RE: Interpreting the results of an NMAP scan



Small Business server has numerous websites available on it that may use
80 and 443. Being premium edition, they also are licensed for ISA which
may be running as a proxy for the internal machines. Otherwise, look for
Outlook Web Access, remote workplace, or the sharepoint intranet created
by most small business installs.

As for the Linksys, ideally remote admin is not enabled and it doesn't
answer to an outside ping. With premium edition, I would rely on ISA to
do firewall activities over a Linksys. The Linksys can be set to only
allow needed ports through, but that should just be the first layer.

Pete

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Dan Fauxpoint
Sent: Wednesday, April 22, 2009 9:58 PM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Interpreting the results of an NMAP scan


Hello,

I am helping a small business owner to evaluate the quality of his IT
setup. This company has one server which runs Windows Small Business
Server 2003 R2 Premium Edition. This server hosts an Exchange instance
which takes care of incoming and outgoing emails.

I ran an namp scan (nmap -T4 -A -v -PE -PA21,23,80,3389 <IP_address>)
from a machine outside of the company network and got the results below.
I am wondering why ports 80 and 443 are open since the server does not
act as a web server. Also I am wondering if the Linksys router should be
visible from the outside world ...

If anybody could comment on this and make suggestions on how to improve
the security of that setup, I would appreciate it.

Cheers,
Dan.

Not shown: 990 closed ports
PORT STATE SERVICE VERSION
25/tcp filtered smtp
80/tcp open http Microsoft IIS
|_ html-title: The page cannot be displayed
135/tcp filtered msrpc
139/tcp filtered netbios-ssn
143/tcp open imap Microsoft Exchange Server 2003 imapd
6.5.7638.1
443/tcp open ssl/https?
|_ sslv2: server still supports SSLv2
| html-title: Microsoft Outlook Web Access
|_ Requested resource was https://<...snipped...>
445/tcp filtered microsoft-ds
993/tcp open ssl/imap Microsoft Exchange Server 2003 imapd
6.5.7638.1
|_ sslv2: server still supports SSLv2
1723/tcp open pptp Microsoft (Firmware: 3790)
8081/tcp open http Linksys router http config (device model
BEFSR41/BEFSR11/BEFSRU31)
| http-auth: HTTP Service requires authentication
|_ Auth type: Basic, realm = Linksys BEFSR41/BEFSR11/BEFSRU31
|_ html-title: 401 Authorization Required





------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Learn all of the latest penetration testing techniques in InfoSec
Institute's Ethical Hacking class.
Totally hands-on course with evening Capture The Flag (CTF) exercises,
Certified Ethical Hacker and Certified Penetration Tester exams, taught
by an expert with years of real pen testing experience.

http://www.infosecinstitute.com/courses/ethical_hacking_training.html
------------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Learn all of the latest penetration testing techniques in InfoSec Institute's Ethical Hacking class.
Totally hands-on course with evening Capture The Flag (CTF) exercises, Certified Ethical Hacker and Certified Penetration Tester exams, taught by an expert with years of real pen testing experience.

http://www.infosecinstitute.com/courses/ethical_hacking_training.html
------------------------------------------------------------------------



Relevant Pages

  • Re: SBS2003 Partitioning
    ... It doesn't matter how small the business is it is a bad practice to sell a workstation for use as a server. ... Businesses come to rely on a server very quickly and within a matter of months may no longer be able to function effectively if the server goes down. ... There is no real advantage to moving the page file from the system partition in a small server with one drive/array, and yes it's a good idea to keep Exchange and SQL on separate partitions but given the size of drive you intend on using probably two partitions, at most three, is your best option. ...
    (microsoft.public.windows.server.sbs)
  • Re: Fault Tolerence on SBS2003 Prem.
    ... > Too often this topic is approached without defining any scale or costs. ... There is always a compromise involved in any business ... > server equipment that improved the recovery time from an annual event from ...
    (microsoft.public.windows.server.sbs)
  • Re: CEICW fails at firewall config
    ... > through Remote Web Workplace on a Windows Small Business Server 2003-based ... > + You connect to a Remote Web Workplace on a Windows Small Business ... you cannot install Firewall Client on the ISA Server. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 R2 Update Errors
    ... title Windows Small Business Server Setup ... Installing Windows Small Business Server 2003 ... string was not in a correct format. ...
    (microsoft.public.windows.server.sbs)
  • RE: "companyweb" not working since Windows Server 2003 Sp2 installed
    ... If the issue is urgent to your business, it is recommended that you contact ... Microsoft Customer Support Services via telephone so that a dedicated ... Support Professional can assist you recover the server in a more efficient ... sub-components are selected to INSTALL. ...
    (microsoft.public.windows.server.sbs)

Quantcast