Closing ports

  • Thread starter Thread starter venki
  • Start date Start date
V

venki

Hi,

there are many ports opened in my server windows 2000
server... around 30 ports are opened.... how should i
close them ?
 
venki said:
Hi,

there are many ports opened in my server windows 2000
server... around 30 ports are opened.... how should i
close them ?

1) that depends on the port number. If you tell us the port number or
google it, you'll see what service you need to shut down.
2) and/or, use a firewall. www.kerio.com, www.sygate.com and
www.zonealarm.com are all free. This is easier than researching every port
and is usually secure enough, although doing both is the most secure.
3) harden your machine as below.

http://securityadmin.info/faq.asp#closeports
http://securityadmin.info/faq.asp#harden
http://securityadmin.info/faq.asp#firewall
 
The ports opened in my computer are
53,75,81,80,90,135,139,443,445,637,1002,1025,1027,1026,1031
,1032,1035,1036,1433,1801,2103,2105,2107,3372,5101,6767

what all should i close now ? we use our server as FTP
server & web server so we should open only 21 & 80 rite ?
 
I won't go through all the ports, but assuming these ports are listening
inbound on your computer [something you can tell by doing Start, Run, typing
CMD, press Enter, type NETSTAT -AN and/or NETSTAT -A and press
Enter], then here's what you can do.

75, 637, 1002, 1801,2103,2105,2107,3372,5101,6767: these ports are a new one
on me. could be you're compromised with a Trojan, virus or something? See
the links below for help.
53, 80, 81: uninstall or disable DNS and IIS services, if they're not being
used, from start, settings, control panel, add remove programs, add remove
windows components
135: ditto, for RPC services, if these are not needed
139: disable the Client for microsoft networks, file and print sharing on
the dial up networking icon or network interface that connects to the Internet
1433: are you running SQL or MSDE? why? disable them?

You can and should also use a firewall to restrict who can access these
ports and services, especially if you want or need them to be running and
accessible to some people but not others.

To see whether you've been hacked, update your anti-virus [www.grisoft.com
is free antivirus if you don't have any] and also see below:

http://securityadmin.info/faq.asp#hacked
http://securityadmin.info/faq.asp#startup
http://housecall.antivirus.com
 
Back
Top