Search Members Help

» Welcome Guest
[ Log In :: Register ]

Mini-ITX Boards Sale, Fanless BareBones Mini-ITX, Bootable 1G DSL USBs, 533MHz Fanless PC <-- SALE $200 each!
Get The Official Damn Small Linux Book. DSL Market , Great VPS hosting provided by Tektonic
Pages: (5) </ 1 2 3 [4] 5 >/

[ Track this topic :: Email this topic :: Print this topic ]

reply to topic new topic new poll
Topic: open ports, portscan showed several ports open Web< Next Oldest | Next Newest >
doobit Offline





Group: Members
Posts: 912
Joined: July 2005
Posted: Dec. 28 2005,19:24 QUOTE

I don't think anyone is taking this badly, really. We are just trying to get to the bottom of it as simply as possible. That might take a few investigative questions, so hang in there, please.

--------------
"Help stop internet piracy...use Linux!"
Back to top
Profile PM WEB MSN 
gray Offline





Group: Members
Posts: 10
Joined: Dec. 2005
Posted: Dec. 28 2005,19:52 QUOTE

OK, I'll keep on trying :)

BTW another portscan site is here http://scan.sygatetech.com and yes I know they are a firewall / security company, but I have just done all the tests through Zonealarm and they couldn't find anything at all. - despite their obvious aim of wanting people to buy security from 'em...
GRC is here http://www.grc.com/default.htm and he too found nothing. Granted in both cases I am behind a firewall but it is a good check to see if they try for a false result.

Personally, I think anyone without a router should have a firewall in place, but speaking as a long-time XP user, Guard Dog is the closest I have seen to a user-friendly GUI for configuring a firewall in Linux.

I used it for a while when running Gentoo, but discovered one issue: even after saving the iptables config file and ensuring that iptables ran at startup, I always had to re-run Guard Dog to access the Web after a reboot, and other people in the Gentoo forums mentioned this - a pity as otherwise it was  simple and effective: stealthed ports all the way. Possibly by now this issue has been fixed. Anyhow I just used that as an example of what could be done.

I try an installtion of the RC2 DSL and see what comes up.

Gray
Back to top
Profile PM 
cbagger01 Offline





Group: Members
Posts: 4264
Joined: Oct. 2003
Posted: Dec. 28 2005,20:08 QUOTE

gray,

Don't take my response personally.

I was just pontificating on the whole ShieldsUp! paranoia.  Unless you and him are the same guy, then please don't feel persecuted by me.

Maybe someone will solve the "mystery of the open ports", but unless you are running DSL embedded or you are running DSL + some additional myDSL extensions, then I cannot see how those ports can be open.

I am not saying that your eyes are lying.

I am just saying that I am at a loss to explain it.
Back to top
Profile PM 
gray Offline





Group: Members
Posts: 10
Joined: Dec. 2005
Posted: Dec. 29 2005,19:49 QUOTE

hehe - nope Ol' GRC and me are definitely not the same people - wish I had his salary and was earning a real currency tho' !!

OK, I shut the PC down totally, to remove any possibility of something coming over from XP and then went over to GRC and Sygate and ALL THE PORTS WERE CLOSED.

I also did specific tests for 554 and for 1755 - BOTH WERE CLOSED

These are the comments each made, Sygate first and GRC second:

1. This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.


2. Solicited TCP Packets: RECEIVED (FAILED) ? As detailed in the port report below, one or more of your system's ports actively responded to our deliberate attempts to establish a connection. It is generally possible to increase your system's security by hiding it from the probes of potentially hostile hackers. Please see the details presented by the specific port links below, as well as the various resources on this site, and in our extremely helpful and active user community.

Unsolicited Packets: PASSED ? No Internet packets of any sort were received from your system as a side-effect of our attempts to elicit some response from any of the ports listed above. Some questionable personal security systems expose their users by attempting to "counter-probe the prober", thus revealing themselves. But your system remained wisely silent. (Except for the fact that not all of its ports are completely stealthed as shown below.)

Ping Reply: RECEIVED (FAILED) ? Your system REPLIED to our Ping (ICMP Echo) requests, making it visible on the Internet. Most personal firewalls can be configured to block, drop, and ignore such ping requests in order to better hide systems from hackers. This is highly recommended since "Ping" is among the oldest and most common methods used to locate systems prior to further exploitation.
---------------------------------------------------------------------

Now I have to ask: is it possible for a Windows service to affect the ports of another system after a reboot ? I remember seeing someplace that a mere reboot doesn't clear memory, only a total shutdown (which is why I did the shut down before starting this) - of course the ideal is to totally remove XP from this box - wonder if the Devs here can tweak wine to run my Pirates (new version) :). I'll try that tomorrow - am on a dial-up here so it all costs - monopoly telco.

Guys and Gals, thanks for your patience

Gray

PS: still don't know why my friends didn't see ports open in SUSE and XP but just in DSL, and before you reckon he hates the OS, HE was the one that mentioned DSL to me (has it on 3 of his own boxes for figuring how to make a Super PC with nodes etc)
Back to top
Profile PM 
cbagger01 Offline





Group: Members
Posts: 4264
Joined: Oct. 2003
Posted: Dec. 29 2005,21:09 QUOTE

FYI,

If you really want a firewall running on DSL, you can install

iptables

from the System area of the Mydsl repository and even

rcfirewall

from the Network area of the repository.

Then you can block/stealth any ports that you wish.  Although I maintain that merely respoding to a port request is not a security risk in and of itself.
Back to top
Profile PM 
24 replies since Dec. 25 2005,09:14 < Next Oldest | Next Newest >

[ Track this topic :: Email this topic :: Print this topic ]

Pages: (5) </ 1 2 3 [4] 5 >/
reply to topic new topic new poll
Quick Reply: open ports

Do you wish to enable your signature for this post?
Do you wish to enable emoticons for this post?
Track this topic
View All Emoticons
View iB Code