Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
General Security
Tag Cloud
access audio blue screen boot bsod connection crash dell desktop driver dvd email error excel firefox hard drive hardware hijackthis internet keyboard laptop malware monitor motherboard network networking outlook problem processor ram recovery router safe mode screen slow sound spyware tdlwsp.dll trojan upgrade vba video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
forwarding ports safe?

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
okeee's Avatar
Senior Member with 510 posts.
 
Join Date: May 2006
19-Oct-2008, 11:12 AM #1
forwarding ports safe?
Because internet is set via a router, I need to forward some ports for some application to connect to internet. Ususally they state that I can pick any port number to forward, but I have no idea which ones are safe, and when I might accidentally open up too many ports. So how do I set a port correctly without making it vulnerable to outside attacks?
lunarlander's Avatar
Computer Specs
Senior Member with 1,333 posts.
 
Join Date: Sep 2007
19-Oct-2008, 11:37 AM #2
Well, if you do port forwarding, an attacker will know for sure that there is a PC at your IP address. Also, depending on the software that is receiving traffic, an attacker may be able to probe the software for responses to identify what it is. Then, the attacker will have to find an exploit that works on that application you have which can grant him access to your computer.

So, whether you choose to port forward or not depends on how much you trust the security of your application. Does it offer responses to anyone that comes knocking? Lets say the application dutifully answers the attacker that 'I am Sendmail', are there any weaknesses to exploit ? You can browse SecurityFocus or SANS's @Risk vulnerabilty lists to see if whitehats have identified any weaknesses. Even if you don't find anything at those sites, it may still possible that blackhats have a secret weapon that the whitehats don't know about. Also, the attacker may not target the application, but may target other parts of the machine like for example the TCP/IP stack of your exposed machine. For example Windows has a recent IGMP vulnerabilty. So it is most important that your machine has up to date windows patches, and that your application is up to date as well.

So you see, security folks will usually be very cautious when forwarding ports. They'll make sure Everything is patched and up to date. And try to expose the minimum surface area for an attacker to play with.

If your application allows you to choose which port to use, then you can choose anything above port 1024, as ports 1-1023 have standard uses by well known applications.

Last edited by lunarlander : 19-Oct-2008 11:44 AM.
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 04:25 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.