RE: Which ports to block?

From: Ed Spencer (espencer_at_usa.net)
Date: 07/26/04

  • Next message: Gethin Jones: "Re: Basic firewall filtering question"
    To: "'Ferino Mardo'" <RMardo@ALJOMAIHBEV.com>, <security-basics@securityfocus.com>
    Date: Mon, 26 Jul 2004 11:42:42 -0800
    
    

    It's safest to block thru 65535. There are many services that run above
    1023 and these would be allowed through the firewall if you don't block
    them (depending on the firewall and implementation). Remember just
    because they're not 'well-known' doesn't mean that they're not
    well-known. ;-)

    Ed Spencer
    MCSE/MCT/MCP/CNA/A+/Network+/Security+
    Network Administrator
    Aramark Corporation
    Denali National Park.

    -----Original Message-----
    From: Ferino Mardo [mailto:RMardo@ALJOMAIHBEV.com]
    Sent: Saturday, July 24, 2004 12:04 AM
    To: security-basics@securityfocus.com
    Subject: Which ports to block?

    In setting up a "deny all" rule from a firewall, is it safe to block
    ports 0 to 65535 or only up to 1023? My interest are only to allow port
    53 udp, 25, and 80.

    ------------------------------------------------------------------------

    ---
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545
    off 
    any course! All of our class sizes are guaranteed to be 10 students or
    less 
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of
    in-the-field 
    pen testing experience in our state of the art hacking lab. Master the
    skills 
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at: 
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ------------------------------------------------------------------------
    ----
    ---
    Incoming mail is certified Virus Free.
    Checked by AVG anti-virus system (http://www.grisoft.com).
    Version: 6.0.726 / Virus Database: 481 - Release Date: 7/22/2004
     
    ---
    Outgoing mail is certified Virus Free.
    Checked by AVG anti-virus system (http://www.grisoft.com).
    Version: 6.0.726 / Virus Database: 481 - Release Date: 7/22/2004
     
    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
    any course! All of our class sizes are guaranteed to be 10 students or less 
    to facilitate one-on-one interaction with one of our expert instructors. 
    Attend a course taught by an expert instructor with years of in-the-field 
    pen testing experience in our state of the art hacking lab. Master the skills 
    of an Ethical Hacker to better assess the security of your organization. 
    Visit us at: 
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------
    

  • Next message: Gethin Jones: "Re: Basic firewall filtering question"

    Relevant Pages

    • RE: Removing Local Admin Rights...
      ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ... pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • RE: HIPAA_Compliance
      ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ... pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • RE: Cisco CSA
      ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ... pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • RE: Minimum password requirements
      ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ... pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • Betr.: RE: fax software in the domain
      ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... pen testing experience in our state of the art hacking lab. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)