Re: I am REALLY Getting Tired of Probes on 445 and 135

From: Leythos (void_at_nowhere.org)
Date: 11/14/04


Date: Sun, 14 Nov 2004 14:22:40 GMT

In article <slrncpdu4g.p0h.jayjwa@atr2.ath.cx>, jayjwa@nowhere.org
says...
> On 2004-10-01, Leythos <void@nowhere.org> wrote:
>
> > I think that all ISP's
> > should force NAT on users via their DSL/Cable modems, and all of the
> > DSL/Cable modems should block outbound 135~139/445/1433/1434. There is
> > no valid reason to connect on those ports - that's what a VPN is for.
>
> I don't. Why should I have any of my Internet access restricted in any way due
> to MS and their legions of users running their glass-jawed OS? If I'm paying
> for Internet access, I want *full* Internet access, not just the ports that
> are "safe" (the ones that there's no MS virus/exploit written for yet).
>
> Following this logic, we should then also block all 1025, 1026, 2145, 5000,
> 5554, 6129, 9898, 12345, 17300, and 31337?

because it's not YOUR internet access, it's a service provided by the
ISP and they can change it at any time without your permission.

While you may not like it, MS machines are the most compromised on the
net and there is little going to change about that. If you're not using
a MS machine then blocking those ports (the ones I mentioned) would mean
little, if anything, to your system. Since the ports I mentioned are not
something that should be used "across" the internet by MS machines,
there is little reason to expose them on networks being used by MS
systems, in fact, it might increase everyone's performance if they were
blocked.

One last thing - nice troll on the MS OS, it's actually quite stable,
quite securable, and quite easy to manage once you learn it, much the
same as Linux.

-- 
-- 
spamfree999@rrohio.com
(Remove 999 to reply to me)


Relevant Pages

  • Re: Domain workstation cannot see the domain for adding user permi
    ... My ISP had provided two dns server ... Now I have internet access via the dsl ... use only domain controllers as their preferred DNS servers because in an AD ... The network has a dsl router which only some machines are allowed to use ...
    (microsoft.public.windowsxp.security_admin)
  • Re: WinXP Pro 10 user limit question
    ... disable Netbios on the 4 machines that only need internet access, ... > need internet access on the new router under 192.168.0.1. ... > the new hub which feeds into my broadband connection. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Virus Protection or Not
    ... Firs off *can* you prevent Internet access "politically"? ... > computers including the CNC machines networked together. ... > that we use as a logon server and as a file server. ...
    (microsoft.public.windows.server.security)
  • Re: Networking
    ... remove internet access on one of the XP machines in such a way that i can ... In Line 3 of the above batch file you must set the correct "Default Gateway" ... You can see what it is by typing this command from a Command ...
    (microsoft.public.windowsxp.general)
  • Re: How to apt-get over ssh tunnel through a firewall?
    ... I have a number of debian machines that live behind a firewall. ... However machines B-D were not granted internet access and live on the general internal network, ... Now machines B-D no longer live on the private network but can ssh into machine A. ...
    (Debian-User)

Loading