Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Too many UDP ports open

Status
Not open for further replies.

Saeed42

ISP
Jul 4, 2001
147
I only have few services running, please see below for chkconfig output, but if I scan my redhat8 server I have few UDP ports open and they are

88 Kerberos 5
123 NTP
138 Netbios-DGM
161 SNMP
520 RIP
1433 ms-sql
1512 win

My question is how can I block these ports or stop their services as I don't need any of those services running.

please I'm a newbie so go easy on me


More info



syslog 0:eek:ff 1:eek:ff 2:eek:n 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
network 0:eek:ff 1:eek:ff 2:eek:n 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
random 0:eek:ff 1:eek:ff 2:eek:n 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
rawdevices 0:eek:ff 1:eek:ff 2:eek:ff 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
xinetd 0:eek:ff 1:eek:ff 2:eek:ff 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
atd 0:eek:ff 1:eek:ff 2:eek:ff 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
gpm 0:eek:ff 1:eek:ff 2:eek:n 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
autofs 0:eek:ff 1:eek:ff 2:eek:ff 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
keytable 0:eek:ff 1:eek:n 2:eek:n 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
kudzu 0:eek:ff 1:eek:ff 2:eek:ff 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
sshd 0:eek:ff 1:eek:ff 2:eek:n 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
iptables 0:eek:ff 1:eek:ff 2:eek:n 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
nfslock 0:eek:ff 1:eek:ff 2:eek:ff 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
rhnsd 0:eek:ff 1:eek:ff 2:eek:ff 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
crond 0:eek:ff 1:eek:ff 2:eek:n 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
anacron 0:eek:ff 1:eek:ff 2:eek:n 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
xfs 0:eek:ff 1:eek:ff 2:eek:n 3:eek:n 4:eek:n 5:eek:n 6:eek:ff
vncserver 0:eek:ff 1:eek:ff 2:eek:ff 3:eek:ff 4:eek:ff 5:eek:n 6:eek:ff
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Don't be content with being average. Average is as close to the bottom as it is to the top
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
TIP:
By the way if you run a WINS servise on your windows mashine
stop it and run Languard again....
and see if the
wins 1512/tcp Microsoft's Windows Internet Name Service
wins 1512/udp Microsoft's Windows Internet Name Service

exists again in the results. =-=-=-=-=-=-=-=-=-=-=-=
Unix Systems Engineer
=-=-=-=-=-=-=-=-=-=-=-=
 
Found this little script Bastille ( which is a wizard that helps novices like me build secure Linux servers and that made my life that much easier.

Thanks for your help.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Don't be content with being average. Average is as close to the bottom as it is to the top
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
As I said before on this topic, what your scanner reports
as open, closed,filtered, unfiltered, etc.. depends on the author as much as the reality of what services are binding sockets.

Next time run lsof -i -n as root on your server to see
a listing of your services binding sockets and then use
a decent network test suite like nessus or saint to corroborate if you must.
nmap and other "scanners" are not infallible, or logical,
all the time.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top