Penetration Testing mailing list archives

Re: [PEN-TEST] Closing Port 139


From: Steve <steve () SECURESOLUTIONS ORG>
Date: Thu, 12 Oct 2000 13:24:13 -0600

RE: [PEN-TEST] Closing Port 139I had heard this "rumor" as well.  But, I
have a test box that I am using the NT packet filtering on and it seems to
be working great.  The box has all ports except for 80 (it is a web server)
filtered.  Seems to be doing its job.

------------------------------------------------------------------------

Steve Manzuik                                   Calgary, Alberta, Canada
Moderator - Win2K Security Advice               (403)660-2997

Security Analyst - Bindview RAZOR Team
smanzuik () razor bindview com
http://razor.bindview.com

* - The opinions expressed in this email are mine, and mine alone.  They - *
* - do not reflect those of my employer or anyone else for that matter.  - *

------------------------------------------------------------------------

  -----Original Message-----
  From: Penetration Testers [mailto:PEN-TEST () SECURITYFOCUS COM]On Behalf Of
Anderson, Harry F.
  Sent: Thursday, October 12, 2000 11:47 AM
  To: PEN-TEST () SECURITYFOCUS COM
  Subject: Re: [PEN-TEST] Closing Port 139


       How well does this work on just NT?  I have been told that the NT
packet filtering does not work consistantly with all ports.   I have wanted
to test it but there is just not enought time in the day.

    - Harry Anderson

    -----Original Message-----
    From:   Ansar Mohammed [SMTP:amohammed () CARIB-LINK NET]
    Sent:   Thursday, October 12, 2000 11:53 AM
    To:     PEN-TEST () SECURITYFOCUS COM
    Subject:        Re: [PEN-TEST] Closing Port 139

    Both Microsoft Windows NT and Proxy Server provide packet filtering at
the
    NIC level.

    It can be accessed from the Security Tab of the Proxy Server properties
and
    the network applet of control panel.

    > -----Original Message-----
    > From: Penetration Testers [mailto:PEN-TEST () SECURITYFOCUS COM]On Behalf
    > Of Kasey Speakman
    > Sent: Thursday, October 12, 2000 9:54 AM
    > To: PEN-TEST () SECURITYFOCUS COM
    > Subject: [PEN-TEST] Closing Port 139
    >
    >
    > How do I close this port?  The situation is that we are using
    > an NT Server
    > machine with MS Proxy Server.  There are no shares on this
    > computer.  The
    > computer has 2 nics.  One goes to the LAN, and the other goes
    > to our router.
    > I have the internet nic unbound from the WINS on both the
    > server and the
    > workstation services, but the other card is bound to the WINS on both
    > services.  Auditing tools still show that the port is open,
    > even though it
    > won't give anyone any connections, but I don't want any
    > attention being
    > drawn to it by that port being open at all.  Help will be appreciated!
    >
    > Thanks,
    >
    > Kasey



    -------------------------------
    --  Even though this E-Mail has been scanned and found clean of
    --  known viruses, OPM can not guarantee this message is virus free.
    -------------------------------
    --  This message was automatically generated.
    -------------------------------


Current thread: