LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-15-2024, 03:01 PM   #1
Jason.nix
Member
 
Registered: Feb 2023
Posts: 563

Rep: Reputation: 10
Post Why should all ports be closed?


Hello,
Usually, when configuring the firewall, only the ports on which a service is running are left open and the rest of the ports are closed. For example, they open ports 80 and 443 for Apache and close the other ports.
When a service is not running on a port, why should that port be closed?

Thank you.
 
Old 02-15-2024, 04:51 PM   #2
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,667

Rep: Reputation: 2710Reputation: 2710Reputation: 2710Reputation: 2710Reputation: 2710Reputation: 2710Reputation: 2710Reputation: 2710Reputation: 2710Reputation: 2710Reputation: 2710
So that if something misbehaves, or malware gets past and wants to open a port, you are still protected.


Being "still protected" is the entire point of having a firewall!
 
1 members found this post helpful.
Old 02-15-2024, 07:35 PM   #3
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,670
Blog Entries: 4

Rep: Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945
This is sort of like the "Principle of Least Privilege." Basically: computers are really awful at knowing when to say "yes," but terrific at saying "no!"

Start by locking every single one of the gates that lead into the pastures where your prize horses are being kept. Then, very-specifically unlock only the handful of gates which must be open, always knowing precisely why you did so.

Also(!) explore additional technologies such as OpenVPN, which you can use to create a "moat" around your entire installation.

Last edited by sundialsvcs; 02-15-2024 at 07:37 PM.
 
Old 02-15-2024, 07:39 PM   #4
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 11,237

Rep: Reputation: 5321Reputation: 5321Reputation: 5321Reputation: 5321Reputation: 5321Reputation: 5321Reputation: 5321Reputation: 5321Reputation: 5321Reputation: 5321Reputation: 5321
Quote:
Originally Posted by wpeckham View Post
So that if something misbehaves, or malware gets past and wants to open a port, you are still protected
Thinking of the time I illegally torrented Windows software and ran it, then later found that my computer was running a TinyFTP server. Good thing the FTP port was closed.

And if you want to judge me for my bad judgement: it was how we lived those days.
 
Old 02-16-2024, 03:52 AM   #5
GazL
LQ Veteran
 
Registered: May 2008
Posts: 6,901

Rep: Reputation: 5025Reputation: 5025Reputation: 5025Reputation: 5025Reputation: 5025Reputation: 5025Reputation: 5025Reputation: 5025Reputation: 5025Reputation: 5025Reputation: 5025
It's a "belt and braces approach": not strictly necessary but reduces the chance of getting caught with your pants down.
 
2 members found this post helpful.
Old 02-16-2024, 11:00 AM   #6
Jason.nix
Member
 
Registered: Feb 2023
Posts: 563

Original Poster
Rep: Reputation: 10
Quote:
Originally Posted by dugan View Post
Thinking of the time I illegally torrented Windows software and ran it, then later found that my computer was running a TinyFTP server. Good thing the FTP port was closed.

And if you want to judge me for my bad judgement: it was how we lived those days.
Hello,
Thank you so much for your reply.
Are you saying that a malware has installed TinyFTP on your system via torrent?
 
Old 02-17-2024, 12:37 AM   #7
Michael Uplawski
Senior Member
 
Registered: Dec 2015
Posts: 1,622
Blog Entries: 40

Rep: Reputation: Disabled
Quote:
Originally Posted by Jason.nix View Post
Hello,
Are you saying that a malware has installed TinyFTP on your system via torrent?
No. It means that, if you have all in your head you do not need a computer in the first place.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Why when I scan the ports of a specific IP using Nmap? It gives me "all ports are filtered." Munir san Linux - Newbie 5 11-20-2017 05:40 PM
Should I be paranoid about having suspicious ports on Nmap...that are closed? Mohtek Linux - Security 1 01-30-2008 07:39 AM
ports, ports, ports cjae Linux - Networking 1 04-09-2006 09:38 AM
How do i insure that all ports are closed except 80 and 22 adamrau Linux - Security 1 09-28-2001 09:32 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration