View Full Version : Security Configuration.
Yvonne York
02-14-08, 12:11 AM
Hiya,
How can Vista (no router) be configured not to use TCP/IP as transport
protocol for NetBIOS, SMB and RPC, thus leaving TCP/UDP ports 135,137-139
and 445 closed.
The best to my understanding is that Seconfig and the application offered by
http://www.ntsvcfg.de/ntsvcfg_eng.html work with WinXP only.
TIA
Sebastian G.
02-14-08, 05:27 AM
Yvonne York wrote:
> Hiya,
> How can Vista (no router) be configured not to use TCP/IP as transport
> protocol for NetBIOS, SMB and RPC, thus leaving TCP/UDP ports 135,137-139
> and 445 closed.
> The best to my understanding is that Seconfig and the application offered by
> http://www.ntsvcfg.de/ntsvcfg_eng.html work with WinXP only.
That they're only written for Windows XP doesn't mean that it stop working
as intended for newer versions of Windows. In fact they included some
changes to address Windows Server 2003 upon my request.
Yvonne York
02-14-08, 05:11 PM
"Sebastian G." <seppi@seppig.de> wrote in message
news:61ijcoF1sgodnU2@mid.dfncis.de...
> Yvonne York wrote:
>
>> Hiya,
>> How can Vista (no router) be configured not to use TCP/IP as transport
>> protocol for NetBIOS, SMB and RPC, thus leaving TCP/UDP ports 135,137-139
>> and 445 closed.
>> The best to my understanding is that Seconfig and the application offered
>> by http://www.ntsvcfg.de/ntsvcfg_eng.html work with WinXP only.
>
>
> That they're only written for Windows XP doesn't mean that it stop working
> as intended for newer versions of Windows.
Wow, I had no idea. That's what I call foresight! I'm going to utilize
Seconfig on my Vista machine.
Thank you very big, Sebastian :-)
> In fact they included some changes to address Windows Server 2003 upon my
request.
I was wondering if you also could request the authors of the programs to add
a note to their respective website stating that the script/configuration is
Vista compatible.
Thanks again.
Sebastian G.
02-14-08, 05:46 PM
ork wr York wrote:
>> That they're only written for Windows XP doesn't mean that it stop working
>> as intended for newer versions of Windows.
>
> Wow, I had no idea. That's what I call foresight!
It has nothing to do with foresight, but rather how Microsoft decides to
keep features and to keep things unchanged for the sake of compatibility.
> I was wondering if you also could request the authors of the programs to add
> a note to their respective website stating that the script/configuration is
> Vista compatible.
If one would be really thorough there had to be a warning to never ever use
Windows Vista because it's trivially insecure in any configuration.
Yvonne York
02-14-08, 06:35 PM
"Sebastian G." <seppi@seppig.de> wrote in message
news:61jumrF1vn1s8U3@mid.dfncis.de...
> ork wr York wrote:
>
>>> That they're only written for Windows XP doesn't mean that it stop
>>> working as intended for newer versions of Windows.
>>
>> Wow, I had no idea. That's what I call foresight!
>
> It has nothing to do with foresight, but rather how Microsoft decides to
> keep features and to keep things unchanged for the sake of compatibility.
Okay then. So the credit goes to Microsoft.
>> I was wondering if you also could request the authors of the programs to
>> add a note to their respective website stating that the
>> script/configuration is Vista compatible.
>
> If one would be really thorough there had to be a warning to never ever
> use Windows Vista because it's trivially insecure in any configuration.
You're sidetracking...oh well.
It doesn't take much effort following the herd...so far so good.
Yvonne York
02-16-08, 07:58 PM
"Yvonne York" <Yvonne@home.com> wrote in message
news:fp2e9p$gb7$1@aioe.org...
> "Sebastian G." <seppi@seppig.de> wrote in message
> news:61ijcoF1sgodnU2@mid.dfncis.de...
>> Yvonne York wrote:
>>
>>> Hiya,
>>> How can Vista (no router) be configured not to use TCP/IP as transport
>>> protocol for NetBIOS, SMB and RPC, thus leaving TCP/UDP ports
>>> 135,137-139 and 445 closed.
>>> The best to my understanding is that Seconfig and the application
>>> offered by http://www.ntsvcfg.de/ntsvcfg_eng.html work with WinXP only.
>>
>> That they're only written for Windows XP doesn't mean that it stop
>> working as intended for newer versions of Windows.
>
> Wow, I had no idea. That's what I call foresight! I'm going to utilize
> Seconfig on my Vista machine.
> Thank you very big, Sebastian :-)
>
> > In fact they included some changes to address Windows Server 2003 upon
> > my
>> request.
SG; The information you provided is wrong! SeconfigXP does *not* work with
Vista! And I believe that this may be the case with the ntsvcf program also.
Since the respective websites don't mention anything about Vista at all...I
should've known better, oh well.
Thanks for nothing and have a wonderful day.
Intuitive
02-18-08, 05:53 AM
Yvonne York wrote:
> Hiya,
> How can Vista (no router) be configured not to use TCP/IP as transport
> protocol for NetBIOS, SMB and RPC, thus leaving TCP/UDP ports
> 135,137-139 and 445 closed.
> The best to my understanding is that Seconfig and the application
> offered by http://www.ntsvcfg.de/ntsvcfg_eng.html work with WinXP only.
> TIA
>
>
Hi Yvonne,
Since the latest version of SMB (which used to use the NetBIOS ports)
has been replaced with CIFS (which uses TCP 445);
unbinding NetBIOS from TCP/IP will not close 445 down.
The new version of CIFS does not need NetBIOS, hence you can access UMB
shares by using the \\ipa.ddr.ess.poo
Only by removing 'File and Printer Sharing' can that be closed.
Yvonne York
02-19-08, 04:56 AM
"Intuitive" <jason_tomasi@hotmail.com> wrote in message
news:fpbo2e$buh$3@lust.ihug.co.nz...
> Yvonne York wrote:
>> Hiya,
>> How can Vista (no router) be configured not to use TCP/IP as transport
>> protocol for NetBIOS, SMB and RPC, thus leaving TCP/UDP ports 135,137-139
>> and 445 closed.
>> The best to my understanding is that Seconfig and the application offered
>> by http://www.ntsvcfg.de/ntsvcfg_eng.html work with WinXP only.
>> TIA
>>
>>
>
> Hi Yvonne,
>
> Since the latest version of SMB (which used to use the NetBIOS ports) has
> been replaced with CIFS (which uses TCP 445);
> unbinding NetBIOS from TCP/IP will not close 445 down.
>
> The new version of CIFS does not need NetBIOS, hence you can access UMB
> shares by using the \\ipa.ddr.ess.poo
>
> Only by removing 'File and Printer Sharing' can that be closed.
Thanks for response Jason.
BTW, Davies of Seconfig advised that a Vista compatible version is in the
making.
vBulletin® v3.7.3, Copyright ©2000-2008, Jelsoft Enterprises Ltd.