How many ports do you have currently forwarded on your router??
I am a big fan of remote access so I have about 16 ports forwarded... that includes a webserver, 2 ftp servers, hamachi listening ports, bittorrent listening ports and remote admin for my router, NAS and XBOX etc...
I hear a lot of people say that for security, you should only forward SSH and then tunnel everything else through that, but I think that would be slow.
I have a bunch of rules setup for games, but I disable them when I'm not playing. I have the remote desktop port open to remote into my machine, and 1 IP on DMZ for my ps3 (didn't feel like finding out ports to open for it...)
Join the Ron Paul Revolution
Ron Paul 2012
I just have one open - for bittorrent. I don't think having RDP on the usual port is any more dangerous than having any other service on its well-known port number. Port scanning tools like nmap will scan thousands of ports in a very short time and give a very good guess as to what service is running on the port. So long as the service itself is secure (strong passwords, no vulnerabilities etc) you're relatively safe.
Interesting thread, by the way :icon_salu
Yea, good point. I used to run on a custom port, but since I upgraded my OS, i forgot about that and just did the usual port. I'm always on top of patch tuesday, and I always use strong password and change them often.
I think I'll go change the port now that I'm thinking about it :)
Oh yea, I have one open for BT too, now how did I forget that :icon_scra
Join the Ron Paul Revolution
Ron Paul 2012
None.... I use UPnP
My rig:
Dell XPS 410
Processor: Core 2 Duo E6600
Memory: 3GB DDR2 PC 6400
HDD: 500GB+250GB
Optical: 16X DVD-R
Video: nVidia GeForce 8800 GTX
Sound: Sound Blaster X-Fi Xtreme Gamer
I would venture to say that for range scanning they are doing 1 port looking for 1 specific service.
Speaking of SSH, according to the internet watchdogs, the 'brute force' attempts on SSH have increased from a handfull of attacks, to hundreds and even thousands of IP's hitting a single target in short amounts of time. Just food for thought for anyone using SSH.
I'll try to dig up a link, but this is like within the past month.
Join the Ron Paul Revolution
Ron Paul 2012
True enough man. I guess it depends on the type of scan they're doing. And every little helps :D
For anyone using SSH, you've been warned:
http://www.securityfocus.com/news/11518
Join the Ron Paul Revolution
Ron Paul 2012
Bookmarks