| Windows 7: How could you close,open-unused ports? |
12 Dec 2012
|
#1 | | Microsoft Windows 7 Ultimate 64-bit Service Pack 1 Thessaloniki |
How could you close,open-unused ports? There is a lot of...noise,amongst not in particularly,high-power users,but also simple home or office users about open ports,net,web ports,being used,either from Windows itself or applications.DCOM is an example of a Windows service,that is "listening" to the net,but also sends data through out it.Skype does that all the time.What about those open ports,can they be "closed'?Should they be closed,for safety reasons,not to allow to be used by malware,spyware,hackware? | My System Specs |
| Computer type PC/Desktop System Manufacturer/Model Number Homebuilt,Quadcore processor on Asus MB OS Microsoft Windows 7 Ultimate 64-bit Service Pack 1 CPU Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz Motherboard ASUS P5B-Deluxe Wi-Fi Edition Memory 4x1024 GB DDR2 Corsair PC2-6400 800 Mhz Graphics Card Gigabyte GTX 650 1024MB GDDR5 Sound Card Realtek ALC883 @ Intel 82801HB ICH8 - High Def Monitor(s) Displays Asus VW195 [19" LCD] Screen Resolution 1440x860 pixels Keyboard MS Generic Mouse MS Optical 6000 PSU Hantol 585W Dual fan Case Chieftec Dragon modded side window Cooling Thermaltake Contac 21 Hard Drives Hitachi HD ATA Device 80 GB
WDC WD IDE Device 80 GB
Maxtor ATA Device 80 GB
WDC WD ATA Device 80GB
Hitachi ATA Device 160GB Internet Speed never enough Antivirus ESET Smart Security 5.0.93.0 |
12 Dec 2012
|
#2 | | Windows 7 Ultimate x64 Buenos Aires |
From a security viewpoint, I would close everything you aren't using right now, and just open specifically what you know you need, the bare minimum you actually use and nothing more.
Generally, you should distinguish the "direction" of the communication. You can have incoming connections, where other PC's "call" yours and outgoing, where you establish a connection with someone else. Both are important, but generally, in a regular home or office PC, the average user does a lot of outgoing connections (web browsing, email, MSN) and accept almost no incoming connections (file sharing on local network typically, and almost nothing from internet).
A firewall is possibly the best line of defense against all of those, so that it blocks all ports and programs that aren't used (so no one can "call home"). Routers are very good at stopping incoming connections from internet to the local network, and software firewalls are good for unwanted outgoing ones. | My System Specs | | Computer type Laptop System Manufacturer/Model Number Toshiba Sattelite A665-S6092 OS Windows 7 Ultimate x64 CPU Intel Core i7-740QM Memory 8 GB DDR3 Graphics Card NVIDIA GeForce 330GT Screen Resolution 1366x768 Cooling Coolermaster Notepal U3 notebook cooling pad Hard Drives Samsung 840 SSD 500GB
1TB USB3 external HD Internet Speed 3mbps ASDL Antivirus Kaspersky Antivirus 2013 Browser Opera 12.15 x64 |
12 Dec 2012
|
#3 | | Microsoft Windows 7 Ultimate 64-bit Service Pack 1 Thessaloniki |
Well stated,the direction also is another component of the equation.To whom is our PC listening to?Who is listening to my PC?Data as well,how much in which direction.How to distinguish which ports to stealth,close or to remain open,and as the thread title initially is asking,how? | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Homebuilt,Quadcore processor on Asus MB OS Microsoft Windows 7 Ultimate 64-bit Service Pack 1 CPU Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz Motherboard ASUS P5B-Deluxe Wi-Fi Edition Memory 4x1024 GB DDR2 Corsair PC2-6400 800 Mhz Graphics Card Gigabyte GTX 650 1024MB GDDR5 Sound Card Realtek ALC883 @ Intel 82801HB ICH8 - High Def Monitor(s) Displays Asus VW195 [19" LCD] Screen Resolution 1440x860 pixels Keyboard MS Generic Mouse MS Optical 6000 PSU Hantol 585W Dual fan Case Chieftec Dragon modded side window Cooling Thermaltake Contac 21 Hard Drives Hitachi HD ATA Device 80 GB
WDC WD IDE Device 80 GB
Maxtor ATA Device 80 GB
WDC WD ATA Device 80GB
Hitachi ATA Device 160GB Internet Speed never enough Antivirus ESET Smart Security 5.0.93.0 |
12 Dec 2012
|
#4 | | Windows 7 Home Premium 64 bit. SP-1 Northern Ohio |
You can slow down some of the danger by not having programs starting at boot. Start them only when you want to use them. Like Skype, IM and such. If you want to use them, (have them active all the time) the ports will have to be open.
