RE: Using Messenger Service for 'Net Send' Functionality --- Dangerous? Why?

From: Rasmus Rønlev (rr.it_at_cbs.dk)
Date: 06/11/05

  • Next message: Justin F. Knox: "Re: Restricting file server to access to domain computers only."
    Date: Sat, 11 Jun 2005 14:09:36 +0200
    To: focus-ms@securityfocus.com
    
    

    Hi Brian,

    If just for the potential spam - there's also been viruses abusing the open
    messenger port - I wouldn't let the service be wide open to anyone to write
    to. However at least with Windows XP SP2 you can rather easily deploy some
    firewall settings, which would allow you to block incoming traffic to the
    port that the service is running on.

    So basically just block the port from anyone but the single or few machines
    that need to be able to use the 'net send' functionality if you must use it
    :)

    Regards,
    r@smus

    -----Original Message-----
    From: deadly.halo@gmail.com [mailto:deadly.halo@gmail.com]
    Sent: 2. juni 2005 21:20
    To: focus-ms@securityfocus.com
    Subject: Using Messenger Service for 'Net Send' Functionality --- Dangerous?
    Why?

    A fellow network administrator at the company I work for is interested in
    implementing a system that utilizes the Messenger Service (not to be
    confused with the MS Messenger chat tool) to initiate Net Send notifications
    to clients throughout the user community. Our network hosts consist of
    Windows 2000/XP machines (XP has the service disabled by default, 2000 may
    as well). I remember that there was a large vulnerability reported at the
    end of 2003 regarding the Messenger Service. I know that the issue was
    addressed in subsequent service packs, but this doesn't necessarily mean
    it's a good idea to use it.

    Bottom line; I'm concerned that enabling the Messenger Service throughout
    the network will open our environment to security vulnerabilities. What are
    you thoughts? Any know issues at this time? Your input would be greatly
    appreciated.

    Regards,

    Brian

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Justin F. Knox: "Re: Restricting file server to access to domain computers only."

    Relevant Pages

    • VideoConf Nightmare
      ... Firewall Router so you can read the instructions on How ... >instructions (from your reply to "audio on messenger" on ... >But as stated, all appeared to work, however, the UPnP ... More on firewall and port opening can be ...
      (microsoft.public.windowsxp.messenger)
    • Re: Application Sharing and Ports
      ... Opening the port yourself will not work as it can't get the ... Microsoft MVP - Windows Messenger/MSN Messenger/Windows Live Messenger ... I would really like to use Window messenger for application sharing and some of the ...
      (microsoft.public.windowsxp.messenger)
    • Instant Messenger BLOCK
      ... Is there a way to block the port that Windows Instant ... stupid feature throughout our network. ... it should stop the instant messenger ...
      (microsoft.public.win2000.security)
    • Re: I need to open a port on our server.
      ... We're using yahoo messenger. ... do I go to open a port? ... over NAT Firewalls or Proxy Firewalls and it does not matter who makes the ... How to Block Dangerous Instant Messengers Using ISA Server ...
      (microsoft.public.windows.server.general)
    • Re: false portscan alarm
      ... What is the reason of that treffic? ... which each have a local source port above 1024 opened outgoing to port 80 ... Windows Messenger? ... UDP packets from that IP have been MSN/Windows messenger spam (which is ...
      (comp.security.firewalls)