Messenger Service used for SPAM

From: Rob Pagé (rob123.page123_at_etech123results.com)
Date: 01/14/04


Date: Wed, 14 Jan 2004 12:51:30 -0800

I've read the Q/A regarding this issue and I have since
disabled the messenger service and am starting to
implement the solution with my clients. However the
document also indicated that the I should be blocking
ports 135, 137, 138, 139 & 445. The troubling thing for
me is that I do have a firewall in place and the only
ports that I have forwarded to this server is 1723. I
have other ports open but they are forwarded to our web
server (80, 21, 25, 443, 8080) and no message has ever
shown up on this server.

Is there a new problem with the messaging service where
it is listening on other ports or has there been a
compromise on the server? Is anybody aware of this
problem? I am concerned that I may be dealing with a
breach and would appreciate some assistance.

If you need to e-mail me directly, just remove the
numerics from my e-mail address.

Thanks

Rob Pagé



Relevant Pages

  • Re: Open Ports
    ... want the ports open even ifs all in house and behind the hardware firewall??? ... it opens up in demo mode. ... server is Cisco Catalyst Express 500 switches for voice over IP. ... will take requests from the clients. ...
    (microsoft.public.windows.server.general)
  • Whos blocking these ports? Please help...
    ... server - one is called Vicomsoft Internet Gateway (proxy server, ... IG basically takes over the TCP/IP routing and does this using ... Each of these ports uses a NIC in the server. ... All the clients are assigned IPs ...
    (microsoft.public.win2000.security)
  • Re: Servers & Routers and Firewalls, Oh my....
    ... This will ensure that the external NIC of the server ... The router, which is> connected to NIC1 is running DHCP so NIC1 can pull an IP> from it. ... The router has> certain ports open and allowing traffic to the IP that> the server pulled. ... > Now, when clients try to use programs that needs those> ports, it's acting like they are not open. ...
    (microsoft.public.windows.server.sbs)
  • Re: Firewalls and RPC (was "Re: Improvement to IPFilter / nfsd in FBSD (6.2+?)")
    ... The large number of RPC services using randomly assigned ports needed by NFS and the fact that machines which trust each other enough to permit filesharing and generally utilize a common set of directory services to keep the user/group mappings synced mean that the NFS server & clients should be considered in the same "trust domain" in most cases. ...
    (freebsd-questions)
  • RE: Remote access issue: Unable to add the interface...
    ... When you are on the outside of the LAN and connect to the server how do you ... open for RWW to work to the clients. ... Incoming ports that should NOT be open ... Routing and Remote Access service seems to be running fine, ...
    (microsoft.public.windows.server.sbs)