Security Basics
RCP open! Yikes! What to do? Sep 18 2013 06:14PM
ToddAndMargo (ToddAndMargo zoho com) (1 replies)
Hi All,

How do I close MSRPC (remote proceedure call) ports
Om Windows 7? These a Remote Procediure Call (RPC),
which to me means ports and services for bad guys to
use. Open RPC scare me.

The is Kaspersky End Point Security
with its firewall activated on Windows 7, 64 bit.

This Windows macine a Virtual Machine (KVM) sitting on
the RHEL host's local network. nmap was run from the host:

Many thanks,

# nmap --reason

Starting Nmap 6.25 ( ) at 2013-09-16 19:42 PDT
Nmap scan report for (
Host is up, received arp-response (0.00044s latency).
Not shown: 989 closed ports
Reason: 989 resets

135/tcp open msrpc syn-ack
139/tcp open netbios-ssn syn-ack
445/tcp open microsoft-ds syn-ack
1110/tcp filtered nfsd-status no-response
5357/tcp open wsdapi syn-ack
49152/tcp open unknown syn-ack
49153/tcp open unknown syn-ack
49154/tcp open unknown syn-ack
49155/tcp open unknown syn-ack
49156/tcp open unknown syn-ack
49157/tcp open unknown syn-ack

The high ports are msrps ports:


Port Serv Process name
49152, msrpc [wininit.exe]
49153, msrpc [svchost.exe, Eventlog]
49154, msrpc [svchost.exe, Schedule]
49155, msrpc [lsass.exe]
49157, msrpc [services.exe]
49159, msrpc [svchost.exe, PolicyAgent]

Computers are like air conditioners.
They malfunction when you open windows


Re: RCP open! Yikes! What to do? Sep 19 2013 08:07AM
Ansgar Wiechers (bugtraq planetcobalt net)


