Re: Pubstro rash

From: Mark Coleman (markc_at_uniontown.com)
Date: 03/17/05

  • Next message: Steve Drees: "RE: Pubstro rash"
    Date: Thu, 17 Mar 2005 16:50:45 -0500
    To: gillettdavid@fhda.edu
    
    

    Hi David,

    >3. Instead of a random high port, the installed FTP server
    >listens on port 53. Which I can't block, because DNS may
    >need to use it, right?
    >
    >4. The FTP banners all claim to be the work of "Droppunx".

    If these are workstations, not servers, then you should be able to block
    TCP 53 INBOUND to them from the world without harming their DNS
    resolution, and effectively block the world's access to these FTP
    servers running on tcp port 53. Since you say they have a banner, I am
    assuming TCP.

    DNS typically (from memory) will use UDP for most requests, but will
    fall over to TCP for requests over 576 bytes in size, but if these are
    workstations then you can allow both TCP/UDP port 53 OUT and still block
    TCP port 53 IN and that shouldn't effect DNS for these workstations.
    TCP, being stateful, lets you descriminate on direction at layer 4.
    Stopping inbound SYNs on port 53 IN will only cause a problem if it's a
    DNS server that the world is trying to hit.

    -Mark Coleman


  • Next message: Steve Drees: "RE: Pubstro rash"

    Relevant Pages

    • Re: DFS and windowsFW help please.
      ... NetBIOS Session Service TCP 139 ... TCP port number between 1024 - 1033 ... Replicateion between my folder is not working however, with the FW off Replication between the two servers does take place. ...
      (microsoft.public.windows.server.general)
    • Re: [FATAL] Kerberos does not have a ticket for <any of my servers>
      ... they should be using TCP. ... Most of the Local servers I've been able to get the Kerberos to pass by ... I'm rebooting the Exchange 2003 Server now to get it update as well as the ...
      (microsoft.public.win2000.active_directory)
    • Re: Updates
      ... forces the max tcp window size to 64k. ... This turns off Receive Window Auto-Tuning, and prevents vista ... slow (but only when communicating with the two 2k3 sp2 servers). ...
      (microsoft.public.cert.exam.mcse)
    • new server 2003 slow login NOT a DNS problem
      ... we have a remote site that had been using Windows 2000 servers until ... UDP:138 ... TCP:445 ...
      (microsoft.public.windows.server.general)
    • Re: Automatic Updates security concern
      ... If those servers are not configured to support SSL ... on tcp 443 then the update clients will be forced to use tcp ... Is there any way of setting the AU repository so it never uses https (tcp ... clients end up ...
      (microsoft.public.security)

  • Quantcast