|
|||||||||||
|
RE: was - RE: Access to well-known ports on Win2K -now [IPSec -Default behavior]
From: Dante Mercurio <dmercurio(at)ccgsecurity.com>
Date: Wed Nov 06 2002 - 11:17:34 EST
M. Dante Mercurio, CCNA, MCSE+I, CCSA
-----Original Message-----
Hello,
As long as you're discussing ipsec filters please permit this bit of
According to the article:
All traffic from any ip port 88 is ASSUMED to be Kerberos traffic and hence is exempt from all ipsec filters. So just by implementing a "block all" ipsec policy, ANYONE can still port scan your computer by binding their scanner to their local port 88 and targeting your computer.
According to this article:
A registry setting was added in Win2K SP1 to support disabling this
I wrote a quick VBScript to then set this key on all computers in an Active Directory OU. If anyone is interested in the script just email me directly. Note the ipsec policy agent needs to be restarted for the change to take effect...this can be scripted as well... Hope someone finds this helpful.
Thanks
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:24 EDT |
||||||||||
|
|||||||||||