Go Back   Cyber Tech Help Support Forums > Operating Systems > Windows NT, 2000, 2003

Notices

Reply
 
Topic Tools
  #1  
Old September 10th, 2004, 07:37 PM
phantomgti's Avatar
phantomgti phantomgti is offline
New Member
 
Join Date: Sep 2004
Location: Vancouver, B.C.
Posts: 5
Win2k Virus?

Hi Everyone,

I am running Win2k behind a linksys DSL/Cable router BEFSR41. I recently did a Symantec Security check and it said that I had 3 ports open (ICMP Ping, Telnet and HTTP). I've contacted Linksys regarding this and they eventually said to return the router to the place I bought it. Done.... I thought the problem would be solved.

I still have the ports open. I don't have port forwarding or anything like that setup on the router. It is the basic setup out of the box.

I ran Norton's antivirus in safe mode and it didn't detect a virus.

Is there something I am missing? or are these ports normally open?

Thanks in advance for any help you could give me.

Trevor
Reply With Quote
  #2  
Old September 10th, 2004, 08:07 PM
MishY's Avatar
MishY MishY is offline
Cyber Tech Help Administrator
 
Join Date: Sep 2000
O/S: Windows Vista 64-bit
Location: England
Age: 31
Posts: 8,563
Blog Entries: 1
I have the v3 version of that router so your menus might differ.

Firstly, check for firmware upgrades on the Linksys website. MAKE SURE YOU DOWNLOAD THE CORRECT FIRMWARE FOR YOUR ROUTER. You will find the version number on the router itself.

Secondly, go to Applications and Gaming and check for Port 80 being open (this is httpd)

Then click on the Security tab and scroll to the very bottom. Enable "Block anonymous internet requests" and Enable "Filter Multicast"
__________________
Searching the forums can help you to find your answers more quickly
Posting Tips & Support Forum Rules | Vivid Development | Get Firefox! | CTH News | Are you hungry ? | Registered Linux User #317145
Reply With Quote
  #3  
Old September 10th, 2004, 08:14 PM
phantomgti's Avatar
phantomgti phantomgti is offline
New Member
 
Join Date: Sep 2004
Location: Vancouver, B.C.
Posts: 5
Hi MishY

Thanks for your response!

I actually do have the v3 of the router and have upgraded the firmware as soon as I got the new router.

I know for sure that the "Applications/Gaming" doesn't have any ports open.

I do have the "Block Anonymous Internet requests" enabled but I'm not too sure if the "Filter Multicast" is enabled or not. I am at work right now and won't be able to check for a few hours.

Do you think this problem is strictly with my router?
Reply With Quote
  #4  
Old September 10th, 2004, 08:23 PM
MishY's Avatar
MishY MishY is offline
Cyber Tech Help Administrator
 
Join Date: Sep 2000
O/S: Windows Vista 64-bit
Location: England
Age: 31
Posts: 8,563
Blog Entries: 1
If you are not portforwarding (or Applications & Gaming) and you are not scanning the router from a PC on your LAN there is no reason why http should be open.

What are you using to scan your network ? Try the "shields up" and do the scan for all service ports (1-1056) on www.grc.com
__________________
Searching the forums can help you to find your answers more quickly
Posting Tips & Support Forum Rules | Vivid Development | Get Firefox! | CTH News | Are you hungry ? | Registered Linux User #317145
Reply With Quote
  #5  
Old September 10th, 2004, 08:25 PM
MishY's Avatar
MishY MishY is offline
Cyber Tech Help Administrator
 
Join Date: Sep 2000
O/S: Windows Vista 64-bit
Location: England
Age: 31
Posts: 8,563
Blog Entries: 1
I've just ran that test and only IDENT showed up and showed close. That is pretty normal and not of concern
__________________
Searching the forums can help you to find your answers more quickly
Posting Tips & Support Forum Rules | Vivid Development | Get Firefox! | CTH News | Are you hungry ? | Registered Linux User #317145
Reply With Quote
  #6  
Old September 10th, 2004, 08:29 PM
MishY's Avatar
MishY MishY is offline
Cyber Tech Help Administrator
 
Join Date: Sep 2000
O/S: Windows Vista 64-bit
Location: England
Age: 31
Posts: 8,563
Blog Entries: 1
Also make sure under UPnP Forwarding you having nothing enabled.

Do you have a DMZ ?
__________________
Searching the forums can help you to find your answers more quickly
Posting Tips & Support Forum Rules | Vivid Development | Get Firefox! | CTH News | Are you hungry ? | Registered Linux User #317145
Reply With Quote
  #7  
Old September 10th, 2004, 09:21 PM
phantomgti's Avatar
phantomgti phantomgti is offline
New Member
 
Join Date: Sep 2004
Location: Vancouver, B.C.
Posts: 5
Red face

"If you are not portforwarding (or Applications & Gaming) and you are not scanning the router from a PC on your LAN there is no reason why http should be open.

What are you using to scan your network ? Try the "shields up" and do the scan for all service ports (1-1056) on
www.grc.com"

That's why I'm confused.... there isn't a reason why the http should be open.

I was using Symantec System Check www.symantec.com/securitycheck/

I'll give the GRC site a go.

"Also make sure under UPnP Forwarding you having nothing enabled.

Do you have a DMZ ?"



No UPnP Forwarding or DMZ.... don't know what's going on.
Reply With Quote
  #8  
Old September 10th, 2004, 09:27 PM
phantomgti's Avatar
phantomgti phantomgti is offline
New Member
 
Join Date: Sep 2004
Location: Vancouver, B.C.
Posts: 5
One other question......

Can those ports only be closed in the router settings? or can I disable them in Windows?
Reply With Quote
  #9  
Old September 11th, 2004, 12:02 AM
phantomgti's Avatar
phantomgti phantomgti is offline
New Member
 
Join Date: Sep 2004
Location: Vancouver, B.C.
Posts: 5
GRC.com

Hi MishY,

Well I think Symantec is on drugs or they want to make you paranoid inorder to buy their software.

I did all the tests at GRC and they came up with only the ident closed like yours was.

Is it possible for you to do the Symantec Security check just to see what they say regarding your connection?

www.symantec.com/securitycheck

Thanks for all your help.

Trevor
Reply With Quote
Reply

Bookmarks

Topic Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 06:28 AM.

[ RSS ]