This is a read-only archive. No new posts or registrations. Privacy Page
Software

Open Telnet port 23

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am using Outpost Firewall Pro.
Telent service is disabled.
I have scanned PC with PCFlank, GRC and Sygate and all found open Telnet port 23 as dangerous and visible to others on the Internet.
“Open ports are dangerous because they're an easy and attractive means of entry for hackers” – Sygate.
Experts in computer security, such as SANS Institute, recommend that the use of Telnet for remote logins should be discontinued under all normal circumstances, for the following reasons:
• Telnet, by default, does not encrypt any data sent over the connection (including passwords), and so it is often practical to eavesdrop on the communications and use the password later for malicious purposes; anybody who has access to a router, switch, hub or gateway located on the network between the two hosts where Telnet is being used can intercept the packets passing by and obtain login and password information (and whatever else is typed) with any of several common utilities like tcpdump and Wireshark.
• Most implementations of Telnet have no authentication that would ensure communication is carried out between the two desired hosts and not intercepted in the middle.
• Commonly used Telnet daemons have several vulnerabilities discovered over the years.
With netstat -a –n can’t see open port 23.
When I manually close this port can’t run Internet.

Is it false positive open port report or I have to better set firewall?

arTech
Unless you're running a server, your computer won't be using Telnet. It usually isn't a service that's installed anyway, so it's nothing to worry about. If you are still worried about it, you can add a new rule to the Windows Firewall. 1. Go to your Start Menu and click Control Panel, 2. Go to the Security Center and then click Windows Firewall 3. Go to the Exceptions tab. 4. Click "add port". 5. Add in the description, put in the following IP address : 127.0.0.1 (this is the Local address) and put the number "23" in both External Port and Internal Port boxes. Choose TCP. 6. Repeat step 5 but choose UDP at the end instead.
I agree, my computer won't be using Telnet, but why is port 23 open when somebody watching my computer from outside?
Ok never mind.

I agree, it will be enough to set Windows Firewall, because I definitely don't know to set Outpost to block port 23. Outpost has nice feature that it runs with other firewall, no conflicts with AV and anti-spyware programs, no conflicts at all.

I have questions:

Step 3. This is Exceptions tab where I can add ports which Firewall will not control? There I read "Windows Firewall is blocking incoming network connection, except for the programs and services selected below. Adding exceptions allow some programs to work better but might increase your security risk".

Step 5. On Add a Port tab I read "Use these settings to open port through Windows Firewall. To find the port number …"?

Is it oppositely that I want?

arTech
Hmm, yes. Doesn't it have a "block" port feature? It's been a while since I've used XP. The new Windows Firewall with Vista/7 allows you to actively block ports, as well as open them. It might be worth looking through the current list to see if Port 23 is open already. If there is an exception for Port 23, then just delete it. Windows Firewall should then block all communication on Port 23.
Unfortunately XP Firewall haven't a "block" port settings. Exception list is empty. Today I activate Windows Firewall, and I already have Outpost Firewall. Perhaps it will be enough, although Sygate show open port 23. arTech
This is a report:

Success: I can see your service on 1xx.1xx.xx.xx on port (23) <– Edited for User Privacy. By Doug
Your ISP is not blocking port 23.

I tried to find process which open port 23 with netstat, TCPView, CurrPorts and Process Explorer. Nothing.

but may be

I have a ADSL connection via router so my computer can share internet with the son's desktop. So open port 23 would be on the router, not on the PC?

arTech
Finally
I found Planet router data sheet.
"Remote management allows you to determine which services/protocols can access to ADE-4400 interface from which computers. You can configure the router for remote Telnet access or upload and download router firmware and configuration files using FTP".
With Internet provider permission and instruction I configured Access Status from All to Disable.
That's it.

Nahumi thank you very much. It is easier when you talking with somebody who want to help and have different idea. It is interesting for me that Outpost firewall can run with Windows firewall. Long time ago I have used Zone Alarm firewall and it automatically turned off Windows firewall.

and just one more thing

"For more and more important security issue, this product serves as an Internet firewall, protecting your network from being accessed by outside users. Not only provides the natural firewall function, it also provides rich firewall features to secure user’s network. All incoming data packets are monitored and filtered. Besides, it can be configured to block internal users from accessing to the Internet". - Planet router.

Now I have 3 firewalls :)

arTech
Good job arTech. ^_^

I usually find that a router's firewall in conjunction with Windows Firewall is more than enough.

In terms of protection, having an AV scanner that scans everything in realtime, something like Avast! 5, is more important these days.

Anyway, good job in figuring it out.

