<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;2Wire 3801HGV - ports open (even when I didn&#x27;t open it)&#x27; in forum &#x27;AT&#x26;T U-verse&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27785776</link>
<description></description>
<language>en</language>
<pubDate>Wed, 19 Jun 2013 14:24:42 EDT</pubDate>
<lastBuildDate>Wed, 19 Jun 2013 14:24:42 EDT</lastBuildDate>

<item>
<title>Re: 2Wire 3801HGV - ports open (even when I didn&#x27;t open it)</title>
<link>http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27833174</link>
<description><![CDATA[ipman posted : Only if you know the type of service it is running. <br><br>I found that TCP port 3476 is open on my 3600. Clearly, it is waiting for some data after connect. I just hope it is not a backdoor to access my LAN. Luckily, I have another router behind it to protect from this madness. But if someone hacked the 3600 and change its DNS, I am screwed. Maybe it is time to use a public DNS like 8.8.8.8.<br><br>Port 25 will result in immediate disconnect. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27833174</guid>
<pubDate>Mon, 17 Dec 2012 20:04:12 EDT</pubDate>
</item>

<item>
<title>Re: 2Wire 3801HGV - ports open (even when I didn&#x27;t open it)</title>
<link>http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27788412</link>
<description><![CDATA[mackey posted : <div class="bquote"><said>said by <a href="/profile/1476678" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1476678');">lanwarrior</a>:</said><p>Is there a syntax I can use to check if the open ports really have open services? I.e. if I telnet to port 25, run some syntax to see if this is truly an SMTP service.</p></div>Yes.<br><br>Port 25: ehlo test.example<br>If there's a mail server there it will respond with something like:<br><pre class="brush: text">telnet gmail-smtp-in.l.google.com 25&#012;Trying 74.125.25.26...&#012;Connected to gmail-smtp-in.l.google.com.&#012;Escape character is '^&#93;'.&#012;220 mx.google.com ESMTP zw4si4576639pbc.64&#012;ehlo test.example&#012;250-mx.google.com at your service, &#91;76.171.149.106&#93;&#012;250-SIZE 35882577&#012;250-8BITMIME&#012;250-STARTTLS&#012;250 ENHANCEDSTATUSCODES&#012;quit&#012;221 2.0.0 closing connection zw4si4576639pbc.64&#012;Connection closed by foreign host.&#012; &#012;</pre><!--end code block-->Both "ehlo test.example" and "quit" were typed by me.<br><br>For ports 80 and 8080: GET / HTTP/1.0 (and then hit 'Enter' twice)<br><pre class="brush: text">telnet google.com 80&#012;Trying 74.125.224.197...&#012;Connected to google.com.&#012;Escape character is '^&#93;'.&#012;GET / HTTP/1.0&#012; &#012;HTTP/1.0 200 OK&#012;Date: Wed, 05 Dec 2012 00:14:15 GMT&#012;Expires: -1&#012;Cache-Control: private, max-age=0&#012;Content-Type: text/html; charset=ISO-8859-1&#012;Set-Cookie: PREF=ID=4683a86bd76be483:FF=0:TM=1354666455:LM=1354666455:S=TEj_dOEgqeCVVkI6; expires=Fri, 05-Dec-2014 00:14:15 GMT; path=/; domain=.google.com&#012;Set-Cookie: NID=66=RsydMO-p4v_qBH_jrcbz9sM84wyPxivLSjgUvWL2NHPsj-qT2PIXBdpiXCpX88-NxsG_wdY4ZhSotKdVjGaOH0RMEMfyvKxEXrE_Tfa5oavkjvgtood6CK0pbv0-lhkq; expires=Thu, 06-Jun-2013 00:14:15 GMT; path=/; domain=.google.com; HttpOnly&#012;P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&amp;answer=151657 for more info."&#012;Server: gws&#012;X-XSS-Protection: 1; mode=block&#012;X-Frame-Options: SAMEORIGIN&#012; &#012;&lt;!doctype html&gt;&lt;html itemscope="itemscope" itemtype="http://schema.org/WebPage"&gt;&lt;head&gt;&lt;meta content="Search the world's information, including webpages, images, videos and more. Google has many special features to help you find exactly what you're looking for." name="description"&gt;&lt;meta content="noodp" name="robots"&gt;&lt;meta itemprop="image" content="/images/google_favicon_128.png"&gt;&lt;title&gt;Google&lt;/title&gt;&lt;script&gt;(function(){&#012;window.google={kEI:"15G-UNfWM4WFiAL3pIGQCQ",getEI:function(a){for(var b;a&amp;&amp;(!a.getAttribute||!(b=a.getAttribute("eid")));)a=a.parentNode;return b||google.kEI},https:function(){return"https:"==window.location.protocol},kEXPI:"25657,39523,39976,40363,4000116,4000473,4000566,4000945,4000955,4001372,4001456,4001569,4001855,4001933,4001959,4001966,4002000,4002036,4002048,4002161,4002240,4002348,4002359,4002378,4002391,4002436,4002460,4002466,4002510,4002562,4002710,4002733,4002756,4002789,4002883",kCSI:{e:"25657,39523,39976,40363,4000116,4000473,4000566,4000945,4000955,4001372,4001456,4001569,4001855,4001933,4001959,4001966,4002000,4002036,4002048,4002161,4002240,4002348,4002359,4002378,4002391,4002436,4002460,&#012;...&#012; &#012;</pre><!--end code block--><br>/M]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27788412</guid>
<pubDate>Tue, 04 Dec 2012 19:15:47 EDT</pubDate>
</item>

