Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to block port 135 on NT4 workstation

Status
Not open for further replies.

hughsie99

Technical User
Jan 9, 2003
14
AU
Hi Folks
Following the recent Blaster/Welchia worm attacks I want to stop NT workstations listening on port 135. We have external firewall blocking, but the attack came from within.

I have Netbios disabled in the Protocol bindings, and have also unchecked LMHosts lookups, but netstat - a still shows TCP port 135 listening.

Have turned off Netbios Helper Service.
Microsoft Networking is not installed, and the only protocols in use are IP and IPX

Any suggestions on what I'm missing.
Thanks
Tony
 
Maybe you can do it from Control Panel >Network > Protocols > TCP/IP > Advanced > Security Configure .
 
You'll need a port blocking app or firewall on each NT workstation to do this (port blocker from - though I use this & it baulks at blockiong 135-9). But, assuming you've install the M$ patch and/or you've bloced port 135 externally and removed all instances of the worm internally you should be ok?
 
If you don't need the Microsoft networking you can disable the computer browser and server services which will close port 135 (but this will also disable microsoft networking)

John
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top