Detect a blocked port
Here is a standard trace on port 80:
$ tracetcp www.ebay.co.uk
Tracing route to 66.135.192.41 [www.ebay.co.uk] on port 80
Over a maximum of 30 hops.
1 1 ms 1 ms 2 ms 192.168.0.1 [wintermute]
2 10 ms 9 ms 11 ms 10.78.128.1
3 10 ms 11 ms 8 ms 62.30.193.33 [gsr01-so.blueyonder.co.uk]
4 10 ms 9 ms 10 ms 172.18.14.45
5 14 ms 13 ms 14 ms 172.18.14.62
6 12 ms 13 ms 14 ms 194.117.136.18 [tele2-witt-pos.telewest.net]
7 12 ms 12 ms 14 ms 166.63.222.37 [zcr1-so-5-0-0.Londonlnt.cw.net]
8 182 ms 164 ms 164 ms 208.172.146.100 [dcr2-loopback.SantaClara.cw.net]
9 163 ms 163 ms 164 ms 208.172.156.198 [bhr1-pos-0-0.SantaClarasc8.cw.net]
10 165 ms 165 ms 167 ms 66.35.194.50 [csr1-ve243.SantaClarasc8.cw.net]
11 165 ms 165 ms 164 ms 66.35.212.190
12 168 ms 169 ms 169 ms 66.135.207.253
13 166 ms 169 ms 171 ms 66.135.207.174
14 * * * Request timed out.
15 Destination Reached in 170 ms. Connection established to 66.135.192.41
Trace Complete.
|
If we do the same trace but this time we use port 135 we can see that it is blocked after hop 2. This block was put in place by my ISP to try to limit the damage being caused by a worm, that spread by exploiting a vulnerability in DCOM.
$ tracetcp www.ebay.co.uk:135
Tracing route to 66.135.192.41 [www.ebay.co.uk] on port 135
Over a maximum of 30 hops.
1 1 ms 1 ms 1 ms 192.168.0.1 [wintermute]
2 10 ms 13 ms 9 ms 10.78.128.1
3 * * * Request timed out.
4 * * * Request timed out.
5 * * * Request timed out.
6 ... continues until maximum number of hops reached.
|
|