[rescue] firewalling windoze crap

Jonathan C. Patschke jp at celestrion.net
Sat Aug 16 19:58:42 CDT 2003


On Sat, 16 Aug 2003, Dave McGuire wrote:

>    What ports do I need to block on my firewall to protect him from this
> latest bullshit?  And what ports in general should I block to help
> protect his machine?

UDP and TCP ports 135 - 139 (RPC, DCOM, NetBIOS).
UDP and TCP port 445 (SMB)
UDP and TCP port 522 (User-location protocol)
UDP port 3389 (Remote Desktop)
TCP ports 5800 - 5999 (WinVNC)

That's a good start, anyway.  I feel like I'm leaving something out.

-- 
Jonathan Patschke   )  "We're Texans.  We figure out ways to do these
Elgin, TX          (    things..."                    --Bill Bradford



More information about the rescue mailing list