944,082 Members | Top Members by Rank

  • Networking Discussion Thread
  • Unsolved
  • Views: 6328
  • Networking RSS
Jul 30th, 2005
0

How to secure computer ports?

Expand Post »
How can I block/close unused ports of the windows network computers? for example, port 7, 135 and 53. Is there a command or a utility?

Thank you.
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
tigoluxa is offline Offline
10 posts
since Jul 2005
Jul 30th, 2005
0

Re: How to secure computer ports?

I guess this is exactly what I need

http://support.microsoft.com/?id=813878
Reputation Points: 10
Solved Threads: 0
Newbie Poster
tigoluxa is offline Offline
10 posts
since Jul 2005
Jul 30th, 2005
0

Re: How to secure computer ports?

Here is how I do a quick lockdown:

Make sure the server is fully patched before you begin.

Run a port scan on the ip from the local segment, take note of all ports that respond.

Look up by port number the app that uses that port.

Determine if that application is necessary on that server, if not stop the service and disable it so it won't start on bootup.

The ports left open you server will need to offer to computers on the network and probably can't be changed, stuff like DHCP or DNS.

If I am dealing with an internet box I start with the same proceedure then put it behind a SOLID firewall (never on box) and open only the required ports for the NAT address. Then I use a tool like nmap from the outside to confirm I can't see anything more than what I expect to from that box.

What does everyone else do?
Reputation Points: 13
Solved Threads: 3
Junior Poster
w1r3sp33d is offline Offline
186 posts
since Dec 2004
Aug 3rd, 2005
0

Re: How to secure computer ports?

A couple notes--

One big item is to make sure you aren't running any unnecessary services. ie: Check your Services and set any unncessary ones to Manual/Disabled.

Also, use the SysInternals tools that can tell you which programs have which ports open. They have great free tools.

I also like to use a personal firewall. I use SyGate. This way I can set very detailed rules down to a specific application. I can also then review the logfiles to see which programs may need other ports open, etc.

For a start, if you're using WinXP SP2, you could use the Windows Firewall.

As w1r3sp33d stated, it's also good to scan your network/workstation from the outside to verify the open ports.

That's what I'd do...

--Chris
Reputation Points: 11
Solved Threads: 0
Newbie Poster
cSc0911 is offline Offline
17 posts
since Aug 2005

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Networking Forum Timeline: VPN to a PC in the same domain problems
Next Thread in Networking Forum Timeline: WEP encryption key





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC