Showing posts with label social networking. Show all posts
Showing posts with label social networking. Show all posts

Thursday, July 21, 2016

Port Assignments for Commonly-Used Services

Port Assignments for Commonly-Used Services

There are many services associated with the Windows 2000 operating system. These services might require more than one TCP or UDP port for the service to be functional. Table C.3 shows the default ports that are used by each service mentioned.
Table C.3 Default Port Assignments for Common Services
Service Name
UDP
TCP
Browsing datagram responses of NetBIOS over TCP/IP
138

Browsing requests of NetBIOS over TCP/IP
137

Client/Server Communication

135
Common Internet File System (CIFS)
445
139, 445
Content Replication Service

560
Cybercash Administration

8001
Cybercash Coin Gateway

8002
Cybercash Credit Gateway

8000
DCOM (SCM uses udp/tcp to dynamically assign ports for DCOM)
135
135
DHCP client

67
DHCP server

68
DHCP Manager

135
DNS Administration

139
DNS client to server lookup (varies)
53
53
Exchange Server 5.0


   Client Server Communication

   135
   Exchange Administrator

   135
   IMAP

   143
   IMAP (SSL)

   993
   LDAP

   389
   LDAP (SSL)

   636
   MTA - X.400 over TCP/IP

   102
   POP3

   110
   POP3 (SSL)

   995
   RPC

   135
   SMTP

   25
   NNTP

   119
   NNTP (SSL)

   563
File shares name lookup
137

File shares session

139
FTP

21
FTP-data

20
HTTP

80
HTTP-Secure Sockets Layer (SSL)

443
Internet Information Services (IIS)

80
IMAP

143
IMAP (SSL)

993
IKE (For more information, see Table C.4)
500

IPSec Authentication Header (AH) (For more information, see Table C.4)

IPSec Encapsulation Security Payload (ESP) (For more information, see Table C.4)


IRC

531
ISPMOD (SBS 2nd tier DNS registration wizard)

1234
Kerberos de-multiplexer

2053
Kerberos klogin
543
Kerberos kpasswd (v5)
464
464
Kerberos krb5
88
88
Kerberos kshell

544
L2TP
1701

LDAP

389
LDAP (SSL)

636
Login Sequence
137, 138
139
Macintosh, File Services (AFP/IP)

548
Membership DPA

568
Membership MSN

569
Microsoft Chat client to server

6667
Microsoft Chat server to server

6665
Microsoft Message Queue Server
1801
1801
Microsoft Message Queue Server
3527
135, 2101
Microsoft Message Queue Server

2103, 2105
MTA - X.400 over TCP/IP

102
NetBT datagrams
138

NetBT name lookups
137

NetBT service sessions

139
NetLogon
138

NetMeeting Audio Call Control

1731
NetMeeting H.323 call setup

1720
NetMeeting H.323 streaming RTP over UDP
Dynamic

NetMeeting Internet Locator Server ILS

389
NetMeeting RTP audio stream
Dynamic

NetMeeting T.120

1503
NetMeeting User Location Service

522
NetMeeting user location service ULS

522
Network Load Balancing
2504

NNTP

119
NNTP (SSL)

563
Outlook (see for ports)


Pass Through Verification
137, 138
139
POP3

110
POP3 (SSL)

995
PPTP control

1723
PPTP data (see Table C.4)


Printer sharing name lookup
137

Printer sharing session

139
Radius accounting (Routing and Remote Access)
1646 or 1813

Radius authentication (Routing and Remote Access)
1645 or 1812

Remote Install TFTP

69
RPC client fixed port session queries

1500
RPC client using a fixed port session replication

2500
RPC session ports

Dynamic
RPC user manager, service manager, port mapper

135
SCM used by DCOM
135
135
SMTP

25
SNMP
161

SNMP Trap
162

SQL Named Pipes encryption over other protocols name lookup
137

SQL RPC encryption over other protocols name lookup
137

SQL session

139
SQL session

1433
SQL session

1024 - 5000
SQL session mapper

135
SQL TCP client name lookup
53
53
Telnet

23
Terminal Server

3389
UNIX Printing

515
WINS Manager

135
WINS NetBios over TCP/IP name service
137

WINS Proxy
137

WINS Registration

137
WINS Replication

42
X400

102



- wong chee tat :)

Wednesday, July 20, 2016

National Cybercrime Action Plan to step up fight against online crime: Shanmugam

National Cybercrime Action Plan to step up fight against online crime: Shanmugam
By Kimberly Spykerman, News 5  Posted 20 Jul 2016 18:41 Updated 20 Jul 2016 22:57

SINGAPORE: Singapore will do more in the battle against online crime through a National Cybercrime Action Plan, Home Affairs Minister and Law Minister K Shanmugam announced on Wednesday (Jul 20).

Speaking at a conference, Mr Shanmugam pointed out that the plan signifies a fundamental relook at the way cybercrime is tackled, and recognised the sea change cybercrime will bring about in society.

"Cybercrime is seen, and rightly identified, as a growing threat. It doesn't recognise national boundaries. They hide behind, they are in the shadows, and they strike. And the scale and the speed with which they can strike is such that it can cause tremendous damage," he said.

Cybercrimes around the world have been increasing, he added.

Mr Shanmugam also pointed out that cyberspace is changing the complexion of crimes all over the world. In the UK, the number of crimes that involved a computer exceeded physical crimes in 2015. In the same year in Singapore, the number of cases under the Computer Misuse and Cybersecurity Act increased by more than 40 per cent compared to 2014.

FOUR KEY PRIORITIES FOR FOUR KEY PRINCIPLES

Singapore will do its part through its action plan that is underpinned by four key principles - prevention, a quick, strong response to incidents of cybercrime, effective laws and close partnerships.

These will translate to four key priorities in the action plan, said Mr Shanmugam.

The first priority is to educate and empower the public to stay safe in cyberspace.

Prevention is key, said Mr Shanmugam, citing the police’s efforts to educate the public through ads, Crimewatch broadcasts, social media and other outreach avenues.

There will also be a special focus on vulnerable groups like the elderly and children. In this area, the police will work with schools and NGOs to raise awareness among these groups.

The police will also transform its existing Scam Alert website into a one-stop self-help portal, where people can get information on the latest modus operandi of cybercriminals, hear from other people’s experiences and report cases.

Secondly, authorities will enhance capabilities to fight cybercrime.

Mr Shanmugam noted that a Cybercrime Command was established in December 2015. It will carry out tasks such as analysing new methods used by cybercriminals, which can then be used to shape crime prevention messages.

The Home Affairs Ministry will also expand the curriculum of the Cyber Security Lab - which is a hands-on training facility - to cover topics like cyber-security fundamentals, digital forensics and malware analysis.

Third, laws will be strengthened to respond to the transnational nature of cybercrimes and the evolving tactics of such criminals. He added that existing laws will be looked at, to ensure they remain relevant even as traditional crimes shift online.

"What happens in the real world will have to be replicated in the virtual world. And we have to develop the tools to make sure they're updated for that," said Mr Shanmugam.

Lastly, local and international partnerships will be established.

Singapore has worked with the Chinese authorities to bust a spate of credit-for-sex scams and plans to support fellow ASEAN member states in developing cybercrime capabilities. An Institute of Safety and Security Studies - where ASEAN member states can also get training - has been established here.

Singapore is also home to Interpol's Global Complex for Innovation, which has a strong focus on cybercrime.

Mr Shanmugam emphasised that the Government will work closely with partners across all sectors to share knowledge and expertise, as well as to build capability.

Singapore, he added, is committed to supporting the global fight against cybercrime, and can contribute in the area of capability development - both regionally and internationally.

"COORDINATED APPROACH IS KEY"

Separately, Interpol chief Jurgen Stock said Singapore - as a hyper-connected, well-developed country - provides opportunities for cybercriminals. He added that mobile devices are set to become bigger targets, with more people using them to carry out important tasks such as banking transactions.

Mr Stock, who is the secretary-general of Interpol, said that is why having a coordinated approach is key to deterring cybercriminals.

"I think Singapore, with a new plan, provides a lot of measures to protect the system," he said. "And this is so important, and we have to understand that we have to build strong partnerships."

"The public has to play its role in protecting their own systems. So we all have to be aware of the way we use our smartphones, the way we use our computers. And we have to protect our critical infrastructure and our societies, and that is a huge task also for the lawmakers," he added.

- CNA/dl


- wong chee tat :)

List of Well-Known Ports

List of Well-Known Ports

Port numbers range from 0 to 65536, but only port numbers 0 to 1024 are reserved for privileged services and designated as well-known ports. This list of well-known port numbers specifies the port used by the server process as its contact port.

Port Number

Description

1TCP Port Service Multiplexer (TCPMUX)
5Remote Job Entry (RJE)
7ECHO
18Message Send Protocol (MSP)
20FTP -- Data
21FTP -- Control
22SSH Remote Login Protocol
23Telnet
25Simple Mail Transfer Protocol (SMTP)
29MSG ICP
37Time
42Host Name Server (Nameserv)
43WhoIs
49Login Host Protocol (Login)
53Domain Name System (DNS)
69Trivial File Transfer Protocol (TFTP)
70Gopher Services
79Finger
80HTTP
103X.400 Standard
108SNA Gateway Access Server
109POP2
110POP3
115Simple File Transfer Protocol (SFTP)
118SQL Services
119Newsgroup (NNTP)
137NetBIOS Name Service
139NetBIOS Datagram Service
143Interim Mail Access Protocol (IMAP)
150NetBIOS Session Service
156SQL Server
161SNMP
179Border Gateway Protocol (BGP)
190Gateway Access Control Protocol (GACP)
194Internet Relay Chat (IRC)
197Directory Location Service (DLS)
389Lightweight Directory Access Protocol (LDAP)
396Novell Netware over IP
443HTTPS
444Simple Network Paging Protocol (SNPP)
445Microsoft-DS
458Apple QuickTime
546DHCP Client
547DHCP Server
563SNEWS
569MSN
1080Socks



- wong chee tat :)

Tuesday, July 19, 2016

Spike in number of phone scam calls impersonating OCBC over past few weeks

Spike in number of phone scam calls impersonating OCBC over past few weeks
Posted 18 Jul 2016 13:24 Updated 18 Jul 2016 13:30

SINGAPORE: A spike in the number of phone scams where OCBC Bank is being impersonated has been observed over the past few weeks, the bank said.

In a media release on Friday (Jul 15), OCBC said it is aware of the scams and has provided additional training to frontline staff on this matter.

According to OCBC, individuals - customers and the general public - typically receive an automated voice call prompting a response. “These calls have impersonated courier companies and in an evolving modus operandi, have also claimed to be from banks including OCBC,” the media release said.

The bank also said the caller’s number is either a truncated 6 to 7 digit number that looks like it is originating from outside Singapore, a private number (no caller ID shown), or in some cases, may even appear as OCBC’s official contact number (+6563633333) or some variation of it (e.g. 06563633333).

Individuals would be transferred to a Mandarin-speaking person with a non-local accent, should they follow the instruction to key in a number, the bank said. This person would ask for the individual’s personal or banking information including:

Name & NRIC
Contact details
Account number
Account balance
Credit card number and the 3-digit CVV number found on the back of the card
Serial number of hardware token in cases involving installation of certain mobile applications
To assess whether the calls are legitimate, OCBC said the bank does not initiate automated voice calls that require an interactive response.

“When initiating communications with customers and members of the public, OCBC adopts English as it is the primary business language and the most widely understood language in Singapore,” it said. “OCBC representatives will typically switch to another language only if the customer has shown or indicated a preference for a language other than English.”

The bank also said while staff may pose questions to customers to verify their identity, questions related to security information such as PIN number, token number, credit card CVV number and account numbers would never be asked.

It added: “OCBC will not request the customer to make any funds transfer to another bank account. All funds transfers are initiated by customers.”

If customers or members of the public are in doubt about the authenticity of the caller or phone call, they are advised to terminate the call and contact the bank at 1800 363 3333 (+65 6363 3333 if overseas) to verify, OCBC said.

- CNA/xk

- wong chee tat :)