<item>
<title>Re: 2Wire 3801HGV - ports open (even when I didn&#x27;t open it)</title>
<link>http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27788042</link>
<description><![CDATA[lanwarrior posted : Crap, I was typing a response and Chrome crashed... Had to re-type.<br><br>Anyways, I have tried running the scan using 2 different mobile hotspots from Clear and T-Mobile and in both cases, NMAP shows the same ports open.<br><br>Is there a syntax I can use to check if the open ports really have open services? I.e. if I telnet to port 25, run some syntax to see if this is truly an SMTP service.<br><br>If there is a tool that can do that (I used to use Nessus, but they're no longer open source), let me know.<br><br>PS: I am now using the ASUS router as an "internal" firewall, so if it is determined that the 2WIRE modem/router that have the open ports, at least my internal network is still secured by the ASUS router. I am not sure if there is a performance issue for having a router connecting to another router...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27788042</guid>
<pubDate>Tue, 04 Dec 2012 17:05:40 EDT</pubDate>
</item>

<item>
<title>Re: 2Wire 3801HGV - ports open (even when I didn&#x27;t open it)</title>
<link>http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27787927</link>
<description><![CDATA[Mangix posted : conspiracy theory: AT&T is doing NAT. So those open ports are not yours. I have no idea...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27787927</guid>
<pubDate>Tue, 04 Dec 2012 16:37:51 EDT</pubDate>
</item>

<item>
<title>Re: 2Wire 3801HGV - ports open (even when I didn&#x27;t open it)</title>
<link>http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27787060</link>
<description><![CDATA[dahan posted : Maybe your office is running a transparent proxy that intercepts connections to those common ports. Have you tried accessing them the way they're supposed to be accessed to see what happens? E.g., try to ftp to your IP address, or open <code>http://your.ip.address</code> in a web browser, etc... if the ports really are open, you'll be able to connect, and maybe get some more info that way.<br><br>If the connections are actually going to your office proxy server, rather than to your U-Verse box, you don't need to worry about it.<br><br>BTW, 110 is POP3, and 143 is IMAP.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27787060</guid>
<pubDate>Tue, 04 Dec 2012 12:39:09 EDT</pubDate>
</item>

<item>
<title>Re: 2Wire 3801HGV - ports open (even when I didn&#x27;t open it)</title>
<link>http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27786725</link>
<description><![CDATA[lanwarrior posted : Try to run the test using nmap or any other open source tool. Make sure you use SYN TCP scan.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27786725</guid>
<pubDate>Tue, 04 Dec 2012 11:11:40 EDT</pubDate>
</item>

