Hi,
 
In a LAN these services and ports are most of the time available. In DMZ zones, the security will be more hardened and you probably will have disabled these services mostly...
 
It's normal that MBSA need these things, it will look at file versions, check registry (if you install hotfixes, they have always a registry key(s)), etc.
 
So if working in a LAN nicely protected by firewall etc., you normally haven't disabled these services and you wouldn't have any issue with remote scanning. If you do have these kind of security measurements implemented and you don't want to change them, you can alternatively write for example a little script to execute on the remote computers/servers (locally ofcourse) that checks the installed hotfixes by looking up their registry keys.... Depends what you need of information and the environment working in.
 
Hope this helps you a very little bit ;-)
 
Rgds,
B
-----Original Message-----
From: Douglas M. Long [mailto:[EMAIL PROTECTED]
Sent: Thursday, March 3, 2005 02:23 PM
To: [email protected]
Subject: [ActiveDir] OT: MBSA

I am reading that remote scans using MBSA require TCP ports 139 and 445 and UDP ports 137 and 138 to be open and Server service, Remote Registry service, and File & Print Sharing must be running.

Aren?t these about the worst ports you could leave open on? Not the best services to be open on a desktop either, are they?

It would be easy enough to open the ports and start the services via group policy, but do I really want to. What are your thoughts? How do you guys do it?

Reply via email to