Re: Open Ports....How to block them all....?

From: Jeff Cochran (jcochran.nospam@naplesgov.com)
Date: 11/19/02


From: jcochran.nospam@naplesgov.com (Jeff Cochran)
Date: Tue, 19 Nov 2002 19:55:38 GMT


>I keep it up to date with SP's and Patches but find that the server keeps
>getting hacked and used as an "FTP" server with that stupid "Serv-U" app.
>What can be done to secure this server so that this doesn't keep happening?
>Is port blocking (leaving only bare necessity open) my only recourse? If so,
>how?
>
>I'm a developer, and know only basic fundamentals of OS/IIS security.....

Step 1: Reformat, reinstall and restore. You may have a backdoor
already installed.

Step 2: http://www.microsoft.com/security/ Install the patches
*before* you come back online. Especially URLScan and the lockdown
tool, making sure you read the docs so you can still use scripts.

Step 3:
http://www.systemexperts.com/win2k/HardenWin2K.html
http://www.anitian.com/corp/papers/Hardening_Win2k.pdf
http://rr.sans.org/win2000/standalone.php
http://www.ntsecurity.net/Articles/Index.cfm?ArticleID=22365

Step 4: Configure your firewall to accept only those ports you wish,
port 80, maybe 20/21, 25, 53, 110 depending on what you're using.
Yep, you *need* a firewall.

Step 5: If you're still paranoid, Network Connections -> TCP/IP ->
Advanced -> Options and configure filtering. Though you may need
ports open that you don't want outsiders to use, and this is an on/off
deal. Firewalls are more configurable.

Good luck.

Jeff



Relevant Pages

  • Re: Firewall - Limit Geographic Area
    ... Firewall - Limit Geographic Area ... > times more secure than a Microsoft Windows machine can be). ... Redhat is conservative about what they release ... > - do not reuse passwords between your server and, say, random ...
    (RedHat)
  • Re: Interesting webserver intrusion (apache 1.3.31, mod_ssl 2.8.18, php 4.3.7)
    ... > fairly tight(only allowing 4 ports in), but perhaps I could tighten it ... The host systems firewall rules govern the access to the jailed system. ... What connections does your server need to ... Perhaps there is a 0-day for your ftp server out there. ...
    (Incidents)
  • Re: Add 2nd NIC after intial install?
    ... My biggest question with 1 NIC is: even if workstations are protected with individual firewall products, what is protecting the SBS server itself if ports are open for remote access through the Linksys firewall? ...
    (microsoft.public.windows.server.sbs)
  • Re: Source Code to Filter out WindowsMessenger POP-UPS
    ... Zone Alarm does NOT support 'server'. ... Very few ports are open, ... >What you are asking for amounts to a firewall. ... I would NOT search for source code to compile ...
    (microsoft.public.inetserver.iis.security)
  • Re: Using Office Outlook with exchange server behind windows firewall
    ... On our network I have windows firewall turned on, on both my small business server and my windows xp workstations. ... Based on an article I read about all the ports that exhange may use I also tried making exceptions for ports ...
    (microsoft.public.windows.server.sbs)