Here is something you could check out by Gibson Research, Shields up. http://www.grc.com/default.htm | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Home made Desktop OS Windows 7 Home Premium 64 bit. SP-1 CPU Intel i7-960-3.2 @ 4.25 Motherboard ASUS P6X58D-E Memory KINGSTON KHX2000C9, Hyper X,12 GIGS Graphics Card MSI/Nvidia/460GTX-Cyclone 1GD5/OC Monitor(s) Displays DYNEX 40 IN. Screen Resolution 1920-1080 or 1280-720 HDMI Keyboard M/S 3000 v 2.0 wireless Mouse M/S 5000 wireless PSU Corsair AX-850 Plus Gold Case Corsair 600T (Black) + side panel with 2 140 mm Noctua fans Cooling Corsair H50/2 Noctua NF-P12 (120 mm) Push/Pull- Hard Drives INTEL SSD 120GB-SER 510
Seagate 1TB SATA 600 7200 rpm Hard Drive Internet Speed 3.0 mb Antivirus Microsoft Security Eesentials Browser I.E. 10 default/Firefox Other Info LG BluRay-Read/Write
Sound system
KLipsch-THX
Asus Router RTN-12
2 Noctua 140 added on top of 600t case
Malwarebytes Anti Malware Professional
Windows 7 Firewall |
12 Dec 2012
|
#5 | | Windows 7 Ultimate x64 Buenos Aires |
A router does incoming blocking more or less automatically, as from outside your network no one can see your PC unless explicitly allowed (which is disabled by default).
For outgoing connections, you have to use a firewall preferably. That way you can select what ports, and which programs can use them, in both directions. Each one is different in the exact steps to setup the rules, but the basics are the same. Windows itself includes a firewall that does a good job, you may see a couple of tutorials about it in the forum, or just choose for another third party one.
Which ports you need to open and in which direction is very dependent on which programs do you use. You have to search each one documentation's for which port to open. For example, web browsers use ports 80 and 443 for HTTP and HTTPS, mail clients 25/110/995, Windows file share use 137, 138 and 139. In any case, be sure to allow only that program on the firewall, so anything else cannot use that hole for its own purposes.
How much data is transfered is easy, just open task manager and the network tab shows that. You may need to add the columns though the view menu => select columns => tick bytes received and bytes sent. | My System Specs | | Computer type Laptop System Manufacturer/Model Number Toshiba Sattelite A665-S6092 OS Windows 7 Ultimate x64 CPU Intel Core i7-740QM Memory 8 GB DDR3 Graphics Card NVIDIA GeForce 330GT Screen Resolution 1366x768 Cooling Coolermaster Notepal U3 notebook cooling pad Hard Drives Samsung 840 SSD 500GB
1TB USB3 external HD Internet Speed 3mbps ASDL Antivirus Kaspersky Antivirus 2013 Browser Opera 12.15 x64 |
13 Dec 2012
|
#6 | | Microsoft Windows 7 Ultimate 64-bit Service Pack 1 Thessaloniki |
Right on the head of the nail for both.I ended up to Gibson's site while trying to close down a port that was used by System PID 4,and that started a query about who else might be using other ports,without me knowing.That does mean(if it does),that either Windows firewall ,neither the routers settings,had made my system bulletproof.So now,here i am finding out that,ports like 5335,500,1025-1027,1030,1032 and each and every one of them,is leading to services(not windows services meant) like LLMNR (5355),network blackjack(1025?),isakmp(500) and so on,which are hard to comprehend.Too much worries about too less harm? | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Homebuilt,Quadcore processor on Asus MB OS Microsoft Windows 7 Ultimate 64-bit Service Pack 1 CPU Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz Motherboard ASUS P5B-Deluxe Wi-Fi Edition Memory 4x1024 GB DDR2 Corsair PC2-6400 800 Mhz Graphics Card Gigabyte GTX 650 1024MB GDDR5 Sound Card Realtek ALC883 @ Intel 82801HB ICH8 - High Def Monitor(s) Displays Asus VW195 [19" LCD] Screen Resolution 1440x860 pixels Keyboard MS Generic Mouse MS Optical 6000 PSU Hantol 585W Dual fan Case Chieftec Dragon modded side window Cooling Thermaltake Contac 21 Hard Drives Hitachi HD ATA Device 80 GB
WDC WD IDE Device 80 GB
Maxtor ATA Device 80 GB
WDC WD ATA Device 80GB
Hitachi ATA Device 160GB Internet Speed never enough Antivirus ESET Smart Security 5.0.93.0 |
13 Dec 2012
|
#7 | | Windows 7 Ultimate x64 Buenos Aires |
First, NOTHING can do your system bulletproof, going online implies some risks always and at most you can aim at reducing those. To be 100% secure from anything, you have to leave your computer turned off
I see that you're using Windows Firewall. You probably need to properly configure it to your needs. By default, it's configured to be easy to use, that is, very insecure, as it opens a lot of incoming ports for I don't know what purposes and does NOT block anything outgoing.
