Re: closing port 445

From: chris000012002 (chris000012002_at_delete-spam.yahoo.com)
Date: 05/07/04


Date: Fri, 7 May 2004 04:02:23 +0100


<snip>

> Just in case I did the patch wrong, and the fw goes down
> I want the system to be safe. Somebody here said, "paranoia comes
> from experience and is not necessarily a bad thing."
>
> I see that several services use port 445 in winxp: rpc locator,
> netbios over tcp/ip, and others.
>
> What if I disable the rpc locator in the services manager and
> disable netbios over tcp/ip for the internet connection?
>
> Port 445 would still be open, but maybe the exploit that
> sasser uses would be closed.
>
> IOW, I'm asking what subservice of port 445 does sasser exploit
> that I can safely disable?
>
> --
> +----------------> Jason Wade <----------------+
> | savon1414_050404@earthlink.net |
> | "Swen, Bagle, come, come, come." |
> | "Destroying viruses, 'til there're none." |
>

No don't disable that service I'm no expert but from what I've read the
service rather important.

http://www.blackviper.com/WinXP/service411.htm#Remote_Procedure_Call_(RPC)

http://www.blackviper.com/WIN2K/win2kservice411.htm#Remote_Procedure_Call_(RPC)



Relevant Pages

  • Re: How to Plug Netbios SSN ( Port TCP/139 ) vulnerability in Windows NT/2000
    ... NetBIOS over TCP/IP can be disabled in TCP/IP ... Advanced - WINS tab - select Disable NetBIOS over TCP/IP). ... > Port scanners are not always reliable or accurate. ...
    (microsoft.public.win2000.security)
  • Re: Robocopy
    ... Probably not as it would use port 139/445 TCP I imagine which are the ports ... If you disable netbios over tcp/ip on the ...
    (microsoft.public.win2000.networking)
  • Re: z/OS using a guest virtual LAN under z/VM
    ... Making the DEVICE name the same as the TRLE name does *not* correspond to what I just posted on the IBMTCP-L list concerning the relationship between the TRLE statement and the DEVICE statement. ... The device name must be the PORT name of the LAN adapter defined in a TRLE for a QDIO connection. ... OSA port operating in either ATM native mode or in QDIO mode. ... If used by TCP/IP, this name must also be defined as the portname in the TCP/IP Profile DEVICE statement. ...
    (bit.listserv.ibm-main)
  • Re: VPN problems
    ... But assuming you want to let people at the office access something else through the VPN tunnel, your easiest method is to set up one Linux box as a router so that everyone's traffic passes through that box and out. ... Anyway, you shouldn't be letting people with Macs connect directly to broadband - and certainly not people with Windows - especially in your case, you should assume the broadband connection is full of evil hackers and worms. ... Only protocols on top of UDP and TCP/IP have ports. ... One of the nice things with OpenVPN is that it uses UDP and so you can easily change the port if you want. ...
    (comp.os.linux.networking)
  • Re: Security for stand alone computer.
    ... >> the port from problems. ... Usually zone alarm can work just fine on a LAN. ... You can use the tcp/ip filtering to only allow in tcp and udp ... > HTTP ...
    (comp.security.firewalls)