Port 443 is open

Discussion in 'Mac OS X Server, Xserve, and Networking' started by oldhifi, Apr 13, 2013.

  1. oldhifi macrumors 6502a

    oldhifi

    Joined:
    Jan 12, 2013
    Location:
    USA
    #1
    I went to shields up and port 443 is open, do I need to close it?
     
  2. justperry macrumors 604

    justperry

    Joined:
    Aug 10, 2007
    Location:
    In the core of a black hole.
    #2
    NO:

    HTTP Secure

     
  3. Superhai macrumors regular

    Superhai

    Joined:
    Apr 21, 2010
    #3
    It is for https web server, if you don't have one, you should terminate the application that uses it.
     
  4. justperry macrumors 604

    justperry

    Joined:
    Aug 10, 2007
    Location:
    In the core of a black hole.
    #4
    I think you are wrong here, any https in the URL Bar of a browser will use this port, if you deny it you can't connect to that site, for instance your Bank.
     
  5. Superhai macrumors regular

    Superhai

    Joined:
    Apr 21, 2010
    #5
    Your browser is not listening to port 443.
     
  6. SandboxGeneral Moderator

    SandboxGeneral

    Staff Member

    Joined:
    Sep 8, 2010
    Location:
    Virgo Supercluster
    #6
    Yes it is. Port 443 is used for all https sites. If you close it you will not be able to browse or otherwise connect to any secure websites or servers. 443 is the standard port that all web browsers use to establish SSL connections. That's where you get the encrypted end-to-end connection from your browser to a site like a bank. Non-encrypted sites use port 80 for regular http traffic.
     
  7. oldhifi thread starter macrumors 6502a

    oldhifi

    Joined:
    Jan 12, 2013
    Location:
    USA
  8. justperry macrumors 604

    justperry

    Joined:
    Aug 10, 2007
    Location:
    In the core of a black hole.
    #8
    If you read the link I provided in my initial post and read the quote you know you are wrong!
     
  9. Superhai macrumors regular

    Superhai

    Joined:
    Apr 21, 2010
    #9
    If you learn TCP/IP you know you are wrong. ;)

    A client (web browser) request a port from the "usually" OS own TCP stack, and in old days only ports from 1025 to around 5000 could be used, nowadays it gets port from 49152 to 65535. They are kept untill the connection closes. The client then contacts the server (https server) which obviously needs to be on a specified port on a specified ip-address (in this case 443) for the client to know who to contact. Now they have established a connection and the server sends whatever data the client wants (or doesn't wants). Then it is closed (there are stuff like keep-alive which reuses the same connection, but that is beyond this post)

    As the remote server never initiates a connection to the client, the client does not need to keep a port open.

    If you however run your own server, or use p2p software, or two-way communicating software (like skype or some kind of messenger) then you need a port open for listening so the remote party are able to initiate the connection.
     
  10. justperry macrumors 604

    justperry

    Joined:
    Aug 10, 2007
    Location:
    In the core of a black hole.
    #10
    You want proof, here it is, a little snitch deny connection on port 443, yahoo is https.
     

    Attached Files:

  11. Superhai macrumors regular

    Superhai

    Joined:
    Apr 21, 2010
    #11
    It proves what I am saying, and that you don't know what is asked in the first post. What little snitch is blocking is the outbound connection to the server on port 443 (i.e. the destination port). Not the port on the client side (source port). If you want to close port 443 on the client, https will still work just fine. Shields up is showing the open ports on the client.
     
  12. sjinsjca macrumors 68000

    sjinsjca

    Joined:
    Oct 30, 2008
    #12
    There is some serious misunderstanding going on here.

    You will be able to browse https sites, because your browser, inside the firewall, will initiate the conversation.

    What ShieldsUp seems to be saying is that it can see port 443 open from OUTSIDE your LAN.

    If you're not running a secure-web server or something of the sort on a machine on your LAN, that's odd. Close it, just for your peace of mind. If you find that breaks some application, then you can always open it again.
     
  13. oldhifi, Apr 13, 2013
    Last edited: Apr 13, 2013

    oldhifi thread starter macrumors 6502a

    oldhifi

    Joined:
    Jan 12, 2013
    Location:
    USA
    #13

    How do I close it? My computer setting is: DNS is off, NO sharing, firewall is ON
     
  14. oldhifi thread starter macrumors 6502a

    oldhifi

    Joined:
    Jan 12, 2013
    Location:
    USA
    #14
    I think I found it:
    on my Uverse firewall settings port 443 is open, this is a router/receiver for my 2nd TV :)
     
  15. thejadedmonkey macrumors 604

    thejadedmonkey

    Joined:
    May 28, 2005
    Location:
    Pa
    #15
    Why is your TV listening for a secure connection?
     
  16. Superhai macrumors regular

    Superhai

    Joined:
    Apr 21, 2010
    #16
    One common reason for 443 port is a web based control panel. Try to https:// and your assigned ip from outside.
     
  17. freejazz-man macrumors regular

    Joined:
    May 12, 2010
  18. Ap0ks macrumors 6502

    Joined:
    Aug 12, 2008
    Location:
    Cambridge, UK
    #18
    +1, good to know there are plenty of easy targets out there ;)

    As Superhai has said, I'd imagine your Uverse firewall has an "Allow remote management" option if you disable that it should stop listening on port 443.
     
  19. jtara macrumors 65816

    Joined:
    Mar 23, 2009
    #19
    I imagine this is open on your UVerse box so that if you suddenly get an urge to record some show, you can log-in from Starbucks and schedule the recording.

    Odd that they wouldn't do that with a website, and have the Uverse box talk to some web service (outbound, not inbound). (I don't have Uverse.)
     

Share This Page