<item>
<title>Re: 2Wire 3801HGV - ports open (even when I didn&#x27;t open it)</title>
<link>http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27786002</link>
<description><![CDATA[NormanS posted : <div class="bquote"><said>said by <a href="/profile/1476678" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1476678');">lanwarrior</a>:</said><p>However, if my testing is correct, it seems that the 2WIRE router is opening up all the above ports to the Internet. <br> </p></div>Port 3479 shows up in an Internet search as registered by AT&T for their U-verse modems.<br><br>Nice! Pace bought 2Wire, and my ISP issued me a Pace 4111N-030 residential gateway. Guess which port is open!<br>  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>----------------------------------------------------------------------<br><br>GRC Port Authority Report created on UTC: 2012-12-04 at 09:02:57<br><br>Results from scan of ports: 3470-3490<br><br>    1 Ports Open<br>    0 Ports Closed<br>   20 Ports Stealth<br>---------------------<br>   21 Ports Tested<br><br>NO PORTS were found to be CLOSED.<br><br><B>The port found to be OPEN was: 3479</B><br><br>Other than what is listed above, all ports are STEALTH.<br><br>TruStealth: FAILED - NOT all tested ports were STEALTH,<br>                   - NO unsolicited packets were received,<br>                   - A PING REPLY (ICMP Echo) WAS RECEIVED.<br><br>----------------------------------------------------------------------<br><HR></BLOCKQUOTE><br><br>I don't have AT&T service; it is Sonic.net, LLC "Fusion" service. <B>The GRC Shields Up! graphic lists port 3479 as, "2Wire RPC".</B><br><br>Port 3479 is <B>NOT</B> listed as listening when I run 'netstat -an' at a command prompt. So you can see my Pace 4111N modem from the Internet, though I have no clue how secure it is; but you can't reach the equipment on the LAN.<br><br>I expect it is used for remote configuration of the modem. Without access to the lowest OS layer in the RG, I see no way to "stealth"  this port.<br><br>FWIW, none of your other enumerated 2Wire open ports tested open on my Pace. Below 1030, and 1720, 5000:<br>  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>----------------------------------------------------------------------<br><br>GRC Port Authority Report created on UTC: 2012-12-04 at 09:16:00<br><br>Results from scan of ports: 0, 21-23, 25, 79, 80, 110, 113, <br>                            119, 135, 139, 143, 389, 443, 445, <br>                            1002, 1024-1030, 1720, 5000<br><br>    0 Ports Open<br>    0 Ports Closed<br>   26 Ports Stealth<br>---------------------<br>   26 Ports Tested<br><br>ALL PORTS tested were found to be: STEALTH.<br><br>TruStealth: FAILED - ALL tested ports were STEALTH,<br>                   - NO unsolicited packets were received,<br>                   - A PING REPLY (ICMP Echo) WAS RECEIVED.<br><br>----------------------------------------------------------------------<br><HR></BLOCKQUOTE><br><br>Port 8080:<br>  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>----------------------------------------------------------------------<br><br>GRC Port Authority Report created on UTC: 2012-12-04 at 09:16:53<br><br>Results from scan of ports: 8070-8090<br><br>    0 Ports Open<br>    0 Ports Closed<br>   21 Ports Stealth<br>---------------------<br>   21 Ports Tested<br><br>ALL PORTS tested were found to be: STEALTH.<br><br>TruStealth: FAILED - ALL tested ports were STEALTH,<br>                   - NO unsolicited packets were received,<br>                   - A PING REPLY (ICMP Echo) WAS RECEIVED.<br><br>----------------------------------------------------------------------<br><HR></BLOCKQUOTE><br><br>Maybe AT&T is doing something with proxies, or maybe there are multiple issues with your hardware.<br><small>--<br>Norman<br>~Oh Lord, why have you come<br>~To Konnyu, with the Lion and the Drum</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27786002</guid>
<pubDate>Tue, 04 Dec 2012 04:25:02 EDT</pubDate>
</item>

