Computing.Net > Forums > Security and Virus > Ports REALLY worth blocking??

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Ports REALLY worth blocking??

Reply to Message Icon

Name: Sgt B@sh
Date: November 19, 2003 at 18:43:19 Pacific
OS: Windows XP
Comment:

Hello gents,

I had viruses and other windows exploits in the past which has prompted me to take action such as blocking open ports and closing known ports used by trojans etc.

I use Norton Personal Firewall have recently configured BOTH system wide-settings and trojan horse settings to block ports 135, 139, 445, 1025, 1028 & 5000.

For a while the system looked secure backed-up with a good virus Scanner and the additional extras like Spyware Blaster, ad-aware etc. Despite this, I couldn't help but notice that surfing the web has become slower to retrive and view webpages. If I unblock the ports web pages load at the normal high speed.

How do I go about this one? Is it worth blocking these ports because legitimate programs also use them and it slows them down, or should I be safe rather than sorry?

Your views please.
Thank-You all.

(Solarian you're welcome to answer this one too if you want, since you possess knowledge of such things :D)




Sponsored Link
Ads by Google

Response Number 1
Name: sonnysandiego
Date: November 19, 2003 at 19:34:50 Pacific
Reply:

Legitimate programs don't use those ports for web browsing. Keep them blocked or you will have worse problems especially with the symptoms you describe.

try CWShredder & see if it finds anything. Then try HiJackThis.


0

Response Number 2
Name: Solarian
Date: November 19, 2003 at 19:37:25 Pacific
Reply:

Sarge:

Long time, no post. 8-)

Seriously, the ports you listed are the most dangerous ones when left unprotected. Not having used Norton Personal Firewall, I can't explain why your web surfing has suffered a speed problem.

I keep all of my PC's ports stealthed (invisible), not just closed. I've never had a speed problem while surfing, and I've used all four of the most popular firewalls: Sygate, Agnitum, Zone Alarm, and Kerio. At the moment, I'm using Sygate.

Have you tested your firewall? If not, there are a couple of good online tests at:

www.grc.com

Look for ShieldsUp.

Another online test can be found at:

www.pcflank.com

Look for Advanced Port Scanner.

The tests won't help you with your speed issue, but they will determine your firewall's effectiveness.

I'm sure someone using Norton Personal Firewall will post and have a solution, or at least a suggestion, for you.

Best of luck, Solarian


0

Response Number 3
Name: Solarian
Date: November 19, 2003 at 19:45:35 Pacific
Reply:

Sarge:

Just read Response Number 1. If you do decide to post a HijackThis log, make sure to mention at the beginning that you've scanned your PC with both Spybot and Ad-Aware (it's a forum rule).

Your problem could very well be related to spyware--one of the first symptoms is browser performance.

Solarian


0

Response Number 4
Name: doghead
Date: November 19, 2003 at 20:36:29 Pacific
Reply:

This thread is sexist.


0

Response Number 5
Name: Solarian
Date: November 19, 2003 at 20:40:27 Pacific
Reply:

LOL! And portist, too.


0

Related Posts

See More



Response Number 6
Name: Lesley
Date: November 20, 2003 at 00:24:59 Pacific
Reply:


I've long since given up pointing out that women use computers also.....lol


0

Response Number 7
Name: JackG
Date: November 20, 2003 at 00:25:16 Pacific
Reply:

If your firewall is completely blocking port 113, instead of showing it closed, then that can cause some web sites to respond slowly. ZoneAlarm has special code to "handle" this ID port, and I would expect your firewall would too. Make sure you have not altered any default settings of your firewall for port 113. It is OK for it to show up as "Closed" on port tests.


0

Response Number 8
Name: Sgt B@sh
Date: November 20, 2003 at 05:57:38 Pacific
Reply:

Afternoon LADIES & Gents

Nice to hear from you again Solarian =D

I did as you said and went to grc.com and went to shields up, to do the online test, only to get the "This page cannot be displayed: cannot find server" error.

Also ran some tests at pcflank.com, the advanced port scanner tells me that ports 23, 135, 137, 138, 139, 1080, 1243, 3128, 12345, 12348, 27374 and 31337 are "closed", except for ports 21 & 80.

