I am posting this as an exercise for Folks who are very new, and are just getting into ports, security, etc.
Please Friends, I know there are some here who could write a thesis on the the scan log below, but please refrain.
I offer this to our posters here who have asked about how to port scan, what does it mean, etc.
The Challenge:
Below is an actual nmap scan.
The address has been removed as it matters not.
You are given this scan and asked to assess it in terms of potential problems, as well as recommendations.
Please post your observations in two parts:
1. What are your initial observations? (i.e. "port xxxx is open and I don't think it should be")
2. What are your recommendations? (i.e. close port xxxx, disable service xxxx, etc.)
-------------------------------------------- SCAN LOG BELOW --------------------------------------------------
Starting nmap V. 3.00 ( www.insecure.org/nmap/ )
Interesting ports on xxxxxx.xxxx.xxx (xxx.xxx.xx.xxx):
(The 1116 ports scanned but not shown below are in state: closed)
Port State Service
21/tcp open ftp
75/tcp filtered priv-dial
80/tcp open http
135/tcp filtered loc-srv
139/tcp open netbios-ssn
147/tcp filtered iso-ip
208/tcp filtered at-8
443/tcp open https
447/tcp filtered ddm-dfm
487/tcp filtered saft
528/tcp filtered custix
535/tcp filtered iiop
560/tcp filtered rmonitor
582/tcp filtered scc-security
596/tcp filtered smsd
999/tcp filtered garcon
1027/tcp open IIS
1110/tcp filtered nfsd-status
1380/tcp filtered telesis-licman
1426/tcp filtered sas-1
1433/tcp open ms-sql-s
1989/tcp filtered tr-rsrb-p3
2000/tcp open callbook
2001/tcp open dc
2025/tcp filtered ellpack
2028/tcp filtered submitserver
2034/tcp filtered scoremgr
2232/tcp filtered ivs-video
3999/tcp filtered remoteanything
4132/tcp filtered nuts_dem
5191/tcp filtered aol-1
12345/tcp filtered NetBus
13709/tcp filtered VeritasNetbackup
32770/tcp filtered sometimes-rpc3
Remote OS guesses: Baystack Instant Internet 400 SoHo Router, NetScreen-100, FreeBSD 4.0-20000208-CURRENT, Linux 1.3.20 (X86), Solaris 2.5, 2.5.1, Solaris 2.6 - 7 (SPARC), Solaris 2.6 - 7 X86, Solaris 2.6
Nmap run completed -- 1 IP address (1 host up) scanned in 49 seconds
------------------------------------ END OF SCAN ---------------------------------------------------
.: Aftiel
