 Link Logger Premium,MVM join:2001-03-29 Calgary, AB
·Shaw
| Re: Place your bets - Closed vs Stealthed said by SpannerITWks :From your screenie you have Ports 135/139/445 open, so naturally i expect those to be probed and/or entered, with whatever consequences if nasties do get in ! You are right and as an example a lot of worms when they see TCP port 135 open try to fingerprint the OS via a scan to TCP port 5000 (UPNP), so just having 135 open would create more traffic just via these extra scans. So I configured the XP system to close the open ports, so this ought to be a fair fight now.
Blake -- Vendor: Author of Link Logger which is a traffic analysis and firewall logging tool |