Concerned about security

Joined
Jun 25, 2006
Messages
171
Reaction score
1
Points
18
Location
Gatineau, QC, Canada
Your Mac's Specs
24" 2.4Ghz C2D iMac, 2GB RAM, 320GB HD - iMac 17, 1.83 GHz C2D - Mac Mini - Airport Extreme Base
Hi,

I ran an online "Shields Up" test from Gibson Research Corp. and was quite taken aback by the results, all except for 5 ports are closed and not stealth.

Hardware:

iMac aluminum 24" running Leopard 1.51
Airport Extreme base station router set with WPA2 security, DSL modem using PPoE.

Any ideas?
Gene
:|
 
Joined
Sep 24, 2007
Messages
235
Reaction score
17
Points
18
Your Mac's Specs
17" MacBook Pro 4GB
This is not a bad thing, really. As it explains on Steve's site, 'Stealth' indicates that your ISP is blocking the port, and not your router/firewall. This tells me that your ISP doesn't permit inbound access on those 5 ports, as a means of preventing people from running their own servers.

'Closed' is the optimal setting. While that will not stop a determined hacker from trying to get at your information, it will prevent possibly 90 - 95% of the skript kiddies and lesser-skilled types from doing anything.

Think of it as double-protection on those 5 ports: If the hacker DOES get past your ISPs filter, he still has to get past your firewall, too.

Perry
 
OP
gemigene
Joined
Jun 25, 2006
Messages
171
Reaction score
1
Points
18
Location
Gatineau, QC, Canada
Your Mac's Specs
24" 2.4Ghz C2D iMac, 2GB RAM, 320GB HD - iMac 17, 1.83 GHz C2D - Mac Mini - Airport Extreme Base
This is not a bad thing, really. As it explains on Steve's site, 'Stealth' indicates that your ISP is blocking the port, and not your router/firewall. This tells me that your ISP doesn't permit inbound access on those 5 ports, as a means of preventing people from running their own servers.

'Closed' is the optimal setting. While that will not stop a determined hacker from trying to get at your information, it will prevent possibly 90 - 95% of the skript kiddies and lesser-skilled types from doing anything.

Think of it as double-protection on those 5 ports: If the hacker DOES get past your ISPs filter, he still has to get past your firewall, too.

Perry

Thanks for the reassurance, perry, I was really worried about this. When I had a Winbox with a firewall, I ran that same test and all ports were "stealth" so I was expecting the same with the iMac.

Now, it shows ports 25, 136, 137, 137, 138, 139 and 445 as being stealth and the rest as closed (for some strange reason, I ran the test again and now have 7 instead of 5).

Cheers,
Gene
 
Joined
Jul 25, 2007
Messages
245
Reaction score
2
Points
18
you may want to try out another popular port scanner which is pcflank.com

however, I wouldn't worry too much about the ports as long as they are closed.
 
Joined
Sep 24, 2007
Messages
235
Reaction score
17
Points
18
Your Mac's Specs
17" MacBook Pro 4GB
Well, port 25 is mail, and the others are all related to various Windows networking protocols that should not be allowed outside of your network anyway. So I'm going to guess you've got an ISP that does not allow you to run your own mail server, and they are taking precautions against people being dumb enough to connect a windows machine directly to the network without a firewall.

You're good to go, unless you actually want to run a mail server at home.
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top