Re: XP SP2 with firewall actived and run symantec security check tools...

From: José Joye (jose.joye_at_KILLTHESPAMSbluewin.ch)
Date: 09/22/04


Date: Wed, 22 Sep 2004 11:05:44 +0200

Thanks,

That's better now...

However, I still have the port 135 which is open. I look at the exception
and did not find anything related.
Is there a way to close this port?

José

"Stephen Cartwright [MSFT]" <scart@online.microsoft.com> wrote in message
news:%23npS5NznEHA.4056@TK2MSFTNGP09.phx.gbl...
> It sounds like you have File and Print sharing exception enabled at least
> for ports 139 and 445, this would also account why ICMP echo request is
> being seen.. If you do not need to share this out then you can disable the
> exception as this does expose your machine as reported by the symantec
> port scan
>
> --
> Stephen Cartwright [MSFT]
>
> "This posting is provided "AS IS" with no warranties, and confers no
> rights."
>
> "José Joye" <jose.joye@KILLTHESPAMSbluewin.ch> wrote in message
> news:edecnVtnEHA.3876@TK2MSFTNGP15.phx.gbl...
>> Thanks!
>> José
>> "PA Bear" <PABear@mvps.org> wrote in message
>> news:e1lp02PnEHA.3196@TK2MSFTNGP10.phx.gbl...
>>> The WinXP firewall is a one-way (incoming) firewall.
>>>
>>> For more help, see...
>>>
>>> Troubleshooting Your Installation of SP2
>>> http://support.microsoft.com/default.aspx?scid=fh;[ln];xpsp2insttshoot
>>>
>>> Changes to Functionality in Microsoft Windows XP Service Pack 2
>>> Network Protection
>>>
>>> http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2netwk.mspx
>>>
>>> Troubleshooting Windows Firewall settings in Windows XP Service Pack 2
>>> http://support.microsoft.com/default.aspx?kbid=875357
>>> --
>>> ~Robear Dyer (PA Bear)
>>> MS MVP-Windows (IE/OE), AH-VSOP
>>>
>>> Are You Ready for WinXP SP2?
>>> http://www.microsoft.com/athome/security/protect/default.aspx
>>>
>>> WinXP SP2 Release Notes
>>> http://support.microsoft.com/default.aspx?scid=kb;en-us;835935
>>>
>>> AumHa Forums
>>> http://forum.aumha.org
>>>
>>> José Joye wrote:
>>>> First, sorry if this has already been asked before. I goooooooogled to
>>>> find
>>>> it but did not get a clear evidence ;-)
>>>>
>>>>
>>>> I installed the SP2 and activated the firewall.
>>>> Then I went to Symantec and run their security checker
>>>> http://security.symantec.com/default.asp?productid=symhome&langid=ie&venid=sym
>>>>
>>>> It tells me that it is open to acker exposures:
>>>>
>>>> - ICMP ping --> Open (In the advanced
>>>> tab,
>>>> of my firewall for ICMP, this is not allowed???)
>>>> - 135 Location Service (loc-srv) --> Open
>>>> - 139 NetBios --> Closed
>>>> - 445 WindowNT/2000 SMB --> Open
>>>>
>>>>
>>>> I tried to look at the docs (...not sure where to find a good one) to
>>>> see if
>>>> I can close/hidde these ports --> but did not find any...
>>>>
>>>>
>>>> Could someone tell me if it is possible to close these ports and how to
>>>> amend the setting so as to be as safe as possible with the integrated
>>>> firewall.
>>>>
>>>>
>>>> Thanks,
>>>> José
>>>
>>
>>
>
>



Relevant Pages

  • Re: Bug with W2K3, SP1, Windows Firewall and FTP
    ... add program not add port. ... I'm confuse as well:) between the advanced tab and exception tab. ... port in the Exceptions and checking the FTP Server in the Advanced ... I decided to try adding a port 21 in the firewall exception list just to ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Login failed for user x, Error: 18456
    ... string returnValue = string.Empty; ... catch (Exception ex) ... Make sure that account that is running the asp.net account has a sql server ... The port could be "moving" on you. ...
    (microsoft.public.sqlserver.programming)
  • Problems with dynamic port binding to consume web service
    ... I'm trying to create an application which use a dynamic web port to call ... Uncaught exception has suspended an ... pepLookup, Guid portId, XLANGMessage msg, Segment seg, String opname, String ... IList toPromote, Boolean ignoreRoutingFailure) ...
    (microsoft.public.biztalk.general)
  • Re: Serialport Object kann nicht zerstört werden
    ... Serialport Klasse zu schicken eine Exception ("Zugriff auf Com1 wurde ... Was macht Dein Programmcode, wenn dieser TimeOut-Fall ... ob der Port geöffnet ist. ... genau der im Protokoll festgelegten Antwort zu quittieren und ...
    (microsoft.public.de.german.entwickler.dotnet.vb)
  • Re: Change RDP Port in XP Firewall
    ... > Windows Firewall for the new exception. ... > box, using the new port, from my XP Home box. ... is in fact UNCHECKED in the Windows Firewall Exception ...
    (microsoft.public.windowsxp.work_remotely)