PDA

View Full Version : Firewall on Windows XP (SP2)


Dr. Paul Caesar - CoullByte (UK) Limited
March 9th 05, 07:21 PM
Could someone advise if the Windows XP Firewall on Service Pack 2 closes the
ports assigned to applications if the application closes?

If not this could allow possible security threats via the ports for a
specific application such as that of Windows Messenger or MSN Messenegr - MSN
Messenger being an application highly used by most people on the net.

The I feel the Firewall should works is as follows:

Application Starts, if not registered on the Firewall throw box to user asking
Open Firewall Port
Application Closes or is Terminated
Close Firewall Port

If this is the way Windows Firewall operates then Windows Firewall should
show if the port is Open or Closed.

Also certain Firewall settings such as File and Print Sharing by default
should have the scope set to subnet only with an option on the bloked box to
untick should you wish for it to be open to all.

Steve Winograd [MVP]
March 9th 05, 09:51 PM
In article >, "Dr.
Paul Caesar - CoullByte (UK) Limited"
ft.com> wrote:
>Could someone advise if the Windows XP Firewall on Service Pack 2 closes the
>ports assigned to applications if the application closes?
>
>If not this could allow possible security threats via the ports for a
>specific application such as that of Windows Messenger or MSN Messenegr - MSN
>Messenger being an application highly used by most people on the net.
>
>The I feel the Firewall should works is as follows:
>
>Application Starts, if not registered on the Firewall throw box to user asking
>Open Firewall Port
>Application Closes or is Terminated
>Close Firewall Port
>
>If this is the way Windows Firewall operates then Windows Firewall should
>show if the port is Open or Closed.
>
>Also certain Firewall settings such as File and Print Sharing by default
>should have the scope set to subnet only with an option on the bloked box to
>untick should you wish for it to be open to all.

Yes, the firewall should close ports when the application closes. To
find out whether it does, run the app, close the app, then do a port
scan. Here are some sites:

http://scan.sygatetech.com
http://www.dslreports.com/scan
https://grc.com/x/ne.dll?bh0bkyd2
--
Best Wishes,
Steve Winograd, MS-MVP (Windows Networking)

Please post any reply as a follow-up message in the news group
for everyone to see. I'm sorry, but I don't answer questions
addressed directly to me in E-mail or news groups.

Microsoft Most Valuable Professional Program
http://mvp.support.microsoft.com

Dr. Paul Caesar - CoullByte (UK) Limited
March 10th 05, 01:27 AM
Thanks for reply.

Have been doing some testing using IIS on WIndows XP Pro with SP2.

Opened port 8080 ans set IIS to listen on this port. Soon as I removed this
port from IIS it shows as Stealth.

It would be usefull however to be able to look at the Firewall and see what
ports are open, closed or stealth.

Paul

Google