Re: Which ports to block?

mike_at_genxweb.net
Date: 07/26/04

  • Next message: Barber, Chris Mr. ATEC/Contractor: "RE: Which ports to block?"
    Date: Mon, 26 Jul 2004 15:07:04 -0400
    To: Ferino Mardo <RMardo@ALJOMAIHBEV.com>
    
    

    Since most firewalls deny all traffic by default in theory you should have to
    only creat teh allow rules for those ports.

    But if you want since most firewalls also read from the top down you will need
    to create the allow rules for those ports then at teh bottom you can do a deny
    all rule. There should be a option to deny all traffic I would use that for
    your last rule.

    Quoting Ferino Mardo <RMardo@ALJOMAIHBEV.com>:

    > In setting up a "deny all" rule from a firewall, is it safe to block
    > ports 0 to 65535 or only up to 1023? My interest are only to allow port
    > 53 udp, 25, and 80.
    >
    > ---------------------------------------------------------------------------
    > Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    > any course! All of our class sizes are guaranteed to be 10 students or less
    > to facilitate one-on-one interaction with one of our expert instructors.
    > Attend a course taught by an expert instructor with years of in-the-field
    > pen testing experience in our state of the art hacking lab. Master the skills
    > of an Ethical Hacker to better assess the security of your organization.
    > Visit us at:
    > http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    > ----------------------------------------------------------------------------
    >
    >

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: Barber, Chris Mr. ATEC/Contractor: "RE: Which ports to block?"

    Relevant Pages

    • Re: locking down snort
      ... IPTables always gets the traffic first so you wouldn't have a problem ... > 'grab' and analyze traffic hitting those ports. ... > Ethical Hacking at the InfoSec Institute. ... > pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • RE: What does this mean?
      ... you info on the ports, what they do, and how to close them. ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • Re: Which ports to block?
      ... only allow those three ports through. ... >Ethical Hacking at the InfoSec Institute. ... >pen testing experience in our state of the art hacking lab. ... >of an Ethical Hacker to better assess the security of your organization. ...
      (Security-Basics)
    • Re: locking down snort
      ... If you are running snort on the same host then snort will be able to ... doesnt bind to the ports, so it will be able to see the traffic. ... > Ethical Hacking at the InfoSec Institute. ... > pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • RE: IM Programs
      ... want to block these ports. ... you don't need an explicit deny for the other ports. ... Access-list 101 deny any tcp any any eq 5000 ... >Now, when applying these to your firewall, make sure the number ...
      (Security-Basics)