Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Check Which Programs on Your Own Laptop Are Listening on the Network and Turn On the Built-in Firewall

Beginner35 minCommand Prompt or Terminal · Windows Security / macOS Firewall

Course: Cyber Security · Chapter 2: Ports and Protocols: SSH, HTTP, HTTPS, FTP/SFTP and DNS

Chapter 2 explains ports; this lab looks at the ports of your own laptop.

Chala mitrano! In Chapter 2 we learnt that a port is like a numbered door on a computer. Today we look at the doors of our own laptop: which programs are waiting at a door for someone to knock, and is the security guard (the firewall) awake? Only our own laptop, only looking and switching on protection. Ekdum simple aahe.

Suppose we are…

Suppose we have just joined Wipro as a fresher and we work from home two days a week. Some days we sit in a café and use its free Wi-Fi. On that Wi-Fi, every other laptop and phone in the café is on the same network as ours. If a program on our laptop is listening (waiting for incoming connections on a port), other devices on that Wi-Fi can try to talk to it. Most listening programs are normal parts of Windows or macOS. But an old file-sharing setting, a forgotten test server or an unknown app should not be open to the whole café.

In this lab we make a list of what is listening on our own laptop, find the program behind each port, switch off what we do not need, and make sure the built-in firewall (the software guard that blocks unwanted incoming connections) is on.

Goal of this lab

By the end you will have:

  • A list of the listening ports on your laptop, with the program behind each one.
  • The difference clear between "listening for everyone" (0.0.0.0, [::] or *) and "listening only for this laptop" (127.0.0.1 or localhost).
  • The built-in firewall turned on and checked from the command line.

What you need (all free)

  • Your own Windows 10/11 laptop or Mac. Nothing to install.
  • Command Prompt (Windows) or Terminal (Mac), which are already on the laptop.
  • Your laptop's admin password.
  • 30–40 minutes.

Safety and ethics

Run these commands only on your own laptop. We only look at our own machine; we do not scan or connect to anyone else's device. On a company laptop, ask your IT team before changing any setting, because company laptops are usually managed centrally.

Part 1 (Windows): See what is listening

  1. Click Start, type cmd, right-click Command Prompt and choose Run as administrator. Click Yes.
  2. Type this command and press Enter:

    netstat -ano | findstr LISTENING
    

    netstat shows network connections, -a means all, -n shows numbers instead of names, and -o adds the PID (process ID, the number Windows gives to each running program). findstr LISTENING keeps only the listening lines.

    What you should see: 10–30 lines like TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1104.

  3. Read each line from left to right: protocol (TCP), local address : port, foreign address, state, and the PID at the end.

  4. Look at the local address. 0.0.0.0:port or [::]:port means the program accepts connections from any network the laptop is on. 127.0.0.1:port or [::1]:port means only programs on this same laptop can connect.
  5. Pick one PID from your list and find its program name (replace 1104 with your PID):

    tasklist /FI "PID eq 1104"
    

    What you should see: one line with the program name, for example svchost.exe or lsass.exe.

  6. Do this for every 0.0.0.0 or [::] line and write a small table on paper: Port, Address, PID, Program, Do I need it?

  7. Compare with the normal Windows list below. Port 135 (svchost.exe, remote procedure calls), port 445 and 139 (System, PID 4, Windows file sharing), port 5040 and 7680 (svchost.exe, Windows services and Delivery Optimization for updates), and ports 49664–49670 (lsass.exe, wininit.exe, services.exe, spoolsv.exe, svchost.exe) are usual.
  8. For a program you do not recognise, open Task Manager (Ctrl + Shift + Esc) → Details tab, find the PID, right-click it → Open file location. Right-click the file → Properties → Digital Signatures to see who made it.
  9. If it is an app you installed and no longer use, remove it from Settings → Apps → Installed apps. If you do not know what it is, run Windows Security → Virus & threat protection → Scan options → Full scan. Do not end Windows system processes at random.

Part 2 (Windows): Turn on and check the firewall

  1. Click Start, type Windows Security and open it. Click Firewall & network protection.

    What you should see: three networks: Domain network, Private network and Public network. One of them says (active).

