Aug 302012
 

I wrote to Comhem yesterday, asking them to stop blocking outbound connections to TCP 25. I also asked them if they are blocking more ports. This interferes when I perform pen.tests, but also forces me to change SMTP in my phone every time I leave my home. It further prevents me from connecting directly to my co-located SMTP server. Luckily I also have a VPN to that server that allows me to connect to it.

Their response was quite unexpected and extremely dis-satisfactory.

1. They can’t open ports for one specific customer – Erhm, NO, you are just too lazy

2. They listed all the other ports they are blocking. Random idiotic ports that are blocked for no reason. Why the hell should they decide if I want to use 12345 or 31337? I actually understand now why my Meterpreter daemons sometimes doesn’t get a return connection. Comhem idiots!

135-139TCP
135UDP
445TCP+UDP
593TCP+UDP
12345TCP
31337UDP
25 TCP
This is the complete list of ports they are blocking according to themselves.