Solved

risky ports on windows 2003

Posted on 2010-09-04
7
851 Views
Last Modified: 2013-12-04
Hello
I did a portscan to our webserver, windows server 2003 sp2 latest patches. I got the
following from nmap scan:

135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn
443/tcp  open  https?
445/tcp  open  microsoft-ds  Microsoft Windows 2003 or 2008 microsoft-ds
1025/tcp open  msrpc         Microsoft Windows RPC
1069/tcp open  msrpc         Microsoft Windows RPC
1070/tcp open  msrpc         Microsoft Windows RPC
2301/tcp open  http          CompaqHTTPServer 9.9 (HP System Management 3.0.1.73; httpd 2.2.6+)
| html-title: HP System Management Homepage
|_Requested resource was http://10.x.x .x /red2301.html?RedirectUrl=/
2381/tcp open  http          Apache SSL-only mode httpd
3389/tcp open  microsoft-rdp Microsoft Terminal Service
7937/tcp open  nsrexec       1 (rpc #390113)
7938/tcp open  rpcbind       2 (rpc #100000)

I would like to know about risky ports especially the last two 7937, and 7938
0
Comment
Question by:alex-2010
7 Comments
 
LVL 26

Accepted Solution

by:
MidnightOne earned 500 total points
Comment Utility
Are you scanning from inside your network or outside?

If these results are from outside the network, shoot your network admin immediately. From the inside, it appears this is a pretty common Windows 2003/2008 system running IIS and PSP on an HP server.
0
 

Author Comment

by:alex-2010
Comment Utility
it is form inside offcourse, i understand that 7937 for the backup system, but what is rpcbind port 7938! is it risky?
0
 
LVL 26

Expert Comment

by:MidnightOne
Comment Utility
It's entirely possible it's a secondary port for the backup - one to communicate with the backup system normally, and the other for errors and status messages. What backup are you running?
0
Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!

 
LVL 38

Expert Comment

by:Adam Brown
Comment Utility
RPC is used for replication in an Active Directory environment. It's used to allow access to remote computers without specific programming. Wikipedia has a little bit of info on it, though it's pretty technical and mostly written toward programmers. http://en.wikipedia.org/wiki/Remote_procedure_call
The RPCBind protocol facilitates in RPC broadcasts and allows communication and function operations on multiple computers at once. If this server is running as a central backup server or is communicating with one, then the RPCBind protocol is being used to assist in that communication. http://uw714doc.sco.com/en/SDK_netapi/xdrD.rpcbind.html has more info, but is extremely technical and very much written for programmers.
0
 
LVL 29

Expert Comment

by:pwindell
Comment Utility
Your wasting you  time scanning from inside the LAN.  Every service running on the machine is going to show listening,...and just because something is listeing does not make it "bad".  The listeing service must be unneeded, unused, and have a known security vulnerability and the "hacker" would have to be physically on the LAN,...and the server would have to have something accessable via the particular service, and "desireable" to the hacker for it to have any "bad" potential.
You need to scan from the outside, and be scanning the firewall that you are using to make the web server available to the outside.
0
 
LVL 26

Expert Comment

by:MidnightOne
Comment Utility
Your wasting you  time scanning from inside the LAN.  
I'd have to disagree with this, but only lightly. Overall, scans inside the network are of far less value than from outside, but scans inside the network are a good way of highlighting things that are running but shouldn't be - such as rogue WAPs, SMTP servers and SQL boxes.
0
 
LVL 29

Expert Comment

by:pwindell
Comment Utility
That's true, but I only make the statement in the particular context I meant it in.
I think it is the term "risky ports" that get me "going".    There is no such thing as a "risky port".  There are apps & services that have a perfectly legitament purpose that have a good reason to exist,...but in the wrong context/situaiton such Apps or services should not be available.  This would be done by either removing, uninstalling, or shutting down the App or service,...or preventing access to the app or service from selected sources.   Focusing on "ports" instead of the app or service that created it I believe is the wrong way to view the issue.  So I like to get people to think correctly about things.
0

Featured Post

Superior storage. Superior surveillance.

WD Purple drives are built for 24/7, always-on, high-definition security systems. With support for up to 8 hard drives and 32 cameras, WD Purple drives are optimized for surveillance.

Join & Write a Comment

As I write this article, I am finishing cleanup from the Qakbot virus variant found in the wild on April 18, 2011.  It was a messy beast that had varying levels of infection, speculated as being dependent on how long it resided on the infected syste…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now