RE: TCP 445 Scan?

From: Frank Knobbe (fknobbe@knobbeits.com)
Date: 03/04/03

  • Next message: R Andersson: "Re: sending out spam through IRC server ?"
    From: Frank Knobbe <fknobbe@knobbeits.com>
    To: incidents@securityfocus.com
    Date: 04 Mar 2003 13:59:31 -0600
    

    On Tue, 2003-03-04 at 10:18, kyle@kylelai.com wrote:
    > [...]
    > The only good defense is to block port 445 and port 139 ports on your
    > firewall, and set strong passwords for every user on your network, including
    > administrator accounts.

    No offense Kyle, but this bad advice. I'm not lashing out at you, but
    I'm starting to get really irritated when people recommend 'simply block
    this port on your firewall'. If that is what you have to do, then you
    have much bigger problems.

    Firewalls should block ALL PORTS by default. Only allow in what you need
    to allow in. Anything else should be blocked. And that should include
    port 445 [1].

    Here again:

    B L O C K A L L B Y D E F A U L T ,
    A L L O W O N L Y W H A T I S N E E D E D .

    Print this out and stick it on your firewall management console :)

    Regards,
    Frank

    [1] Unless you really need it for some weird reason. But that would make
    all this a mute point anyway.

    
    



  • Next message: R Andersson: "Re: sending out spam through IRC server ?"

    Relevant Pages

    • Re: keeping ports open
      ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
      (microsoft.public.security)
    • Re: How to Maintain an IIS Server?
      ... > server running on a Windows 2000 server. ... before a firewall and antivirus have been installed]. ... open ports; however, this will not identify which program is using the port. ...
      (microsoft.public.inetserver.iis.security)
    • Re: CEICW fails at firewall config
      ... ISA Server prevents connection to a remote desktop when you connect through ... Remote Web Workplace on a Windows Small Business Server 2003-based computer ... Acceleration Server as a firewall. ... connection uses TCP port 4125. ...
      (microsoft.public.windows.server.sbs)
    • Re: How to Maintain an IIS Server?
      ... >> server running on a Windows 2000 server. ... > before a firewall and antivirus have been installed]. ... > program or executable using that port. ...
      (microsoft.public.inetserver.iis.security)
    • Re: Is secedit.exe left by a hacker?
      ... > tested on port 445. ... > I have a Linksys router that I use as a firewall to my ... Secedit.exe is the name of a legitimate Windows file, ... investigate the files on your computer - antivirus with the latest updates ...
      (microsoft.public.win2000.security)