I've scanned my PC with Ad-aware and Spybot S&D and here's my Hijack-this log: -

Logfile of HijackThis v1.97.7
Scan saved at 13:52:05, on 20/11/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
G:\Program Files\Norton Personal Firewall\NISUM.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
G:\Program Files\Norton Personal Firewall\NISSERV.exe
G:\Program Files\Norton Personal Firewall\SymProxySvc.exe
G:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
G:\WINDOWS\Explorer.exe
G:\PROGRA~1\POP-UP~1\dpps2.exe
G:\Program Files\Norton Personal Firewall\IAMAPP.exe
G:\Program Files\Winamp\Winampa.exe
G:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
G:\WINDOWS\System32\ctfmon.exe
G:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
G:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
G:\Program Files\Internet Explorer\IEXPLORE.exe
G:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Documents and Settings\ManUTD\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=:0
F2 - REG:system.ini: UserInit=G:\WINDOWS\System32\Userinit.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - G:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O4 - HKLM\..\Run: [Pop-Up Stopper] "G:\PROGRA~1\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iamapp] G:\Program Files\Norton Personal Firewall\IAMAPP.exe
O4 - HKLM\..\Run: [WinampAgent] "G:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [WebScan] G:\PROGRA~1\ACCELE~1\ANTI-V~1\DEFSCA~1.exe -k
O4 - HKCU\..\Run: [siabcs] G:\Program Files\Steganos Internet Anonym 2\siabcs.exe
O4 - HKCU\..\Run: [Steam] G:\Program Files\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "G:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [CTFMON.EXE] G:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item:
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37944.7933449074
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

As for port 113 it doesn't stae if it's closed or open Jack.

Thank-you ALL for your advice and assistance.

Hope to hear from you soon (yes you too Solarian). :D



0

Response Number 9
Name: efabes
Date: November 20, 2003 at 08:40:32 Pacific
Reply:

Hi Guys,

I do not see anything suspicious in the log (though someone else might).

I have complained about NPF before. You seem to be having some of the problems I did. Norton also tended to "forget" some of my rules which had worked previously (and there was no virus).

I would disable norton and try the free version of Zone Alarm. If your problems dissappear, you know to get rid of Norton.


0

Response Number 10
Name: wawadave
Date: November 20, 2003 at 10:21:05 Pacific
Reply:

hello
the only thing i can see with why your d/ls are slower with is that your cpu is working a bit harder runing your fire wall with the ports blocked.not knowing what your cpu ram situation is.


0

Response Number 11
Name: Sgt B@sh
Date: November 20, 2003 at 12:28:07 Pacific
Reply:

My CPU speed is 1.2 Ghz, I have 256 MB Ram and I am currently using Norton Personal Firewall, (Considering the use of Zone Alarm Pro in the meantime).


0

Response Number 12
Name: Solarian
Date: November 20, 2003 at 14:42:33 Pacific
Reply:

Sarge:

Just an opinion from personal experience. There's no need to shell out $ for the Pro version of Zone Alarm--unless you want the extra bells and whistles.

The free version will completely stealth your computer.

Solarian


0

Response Number 13
Name: Sgt B@sh
Date: November 20, 2003 at 16:02:38 Pacific
Reply:

My intention was to use the free version, but upon testing it at pcflank.com, the results show exactly the same ports closed & open as with Norton Personal Firewall. I was hoping to stealth my computer like you mentioned. Maybe I haven't figured how exactly to stealth it. Thanx for your thoughts on that, will re-consider now :D


0

Response Number 14
Name: efabes
Date: November 21, 2003 at 13:56:43 Pacific
Reply:

Are the sites loading faster without Norton?

I have zone alarm on my lesser-used pc. It is set to medium security in the internet zone and shows up as full stealth at grc (though I also have port 113 forwarded on my router).

I do not remember what other settings I changed and will not have access to it right now.


0

Sponsored Link
Ads by Google
Reply to Message Icon

trojanhorse downloader.wi... need help with trojan.dow...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Ports REALLY worth blocking??

Port 9339 is blocked by my router. www.computing.net/answers/security/port-9339-is-blocked-by-my-router/26840.html

Ports still stealth blocked! www.computing.net/answers/security/ports-still-stealth-blocked/9042.html

Blocking Ports www.computing.net/answers/security/blocking-ports-/12392.html