  2. Each of the three should say Firewall is on. If one says off, click it and switch Microsoft Defender Firewall to On.

  3. Set café and other outside Wi-Fi to the stricter Public profile: Settings → Network & internet → Wi-Fi → your network's properties → Network profile type → Public network (Recommended).
  4. Check from the command line:

    netsh advfirewall show allprofiles state
    

    What you should see: State ON under Domain, Private and Public profile settings.

Part 3 (Mac): See what is listening

  1. Press Cmd + Space, type Terminal and press Enter.
  2. Type this command and press Enter. Type your Mac login password when asked (nothing appears while you type; that is normal).

    sudo lsof -i -P -n | grep LISTEN
    

    lsof lists open files, and on a Mac network connections count as files. -i means network connections only, -P shows port numbers instead of names, -n skips name lookups, and grep LISTEN keeps only the listening lines.

    What you should see: lines such as ControlCe 512 you ... TCP *:7000 (LISTEN). The first column is the program, the second is the PID, the last column is address:port.

  3. Read the last column. *:port means any network can connect. 127.0.0.1:port or localhost:port means only this Mac.

  4. To see the full path of a program, use its PID (replace 512):

    ps -p 512 -o pid,comm
    
  5. Compare with the usual macOS list: ControlCenter on ports 5000 and 7000 is the AirPlay Receiver, rapportd is Continuity and Handoff between your Apple devices, and sharingd is AirDrop and sharing.

  6. If you do not use AirPlay to your Mac, switch it off: System Settings → General → AirDrop & Handoff → AirPlay Receiver → Off. Run the command from step 15 again.

    What you should see: ports 5000 and 7000 are no longer in the list.

Part 4 (Mac): Turn on and check the firewall

  1. Click the Apple menu → System Settings → Network → Firewall, and switch the firewall on. (On macOS Monterey or older: System Preferences → Security & Privacy → Firewall → Turn On Firewall.)
  2. Click Options… and switch on Enable stealth mode, so the Mac does not answer test messages such as ping from other devices on the network. Click OK.
  3. Check from Terminal:

    /usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate
    

    What you should see: Firewall is enabled. (State = 1).

Ravindra Bagale's Tip

Many students see 20 listening lines and panic: "my laptop is hacked!" Ghabru naka. Most of them are Windows or macOS itself. First find the program name and who signed it, then decide. And never kill System, lsass.exe or svchost.exe just because you don't recognise the name.

Common mistakes

Mistake What happens Fix
Running netstat -ano in a normal (non-admin) window and then using -b -b (show program names) fails with "requested operation requires elevation" Open Command Prompt with Run as administrator, or use tasklist /​FI "PID eq ..."
Forgetting sudo on the Mac lsof shows only your own programs, not system ones Run sudo lsof -​i -​P -​n \| grep LISTEN
Treating 127.0.0.1 lines as a risk You waste time on programs that only talk to your own laptop Focus on 0.0.0.0, [::] and * lines
Ending system processes in Task Manager Windows can freeze or restart Look up the name and signature first; remove only apps you installed
Turning the firewall on for only the active network The next Wi-Fi uses a profile that is still off Make sure all three Windows profiles say Firewall is on
Marking café Wi-Fi as Private Windows treats strangers' devices as trusted and may allow sharing Use Public network for any Wi-Fi outside home

Self-check checklist

0 of 6 done

Try-at-home challenge

See a listening port appear and disappear with your own eyes. If Python is installed on your laptop:

  1. Open a second Command Prompt or Terminal and run python -m http.server 8000 --bind 127.0.0.1 (on a Mac you may need python3).
  2. In the first window, run the listening-ports command again and find port 8000. Note that the address is 127.0.0.1.
  3. Press Ctrl + C in the second window to stop it, then run it again without --bind 127.0.0.1.
  4. Check the address now. Did Windows show a firewall pop-up asking whether to allow Python on Public networks? Choose Cancel / do not allow on Public.
  5. Stop the server with Ctrl + C and confirm that port 8000 has gone from the list.

Write two lines in your notes: why 127.0.0.1 is safer for a test server, and what the firewall pop-up protected you from.

Samjla ka? Know your own doors first, then keep the guard awake. Aata pudhe jaauya: Chapter 3 explains how these connections are built, layer by layer.