RE: TCP 445 Scan?

From: kyleat_private
Date: Wed Mar 05 2003 - 09:37:00 PST

  • Next message: Dan Hanson: "New SecurityFocus article announcement"

    Hi Frank,
    As of the best practice, there should definitely be a "clean up rule" to
    deny all ports that are not explicitly allowed, so I agree with you there.
    
    Just a note, as I mentioned, "SMB over TCP" type of traffic will try port
    445 first.  If port 445 is blocked, then it will try port 139 as a default
    behavior of Windows.
    
    Strong Passwords are the key defense to this type of worm/Trojans,
    especially the Local Administrator Passwords.
    
    Cheers,
    /Kyle
    
    Kyle Lai, CISSP, CISA
    KLC Consulting, Inc.
    617-921-5410
    klaiat_private
    www.klcconsulting.net
    
    -----Original Message-----
    From: Frank Knobbe [mailto:fknobbeat_private]
    Sent: Tuesday, March 04, 2003 3:00 PM
    To: incidentsat_private
    Subject: RE: TCP 445 Scan?
    
    
    On Tue, 2003-03-04 at 10:18, kyleat_private wrote:
    > [...]
    > The only good defense is to block port 445 and port 139 ports on your
    > firewall, and set strong passwords for every user on your network,
    including
    > administrator accounts.
    
    
    No offense Kyle, but this bad advice. I'm not lashing out at you, but
    I'm starting to get really irritated when people recommend 'simply block
    this port on your firewall'. If that is what you have to do, then you
    have much bigger problems.
    
    Firewalls should block ALL PORTS by default. Only allow in what you need
    to allow in. Anything else should be blocked. And that should include
    port 445 [1].
    
    
    Here again:
    
    B L O C K   A L L   B Y   D E F A U L T ,
    A L L O W   O N L Y   W H A T   I S   N E E D E D .
    
    Print this out and stick it on your firewall management console :)
    
    Regards,
    Frank
    
    
    
    [1] Unless you really need it for some weird reason. But that would make
    all this a mute point anyway.
    
    ---
    Outgoing mail is certified Virus Free.
    Checked by AVG anti-virus system (http://www.grisoft.com).
    Version: 6.0.459 / Virus Database: 258 - Release Date: 2/25/2003
    
    
    ----------------------------------------------------------------------------
    
    <Pre>Lose another weekend managing your IDS?
    Take back your personal time.
    15-day free trial of StillSecure Border Guard.</Pre>
    <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A>
    



    This archive was generated by hypermail 2b30 : Wed Mar 05 2003 - 14:32:12 PST