Reply
 
Thread Tools Display Modes
  #1  
Old 09-07-2007, 02:57 PM
cutback cutback is offline
Junior Member
 
Join Date: Sep 2007
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Default FireWall and GRC port scan
Hello
Absolutely reeking fresh newbie to this
Sick of M$
Testing various Linux distros and found PCBSD: LOVE IT

STill getting to grips with various aspects of both Linux and PCBSD after many years of Windoze

I thought the FWall would by default block ports: scanned at GRC
http://www.grc.com/default.htm
"shields up' and found Port 22 ssh remote login = open
Also 139, 179, and 445: stealthed but not closed.

Currently running the VMWare file in licensed version of workstation on Windows hosts: which could be it, I have enough trouble following FW set-ups without involving VMs.

If I ran the PCBSD as primary system, would I have any ports open?
Exactly what is protecting my system if I am in a VM on the web: the VM FW or the system FW?

Any advice.

Sorry if this is a dumb question.
While I hang around here a bit more, Ill try and keep quiet while absorbing.
Regards.
Reply With Quote
  #2  
Old 09-07-2007, 03:46 PM
Galactic Dominator Galactic Dominator is offline
Senior Member
 
Join Date: May 2006
Posts: 168
Thanks: 0
Thanked 0 Times in 0 Posts
Default
I was going to write a post with my feeling on Steve Gibson, however I found someone has already done it fairly well.

Steve Gibson = grc.com = Gibson research

Quote:
No, geoboy, Steve Gibson is not an idiot. It's too easy to state that. His idiocy has gone to the point where I no longer think he's an idiot, but that he has a deliberate agenda. Probably to sell his crap.

Steve Gibson is a paranoid alarmist wacko, and you really should take anything he says with a heaping mound of salt. The funny thing about Steve is that he takes the littlest tiniest thing, which is in fact not a threat, and creates an elaborate contrived fantasy world where this tiny thing has the most dire consequences imaginable. The fact that it's complete nonsensical bullshit he just dismisses without even arguing about it.

His website and the software he's created is a stunning testament to his paranoid delusions. He has all this software on there, most of it hand coded in freakin' assembler because he doesn't trust compilers or some damned loony shit, and he makes these huge pages describing why he coded it, using hand written (and UGLY) html, with all these freakin' weird color schemes and boxes full of quotes and such, like he's trying to convince even himself that he's not completely insane.

The most hilarious part is that nearly all of his software is completely and totally useless. SpinRite, for example, DOESN'T WORK. It doesn't do a damned thing. At most, at absolute most, it spins your drive for a while and moves the head around a bunch. In certain cases, it can damage the data on the drive by reopening known bad sectors. But in absolutely no case will it fix a drive. In absolutely no case will it make a drive last longer or anything like that. It's complete hokus pokus BS.

ShieldsUp goes to all this trouble to do a network scan of your machine, and gives this bogus "stealth" mode back, never actually mentioning that a status of "closed" is just as secure. Yeah, so they know you're there. BFD, if it's closed, then it's CLOSED. No connections allowed. That's what CLOSED means!

The rest of his site is similar. He creates a utility to turn of UPnP, as if simply turning it off in the UPnP config didn't work. It does, BTW, and that's all his utility actually does. Only it takes him 22k of hand coded machine language to do it. Not only that, but UPnP is not even a security risk anymore. The patch was out for it within weeks of XP's release. And UPnP is incredibly useful for anybody using a NAT router (most people with broadband, I suspect). So it's worse than worthless.

The bottom line is that people who actually know how this stuff works tend to ignore Steve Gibson. Because he's a nut.
You can find the original here.

http://digg.com/security/Steve_Gibson_T ... e_Internet

Actually, I think I would have been quite a harder on him. He is a total crackpot loon who makes money by instilling fear in the consumer where there is little to no cause for the fear.

Quote:
If I ran the PCBSD as primary system, would I have any ports open?
Depends on your setup....usually I have at least port 22 open.

Quote:
Exactly what is protecting my system if I am in a VM on the web: the VM FW or the system FW?
VM FW
Quote:
"shields up' and found Port 22 ssh remote login = open
My advice is as you get more used to *nix you'll come to appreciate ssh and live with being open. Just watch for for CERTS on it and an update when needed....not very often relatively speaking. Course, you could run it on different port, but at the end of the day security through obscurity never works.
Quote:
Also 139, 179, and 445: stealthed but not closed.
So what? I'd only start to worry about that if you were running SAMBA and if so adjust your FW accordingly.
Reply With Quote
  #3  
Old 09-07-2007, 04:39 PM
sblevin sblevin is offline
Senior Member
 
Join Date: Jun 2005
Location: Australia
Posts: 909
Thanks: 0
Thanked 0 Times in 0 Posts
Default
Mr Gibsons site http://www.grc.com/default.htm

HEHEHEHEHE! Don't read it - just look at it and you'll see it's not a informational site ... it's a RANSOM NOTE!!! :)
Reply With Quote
  #4  
Old 09-07-2007, 11:34 PM
cutback cutback is offline
Junior Member
 
Join Date: Sep 2007
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Default
ROFL

Heh: I remeber well the SteveGibson "help the sky is falling" shite.

I recall Stevie actually saved the world.

:roll:
http://www.radsoft.net/resources/rants/ ... 4,00.shtml

the great grcsucks.com has gone, shame.

Thanks for replies.
Just interested in the port scans
If you dont mind dealing with newbs I'll hang around.

regards.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HP photosmart C4280 , doesn't scan Lucas Murad Installing PC-BSD 2 07-01-2008 10:44 PM
Howto "Mount" usb scan device L1mP General Questions 2 01-12-2007 05:31 PM
Scan for bad blocks during install? + hostname brianwc Installing PC-BSD 9 06-06-2006 06:33 AM
Firewall? robzilla General Questions 3 02-23-2006 09:12 AM
Firewall General Questions 5 09-27-2005 12:21 AM


All times are GMT. The time now is 09:58 PM.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

Copyright 2005-2010, The PC-BSD Project. PC-BSD and the PC-BSD logo are registered trademarks of iXsystems.
All other content is freely available for sharing under the terms of the Creative Commons Attribution License.