Hi

I use the free version of Sygate for my firewall and have done all the port
scans etc to check it and after a bit of messing around it says i am
stealthed to the world!

However when i run a common ports scan at 'shield up' it says port 23 used
by Telnet is only closed and not stealthed and a potential security risk.

What is Telnet? Do i need it? If not how do i disable/block it? If i do how
do i stealth this port?

Hope someone can help an amateur

Darren

Re: telnet, do i need it and is it safe? by Miha

Miha
Sat Aug 28 04:18:20 CDT 2004

Hi Darren,

If scan reports tells you that Telnet is closed this means that either
Telnet service isn't running or firewall it blocking access to the service.
For any more information it would help if you told us what operating system
you are running on your computer. On Windows 2000 and Windows XP telnet
service is disabled or not running by default.

Here is how to check your Windows XP or Windows 2000 client if the Telnet
service is disabled. Right click on My Computer -> Manage -> double click on
Services and Applications -> Services -> in right pane school down till you
get to Telnet service.
Here look under Status row and it should be empty. Also look under Startup
Type and in Windows XP will be Disabled while in Windows 2000 it will be
Manual. You can even change this in Windows 2000 by double clicking on the
service and from Startup Type drop down menu select Disabled.

Mike

"Darren" <Darren@discussions.microsoft.com> wrote in message
news:630E8AD6-E03D-498D-9FE3-E700BA755ABD@microsoft.com...
> Hi
>
> I use the free version of Sygate for my firewall and have done all the
port
> scans etc to check it and after a bit of messing around it says i am
> stealthed to the world!
>
> However when i run a common ports scan at 'shield up' it says port 23 used
> by Telnet is only closed and not stealthed and a potential security risk.
>
> What is Telnet? Do i need it? If not how do i disable/block it? If i do
how
> do i stealth this port?
>
> Hope someone can help an amateur
>
> Darren



Re: telnet, do i need it and is it safe? by Darren

Darren
Sat Aug 28 04:55:01 CDT 2004

Hi Mike

Thanks for the reply

I am using XP home.

I did what you said but Telnet isnt in the list.

Darren

"Miha Pihler" wrote:

> Hi Darren,
>
> If scan reports tells you that Telnet is closed this means that either
> Telnet service isn't running or firewall it blocking access to the service.
> For any more information it would help if you told us what operating system
> you are running on your computer. On Windows 2000 and Windows XP telnet
> service is disabled or not running by default.
>
> Here is how to check your Windows XP or Windows 2000 client if the Telnet
> service is disabled. Right click on My Computer -> Manage -> double click on
> Services and Applications -> Services -> in right pane school down till you
> get to Telnet service.
> Here look under Status row and it should be empty. Also look under Startup
> Type and in Windows XP will be Disabled while in Windows 2000 it will be
> Manual. You can even change this in Windows 2000 by double clicking on the
> service and from Startup Type drop down menu select Disabled.
>
> Mike
>
> "Darren" <Darren@discussions.microsoft.com> wrote in message
> news:630E8AD6-E03D-498D-9FE3-E700BA755ABD@microsoft.com...
> > Hi
> >
> > I use the free version of Sygate for my firewall and have done all the
> port
> > scans etc to check it and after a bit of messing around it says i am
> > stealthed to the world!
> >
> > However when i run a common ports scan at 'shield up' it says port 23 used
> > by Telnet is only closed and not stealthed and a potential security risk.
> >
> > What is Telnet? Do i need it? If not how do i disable/block it? If i do
> how
> > do i stealth this port?
> >
> > Hope someone can help an amateur
> >
> > Darren
>
>
>

RE: telnet, do i need it and is it safe? by MAP

MAP
Sat Aug 28 07:11:01 CDT 2004



"Darren" wrote:

> Hi
>
> I use the free version of Sygate for my firewall and have done all the port
> scans etc to check it and after a bit of messing around it says i am
> stealthed to the world!
>
> However when i run a common ports scan at 'shield up' it says port 23 used
> by Telnet is only closed and not stealthed and a potential security risk.
>
> What is Telnet? Do i need it? If not how do i disable/block it? If i do how
> do i stealth this port?
>
> Hope someone can help an amateur
>
> Darren

http://www.blackviper.com/WinXP/service411.htm#Telnet

http://www.blackviper.com/WinXP/servicecfg.htm



Re: telnet, do i need it and is it safe? by Lawrence

Lawrence
Sat Aug 28 12:08:25 CDT 2004

The telnet service is not part of xp home and if you have something
listening on that port I would be rightly concerned. Please do the
following so I can see what your autostartup programs are:

Create a directory on your hardrive to save HijackThis.exe. A directory
like c:\hijackthis. If you do not do this, you will not be able to use the
backup/restore features.

Download HijackThis from:

http://www.spywareinfo.com/~merijn/files/hijackthis.zip

or here:

http://www.bleepingcomputer.com/files/spyware/hijackthis.zip

Save this file into the directory you made previously and then run the
program named hijackthis.exe. When the program opens click on the Config
button, then click on the Misc Tools button, and click on the Check for
update online button. When it completes checking/applying updates press the
back button.

Now click on the Scan button and when it is finished click on the Save Log
button. A Notepad window will open with the contents of this log. Click on
Edit then click on Select all. Then click on Edit and then Click on Copy.

Create a reply to this post here or register an account and post a message
in the HijackThis Logs forums at http://www.bleepingcomputer.com and right
click in message area and select paste to paste the log into the post.

Someone will reply to you after reading this post. DO NOT fix any entries
unless you understand what you are doing.

To see a tutorial with screenshots on using HijackThis you can click on the
link below:

http://www.bleepingcomputer.com/forums/index.php?showtutorial=42

--
Lawrence Abrams
http://www.bleepingcomputer.com
Source for Original Content, Tutorials, and Support for the beginning
computer user.

"Darren" <Darren@discussions.microsoft.com> wrote in message
news:D335D2A5-7438-441B-821D-2DA966518EB0@microsoft.com...
> Hi Mike
>
> Thanks for the reply
>
> I am using XP home.
>
> I did what you said but Telnet isnt in the list.
>
> Darren
>
> "Miha Pihler" wrote:
>
> > Hi Darren,
> >
> > If scan reports tells you that Telnet is closed this means that either
> > Telnet service isn't running or firewall it blocking access to the
service.
> > For any more information it would help if you told us what operating
system
> > you are running on your computer. On Windows 2000 and Windows XP telnet
> > service is disabled or not running by default.
> >
> > Here is how to check your Windows XP or Windows 2000 client if the
Telnet
> > service is disabled. Right click on My Computer -> Manage -> double
click on
> > Services and Applications -> Services -> in right pane school down till
you
> > get to Telnet service.
> > Here look under Status row and it should be empty. Also look under
Startup
> > Type and in Windows XP will be Disabled while in Windows 2000 it will be
> > Manual. You can even change this in Windows 2000 by double clicking on
the
> > service and from Startup Type drop down menu select Disabled.
> >
> > Mike
> >
> > "Darren" <Darren@discussions.microsoft.com> wrote in message
> > news:630E8AD6-E03D-498D-9FE3-E700BA755ABD@microsoft.com...
> > > Hi
> > >
> > > I use the free version of Sygate for my firewall and have done all the
> > port
> > > scans etc to check it and after a bit of messing around it says i am
> > > stealthed to the world!
> > >
> > > However when i run a common ports scan at 'shield up' it says port 23
used
> > > by Telnet is only closed and not stealthed and a potential security
risk.
> > >
> > > What is Telnet? Do i need it? If not how do i disable/block it? If i
do
> > how
> > > do i stealth this port?
> > >
> > > Hope someone can help an amateur
> > >
> > > Darren
> >
> >
> >



Re: telnet, do i need it and is it safe? by Kent

Kent
Sat Aug 28 12:42:47 CDT 2004

Darren wrote on 28-Aug-2004 12:49 AM:

> Hi
>
> I use the free version of Sygate for my firewall and have done all the port
> scans etc to check it and after a bit of messing around it says i am
> stealthed to the world!
>
> However when i run a common ports scan at 'shield up' it says port 23 used
> by Telnet is only closed and not stealthed and a potential security risk.
>
> What is Telnet? Do i need it? If not how do i disable/block it? If i do how
> do i stealth this port?
>
> Hope someone can help an amateur
>
> Darren

Open a command prompt and run the command "netstat -an" and see if it
reports any process listening on port 23. If it isn't
%windir%\system32\tlntsvr.exe, then it is likely something bad. If it is
tlntsvr.exe, you can disable it in services.msc, but you said you were
using XP Home, so it shouldn't show up.

However, I note that using the Windows Firewall included in SP2 on XP
Pro, if the firewall is disabled, ShieldsUp! reports that telnet port 23
is "closed" meaning that my machine replied and said that the service is
not available, instead of stealthed, which means my machine didn't reply
at all.

If I enable the Windows Firewall, then port 23 is stealthed. The telnet
service is disabled on my machine. The Microsoft Baseline Security
Analyzer also complains about telnet service when it isn't running,
probably for the same reason. XP replies to telnet connection requests,
even when the telnet server isn't running or isn't installed (Home).

So set your firewall to explicitly stealth port 23. And check some other
scan sites to make sure that port 23 really is reporting itself as
closed, instead of keeping its mouth shut.

--
Kent W. England, Microsoft MVP for Windows Security

Re: telnet, do i need it and is it safe? by N

N
Sat Aug 28 23:38:06 CDT 2004

In article <630E8AD6-E03D-498D-9FE3-E700BA755ABD@microsoft.com>, =?Utf-8?B?
RGFycmVu?= says...

> I use the free version of Sygate for my firewall and have done all the port
> scans etc to check it and after a bit of messing around it says i am
> stealthed to the world!

> However when i run a common ports scan at 'shield up' it says port 23 used
> by Telnet is only closed and not stealthed and a potential security risk.

The port is only closed? Not a problem. Closed is as good as "stealth".

> What is Telnet? Do i need it? If not how do i disable/block it? If i do how
> do i stealth this port?

Telnet is a text terminal of sorts. It can be used to access POP3 servers,
NNTP servers, and HTTP servers to find out what is on the servers. You can
even access SMTP servers and compose an email message; but you have to
understand the components of an SMTP message; MSOE automatically does all of
the detail work that you would have to do using Telnet for email.

Unless you are interested in doing those things, you don't really need it.

> Hope someone can help an amateur

Back to your question about port 23 only being closed; something is
returning a, probably, RST, ACK packet to Shields Up!. If SU had gotten a
SYN, ACK packet, it would have responded with an ACK packet, and gotten a
response to the ACK packet; at that time SU would report the port as "open",
then move on to the next sequential port.

Are you running Windows XP with a direct connection to the Internet? No
router, just computer>>>modem>>>Internet? If so, then Sygate is all that
stands between your computer and the Internet. There is something about
Sygate which is allowing the RST, ACK packet to get back to SU. You need to
study the Sygate docs to learn how to squelch that if your goal is to
achieve "True Stealth".

BTW, GRC has a whole slew of forums for just such questions. A couple of the
MVPs here don't care much for that site, but you might find some useful
information in the news groups. GRC does not utilize the Microsft CDO for
Windows 2000 web-to-news interface; you will have to manually configure your
news client. If I get the format right, try:

news://news.grc.com/grc.shieldsup

You did say the port was closed, didn't you? If you meant "open"; well, then
you need to follow the other advice given here.

--
Norman
~Win dain a lotica, En vai tu ri, Si lo ta
~Fin dein a loluca, En dragu a sei lain
~Vi fa-ru les shutai am, En riga-lint

Re: telnet, do i need it and is it safe? by Darren

Darren
Sun Aug 29 00:13:10 CDT 2004

Hi

Thanks Norman that has shed light on it for me.

Darren

"N. Miller" wrote:

> In article <630E8AD6-E03D-498D-9FE3-E700BA755ABD@microsoft.com>, =?Utf-8?B?
> RGFycmVu?= says...
>
> > I use the free version of Sygate for my firewall and have done all the port
> > scans etc to check it and after a bit of messing around it says i am
> > stealthed to the world!
>
> > However when i run a common ports scan at 'shield up' it says port 23 used
> > by Telnet is only closed and not stealthed and a potential security risk.
>
> The port is only closed? Not a problem. Closed is as good as "stealth".
>
> > What is Telnet? Do i need it? If not how do i disable/block it? If i do how
> > do i stealth this port?
>
> Telnet is a text terminal of sorts. It can be used to access POP3 servers,
> NNTP servers, and HTTP servers to find out what is on the servers. You can
> even access SMTP servers and compose an email message; but you have to
> understand the components of an SMTP message; MSOE automatically does all of
> the detail work that you would have to do using Telnet for email.
>
> Unless you are interested in doing those things, you don't really need it.
>
> > Hope someone can help an amateur
>
> Back to your question about port 23 only being closed; something is
> returning a, probably, RST, ACK packet to Shields Up!. If SU had gotten a
> SYN, ACK packet, it would have responded with an ACK packet, and gotten a
> response to the ACK packet; at that time SU would report the port as "open",
> then move on to the next sequential port.
>
> Are you running Windows XP with a direct connection to the Internet? No
> router, just computer>>>modem>>>Internet? If so, then Sygate is all that
> stands between your computer and the Internet. There is something about
> Sygate which is allowing the RST, ACK packet to get back to SU. You need to
> study the Sygate docs to learn how to squelch that if your goal is to
> achieve "True Stealth".
>
> BTW, GRC has a whole slew of forums for just such questions. A couple of the
> MVPs here don't care much for that site, but you might find some useful
> information in the news groups. GRC does not utilize the Microsft CDO for
> Windows 2000 web-to-news interface; you will have to manually configure your
> news client. If I get the format right, try:
>
> news://news.grc.com/grc.shieldsup
>
> You did say the port was closed, didn't you? If you meant "open"; well, then
> you need to follow the other advice given here.
>
> --
> Norman
> ~Win dain a lotica, En vai tu ri, Si lo ta
> ~Fin dein a loluca, En dragu a sei lain
> ~Vi fa-ru les shutai am, En riga-lint
>