Re: Port Scanning Issue

From: Recon (Recon1025@msn.com)
Date: 06/18/02


From: "Recon" <Recon1025@msn.com>
Date: Tue, 18 Jun 2002 11:18:48 -0700


I tried many scanners including Superscanner 3.0 and Fscan
from foundstone. If i configure the firewall with DEFAULT
CONFIGURATIONS worse problems arise such as new ports like
389,1720 and 21 including the others that i had. The
firewall in this example is the one which comes by default
with winxp pro. Your help is greatly appreciated.
>-----Original Message-----
>It is a stretch of the imagination that a config of the
machine
>you are using causes a change in the port bindings of
other
>machines. How many scanners have you tried ? This sounds
>more like some sort of issue with your scanner.
>
>--
>Roger
>
>
>"Recon" <Recon1025@msn.com> wrote in message
>news:f82101c215f5$9ae51370$3bef2ecf@TKMSFTNGXA10...
>> Everytime I start port scanning my computer, another
host
>> in my domain or ever outside of it I get to see the same
>> two open ports 25 and 110 which are SMTP and POP3 as you
>> all know. However when i enable my firewall which comes
>> builtin winxp pro (the one I'm using) more ports like
LDAP
>> 389 and netmeetings port 1720 and even ftp 21 decide to
>> open on every host i scan including mine. After
inspection,
>> connection to those port fails with a "NOT A SOCKET"
error
>> according to netcat and telnet by specifying which
ports I
>> need to connect to. Even if you disable the
firewall,ports
>> 21,389,1720 will be gone but ports 25 and 110 decide to
>> stay open on every host I scan. Is there any logical
>> explanation to this? Any solution?
>>
>> Your help is greatly appreciated...
>> Cheers
>>
>
>
>.
>



Relevant Pages

  • Re: Scanned for open relay ?
    ... Any spammer,hacker, or crook can go to these types of lists and find their ... an extremely inefficient firewall. ... someone is knocking at a whole slew of ports fishing for anything they can ... these scanners and complain so that may not be a bad thing in this case. ...
    (comp.security.firewalls)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: iptables configuration
    ... >> that if a 'virus/trojan' initiated a connection to the net, the firewall ... >> would not protect the LAN. ... The LAN is NATed with private IPs to one public IP. ... the ports that are used by services running on linux. ...
    (comp.os.linux.security)
  • Re: Norton Personal Firewall 2003
    ... |> First thing I would do is put the GRC test site into the Exclusions ... | ports they will not get the same result being in my blocklist, ... the firewall checks unsolicited inbound communications attempts. ...
    (comp.security.firewalls)
  • Re: How to stealth against ping/echo requests?
    ... I just started using the Online-Armor firewall. ... Some ports are even open. ... Are you behind a router? ... Every time it founds a new LAN, it asks if you want to trust it ...
    (comp.security.firewalls)