Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 21, 2010, 10:57:24 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373586
Posts
41456
Topics
94202
Members
Latest Member:
rmanero
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Firewall
Help for v2
Open ports to allow P2P clients: The risks [RESOLVED]
« previous
next »
Pages:
[
1
]
Author
Topic: Open ports to allow P2P clients: The risks [RESOLVED] (Read 3178 times)
vespatian
Newbie
Offline
Posts: 6
Open ports to allow P2P clients: The risks [RESOLVED]
«
on:
August 12, 2006, 09:41:45 AM »
Hi all... Thanks for the great FAQ and help pages
I have followed the FAQ and managed to sort out the NAT error when using Azureus with CPF. Really fast transfers now
However, after scanning my ports with GRC 'Shields Up' I have noticed that the port I am using for Azureus is wide open on the internet, not just fo Azureus.
Is this a serious security risk? Is it not posible to only allow TCP/UDP connections from Azureus to this port? I am using one of the ports recommended by Azureus.
Would be nice if someone could clarify the risks to me and any possible solution
Thanks!
(J)
«
Last Edit: August 13, 2006, 06:16:41 AM by panic
»
Logged
BullHorn
Comodo's Hero
Offline
Posts: 230
Nexus23
Re: Open ports to allow P2P clients
«
Reply #1 on:
August 12, 2006, 09:46:15 AM »
Quote from: BullHorn on August 12, 2006, 09:38:30 AM
That's exactly what I did with mIRC so I could use DCC and I had the exact same question and problem but no answer.
The port is wide open, right? For all TCP/UDP incoming through port ####, it isn't only set to be allowed by mIRC.
I'd like to be enlightened.
Logged
Windows XP SP2
Comodo Personal Firewall 3.0.7.208
NOD32 2.7
vespatian
Newbie
Offline
Posts: 6
Re: Open ports to allow P2P clients
«
Reply #2 on:
August 12, 2006, 10:12:30 AM »
Quote from: BullHorn on August 12, 2006, 09:46:15 AM
Hey Bullhorn! Yup... Port is wide open for any connection... I opened peerguardian to see the log for 'allowed connections' and there were several connections coming in for that exact port with Azureus not even running!
No sign of worms or intrusions as such, but I dont like the idea of all these random connections :S
«
Last Edit: August 12, 2006, 10:16:38 AM by vespatian
»
Logged
BullHorn
Comodo's Hero
Offline
Posts: 230
Nexus23
Re: Open ports to allow P2P clients: The risks
«
Reply #3 on:
August 12, 2006, 02:29:55 PM »
No answers yet...
Anyway, even if this IS a security issue, I'm sure it'll be easily fixed. Just add another box in that Network Monitor. Whenever you "add" a new allowed port, just choose target the application that you want to allow this port for.
Logged
Windows XP SP2
Comodo Personal Firewall 3.0.7.208
NOD32 2.7
egemen
Administrator
Comodo's Hero
Offline
Posts: 2191
Re: Open ports to allow P2P clients: The risks
«
Reply #4 on:
August 12, 2006, 04:20:40 PM »
Quote from: vespatian on August 12, 2006, 09:41:45 AM
Hi all... Thanks for the great FAQ and help pages
I have followed the FAQ and managed to sort out the NAT error when using Azureus with CPF. Really fast transfers now
However, after scanning my ports with GRC 'Shields Up' I have noticed that the port I am using for Azureus is wide open on the internet, not just fo Azureus.
Is this a serious security risk? Is it not posible to only allow TCP/UDP connections from Azureus to this port? I am using one of the ports recommended by Azureus.
Would be nice if someone could clarify the risks to me and any possible solution
Thanks!
(J)
When you open the port, if an application listens on that port, it will be shown open. But if you close the listening application, it will be stealhted.
So the fact is "If Azerus is running and listening on the port you allowed in network rules, that port will be open. If Azerus is not listening, it wont be."
Have you opened all the ports? Let me see your network rules pls.
Egemen
Logged
BullHorn
Comodo's Hero
Offline
Posts: 230
Nexus23
Re: Open ports to allow P2P clients: The risks
«
Reply #5 on:
August 12, 2006, 04:23:35 PM »
Oh, now I get it.
All I gotta make sure is that I don't set a program to use a port that is used by some other oftenly-used Windows or similar important port, am I right?
Logged
Windows XP SP2
Comodo Personal Firewall 3.0.7.208
NOD32 2.7
vespatian
Newbie
Offline
Posts: 6
Re: Open ports to allow P2P clients: The risks
«
Reply #6 on:
August 12, 2006, 05:30:50 PM »
Quote from: egemen on August 12, 2006, 04:20:40 PM
When you open the port, if an application listens on that port, it will be shown open. But if you close the listening application, it will be stealhted.
So the fact is "If Azerus is running and listening on the port you allowed in network rules, that port will be open. If Azerus is not listening, it wont be."
Have you opened all the ports? Let me see your network rules pls.
Egemen
Thanks egemen!
Hmmmm... GRC saw that port 'open' even when Azureus was not running. As far as I know no other application uses that port... It is within the range suggested by Azureus (begins at 49152)
Network rule I set up other than the defaul ones:
TCP/UDP In (ALLOWED)
Source IP: Any
Remote IP: My computer's network IP
Source Port: Any
Remote Port: My Azureus Port
«
Last Edit: August 12, 2006, 05:35:00 PM by vespatian
»
Logged
vespatian
Newbie
Offline
Posts: 6
Re: Open ports to allow P2P clients: The risks
«
Reply #7 on:
August 12, 2006, 05:44:16 PM »
Hello again. You are absolutely right... When I shut down Azureus this time the specific port was stealthed.
My bad.
Thanks for help
(L)
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 2191
Re: Open ports to allow P2P clients: The risks
«
Reply #8 on:
August 13, 2006, 06:11:45 PM »
Quote from: BullHorn on August 12, 2006, 04:23:35 PM
Oh, now I get it.
All I gotta make sure is that I don't set a program to use a port that is used by some other oftenly-used Windows or similar important port, am I right?
Yes. Windows usualy does not use any ports other than well-known ones like 445,139,80,1900. The ports used by p2p clients are usually some random ports and not shared by any other common services.
Egemen
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.047 seconds with 20 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com