New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1145
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Norton Internet Security 2004 and online security check

 
Post new topic   Reply to topic       Computer Cops Forum Index -> General Symantec
View previous topic :: View next topic  
Author Message
talisair

1st Responder
1st Responder
Premium Member
Premium Member


Joined: May 15, 2004
Posts: 77
Location: UK

PostPosted: Sat May 15, 2004 9:16 pm    Post subject: Norton Internet Security 2004 and online security check
Reply with quote

Sorry I have alreay posted this under general security, new user - didn't know there was a dedicated norton area ...

I am connected through a University network as I am living in Halls; I have Norton Internet Security 2004 installed on my system which is running Windows XP Home Edition. My problem is, when I go to the Symantec online security check web page it scans my system for security threats and seems to find numerous ports open which it tells me should not be ... the solution it offers is for me to install a firewall program ... such as Norton Internet Security 2004!! If I have Symantec's own security program, the latest up-to-date version, why does thier security check show me as being vulnerable? Can anyone offer some insight??
Back to top
View users profile Send private message
talisair

1st Responder
1st Responder
Premium Member
Premium Member


Joined: May 15, 2004
Posts: 77
Location: UK

PostPosted: Sat May 15, 2004 10:48 pm    Post subject:
Reply with quote

If it helps, here are the results of the security check; Norton says that ports will be either Open, Closed, or Stealth (Open being bad, closed bad but not so bad, and Stealth being good) The ports it tells me are open are:

ICMP Ping Ping. Ping is a network troubleshooting utility. It asks your computer to acknowledge its existence. If your computer responds positively to a ping, hackers are more likely to target your computer.


21 FTP (File Transfer Protocol). FTP is used to transfer files between your computer and other computers. Port 21 should be open only if you're running an FTP server.


22 SSH. TCP connections to this port might indicate a search for SSH, which has a few exploitable features. SSH is a secure replacement for Telnet. The most common uses of SSH are to securely login and copy files from a server.


23 Telnet. Telnet can be used to log into your computer from a terminal anywhere in the world. This port should be open only if you're running a Telnet server.


79 Finger. Finger is an Internet utility that allows someone to obtain information about you, including your full name, logon status, and other profile information.


80 HTTP (Hypertext Transfer Protocol). HTTP is used to transfer Web pages over the Internet. Port 80 should be open only if you're running a Web server.



... and the ports it tells me are Closed are:

25 SMTP (Simple Mail Transfer Protocol). A protocol for host-to-host mail transport. This port should be open only if you're running a mail server.


110 POP3 (Post Office Protocol). Internet mail servers and mail filter applications use this port. This port should be open only if you're running a mail server.


113 Ident / Authentication. This service is required by some mail, news, or relay chat servers to allow access. A stealth result on this port could cause performance problems.


119 NNTP (Network News Transfer Protocol). A service used by News servers to distribute Usenet articles to newsreader applications and between other servers.


135 Location service (loc-srv). This port is used to direct RPC (Remote Procedure Calls) services to the appropriate dynamically mapped ports. Hackers can use this to determine which port is used by several Windows services. This port should not be visible from the Internet.


139 NetBIOS. NetBIOS is used for Windows File & Print sharing. If port 139 is open, your computer is open to sharing files over the Internet. Other components of NetBIOS can expose your computer name, workgroup, user name, and other information. To learn more about preventing connections to your NetBIOS ports, see: NetBIOS Information and Configuration Instructions


143 IMAP (Internet Message Access Protocol). IMAP is a sophisticated protocol for electronic mail delivery. This port should be open only if you're running an IMAP server.


443 HTTP over TLS/SSL. A protocol for providing secure HTTP communication. It should be open only if you're running a Web server.


445 Windows NT / 2000 SMB. A standard used to exchange Server Message Blocks, and can be exploited in multiple ways, including gaining your passwords.


1080 SOCKS. This protocol allows computers access to the Internet through a firewall. It is used when one IP address is shared among several computers. Generally this protocol only allows access out to the Internet. However, it is frequently configured incorrectly to allow hackers to pass traffic inwards through the firewall.


1723 PPTP (Point-to-Point Tunneling Protocol). This service is used for virtual private networking connections.


5000 UPnP (Universal Plug and Play). This service is used to communicate with any UPnP devices attached to your network.


5631 pcAnywhere. This port is used by Symantec pcAnywhere when in host mode.

_________________
"Waiting for perfection is merely a way of turning your back on reality, placing a higher value on what's inside your head than what is evident all around you" - Michael Marshall Smith
Back to top
View users profile Send private message
Prince_Serendip

AVPE Host
Premium Member
Premium Member


Joined: Sep 07, 2002
Posts: 1026
Location: Canada

PostPosted: Sun May 16, 2004 6:46 am    Post subject:
Reply with quote

Have you enabled and configured your Norton Personal Firewall, which is included with Norton Internet Security 2004? It may not be loaded automatically. Wink

Full Title: Symantec Support: How to configure the Personal Firewall in Norton Internet Security or Norton Personal Firewall

How to configure the Norton Personal Firewall

This should help you get started. Good thing you did those scans or you might have missed something important.

Best regards and welcome to Computer Cops!

_________________
ASAP Expert | Please donate to Computer Cops!
Back to top
View users profile Send private message
jvmorris

Security Expert
Security Expert



Joined: Dec 10, 2002
Posts: 152
Location: USA

PostPosted: Sun May 16, 2004 7:58 am    Post subject:
Reply with quote

Talisair,

In a situation like this, my first speculation would be that the Symantec test site is actually probing your university's Internet gateway/router rather than your machine.

Part of my reason for that conjecture is that it failed to pick up the fact that you are, in fact, running NIS! (which it should have detected)

Other possibility here is that your university is actually running proxy servers and that, in reality, the Symantec site is checking those rather than your machine.

Run the test again, noting the time on your PC's clock. Note the displayed results. Then open the NIS firewall event log. Check to see if these events are reflected in the firewall event log. If they are not , the the Symantec online checker is not checking your machine.

_________________
Regards,
Joseph V. Morris
'The man who was not there"
Back to top
View users profile Send private message
talisair

1st Responder
1st Responder
Premium Member
Premium Member


Joined: May 15, 2004
Posts: 77
Location: UK

PostPosted: Sun May 16, 2004 8:01 am    Post subject:
Reply with quote

Hi Prince ... yeah I have been through all the configuration settings, have tried various combinations and I am, apparently, still vulnerable. I wonder, do you think that it is possible the Symantec online security check gets false readings because of the fact that I am also sitting behind the University's own firewall and protection?
_________________
"Waiting for perfection is merely a way of turning your back on reality, placing a higher value on what's inside your head than what is evident all around you" - Michael Marshall Smith
Back to top
View users profile Send private message
talisair

1st Responder
1st Responder
Premium Member
Premium Member


Joined: May 15, 2004
Posts: 77
Location: UK

PostPosted: Sun May 16, 2004 8:03 am    Post subject:
Reply with quote

Ahhhh, thank you Joseph ... sort of fits in with what I was thinking ... I shall check that now.
_________________
"Waiting for perfection is merely a way of turning your back on reality, placing a higher value on what's inside your head than what is evident all around you" - Michael Marshall Smith
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> General Symantec All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops