pen-test
[Top] [All Lists]

Re: Re: Strange ports

To: brian.marino@onenterprises.com
Subject: Re: Re: Strange ports
From: "Tim Shea" <tim@tshea.net>
Date: Fri, 22 Jun 2007 13:24:09 -0500 (CDT)
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Importance: Normal
In-reply-to: <20070622114121.8452.qmail@securityfocus.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <20070622114121.8452.qmail@securityfocus.com>
Reply-to: tim@tshea.net
Resent-date: Fri, 22 Jun 2007 17:34:17 -0600 (MDT)
Resent-from: pen-test-return-1078484441@securityfocus.com
Resent-message-id: <20070622233417.5F3AD2379BE@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: SquirrelMail/1.4.8-1.fc5
Per the original note - this was a scan of an external firewall.

There is no reason for udp/53 to be open unless this is a stateless
firewall (doubtful per the scan).  Internal clients would be coming
through the internal interface of the firewall and udp/53 would need to be
opened on that interface not the external interface.

But to be quite frank - I am shocked how many people are weighing in on
what "needs to be opened" without knowing one single requirement.  He
asked an opinion on a couple of ports.  What is opened or not depends upon
that companies architecture and how they have things deployed.  He needs
to work with those folks to determine what is valid or not.

t.s


> I would agree that port 53 UDP needs to be open.  Port 53 TCP does not
> unless you are doing large DNS zone transfers.
>
> ------------------------------------------------------------------------
> This List Sponsored by: Cenzic
>
> Are you using SPI, Watchfire or WhiteHat?
> Consider getting clear vision with Cenzic
> See HOW Now with our 20/20 program!
>
> http://www.cenzic.com/c/2020
> ------------------------------------------------------------------------
>
>


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>