Open the advanced firewall settings (look for "firewall with advanced security" in start menu search) and there you can find both the incoming and outgoing rules that actually apply, to fine tune them to your particular usage.
My personal preference is to begin with everything blocked (configure to block all except rules allowing it). That way you're effectively off the internet. Then selectively open ports one by one so your programs begin working again. While this is hard to do by hand and you need to know what are you doing, it gives you optimal security if you have the patience. In particular, I don't know any of the services you're naming. And if you don't know them neither, probably you're not using them, so it would be a good idea to block them until something breaks. | My System Specs | | Computer type Laptop System Manufacturer/Model Number Toshiba Sattelite A665-S6092 OS Windows 7 Ultimate x64 CPU Intel Core i7-740QM Memory 8 GB DDR3 Graphics Card NVIDIA GeForce 330GT Screen Resolution 1366x768 Cooling Coolermaster Notepal U3 notebook cooling pad Hard Drives Samsung 840 SSD 500GB
1TB USB3 external HD Internet Speed 3mbps ASDL Antivirus Kaspersky Antivirus 2013 Browser Opera 12.15 x64 |
13 Dec 2012
|
#8 | | Windows 7 Home Premium 64 bit. SP-1 Northern Ohio |
P2P and torrants can also leave ports open. Which is about as good of way of getting infected I can think of. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Home made Desktop OS Windows 7 Home Premium 64 bit. SP-1 CPU Intel i7-960-3.2 @ 4.25 Motherboard ASUS P6X58D-E Memory KINGSTON KHX2000C9, Hyper X,12 GIGS Graphics Card MSI/Nvidia/460GTX-Cyclone 1GD5/OC Monitor(s) Displays DYNEX 40 IN. Screen Resolution 1920-1080 or 1280-720 HDMI Keyboard M/S 3000 v 2.0 wireless Mouse M/S 5000 wireless PSU Corsair AX-850 Plus Gold Case Corsair 600T (Black) + side panel with 2 140 mm Noctua fans Cooling Corsair H50/2 Noctua NF-P12 (120 mm) Push/Pull- Hard Drives INTEL SSD 120GB-SER 510
Seagate 1TB SATA 600 7200 rpm Hard Drive Internet Speed 3.0 mb Antivirus Microsoft Security Eesentials Browser I.E. 10 default/Firefox Other Info LG BluRay-Read/Write
Sound system
KLipsch-THX
Asus Router RTN-12
2 Noctua 140 added on top of 600t case
Malwarebytes Anti Malware Professional
Windows 7 Firewall |
13 Dec 2012
|
#9 | | Microsoft Windows 7 Ultimate 64-bit Service Pack 1 Thessaloniki |
Fiddled around with Gibson's site,scanned my ports for Internet Vulnerability,first 1056 ports came out as stealthed,tried out an app called DCOMbobulator,in order to disable DCOM,as a safety measure(that it didnt,is another issue),also tried a firewall leakage tester that turned out that my firewall WAS penetrated by it.The app is really small and does not provide additional info,on which port was used.Windows firewall has several rules grayed out(most of them) but many are in green,inbound and outbound.Installed ZoneAlarm,it only messed up my system. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Homebuilt,Quadcore processor on Asus MB OS Microsoft Windows 7 Ultimate 64-bit Service Pack 1 CPU Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz Motherboard ASUS P5B-Deluxe Wi-Fi Edition Memory 4x1024 GB DDR2 Corsair PC2-6400 800 Mhz Graphics Card Gigabyte GTX 650 1024MB GDDR5 Sound Card Realtek ALC883 @ Intel 82801HB ICH8 - High Def Monitor(s) Displays Asus VW195 [19" LCD] Screen Resolution 1440x860 pixels Keyboard MS Generic Mouse MS Optical 6000 PSU Hantol 585W Dual fan Case Chieftec Dragon modded side window Cooling Thermaltake Contac 21 Hard Drives Hitachi HD ATA Device 80 GB
WDC WD IDE Device 80 GB
Maxtor ATA Device 80 GB
WDC WD ATA Device 80GB
Hitachi ATA Device 160GB Internet Speed never enough Antivirus ESET Smart Security 5.0.93.0 How could you close,open-unused ports? problems? All times are GMT -5. The time now is 09:05 AM. | |