Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 17 Dec 2002 01:02:34 -0000
From:      "Petersen" <petersen@britersen.co.uk>
To:        "Robin P. Blanchard" <robin.blanchard@georgiacenter.org>
Cc:        <stable@freebsd.org>
Subject:   RE: ipfilter / ipnat quandry
Message-ID:  <KOEDJPGCNAIOODFOCJJICEBCFMAA.petersen@britersen.co.uk>
In-Reply-To: <1040064948.3dfe21b49d39a@www.gactr.uga.edu>

next in thread | previous in thread | raw e-mail | index | archive | help
Robin P. Blanchard wrote:

>
> The only external port I've allowed in is SSH, yet nmapping the box
> yields a slew of purportedly other open ports. Have I broken my
> ruleset somewhere? Please advise.
>
> # nmap -v -sS -O a.b.c.d
<snip>
> Interesting ports on name.of.host(a.b.c.d):
> (The 1581 ports scanned but not shown below are in state: closed)
> Port       State       Service
> 22/tcp     open        ssh
> 137/tcp    filtered    netbios-ns
> 138/tcp    filtered    netbios-dgm
> 139/tcp    filtered    netbios-ssn
> 161/tcp    filtered    snmp
> 162/tcp    filtered    snmptrap
> 199/tcp    filtered    smux
> 391/tcp    filtered    synotics-relay
> 705/tcp    filtered    unknown
> 1234/tcp   filtered    hotline
> 1433/tcp   filtered    ms-sql-s
> 1900/tcp   filtered    UPnP
> 1993/tcp   filtered    snmp-tcp-port
> 5050/tcp   filtered    mmcc
> 6346/tcp   filtered    gnutella
> 6666/tcp   filtered    irc-serv
> 6667/tcp   filtered    irc
> 6668/tcp   filtered    irc
> 6699/tcp   filtered    napster
> 8888/tcp   filtered    sun-answerbook

What slew of open ports. I see only 1 (sshd), 19 that don't appear to exist
at all (ie, they aren't answering syns), and 1581 that are just closed.

Petersen


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?KOEDJPGCNAIOODFOCJJICEBCFMAA.petersen>