Re: Windows Server 2000 port lock down

From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 08/27/05

  • Next message: Bow Sineath: "Re: what to do?"
    Date: Sat, 27 Aug 2005 02:32:38 +0200
    To: security-basics@securityfocus.com
    
    

    On 2005-08-26 SandySue@epix.net wrote:
    > Can anyone direct me to a set of windows commands to close ports on a
    > Windows 2000 server (or if necessary, a third party application that
    > can be loaded on a Windows 2000 server to close ports). I'm looking
    > for a solution to close ports that encompasses the least amount of
    > process overhead; the goal is lock down outbound traffic. The
    > solution must work on a 2000 Server.

    Disable the services you don't want to provide. Remove services that
    can't (or must not) be disabled from external interfaces. There is no
    out-of-the-box solution, because nobody could guess which services you
    need to provide and which you don't.

    net help stop
    sc /?
    netstat /?

    http://support.microsoft.com/default.aspx?scid=kb;en-us;832017
    http://www.hsc.fr/ressources/breves/min_srv_res_win.en.html
    http://www.blackviper.com/WIN2K/servicecfg.htm
    http://www.ntsvcfg.de/ntsvcfg_eng.html (the script could be used as a
    template)

    HTH

    Regards
    Ansgar Wiechers

    -- 
    "Another option [for defragmentation] is to back up your important files,
    erase the hard disk, then reinstall Mac OS X and your backed up files."
    --http://docs.info.apple.com/article.html?artnum=25668
    

  • Next message: Bow Sineath: "Re: what to do?"

    Relevant Pages

    • Re: Whats a decent modem/router for tech savy user?
      ... It is not possible to route or deny traffic to specific ports based on the source IP address. ... But it wont route back inside the LAN - needs internal DNS server spoofing. ... Normally, this option should be Enabled, so that an Internet connection will be made automatically, whenever Internet-bound traffic is detected. ... Specifying a Default DMZ Server allows you to set up a computer or server that is available to anyone on the Internet for services that you haven't defined. ...
      (uk.telecom.broadband)
    • Re: Cannot connect to RWW from home PC
      ... That would be the address you need a DNS record for. ... You say "And in the router you need to forward to your external nic IP" ... Still can't telnet to any of your ports at your public ip address. ... Heres' the info for our server: ...
      (microsoft.public.windows.server.sbs)
    • Re: Netopia 3347NWG with Remote Desktop and Remote Web Workplace
      ... Glad you're back in business Greg! ... Ports Closed ... Despite this, Remote Web Workplace DOES WORK now, and Connect to Server ... Exchange BPA updates), ...
      (microsoft.public.windows.server.sbs)
    • Solution -> Re: SSH tunnel question.
      ... change IPS and ports around but that is not a big deal. ... telnet/ftp/rsh open on a server including on the Internet facing ports! ... I will go from the corp desktop to a hop ... through the firewall to the hop ...
      (SSH)
    • Re: Exch2003 front-end questions
      ... all the supported protocol ports must be open on the inner ... communication between the front-end server and the back-end servers. ... lists the ports required for the intranet firewall. ...
      (microsoft.public.isa)