Hi Frank, As of the best practice, there should definitely be a "clean up rule" to deny all ports that are not explicitly allowed, so I agree with you there. Just a note, as I mentioned, "SMB over TCP" type of traffic will try port 445 first. If port 445 is blocked, then it will try port 139 as a default behavior of Windows. Strong Passwords are the key defense to this type of worm/Trojans, especially the Local Administrator Passwords. Cheers, /Kyle Kyle Lai, CISSP, CISA KLC Consulting, Inc. 617-921-5410 klaiat_private www.klcconsulting.net -----Original Message----- From: Frank Knobbe [mailto:fknobbeat_private] Sent: Tuesday, March 04, 2003 3:00 PM To: incidentsat_private Subject: RE: TCP 445 Scan? On Tue, 2003-03-04 at 10:18, kyleat_private wrote: > [...] > The only good defense is to block port 445 and port 139 ports on your > firewall, and set strong passwords for every user on your network, including > administrator accounts. No offense Kyle, but this bad advice. I'm not lashing out at you, but I'm starting to get really irritated when people recommend 'simply block this port on your firewall'. If that is what you have to do, then you have much bigger problems. Firewalls should block ALL PORTS by default. Only allow in what you need to allow in. Anything else should be blocked. And that should include port 445 [1]. Here again: B L O C K A L L B Y D E F A U L T , A L L O W O N L Y W H A T I S N E E D E D . Print this out and stick it on your firewall management console :) Regards, Frank [1] Unless you really need it for some weird reason. But that would make all this a mute point anyway. --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.459 / Virus Database: 258 - Release Date: 2/25/2003 ---------------------------------------------------------------------------- <Pre>Lose another weekend managing your IDS? Take back your personal time. 15-day free trial of StillSecure Border Guard.</Pre> <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A>
This archive was generated by hypermail 2b30 : Wed Mar 05 2003 - 14:32:12 PST