Post Thu Jan 22, 2009 10:08 am

SQL on TCP 54320

Hey all,

I ran into an interesting problem here in our lab. I installed a Server 2008 box with IIS and SQL server 2005 and 2008 on it. I ran an Nmap and Nessus scan on it and found 54320 open on it. So I went and ran netstat -ab on the server to see what process was using it only to discover to my surprise that it was being used by sqlserver.exe. I know that bo2k is not on the system since it is a clean install. Any ideas? Have any of you seen this before? Thanks.
Mike Conway
CISSP
CompTia Security +
C|EH