Re: Firewall rule closed ALL but Port UDP 137 open

From: Tutaepaki (replyto@newsgroup.not.me)
Date: 10/30/02


From: "Tutaepaki" <replyto@newsgroup.not.me>
Date: Thu, 31 Oct 2002 09:01:54 +1300


"Markus Dubois" <Markus.Dubois@gmx.ch> wrote in message
news:186d15f6.0210300045.77aeba03@posting.google.com...
> Hi,
>
> on my home internet PC (Win98 Shared internet access, firewalled with
> Norton Internet Security 2002) a nmap scan shows port udp 137 open.
> Even if i make a rule on top with
> block all any any
>
> Very odd situation. There is nothing open according to my
> firewall-rule but nmap shows this open port......
>
> Why?
>
> Regards
>
> Markus

NMAP, and other port scanners don't do a very good job of scanning UDP
ports. UDP is stateless, therefore there is no response you can rely on to
indicate that the port is open. If you've set up your firewall to simply
drop
packets without sending a response, most port scaners will report the port
as open.



Relevant Pages

  • Re: how nmap can know my firewalled servers ?
    ... UDP or ICMP protocol), it will mark the port as closed. ... descrition, how NMAP determins, if the UDP port is open or closed. ... Try Webroot's Spy Sweeper Enterprisefor 30 days for FREE with no ...
    (Security-Basics)
  • Re: IP Chains -- DENY or REJECT
    ... >-sU UDP scans: This method is used to determine which UDP (User Data? ... > to send 0 byte udp packets to each port on the target machine. ... is depend on specification of nmap. ... Which useage is correct, DENY or REJECT? ...
    (comp.os.linux.security)
  • Re: Unknow process listening on high port
    ... Nmap failed to give any more information, ... 100000 2 udp 111 portmapper ... 100021 1 udp 32828 nlockmgr ... > BTW, I'm just guessing but, 39207 looks to be an RPC port to me. ...
    (Security-Basics)
  • nmap -- UDP scanning
    ... It is well documented that UDP scanners wait for an "icmp port unreachable" message to differentiate between open/filtered ... Seen as this method cannot be used, it does not seem feasible for nmap to generate any meaningful information in this ... If the port is open, nmap sends two udp packets with a length of zero -- no data is returned. ...
    (Pen-Test)
  • Re: IP Chains -- DENY or REJECT
    ... You've got the proto UDP below, not tcp, so from man nmap: ... -sU UDP scans: This method is used to determine which UDP (User Data­ ... When running an nmap UDP port scan, it shows certain ports> open. ...
    (comp.os.linux.security)