Cheers,
Nahumi
Good Work people! arTech, I edited your IP address in post #7 to conceal it for your privacy. Spam-bots scan and scrape Forum sites, possibly leading to unwanted SPAM coming to your address. I don't think it is a good thing to post a machine's actual IP, even though it is trivial for a hacker to discover if they are determined to do so. You can edit it back to display your IP information, if you wish, but I don't advise it. Doug
Wisely Doug, thanks 78 people (- 2 Nahumi and Doug) are saw my actual IP address until now. What actual IP address show except location? What is the interest somebody to send SPAM? Are there some risk except disturbing? Unfortunately discovering IP address is really trivial for a hacker (WTT *7.2**.**4.*5*). arTech

Are there some risk except disturbing?


Mostly SPAM is just annoying.

But the bot-nets that scavenge websites tend to collaborate (sell their information to each other)
Eventually, much/most of a person's personally identifying information can be pasted together.

Some folks will naively state: "I don't care about what they find out… I don't have anything to hide."

To me, that statement misses the point.

Identity thieves and other bad-guys realize that any one individual is unlikely to have much in the way of resources worth the effort of trying to exploit.
Their profit is in larger numbers.

Sure, they will attempt social engineering phishing against people on their SPAM lists.

But worse (in my opinion) is using an innocent individual's IP or even their ISP and machine directly to propagate sale of stolen credit cards or porn, or some such thing.

The bad-guy will then vanish after the first few rounds of profit taking, but they leave behind a trail of addresses that they used to sell their stolen or contraband stuff.
And those addresses, could lead the authorities to believe that you and other innocents were the ones perpetrating the scam.

That might only be annoying, while the authorities sorted things out.
But again worse, is that by allowing your email, IP, or other identifying information to be available, innocent people actually make it easier for the bad-guys to hide themselves behind zombie machines or spoofed addresses to carry out their illegal activity.

Therefore, we at WTT Forums make every effort to assist and make sure that Member information is not unnecessarily exposed.

The above is my opinion.

Doug
This sound seriously. My Post #7 is inconsistently with my opinion and ambition to act preventive. This Topic "Open Telnet port 23" show my point of view. Insignificant number of people attend about these details. And what happened. I was indiscreet for a moment (partly because this forum has nice rules and nice public). I worry now. It is a just one number and one moment. Is it enough for severe scenario? I don't need answer. I have to watch carefully and close security holes. arTech
These guys are like any other mugger/home-invasion burgler…. They tend to opportunistically attack those who appear to be easy pickings. No sense in leaving something like an IP or email address laying around where scan-bots regularly browse. WTT welcomes many legitimate search indexing bots. They help us get our Forum solutions listed in the search engines, so that other readers/researchers can benefit. At the same time, we work hard to prevent malicious bots and other scammers from posting and gaining access here at WTT. You've done nothing wrong, and it would be highly unlikely that any harm might result to you, because your IP was published only for a very brief period of time before edited. Leaving it published for an indefinite period of time, might be another story. My action and my comments are meant only as informative and as a courtesy to you and other member/readers.
Observation

My ISP said:
1. It is dynamic IP address of router which changes from time to time.
2. We can’t to hide IP address.
3. It is NAT (Network Address Translation) router which act as hardware firewall.

I said:
1. Discovering of IP address is really trivial as I showed on WTT forum IP address sample.

Gibson Research Corporation said:
1. NAT performed by the router allows multiple computers (machines) connected to the LAN behind the router to communicate with the external Internet.
2. One of the key benefits of NAT routers is that the router appears to the Internet as a single machine with a single IP address. This effectively masks the fact that many computers on the LAN side of the router may be simultaneously sharing that single IP.
3. All NAT routers inherently function as very effective hardware firewalls. As a hardware firewall they prevent "unsolicited", unexpected, unwanted, and potentially annoying or dangerous traffic from the public Internet from passing through the router and entering the user's private LAN network.
4. Since the NAT router links the internal private network to the Internet, it sees everything sent out to the Internet by the computers on the LAN. It memorizes each outgoing packet's destination IP and port number in an internal "connections" table and assigns the packet its own IP and one of its own ports for accepting the return traffic. Finally, it records this information, along with the IP address of the internal machine on the LAN that sent the outgoing packet, in a "current connections" table. When any incoming packets arrive at the router from the Internet, the router scans its "current connections" table to see whether this data is expected by looking for the remote IP and port number in the current connections table. If a match is found, the table entry also tells the router which computer in the private LAN is expecting to receive the incoming traffic from that remote address. So the router re-addresses (translates) the packet to that internal machine and sends it into the LAN. If the arriving packet does not exactly match traffic that is currently expected by the router, the router figures that it's just unwanted "Internet noise" and discards the unsolicited packet of data.

Now relly good part for our members:
With a NAT router protecting your connection to the Internet — even if you only have one computer on the LAN behind the router — none of the Internet scanning and worms and hackers and other annoying and malicious Internet nonsense can get to your computer.

arTech

PS …mugger/home-invasion burgler… is as you said grrrrwergnwrgng to me.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI