Re: blocking remote telnet
hs-Jsmql6Mm5bsaF16iPYe0/[email protected] Fri, 15 Jun 2007 12:00:48 +0200
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <[email protected]> |
Hi Jim, maybe a local signed on user which does a telnet to 127.0.0.1 (localhost)? -h -----Ursprüngliche Nachricht----- Von: Jim Franz [mailto:franz400-goaWJWIt5zpWk0Htik3J/[email protected]] Gesendet: Mittwoch, 6. Juni 2007 04:54 An: security400-Zwy7GipZuJhWk0Htik3J/[email protected] Betreff: [Security400] blocking remote telnet Customer's network admin swears firewall blocks port 23 (telnet, both tcp&udp). I tested remotely from windows, and telnet appears blocked. But I have a couple pages of someone remotely trying to guess a password for "root" and "admin" with existing virtual device names like qpadev0001. My TCP Service table says telnet is 23. No ssl configured, but telnet-ssl is port 992. Is there another service or port to block ??? Netstat is showing several services listening that I don't recognize. Any reference to all the services and what starts them? jim franz _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.