 ghost16825 Use security metrics Premium join:2003-08-26
1 edit | reply to matunga Re: [Kerio 4.x] port 44334 is OPEN: BIG SECURITY H
Probably irrelevant but regarding Kerio 2.15:
2.15 opens port 44334 but when the firewall is ENABLED stealths this port. However, if you DISABLE the firewall, while it's disabled obviously nothing is stealthed hence 2.15 will show 44334 as open. What this means: If you disable the firewall (2.15 or 4) temporarily and during this time someone scans port 44334 and sees it's open, they know you are running a Kerio firewall. (Even if the remote admin/password for a localhost option is OFF)
I tested this using the Shields Up site, but the question is how well does this port stealth with other types of scans like FIN, ACK etc.when the firewall is ENABLED?
I don't like the idea of an app leaving an port open (even if it is a firewall) and then having a firewall stealth it. I'd rather have as many ports closed as I can and then use the firewall as an added measure. |