Re: advice about a worm intrusion alert



Arnie Rowland wrote:
Port 1434 is the SQL Browser service used for locating SQL Servers.

I would NOT allow Ports 1434 or 1433 to be open to the outside.

Is this a NAT router directly connected to your DSL/Cable modem?


Thanks for the reply. This is all a mystery to me.
Set up is an ADSL Router with NATS firewall incorporated. I have Skype if that is relevant - the entry for that against its icon in Zone Alarm is "Listening to Port(s) TCP:80,443,14695"

The router is set with IP Filtering enabled, for filtering inbound traffic - there are no entries in the table in that section.
The section on Virtual Server Configuration DMZ host has:
"Those IP packets from the Internet that do NOT belong to any applications configured in the port forwarding table will be: Discarded"
There is nothing set up in the port forwarding section

Any more checking I should do? The router NATS seems to do its job in terms of the Shields Up tests, but I haven't then disabled the NATS to test the actual ZA software firewall on the machine itself.

--
Rev Robert M Jones, Wimborne Baptist Church, UK
http://www.wimborne-baptist.org.uk
Free trial of Mailwasher Pro - effective email spam filter - (commission
goes to our partners in Bulgaria)
http://fta.firetrust.com/index.cgi?id=420
.



Relevant Pages

  • RE: nmap reveals trinoo_master on router
    ... I would recommend for you to go and read the nmap documentation ... Nmap cannot determine whether the port is open because packet ... filtering prevents its probes from reaching the port. ... could be from a dedicated firewall device, router rules, or host-based ...
    (Incidents)
  • Re: TCP/IP Ports
    ... I don't know of any way to force upd return port to be in a specific range. ... Your router should be blocking uninitiated inbound attempts in a default ... > on the external adapter performing the same task?). ... > has packet filtering switched on. ...
    (microsoft.public.security)
  • RE: nmap reveals trinoo_master on router
    ... filtering can also be done by your gateway's ISP ... Objet: Re: nmap reveals trinoo_master on router ... this port on my internal IP address range, ...
    (Incidents)
  • Re: looking for new router for home based networking and broadband with content filtering
    ... > with content filtering for usenet and so on. ... > 802.11G has a known issue with port blocking. ... The Belkin I use has this parental control provided by cerberian ... > router and took it back the next day. ...
    (comp.security.firewalls)
  • Re: Using Remote Desktop From an SBS Domain
    ... when you tried to RDP while attached directly to a port on your router? ... So if 3389 needs forwarded on the client end too then that is what the ... Hopefully next week I can attempt a connection while my ISP watches the ...
    (microsoft.public.windows.server.sbs)