
TECH TIPS
Check your Windows port associations
Tom Lancaster 12.09.2003
Rating: -3.78- (out of 5)




|
One vulnerable aspect of "Windows out of the box" is the UDP and TCP
ports it uses to support file and print sharing, directory services
and name resolution. Using these ports on any local area network for
these purposes is tolerable. But for any link to the Internet, they definitely are not. One of my favorite security tools makes a compelling case for why you should never utilize either one. (See the screen text capture below, picked up verbatim from my Windows 2000 Professional laptop on my home network).
The tool in the illustration here is FPort. It's from a company named Foundstone. It's a company that includes as principals two of the folks behind the wildly successful (and entirely useful) Hacking Exposed books—namely George Kurtz and Stuart McClure. It also includes long-time PC Magazine programming editor, book author, and Windows guru Chris Prosise.
FPort lists all open TCP and UDP ports it discovers, along with the associated process ID (Pid) and process name (Process). The tool is free, easy to download, and
To continue reading for free, register below or login
To read more you must become a member of SearchSecurity.com

a snap to use; in the directory where Fport.exe resides, open a command window and type Fport at the command line.
Why is this tool valuable? Because it shows all TCP and UDP ports open on the machine where it runs. This defines the set of ports you should inspect and block at the interface (or firewall) that connects your machine or network to the Internet. For the screen display shown above, you'd want to close all ports shown below 1,024 and be pretty picky about which applications (namely, the Task Scheduler, MSTask.exe; various elements of Norton Internet Security, Internet Explorer and so forth) are allowed Internet access.
By combining judicious external scans of your system(s) or network (readily available at Gibson Research or Symantec (to name just two of many such tools) with the "inside view" that FPort provides, you can easily learn what ports to check and block, as needed.
Thomas Alexander Lancaster IV is a consultant and author with over 10 years experience in the networking industry, focused on Internet infrastructure.
 |

|
Rate this Tip
|
To rate tips, you must be a member of SearchSecurity.com. Register now
to start rating these tips. Log in if you are already a member.
|


');
// -->
DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.
|
 |
|
|
 |
|
 |