Link to home
Start Free TrialLog in
Avatar of Pau Lo
Pau Lo

asked on

Gateway Server

How dangerous is it for details (ip address and open port number) of one of our internal gateway servers to be leaked outside the organisation? Is this information relatively easy to get hold of by hackers anyway if they wanted? Or have we been exposed to major security concerns?
ASKER CERTIFIED SOLUTION
Avatar of nttranbao
nttranbao

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of nttranbao
nttranbao

Also notice that it is the port opened on your firewall/gateway, so scan against your public IP of your gateway first. You may want to scan internal servers from your LAN to learn more.
Avatar of Pau Lo

ASKER

can you go into a bit more detail on nessus and how it will help in this situation?
Avatar of Pau Lo

ASKER

for info port 8443
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Pau Lo

ASKER

Many Thanks, I've found lots of potential vulnerabilities surrounding cross site scripting on port 8443
Avatar of bbao
generally speaking, port number itself has nothing to do with vulnerabilities as it is just a number used to determine the communication channel between two network nodes. potential vulnerabilities are from (caused) by the application behind (working/listening on) the port number.

therefore, we need to talk about the application or service serving on the port, as well the network topology related to the port exposed on LAN even WAN. could you please let us know more specific information about it?

> How dangerous is it for details (ip address and open port number) of one of our internal gateway servers to be leaked outside the organisation?

commonly, just leaking information of IP address and port number should not be a big issue, as network protection should be based on making the relevant services robust, not just to keep IP and port number in secure. just like web access, you have to tell other people your web server's IP address, and keep its port 80 open for incoming web traffic. the key is to keep your web server (service, such as IIS) working safely by filtering malicious URL and unauthorised data access.

hope it helps,
bbao
Avatar of Pau Lo

ASKER

> application or service serving on the port

This is remote support software done by our external IT vendor
Avatar of Pau Lo

ASKER

Feel free to add any further comments