Re: telnet, do i need it and is it safe?

From: Kent W. England [MVP] (kwe_at_mvps.org)
Date: 08/28/04


Date: Sat, 28 Aug 2004 10:42:47 -0700

Darren wrote on 28-Aug-2004 12:49 AM:

> Hi
>
> I use the free version of Sygate for my firewall and have done all the port
> scans etc to check it and after a bit of messing around it says i am
> stealthed to the world!
>
> However when i run a common ports scan at 'shield up' it says port 23 used
> by Telnet is only closed and not stealthed and a potential security risk.
>
> What is Telnet? Do i need it? If not how do i disable/block it? If i do how
> do i stealth this port?
>
> Hope someone can help an amateur
>
> Darren

Open a command prompt and run the command "netstat -an" and see if it
reports any process listening on port 23. If it isn't
%windir%\system32\tlntsvr.exe, then it is likely something bad. If it is
tlntsvr.exe, you can disable it in services.msc, but you said you were
using XP Home, so it shouldn't show up.

However, I note that using the Windows Firewall included in SP2 on XP
Pro, if the firewall is disabled, ShieldsUp! reports that telnet port 23
is "closed" meaning that my machine replied and said that the service is
not available, instead of stealthed, which means my machine didn't reply
at all.

If I enable the Windows Firewall, then port 23 is stealthed. The telnet
service is disabled on my machine. The Microsoft Baseline Security
Analyzer also complains about telnet service when it isn't running,
probably for the same reason. XP replies to telnet connection requests,
even when the telnet server isn't running or isn't installed (Home).

So set your firewall to explicitly stealth port 23. And check some other
scan sites to make sure that port 23 really is reporting itself as
closed, instead of keeping its mouth shut.

-- 
Kent W. England, Microsoft MVP for Windows Security


Relevant Pages

  • How to stealth port 113 (ident/auth) for users of [NAT] routers
    ... not stealth port 113 using their firewall software (Norton ... Turns out it wasn't a fault of their firewall. ... My NAT router was the culprit although it has some ... router to block traffic on port 113, ...
    (microsoft.public.security)
  • Re: choosing firewall and antivirus: Norton or McAfee ? And anonym
    ... stealthed, whereas a non-stealth firewall will issue a reset, causing the ... spoofee to reject the spoofed data traffic. ... trojans and worms I'd guess that having even ONE port non-stealhed makes ... "other" stealth useless. ...
    (microsoft.public.security)
  • Re: Firewall question 2
    ... U should never have 2 or more firewall installed AND running ... If a port is showing as closed, it can be scanned and eventually be broken ... Results from stealth scan at TCP/IP address: ... There is NO EVIDENCE WHATSOEVER that a port ...
    (comp.security.firewalls)
  • Re: Viewers get error message. Need to conferm theory.
    ... Are you sure you've enabled not just port forwarding, ... Firewall) and port forwarding ... It should be the "Internet IP" reported by your router. ... Can he "telnet" to that address? ...
    (microsoft.public.windowsmedia.encoder)
  • Re: choosing firewall and antivirus: Norton or McAfee ? And anonym
    ... A stealth port just means it can not be detected at all and may or may not ... firewall then there is no way to spoof it anyhow. ... is authorized/trusted such as traffic from the same network as the computer ...
    (microsoft.public.security)