",
"30100" => "NetSphere",
"30101" => "NetSphere",
"30102" => "NetSphere",
"30103" => "NetSphere",
"30103" => "(UDP) - NetSphere",
"30133" => "NetSphere",
"30303" => "Sockets des Troie",
"30700" => "Mantis",
"30947" => "Intruse",
"30999" => "Kuang2",
"31221" => "Knark",
"31335" => "Trinoo",
"31336" => "Bo Whack, Butt Funnel",
"31337" => "ADM worm, Back Fire, Back Orifice 1.20 patches, Back Orifice (Lm), Back Orifice russian, Baron Night, Beeone, bindshell, BO client, BO Facil, BO spy, BO2, cron / crontab, Freak88, Freak2k, Gummo, icmp_pipe.c, Linux Rootkit IV (4), Sm4ck, Sockdmini",
"31337" => "(UDP) - Back Orifice, Deep BO",
"31338" => "Back Orifice, Butt Funnel, NetSpy (DK)",
"31338" => "(UDP) - Deep BO, NetSpy (DK)",
"31339" => "NetSpy (DK), NetSpy (DK)",
"31557" => "Xanadu",
"31666" => "BOWhack",
"31745" => "BuschTrommel",
"31785" => "Hack'ack",
"31787" => "Hack'ack",
"31788" => "Hack'ack",
"31789" => "(UDP) - Hack'ack",
"31790" => "Hack'ack",
"31791" => "(UDP) - Hack'ack",
"31792" => "Hack'ack",
"32001" => "Donald Dick",
"32100" => "Peanut Brittle, Project nEXT",
"32418" => "Acid Battery",
"32791" => "Acropolis",
"33270" => "Trinity",
"33333" => "Blakharaz, Prosiak",
"33567" => "Lion, T0rn Rootkit",
"33568" => "Lion, T0rn Rootkit",
"33577" => "Son of PsychWard",
"33777" => "Son of PsychWard",
"33911" => "Spirit 2000, Spirit 2001",
"34324" => "Big Gluck, TN",
"34444" => "Donald Dick",
"34555" => "(UDP) - Trinoo (for Windows)",
"35555" => "(UDP) - Trinoo (for Windows)",
"37237" => "Mantis",
"37266" => "The Killer Trojan",
"37651" => "Yet Another Trojan - YAT",
"38741" => "CyberSpy",
"39507" => "Busters",
"40412" => "The Spy",
"40421" => "Agent 40421, Masters Paradise",
"40422" => "Masters Paradise",
"40423" => "Masters Paradise",
"40425" => "Masters Paradise",
"40426" => "Masters Paradise",
"41337" => "Storm",
"41666" => "Remote Boot Tool - RBT, Remote Boot Tool - RBT",
"44444" => "Prosiak",
"44575" => "Exploiter",
"44767" => "(UDP) - School Bus",
"45559" => "Maniac rootkit",
"45673" => "Acropolis",
"47017" => "T0rn Rootkit",
"47262" => "(UDP) - Delta Source",
"48004" => "Fraggle Rock",
"48006" => "Fraggle Rock",
"49000" => "Fraggle Rock",
"49301" => "OnLine KeyLogger",
"50000" => "SubSARI",
"50130" => "Enterprise",
"50505" => "Sockets des Troie",
"50766" => "Fore, Schwindler",
"51966" => "Cafeini",
"52317" => "Acid Battery 2000",
"53001" => "Remote Windows Shutdown - RWS",
"54283" => "SubSeven, SubSeven 2.1 Gold",
"54320" => "Back Orifice 2000",
"54321" => "Back Orifice 2000, School Bus",
"55165" => "File Manager trojan, File Manager trojan, WM Trojan Generator",
"55166" => "WM Trojan Generator",
"57341" => "NetRaider",
"58339" => "Butt Funnel",
"60000" => "Deep Throat, Foreplay, Sockets des Troie",
"60001" => "Trinity",
"60008" => "Lion, T0rn Rootkit",
"60068" => "Xzip 6000068",
"60411" => "Connection",
"61348" => "Bunker-Hill",
"61466" => "TeleCommando",
"61603" => "Bunker-Hill",
"63485" => "Bunker-Hill",
"64101" => "Taskman",
"65000" => "Devil, Sockets des Troie, Stacheldraht",
"65390" => "Eclypse",
"65421" => "Jade",
"65432" => "The Traitor (= th3tr41t0r)",
"65432" => "(UDP) - The Traitor (= th3tr41t0r)",
"65530" => "Windows Mite",
"65534" => "/sbin/initd",
"65535" => "Adore worm, RC1 trojan, Sins"
);

$host = $REMOTE_ADDR;

echo "당신의 IP.ADDRESS $host 입니다.

자신의 컴퓨터에 해킹이 가능한 포트가 열려 있는지 검사합니다.



\n";

$strNumberFound = 0;

echo "트로이 검색을 시작합니다...
\n";

foreach($trojans as $port=>$desc) {
$fp = fsockopen($host, $port);
if(!$fp) {
echo "접속 포트 $port 검사 해킹프로그램 $desc
\n";
} else {
echo "$desc 로 $port 포트에 해킹이 가능합니다.\n
\n";
$strNumberFound++;
fclose($fp);
}
flush();
}

if($strNumberFound == 0) {
echo "\n\n $host 에서 해킹이 가능한 포트를 찾지 못하였습니다.

";
} else {
echo "$strNumberFound 개의 해킹 가능한 포트가 열여 있습니다
\n";
echo "지금 당신의 컴퓨터는 해킹 될 가능성이 있습니다. 바이러스 검사와 트로이 제거프로그램을 사용하길 권합니다.


\n";
}

?>