Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.
port 139 how to close & why not?
Name: smanish Date: April 12, 2003 at 05:53:11 Pacific OS: windows xp CPU/Ram: P3/128MB
Comment:
how to close port 139 (using zone alarm or otherwise) and what are the harms in closing it ? cud not find any file c:/windows/system/vnbt.386
Name: murve Date: April 12, 2003 at 08:07:58 Pacific
Reply:
hi smanish, for more info on this issue go to www.thepublicworks.com security section and link to Disable Ports 137-139. hope this helps, murve
0
Response Number 2
Name: DRVR Date: April 12, 2003 at 09:02:51 Pacific
Reply:
The article above has good info, but this is a very simple answer here:
If you disable Port 137-139 (NetBIOS) then two things can happen.
Good: You will be (mostly) invisible on a Windows network. This make you a harder target.
Bad: You will be invisible on a Windows network. People will not be able access your computer to get files, send net.exe messages, etc.
By the way, ZoneAlarm doesn't resist SubSeven and LiquidAV attacks, it goes down all too easily. The only firewall that I've found to resist these attacks is Symantec Personal Firewall.
0
Response Number 3
Name: smanish Date: April 12, 2003 at 11:07:45 Pacific
Reply:
thanks friends .. i m trying to follow up ur steps .. i wud appreciate if u also read my other message which details my problem .. its message id is 4772 thanks in advance ;)
Name: Brad Peterson Date: April 13, 2003 at 20:41:43 Pacific
Reply:
Closing port 139 is a good idea simply because it makes you more secure. There are many writeups on what attacks can happen on port 139, but there are probably other vulnerabilites that haven't been discovered yet. It's better to play it safe and block ports such as 139 for protection.
I personally use ZoneAlarm. It allows me to configure IP addresses I can "trust" to send me data over port 139 (thus I can network with them), and ZoneAlarm blocks port 139 requests from all other IP addresses.
Summary: The easy way would be to get either a router with a firewall to block access to it, or use a software firewall like zonealarm, which will tell you anytime a program on your system tries to open a port...