Penetration Testing mailing list archives
Re: Re: Strange ports
From: "Tim Shea" <tim () tshea net>
Date: Fri, 22 Jun 2007 13:24:09 -0500 (CDT)
Per the original note - this was a scan of an external firewall. There is no reason for udp/53 to be open unless this is a stateless firewall (doubtful per the scan). Internal clients would be coming through the internal interface of the firewall and udp/53 would need to be opened on that interface not the external interface. But to be quite frank - I am shocked how many people are weighing in on what "needs to be opened" without knowing one single requirement. He asked an opinion on a couple of ports. What is opened or not depends upon that companies architecture and how they have things deployed. He needs to work with those folks to determine what is valid or not. t.s
I would agree that port 53 UDP needs to be open. Port 53 TCP does not unless you are doing large DNS zone transfers. ------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
Current thread:
- RE: Strange ports, (continued)
- RE: Strange ports Erin Carroll (Jun 19)
- Re: Strange ports Jason Barbier (Jun 19)
- Message not available
- Re: Strange ports StaticRez (Jun 19)
- Message not available
- Re: Strange ports zion (Jun 19)
- Re: Strange ports R. DuFresne (Jun 21)
- Re: Strange ports Christine Kronberg (Jun 22)
- Re: Strange ports R. DuFresne (Jun 21)
- Re: Strange ports Tim Shea (Jun 19)
- Re: Strange ports killy (Jun 24)
- Re: Strange ports ebk_lists (Jun 19)
- Re: Re: Strange ports brian . marino (Jun 22)
- Re: Re: Strange ports Tim Shea (Jun 22)
- Re: Re: Strange ports Thor (Hammer of God) (Jun 22)