Page 1 of 1

Does Opening A Port Open PC For Attack...? Advice Needed...

PostPosted: Sat Mar 26, 2011 6:34 pm
by ComfyGray
Hi All,

Right, I run the AWESOME Subsonic on Windows7, Comodo Firewall playing music through an LG Android phone on version 2.1

Set port forwarding on my router to 4040 and so far everything seems sweet.

But, if I test the port on ShieldUP! The report for my subsonic port of 4040 comes back with

Solicited TCP Packets: RECEIVED (FAILED) — As detailed in the port report below, one or more of your system's ports actively responded to our deliberate attempts to establish a connection. It is generally possible to increase your system's security by hiding it from the probes of potentially hostile hackers. Please see the details presented by the specific port links below, as well as the various resources on this site, and in our extremely helpful and active user community.



Unsolicited Packets: PASSED — No Internet packets of any sort were received from your system as a side-effect of our attempts to elicit some response from any of the ports listed above. Some questionable personal security systems expose their users by attempting to "counter-probe the prober", thus revealing themselves. But your system remained wisely silent. (Except for the fact that not all of its ports are completely stealthed as shown below.)



Ping Reply: RECEIVED (FAILED) — Your system REPLIED to our Ping (ICMP Echo) requests, making it visible on the Internet. Most personal firewalls can be configured to block, drop, and ignore such ping requests in order to better hide systems from hackers. This is highly recommended since "Ping" is among the oldest and most common methods used to locate systems prior to further exploitation.

Port
Status Protocol and Application

4040
OPEN! yo-main
Yo.net main service



Now then, firstly - what the heck is yo.net?

Secondly, does having port 4040 forwarded like this mean I now have an open port screaming out for attacks as I would have expected that the port would only be open to Subsonic but it seems it is failing security tests and is leaving my PC vunerable?

any advice whatso ever would be greatly appreciated as I am rubbish with routers, ports and things like that.

Much thanks.
Comfy

PostPosted: Sat Mar 26, 2011 10:48 pm
by GJ51
It has to be open for SS to function outside your network and be accessible over internet. The router specifies that traffic for 4040 gets sent to the system that hosts SS where it recieves the data request and initiates the logon protocol. The only thing open to attack is the logon screen. Theoretically, a brute force attack on the admin password should be sufficient for someone to logon and play your tunes. A strong admin password should maske it take a few days with a Cray 9000 running a cracker. That's what I'd do with a Cray 9000 if I had one. You know, go around hacking into Subsonic sites so I could listen to other peoples music. Yes, a very productive use of my time and resources indeed. :wink:

Now what was your IP address again...