Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: was - RE: Access to well-known ports on Win2K -now [IPSec -Default behavior]

From: Roger Seielstad <roger(at)wiredeuclid.COM>
Date: Tue Nov 05 2002 - 20:52:33 EST


Would that not be traffic destined to port 88, not sourced from port 88? Or is Kerberos 88 to 88 (like ISAKMP is 500 to 500)?



Roger D. Seielstad
Email Geek

-----Original Message-----
From: Fred Williams [mailto:A20FBW1@wpo.cso.niu.edu] Sent: Tuesday, November 05, 2002 1:29 PM To: focus-ms@securityfocus.com; security-basics@securityfocus.com Subject: was - RE: Access to well-known ports on Win2K -now [IPSec -Default behavior]

Hello,

As long as you're discussing ipsec filters please permit this bit of
"thread drift"... Most all of you know this already but there are always
new readers or perhaps those new to Win2k ipsec policies...

According to the article:
Traffic That Can--and Cannot--Be Secured by IPSec http://support.microsoft.com/default.aspx?scid=kb;en-us;Q253169

All traffic from any ip port 88 is ASSUMED to be Kerberos traffic and hence is exempt from all ipsec filters. So just by implementing a "block all" ipsec policy, ANYONE can still port scan your computer by binding their scanner to their local port 88 and targeting your computer.

According to this article:
IPSec Does Not Secure Kerberos Traffic Between Domain Controllers http://support.microsoft.com/default.aspx?scid=KB;EN-US;q254728&

A registry setting was added in Win2K SP1 to support disabling this
"feature" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSEC
REG_DWORD: NoDefaultExempt
Value: 1

Do you need help?X

I wrote a quick VBScript to then set this key on all computers in an Active Directory OU. If anyone is interested in the script just email me directly. Note the ipsec policy agent needs to be restarted for the change to take effect...this can be scripted as well... Hope someone finds this helpful.

Thanks
Fred Received on Wed Nov 6 19:48:45 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:24 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library