LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-19-2002, 06:30 AM   #1
Chijtska
Member
 
Registered: Jan 2002
Location: High Falls, GA
Distribution: Mandrake8.2, FreeBSD, Solaris
Posts: 362

Rep: Reputation: 30
Port 139 question


I am told by anyone that helps me with my security whenever they run an nmap on me that i need to close 139... everyone says that is a bad port to have open yet it seems i must have it on in order network my computers... are there any serious exploits for this?
 
Old 02-19-2002, 09:23 AM   #2
kill-hup
Member
 
Registered: Aug 2000
Location: NY - USA
Distribution: Slackware
Posts: 109

Rep: Reputation: 15
TCP port 139 is used for NETBIOS - I assume you are running samba/nmbd on you Linux box. Assuming you have everything configured as securely as possible, (and you absolutely need it to do whatever you are doing) I wouldn't worry about it.

The rule of thumb with network services is to disable anything you don't need. NETBIOS is normally one of them, but if you need it, just make sure it's secured.
 
Old 02-19-2002, 10:34 AM   #3
Malicious
Member
 
Registered: Jan 2002
Location: Galveston Island
Distribution: suse, redhat
Posts: 208

Rep: Reputation: 30
If port 139 is open on the internet connection, you are at risk, if nothing more than to let a scanner know that there is a system at that ip. I don't know how your local lan and internet access is set up, but I would disable sharing on the internet connection. In Windows boxes, it's done in the adapter/service binding. In Samba, just don't configure that connection in the "hosts allow".
 
Old 02-19-2002, 11:07 AM   #4
Chijtska
Member
 
Registered: Jan 2002
Location: High Falls, GA
Distribution: Mandrake8.2, FreeBSD, Solaris
Posts: 362

Original Poster
Rep: Reputation: 30
yeah, i get it that sharing can be a risk, however, that is a must have for my network at the moment... any ideas?

thanks
 
Old 02-19-2002, 12:20 PM   #5
spyguy703
LQ Newbie
 
Registered: Feb 2002
Location: San Jose, CA
Distribution: RedHat, Mandrake
Posts: 5

Rep: Reputation: 0
You can allow NetBios between your hosts on your LAN. However, you do not want to allow NetBios connections into your network from outside.

Hopefully you are nat'ing your PC's and they have private IP addresses. (192.168.1.1...etc)

What kind of firewall do you have? What does your network setup look like?
 
Old 02-19-2002, 09:00 PM   #6
Chijtska
Member
 
Registered: Jan 2002
Location: High Falls, GA
Distribution: Mandrake8.2, FreeBSD, Solaris
Posts: 362

Original Poster
Rep: Reputation: 30
i have no firewalls...

my network is a server running mandrake 8.1
printer
usb dsl modem

hub--

client 1--suse 6.2

client 2--windows 2000

server has dhcp, smaba-server, and internet connection sharing running...

% nmap localhost
Starting nmap V. 2.54BETA22 ( www.insecure.org/nmap/ )
Interesting ports on localhost.localdomain (127.0.0.1):
(The 1535 ports scanned but not shown below are in state: closed)
Port State Service
53/tcp open domain
80/tcp open http
139/tcp open netbios-ssn
631/tcp open cups
901/tcp open samba-swat
953/tcp open rndc
6000/tcp open X11
 
Old 02-19-2002, 09:21 PM   #7
Malicious
Member
 
Registered: Jan 2002
Location: Galveston Island
Distribution: suse, redhat
Posts: 208

Rep: Reputation: 30
Go here to find out what ports are open to the internet:

http://grc.com/default.htm

Go to the ShieldsUp part and do the Test My Shields and Port Probe thingies. It will give you an idea of how open your network is to the internet. Some of the ports available to the local host may not be available to the net.
 
Old 02-20-2002, 12:12 PM   #8
spyguy703
LQ Newbie
 
Registered: Feb 2002
Location: San Jose, CA
Distribution: RedHat, Mandrake
Posts: 5

Rep: Reputation: 0
Chijtska,

You need a host-based firewall for the computer that is directly on the internet...in this case, it looks like your windows box with Internet Connection Sharing.

Try the free version of ZoneAlarm. Something is better than nothing at all.
 
Old 02-20-2002, 12:46 PM   #9
Chijtska
Member
 
Registered: Jan 2002
Location: High Falls, GA
Distribution: Mandrake8.2, FreeBSD, Solaris
Posts: 362

Original Poster
Rep: Reputation: 30
where would i get zone alarm? everytime i install a firewall i cant share my internet connection or files for some reason...any idea why this is?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
connection refused Samba port 139 cbriscoejr Linux - Networking 4 10-14-2004 10:34 AM
netbios-ssn 139 port?? yenonn Linux - Security 5 09-19-2003 11:24 PM
Samba (port 139) open to the world Tezdread Linux - Networking 4 03-09-2003 10:17 AM
Port 139 jmarsh Linux - Networking 5 03-06-2003 11:01 AM
how to access tcp/139 port cmardhekar Linux - General 1 08-20-2001 06:03 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:57 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration