Outbound ports to firewall?

From: Parker Morse (morse_at_sinauer.com)
Date: 09/24/04

  • Next message: Jason Dixon: "Re: Outbound ports to firewall?"
    To: redhat-list@redhat.com
    Date: Fri, 24 Sep 2004 09:29:25 -0400
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Like most people, I've put some effort into filtering incoming email
    and firewalling my network to prevent nasties from getting in. But
    recent discussion of preventing the spread of Windows worms, viruses,
    etc. etc. has led me to a question I don't have an answer for.

    Let's assume, for a thought experiment, that one of the Windows boxen
    inside my gateway firewall is infected with *something*, who knows
    what. To protect the rest of the 'net from this little bundle of
    pestilence in the time before I track it down and choke it to death, I
    should probably have some firewall rules to keep the bulk of the
    nastiness from leaving my network. Outbound rules.

    What ports should I consider closing up to keep hypothetical infected
    inside my network from phoning home and/or spreading the infection?

    Thanks,

    pjm
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.4 (Darwin)

    iD8DBQFBVCE4nRVGoRROKxIRAlY6AJwNfaqDNjqkUXf/q9qP+XKfM4hcwwCdHGMs
    ewSWmlTgQ3uCEu6WfxNazpQ=
    =NEYK
    -----END PGP SIGNATURE-----

    -- 
    redhat-list mailing list
    unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe
    https://www.redhat.com/mailman/listinfo/redhat-list
    

  • Next message: Jason Dixon: "Re: Outbound ports to firewall?"

    Relevant Pages

    • Re: Firestarter on Fedora
      ... You've not indicated any network masks, ... If you put your 'eth1' and your Windows boxen in different network ... Above command will also overwrite your existing firewall rules. ...
      (comp.os.linux.networking)
    • Re: welchia worm removal tool
      ... Go to www.microsoft.com/security and click on Blaster for information. ... install or enable a firewall on the computer that blocks port ... infected or untrusted hosts to prevent infection. ... your network or your firewall at your network ingress / egress points ...
      (microsoft.public.security)
    • Re: [opensuse] no network browse after todays kernel upgrade
      ... So, I edited the firewall rules, and added also: ... UDP needs 137 and 138 at least. ... which would have reloaded the firewall, ... This does not allow me to browse the network, I do not see any domain ...
      (SuSE)
    • Re: Nachi worm puzzle
      ... You'll find that relying on a firewall to keep you free of viruses will not ... There are other ways a virus can get on your network, ... > are unable to ping the other pcs therefore where has the infection come ...
      (microsoft.public.security)
    • Re: ? WINS*.EXE installed as part of Windows
      ... system is susceptable to infection as soon as the network becomes active. ... > So you're saying that Windows becomes infected DURING the INSTALL, ... >> XP Firewall on the connection, it will be infected within seconds. ...
      (microsoft.public.security.virus)