3 ms·
Redhat used to ship running pop2, pop3 and imapd running by default, all open. Windows was SO exploitable that ISPs to this day block 137-139 and 445 just so pe
by IcePic 6y ago
Redhat used to ship running pop2, pop3 and imapd running by default, all open. Windows was SO exploitable that ISPs to this day block 137-139 and 445 just so people do not get hacked immediately.
Par for the course was to get owned within hours (or minutes) if you were on the net, that was the context where not-getting-random-remote-admins was a differentiating factor.
- staticassertion 6y agoSure, of course. I'm talking within last decade.
- IcePic 6y agoWell, do ISPs suddenly allow 137-139,445 nowadays or is this still considered to be a hole wide enough for a truck to drive through? If those are still blocked, then the major OS in this world still proves that there are bad defaults and good defaults, one which leads to compromise and one that leaves you secure until you screw up in some other way. If other OSes have "caught up" with not starting and exposing lots of random* daemons just because they exist on disk on a default install, then that is for the better of the world. That doesn't take away the idea that some OSs did it long before others, and hence have given their users a safer experience for a longer time. *) random in the sense that "running a pop2 daemon when your box wasn't even intended to be a mail server" is beyond silly. Same for httpd, ftpd, ntpd-claiming-to-be-stratum-1-on-motherboard-clock (happened) and all other services a full default installation might provide.
- flomo 6y ago137-139 was originally about the old lanman broadcast stuff more than "security". They did not want your "network neighborhood" to be populated with your actual neighbors because that's creepy. I assume MS fixed this at some point, and I also assume ISPs will never change this.