• November 01, 2024, 08:39:17 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Security scan fails w/ TFTP Server open - how to close??  (Read 7051 times)

nynyny2

  • Level 1 Member
  • *
  • Posts: 9
Security scan fails w/ TFTP Server open - how to close??
« on: March 18, 2013, 08:02:55 AM »

Recently had an external security scan done on my DIR 655 and scan results are stating I have an accessible TFTP Server running.   ???

I've been through all the settings, and even upgraded to the latest firmware. Yet security scans are telling me I've got a TFTP Server running. Why would one be showing on the external interface, and how can I stop it?
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Security scan fails w/ TFTP Server open - how to close??
« Reply #1 on: March 18, 2013, 08:18:32 AM »

What security scans are you running? Are these 3rd party programs or a web site?

Link>What Firmware version is currently loaded? Found on routers web page under status.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

nynyny2

  • Level 1 Member
  • *
  • Posts: 9
Re: Security scan fails w/ TFTP Server open - how to close??
« Reply #2 on: March 18, 2013, 08:37:07 AM »

Hardware Version: B1      Firmware Version: 2.10NA

External vendor (similar to SecurityMetrics, but not them). They're saying PORT 69 TFTP SERVER is running and directory traversal can occur.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Security scan fails w/ TFTP Server open - how to close??
« Reply #3 on: March 18, 2013, 08:38:48 AM »

What do other sites report? Not all sites report the same and could lead to false positives.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

nynyny2

  • Level 1 Member
  • *
  • Posts: 9
Re: Security scan fails w/ TFTP Server open - how to close??
« Reply #4 on: March 18, 2013, 08:41:16 AM »

Some free web-based services didn't report any ports open. But then I'm not sure how reliable they are.

If there's a device (like Ooma) running a TFTP server, would that cause the router to automatically open port 69 on the router? If yes, how can I tell what device is causing it to listen on port 69?
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Security scan fails w/ TFTP Server open - how to close??
« Reply #5 on: March 18, 2013, 08:45:21 AM »

You might install wireshark on your PC then do a capture and look for anything regarding the OOMA on the IP address it's assigned.

I would try different web sites to see. I trust Gibson Research as one site.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

nynyny2

  • Level 1 Member
  • *
  • Posts: 9
Re: Security scan fails w/ TFTP Server open - how to close??
« Reply #6 on: March 18, 2013, 09:11:14 AM »

GRC reports nothing open, and an external online scanner using NMAP shows nothing as well.

But can you answer this; if a TFTP Server was running internally, does it automatically open port 69? I can't see why it would do this, or how (since it's just listening).
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Security scan fails w/ TFTP Server open - how to close??
« Reply #7 on: March 18, 2013, 09:16:32 AM »

http://en.wikipedia.org/wiki/Trivial_File_Transfer_Protocol seems to use port 69.

You might run a scan test with and with out any other devices connected to the router to see if you get the same results.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.