Technology Get the latest on technology, electronics and software…

Question for the computer security experts

Thread Tools
 
Old 12-22-2006, 11:58 AM
  #1  
X spots the mark
Thread Starter
 
whynot's Avatar
 
Join Date: Dec 2005
Location: Concrete jungles
Age: 42
Posts: 1,519
Likes: 0
Received 0 Likes on 0 Posts
Question for the computer security experts

I've been using the Zonealarm security suite for a while, have the latest version 6.5. Last night I decided to scan ports 1-1250 and it turns out that at least 3 ports were open! wtf! The settings in zonealarm seem to be right, internet zone security is set on high. Why aren't all the ports stealthed, or at least closed?
Old 12-22-2006, 12:01 PM
  #2  
On the way!
 
fla-tls's Avatar
 
Join Date: Oct 2001
Location: Orlando, FL
Age: 56
Posts: 3,715
Likes: 0
Received 0 Likes on 0 Posts
Sounds like a question for the fine folks a Zonealarm. Maybe bug in the software? Maybe a misconfiguration of the software?
Old 12-22-2006, 12:25 PM
  #3  
...I like stories...
 
GBockers's Avatar
 
Join Date: Apr 2006
Location: Boston Metro
Age: 63
Posts: 284
Likes: 0
Received 0 Likes on 0 Posts
I don't use software based Firewall but...

Originally Posted by whynot
I've been using the Zonealarm security suite for a while, have the latest version 6.5. Last night I decided to scan ports 1-1250 and it turns out that at least 3 ports were open! wtf! The settings in zonealarm seem to be right, internet zone security is set on high. Why aren't all the ports stealthed, or at least closed?
The opened ports should be stealthed; obviously if they're 53, 80, 443 and the pop3 port (escapes me) those are necessary for internet access and email.

G
Old 12-22-2006, 12:39 PM
  #4  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,456
Received 2,211 Likes on 1,210 Posts
What ports?
Old 12-22-2006, 12:43 PM
  #5  
On the way!
 
fla-tls's Avatar
 
Join Date: Oct 2001
Location: Orlando, FL
Age: 56
Posts: 3,715
Likes: 0
Received 0 Likes on 0 Posts
Guys - Zonealarm should stealth ALL ports in it's default configuration. If he has open ones it's either a bug in the software, or somehow it's configured to hold those open.

Also, how are you testing this - grc.com shields up?
Old 12-22-2006, 01:06 PM
  #6  
o-qua tangin wann
 
blumpkin's Avatar
 
Join Date: Sep 2003
Location: NJ
Posts: 2,445
Likes: 0
Received 0 Likes on 0 Posts
i dislike zone alarms
Old 12-22-2006, 01:10 PM
  #7  
X spots the mark
Thread Starter
 
whynot's Avatar
 
Join Date: Dec 2005
Location: Concrete jungles
Age: 42
Posts: 1,519
Likes: 0
Received 0 Likes on 0 Posts
I don't remember which ports were open, it was in the 1-50 range. I tested with shieldsup and a few other sites. All seem to give somewhat different results. The only security scan which told me that the firewall passed all tests successfully was the Symantec one which is basically a joke.
Old 12-22-2006, 01:15 PM
  #8  
On the way!
 
fla-tls's Avatar
 
Join Date: Oct 2001
Location: Orlando, FL
Age: 56
Posts: 3,715
Likes: 0
Received 0 Likes on 0 Posts
My DSL modem/router stealths all of the ports, but will respond to pings - so therefore shields up will report a failure. Since it protects me by NAT I don't need a computer-based firewall.

I haven't needed zonealarm since I had a USB DSL modem that would dump me right on the Internet - but that was years ago.
Old 12-22-2006, 01:37 PM
  #9  
X spots the mark
Thread Starter
 
whynot's Avatar
 
Join Date: Dec 2005
Location: Concrete jungles
Age: 42
Posts: 1,519
Likes: 0
Received 0 Likes on 0 Posts
Originally Posted by fla-tls
My DSL modem/router stealths all of the ports, but will respond to pings - so therefore shields up will report a failure. Since it protects me by NAT I don't need a computer-based firewall.

I haven't needed zonealarm since I had a USB DSL modem that would dump me right on the Internet - but that was years ago.
so should I be concerned about those ports being reported as open? does it compromise my computer's security?
Old 12-22-2006, 01:56 PM
  #10  
On the way!
 
fla-tls's Avatar
 
Join Date: Oct 2001
Location: Orlando, FL
Age: 56
Posts: 3,715
Likes: 0
Received 0 Likes on 0 Posts
Is your computer behind a dsl or cable router? If so, it's your router that's responding to the shields up site - not your computer. Try shields up with and without zonealarm. You should get the same results.

Make sure your remote management features for the modem/router are set to disabled and try again. That may shut off those ports.
Old 12-22-2006, 04:06 PM
  #11  
X spots the mark
Thread Starter
 
whynot's Avatar
 
Join Date: Dec 2005
Location: Concrete jungles
Age: 42
Posts: 1,519
Likes: 0
Received 0 Likes on 0 Posts
I have a cable modem, I really doubt it's got a built in router
Old 12-22-2006, 08:19 PM
  #12  
On the way!
 
fla-tls's Avatar
 
Join Date: Oct 2001
Location: Orlando, FL
Age: 56
Posts: 3,715
Likes: 0
Received 0 Likes on 0 Posts
Many actually do now. If you are hooked up to the modem with you network card, type "ipconfig /all" at a command prompt and look at the address of your network card.

If your address begins with 10 or 172.31 or 192.168 then your modem most likely is a router. Those are private addresses not used on the Internet. The most common is 192.168.
Old 12-22-2006, 11:16 PM
  #13  
Still trolling
 
suXor's Avatar
 
Join Date: Oct 2002
Location: Wylie, Texas
Posts: 4,623
Likes: 0
Received 1 Like on 1 Post
I run no firewall software on my PC. I do use a router on my network. Router > *

Zone Alarm and the like are messy....
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
navtool.com
3G MDX (2014-2020)
32
01-20-2016 11:43 AM
navtool.com
5G TLX Audio, Bluetooth, Electronics & Navigation
31
11-16-2015 08:30 PM
navtool.com
1G RDX Audio, Bluetooth, Electronics & Navigation
1
09-25-2015 05:15 PM
rboller
3G TL Audio, Bluetooth, Electronics & Navigation
0
09-23-2015 02:49 PM



Quick Reply: Question for the computer security experts



All times are GMT -5. The time now is 10:49 AM.