<item>
<title>Re: 2Wire 3801HGV - ports open (even when I didn&#x27;t open it)</title>
<link>http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27785897</link>
<description><![CDATA[lanwarrior posted : Yes, the IP address is correct. I tried it twice:<br><br>1). Through &raquo;<A HREF="http://www.whatismyip.com/" >www.whatismyip.com/</A><br>2). Using Dynamic DNS<br><br>I did not port forwards or put anything on DMZ. <br><br>I went to Settings --> Firewall --> Advanced Configuration --> "Stealth Mode" and verified this was ALREADY checked.<br><br>The ports are open, according to NMAP:<br><br>Discovered open port 80/tcp <br>Discovered open port 25/tcp <br>Discovered open port 110/tcp <br>Discovered open port 21/tcp <br>Discovered open port 443/tcp <br>Discovered open port 8080/tcp <br>Discovered open port 143/tcp <br>Discovered open port 3479/tcp <br><br>For testing, I unplug EVERYTHING from the 3801HGV and connect only the ASUS router. This ASUS router has been configured to block EVERYTHING. Then I configure the WAN IP address for the ASUS router and test it again as follow:<br><br>I. ASUS router uses private IP address from 2WIRE DHCP (192.168.1.xxx)<br>Run NMAP again (I was connected to the office via VPN, so all traffic are routed through there). The SAME IP addresses above are shown.<br><br>II. ASUS router uses public IP address from 2WIRE<br>From 2WIRE, go to Settings --> LAN --> IP Address allocation and for the ASUS router selected "Public (Select WAN IP mapping). The ASUS WAN port now have the public IP address (99.xxx.xxx.xxx). Run NMAP again, SAME IP addresses are shown.<br><br>Any other test I should do to ensure the ports were NOT open on the 2Wire router? I am not a security expert, so other than NMAP port scanning from another network (not while connected to the U-Verse network), I am not sure what other test I can do.<br><br>However, if my testing is correct, it seems that the 2WIRE router is opening up all the above ports to the Internet. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27785897</guid>
<pubDate>Tue, 04 Dec 2012 01:09:31 EDT</pubDate>
</item>

<item>
<title>Re: 2Wire 3801HGV - ports open (even when I didn&#x27;t open it)</title>
<link>http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27785865</link>
<description><![CDATA[Mangix posted : I'm gonna assume several things:<br><br>1. The IP that you're nmapping is the correct one.<br><br>2. You have no port forwards or any DMZ+'ed clients.<br><br>Resetting the RG to defaults should alleviate issues such as these. There should be a setting called something like "Stealth ports" in the advanced firewall settings which should fix this.<br><br>That being said, are you sure that the ports are OPEN and not CLOSED? AFAIK a port can be OPEN, CLOSED, or, STEALTH with the latter being the state where the router does not reply to a port scan.<br><br>As for turning the RG into a modem, not possible at this time. The best you can do is connecting the ASUS router behind the 2Wire router and DMZ+ing the ASUS router giving it a public IP as well as all the ports open to it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27785865</guid>
<pubDate>Tue, 04 Dec 2012 00:48:43 EDT</pubDate>
</item>

<item>
<title>2Wire 3801HGV - ports open (even when I didn&#x27;t open it)</title>
<link>http://www.dslreports.com/forum/2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27785776</link>
<description><![CDATA[lanwarrior posted : I have a 2WIRE 3801HGV and I did NOT open any ports, nor forwarding anything. I enabled Firewall, with additional things such as:<br>- Strict UDP session<br>- NO Inbound NetBIOS session<br>- etc..etc..<br><br>Running NMAP from my office (thus I am not connected to the U-Verse service), I see the following ports open:<br><br>- TCP 21: FTP<br>- TCP 25: SMTP<br>- TCP 80: HTTP<br>- TCP 110: POP<br>- TCP 143: IMAP<br>- TCP 443: HTTPS<br>- TCP 8080: ???<br>- TCP 3479: 2Wire RPC<br><br>The one that concern me are those with the (*) above.<br><br>1). Why are these ports open when I explicitly did NOT open or forward them?<br><br>2). Anyway I can block them? <br><br>3). If no. 2 is NO, can I turn the 2WIRE 3801HGV as a modem only instead of modem/router hybrid? I have an unused ASUS RT-N56U router that I can install custom firmware and make that as the primary router.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/2Wire-3801HGV-ports-open-even-when-I-didnt-open-it-27785776</guid>
<pubDate>Tue, 04 Dec 2012 00:07:23 EDT</pubDate>
</item>

</channel>
</rss>
