Security Basics mailing list archives

RE: Which ports to block?


From: "David Gillett" <gillettdavid () fhda edu>
Date: Mon, 2 Aug 2004 09:01:26 -0700

  "deny all" should block all ports.  It's purpose is to catch traffic
that has not been approved as safe, and that includes the various
backdoors, trojans, viruses, spyware, games, etc, that generate traffic
above port 1023.

David Gillett


-----Original Message-----
From: Ferino Mardo [mailto:RMardo () ALJOMAIHBEV com]
Sent: Saturday, July 24, 2004 1:04 AM
To: security-basics () securityfocus com
Subject: Which ports to block?


In setting up a "deny all" rule from a firewall, is it safe to block
ports 0 to 65535 or only up to 1023? My interest are only to 
allow port
53 udp, 25, and 80.

--------------------------------------------------------------
-------------
Ethical Hacking at the InfoSec Institute. Mention this ad and 
get $545 off 
any course! All of our class sizes are guaranteed to be 10 
students or less 
to facilitate one-on-one interaction with one of our expert 
instructors. 
Attend a course taught by an expert instructor with years of 
in-the-field 
pen testing experience in our state of the art hacking lab. 
Master the skills 
of an Ethical Hacker to better assess the security of your 
organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
--------------------------------------------------------------
--------------


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------

Current thread: