Computing.Net > Forums > Windows XP > I could use some help on this one..

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Click here to start participating now! Also, check out the New User Guide.

I could use some help on this one..

Reply to Message Icon

Name: Sabertooth
Date: July 21, 2004 at 10:56:16 Pacific
OS: XP Pro SP2 v.2149
CPU/Ram: Mobile XP 2600+ @ 2.52Ghz
Comment:

I decided to audit my PC last night by running the following tests (advanced).

0. http://www.auditmypc.com/
1. http://www.dslreports.com/secureme_go
2. https://grc.com/
3. http://hackerwhacker.com/
4. http://www.pcflank.com/about.htm
5. http://scan.sygatetech.com/probe.html

Everything went well for the most part except the Shields UP, the PC failed the TruStealth analysis because it found port 1033 open, thereafter I ran wwdc.exe (Windows Worms Doors Cleaner) and disabled DCOM, LOCATOR and NetBIOS.

Repeated the tests this morning, same result except now TruStealth analysis finds port 1027 open in addition to port 1033, I have a software firewall (KPF 4.0.16).

Is there anyway to manually configure Kerio to stealth those two ports, I have gone over KPF settings and can't seem to find how. I have tried various software firewalls and like the simplicity and performance of KPF so far and will really appreciate any help.

Thx.

____________________________
The greatest risk is not taking one




Response Number 1
Name: sidtheman
Date: July 21, 2004 at 11:44:26 Pacific
+1
Reply:

I had the same problem when i used Kerio and Norton 2003. THe ports kept showing as open.

Then I switched to the free version of ZA a few mths back, and it seems like it did the job. Try it out and run the shields up test, it should stealth all the ports. I think ZA does the job. Just don't buy ver 5 yet tho!!



Response Number 2
Name: Sabertooth
Date: July 21, 2004 at 11:58:50 Pacific
+1
Reply:

Tried ZA in the past, but it leaves too much to be desired in the registry after I removed it. Will test run v.5 and see what happens.

____________________________
The greatest risk is not taking one



Response Number 3
Name: XpUser
Date: July 21, 2004 at 12:12:27 Pacific
+1
Reply:

Hi Sabertooth,

The links below contains relevant info regarding Ports 1033 and 1027.

GRC Port Authority Database: Port 1033

GRC Port Authority Database: Port 1027

Purpose of Port 1033 is local netinfo port. Trojan sightings include NetSpy.

As for Port 1027, the webpage included a very lengthy argument, background and additional info mostly about Microsoft OS tendency to use this port. The article even suggested hiding your PC behind router NAT might be your best defense.

Regards

i_XpUser



Response Number 4
Name: XpUser
Date: July 21, 2004 at 12:14:45 Pacific
+1
Reply:

OOOPPSS bad link for port 1027 sorry my friend. .. This one should work :-)

GRC Port Authority Database: Port 1027

i_XpUser



Response Number 5
Name: Sabertooth
Date: July 21, 2004 at 12:27:32 Pacific
+1
Reply:

XpUser,

The two links you posted has been the reason my imaginary tail has remained tucked in between my legs all day. If you probe those two ports are they open, closed or stealthed on your PC?.

____________________________
The greatest risk is not taking one



Related Posts

See More



Response Number 6
Name: XpUser
Date: July 21, 2004 at 12:30:43 Pacific
+1
Reply:

Hey Saber - Hmmmm you wanna me to take the leap and test mine for comparative purpose with yours?

i_XpUser



Response Number 7
Name: per
Date: July 21, 2004 at 12:32:13 Pacific
+1
Reply:

Hi Sabretooth- I am using ZA 5.0 and my ports are stealthed on those links. I am also behind a router. Rgds.



Response Number 8
Name: XpUser
Date: July 21, 2004 at 12:34:00 Pacific
+1
Reply:

Hi Per,

The link for the Test, Plz?

OK Saber I'll take the leap

i_XpUser



Response Number 9
Name: per
Date: July 21, 2004 at 12:35:37 Pacific
+1
Reply:

Hi XpUser-Your links, test this port.



Response Number 10
Name: Sabertooth
Date: July 21, 2004 at 12:48:18 Pacific
+1
Reply:

per,

....sic...sic probe this port?


I assume it is safe to speculate KPF will not allow manual port stealthing? also anyone out there experience any compatibility issues with ZA and KPF together?

____________________________
The greatest risk is not taking one



Response Number 11
Name: per
Date: July 21, 2004 at 12:50:04 Pacific
+1
Reply:

Yeah, sorry, probe this port. Never used KPF, always ZA.



Response Number 12
Name: XpUser
Date: July 21, 2004 at 12:56:13 Pacific
+1
Reply:

Here's the test report from GRC

GRC Port Authority Report created on UTC: 2004-07-21 at 19:53:42

Results from scan of ports: 0-1055

0 Ports Open
1 Ports Closed
1055 Ports Stealth
---------------------
1056 Ports Tested

NO PORTS were found to be OPEN.

The port found to be CLOSED was: 113

Other than what is listed above, all ports are STEALTH.

I'm using NIS 2004 FW and behind Linksys BEFSR41 router.


i_XpUser



Response Number 13
Name: per
Date: July 21, 2004 at 12:59:17 Pacific
+1
Reply:

I believe you can stealth 113 in your router setup. I have d-link so you will have to read the directions. Oh man, I hate to read directions. LOL!.



Response Number 14
Name: XpUser
Date: July 21, 2004 at 13:05:39 Pacific
+1
Reply:

Thanks, Per.

I have Linksys BEFSR41 - anyone familiar with stealthing Port 113?

i_XpUser



Response Number 15
Name: Sabertooth
Date: July 21, 2004 at 13:11:00 Pacific
+1
Reply:

....never thought I'd miss my netgear router this soon......;~(

____________________________
The greatest risk is not taking one



Response Number 16
Name: per
Date: July 21, 2004 at 13:14:48 Pacific
+1
Reply:

Port 113 info-grc.com/port_113.htm. You have to set up the router to send any 113 querys to a false ip. See section -nat routers.



Response Number 17
Name: XpUser
Date: July 21, 2004 at 13:15:08 Pacific
+1
Reply:

....never thought I'd miss my netgear router this soon......;~(

Why not get another one quickly so you can freely wangle your tail like a happy dog?

i_XpUser



Response Number 18
Name: XpUser
Date: July 21, 2004 at 13:16:33 Pacific
+1
Reply:

Port 113 info-grc.com/port_113.htm. You have to set up the router to send any 113 querys to a false ip. See section -nat routers.

Thanks buddy!

i_XpUser



Response Number 19
Name: per
Date: July 21, 2004 at 13:20:23 Pacific
+1
Reply:

You are Welcome. Let us know how it worked out.



Response Number 20
Name: Sabertooth
Date: July 21, 2004 at 13:28:15 Pacific
+1
Reply:

I'll probably drop by best buy to pick-up another one tommorrow. Giving it away to my ex's dad was the last favor to him before parting ways.

He does not need the router, he can barely check his mail on one PC let alone two networked to share a connection, but am afraid asking him for it might want to make him return the favor by having her back as well..lol

____________________________
The greatest risk is not taking one



Response Number 21
Name: per
Date: July 21, 2004 at 13:29:58 Pacific
+1
Reply:

Is that a bad thing? LOL!



Response Number 22
Name: XpUser
Date: July 21, 2004 at 13:31:43 Pacific
+1
Reply:

Saber -

Feel free to join our "Divorcers Club" :-)) I think you already know theres many of us belonging there! By the way marriage isn't made to last for all eternity!

i_XpUser



Response Number 23
Name: Sabertooth
Date: July 21, 2004 at 13:35:51 Pacific
+1
Reply:

Per,

You know how a lifer feels after getting a one-day pass to hooters?

____________________________
The greatest risk is not taking one



Response Number 24
Name: per
Date: July 21, 2004 at 13:38:11 Pacific
+1
Reply:

No, I lived most of my life on the road among many beautiful flight atts. One eyed dog in a meat market.LOL!



Response Number 25
Name: sonnysd1
Date: July 21, 2004 at 13:53:51 Pacific
+1
Reply:

re: stealthing port 113 on Linksys

The latest firmware for a BEFSX41 has an option to stealth 113. Same is probably true for the BEFSR41. Research the firmware before upgrading, some people have reported problems.



Response Number 26
Name: Sabertooth
Date: July 21, 2004 at 13:57:17 Pacific
+1
Reply:

....why on the road? did your plane run out of jet fuel. Oh! I think I know what it was, the captain wanted in on every bit of the action too....:~)

____________________________
The greatest risk is not taking one



Response Number 27
Name: per
Date: July 21, 2004 at 14:04:11 Pacific
+1
Reply:

I was the captain and got most of the action. LOL!



Response Number 28
Name: XpUser
Date: July 22, 2004 at 05:47:03 Pacific
+1
Reply:

Per and blackdogx.

Thanks for the info.

The firmware for my BEFSR41 V1 used to be 1.45. I updated it to 1.46. Ran the GRC test again. Here's result:

GRC Port Authority Report created on UTC: 2004-07-22 at 12:21:04

Results from scan of ports: 0-1055

0 Ports Open
0 Ports Closed
1056 Ports Stealth
---------------------
1056 Ports Tested

ALL PORTS tested were found to be: STEALTH.

TruStealth: PASSED
- ALL tested ports were STEALTH,
- NO unsolicited packets were received,
- NO Ping reply (ICMP Echo) was received.

i_XpUser



Response Number 29
Name: Sabertooth
Date: July 25, 2004 at 21:26:18 Pacific
+1
Reply:

Thanks y'all.

I replaced KPF with ZA and now the coast is clear, results below.

Results from scan of ports: 0-1055

0 Ports Open
0 Ports Closed
1056 Ports Stealth
---------------------
1056 Ports Tested

ALL PORTS tested were found to be: STEALTH.

TruStealth: PASSED
- ALL tested ports were STEALTH,
- NO unsolicited packets were received,
- NO Ping reply (ICMP Echo) was received.

____________________________
The greatest risk is not taking one



Response Number 30
Name: XpUser
Date: July 26, 2004 at 16:33:57 Pacific
+1
Reply:

Sabertooth,

Glad to hear all is well now :-)

Regards


i_XpUser



Response Number 31
Name: Sabertooth
Date: July 26, 2004 at 21:32:52 Pacific
+1
Reply:

Latest!

Got me a shiny new Network Anywhere (Linksys NR014-WM) router over the weekend pending till the store actually gets in the Netgear wireless router I had ordered, installed the darn thing with little effort but to my surprise I failed the TruStealth test that I had passed yesterday before adding the router. No kidding aagggrrhh!

____________________________
The greatest risk is not taking one



Response Number 32
Name: Sabertooth
Date: July 26, 2004 at 21:59:54 Pacific
+1
Reply:

Finally!, passed the TruStealth test with my router installed and the results:

From scan of ports: 0-1055

0 Ports Open
0 Ports Closed
1056 Ports Stealth
---------------------
1056 Ports Tested

ALL PORTS tested were found to be: STEALTH.

TruStealth: PASSED
- ALL tested ports were STEALTH,
- NO unsolicited packets were received,
- NO Ping reply (ICMP Echo) was received.

I had to manually resolve the port 113 issue by configuring the router's port forwarding settings, time to celebrate with a late night beer cheers!.

____________________________
The greatest risk is not taking one



Reply to Message Icon

Send Files dvd-rom error message



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Google Ads



Results for: I could use some help on this one..

Win xp help popups problem www.computing.net/answers/windows-xp/win-xp-help-popups-problem/94716.html

some sounds dont work www.computing.net/answers/windows-xp/some-sounds-dont-work/131146.html

XP Pro Internet problem www.computing.net/answers/windows-xp/xp-pro-internet-problem/81412.html