Commonly Probed Ports
In this section, I will list ports that are commonly probed and attacked. Blocking these ports is a minimum requirement for perimeter security, not a comprehensive firewall specification list. A far better rule is to block all unused ports. A good rule in security is to adhere to the principle of least privilege for all entities in your network. This includes users and systems. The principle of least privilege says to give an entity the least amount of access needed to perform its job and nothing else. If a port is not actively being used, it should be closed.
Even if you believe these ports are blocked, you should still actively monitor them to detect intrusion attempts. Remember, a common way for attackers to create backdoors ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access