Labs · Cyber Security
Lab: Check Which Programs on Your Own Laptop Are Listening on the Network and Turn On the Built-in Firewall
Course: Cyber Security · Chapter 2: Ports and Protocols: SSH, HTTP, HTTPS, FTP/SFTP and DNS
Chapter 2 explains ports; this lab looks at the ports of your own laptop.
Chala mitrano! In Chapter 2 we learnt that a port is like a numbered door on a computer. Today we look at the doors of our own laptop: which programs are waiting at a door for someone to knock, and is the security guard (the firewall) awake? Only our own laptop, only looking and switching on protection. Ekdum simple aahe.
चला मित्रांनो! Chapter 2 मध्ये आपण शिकलो की port म्हणजे computer चा एक numbered दरवाजा. आज आपण आपल्याच laptop चे दरवाजे बघणार: कोणते programs दरवाज्यावर कोणी knock करेल याची वाट बघत आहेत, आणि security guard (firewall) जागा आहे का? फक्त आपला laptop, फक्त बघायचं आणि protection चालू करायचं. एकदम simple आहे.
चलो दोस्तों! Chapter 2 में हमने सीखा कि port यानी computer का एक numbered दरवाज़ा। आज हम अपने ही laptop के दरवाज़े देखेंगे: कौन से programs दरवाज़े पर किसी के knock करने का इंतज़ार कर रहे हैं, और security guard (firewall) जाग रहा है या नहीं? सिर्फ अपना laptop, सिर्फ देखना और protection चालू करना। बिल्कुल simple है।
Suppose we are…
Suppose we have just joined Wipro as a fresher and we work from home two days a week. Some days we sit in a café and use its free Wi-Fi. On that Wi-Fi, every other laptop and phone in the café is on the same network as ours. If a program on our laptop is listening (waiting for incoming connections on a port), other devices on that Wi-Fi can try to talk to it. Most listening programs are normal parts of Windows or macOS. But an old file-sharing setting, a forgotten test server or an unknown app should not be open to the whole café.
In this lab we make a list of what is listening on our own laptop, find the program behind each port, switch off what we do not need, and make sure the built-in firewall (the software guard that blocks unwanted incoming connections) is on.
Goal of this lab
By the end you will have:
- A list of the listening ports on your laptop, with the program behind each one.
- The difference clear between "listening for everyone" (
0.0.0.0,[::]or*) and "listening only for this laptop" (127.0.0.1orlocalhost). - The built-in firewall turned on and checked from the command line.
What you need (all free)
- Your own Windows 10/11 laptop or Mac. Nothing to install.
- Command Prompt (Windows) or Terminal (Mac), which are already on the laptop.
- Your laptop's admin password.
- 30–40 minutes.
Safety and ethics
Run these commands only on your own laptop. We only look at our own machine; we do not scan or connect to anyone else's device. On a company laptop, ask your IT team before changing any setting, because company laptops are usually managed centrally.
Part 1 (Windows): See what is listening
- Click Start, type
cmd, right-click Command Prompt and choose Run as administrator. Click Yes. -
Type this command and press Enter:
netstat -ano | findstr LISTENINGnetstatshows network connections,-ameans all,-nshows numbers instead of names, and-oadds the PID (process ID, the number Windows gives to each running program).findstr LISTENINGkeeps only the listening lines.What you should see: 10–30 lines like
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1104. -
Read each line from left to right: protocol (TCP), local address : port, foreign address, state, and the PID at the end.
- Look at the local address.
0.0.0.0:portor[::]:portmeans the program accepts connections from any network the laptop is on.127.0.0.1:portor[::1]:portmeans only programs on this same laptop can connect. -
Pick one PID from your list and find its program name (replace
1104with your PID):tasklist /FI "PID eq 1104"What you should see: one line with the program name, for example
svchost.exeorlsass.exe. -
Do this for every
0.0.0.0or[::]line and write a small table on paper: Port, Address, PID, Program, Do I need it? - Compare with the normal Windows list below. Port 135 (
svchost.exe, remote procedure calls), port 445 and 139 (System, PID 4, Windows file sharing), port 5040 and 7680 (svchost.exe, Windows services and Delivery Optimization for updates), and ports 49664–49670 (lsass.exe,wininit.exe,services.exe,spoolsv.exe,svchost.exe) are usual. - For a program you do not recognise, open Task Manager (Ctrl + Shift + Esc) → Details tab, find the PID, right-click it → Open file location. Right-click the file → Properties → Digital Signatures to see who made it.
- If it is an app you installed and no longer use, remove it from Settings → Apps → Installed apps. If you do not know what it is, run Windows Security → Virus & threat protection → Scan options → Full scan. Do not end Windows system processes at random.
Part 2 (Windows): Turn on and check the firewall
-
Click Start, type Windows Security and open it. Click Firewall & network protection.
What you should see: three networks: Domain network, Private network and Public network. One of them says (active).
-
Each of the three should say Firewall is on. If one says off, click it and switch Microsoft Defender Firewall to On.
- Set café and other outside Wi-Fi to the stricter Public profile: Settings → Network & internet → Wi-Fi → your network's properties → Network profile type → Public network (Recommended).
-
Check from the command line:
netsh advfirewall show allprofiles stateWhat you should see:
State ONunder Domain, Private and Public profile settings.
Part 3 (Mac): See what is listening
- Press Cmd + Space, type Terminal and press Enter.
-
Type this command and press Enter. Type your Mac login password when asked (nothing appears while you type; that is normal).
sudo lsof -i -P -n | grep LISTENlsoflists open files, and on a Mac network connections count as files.-imeans network connections only,-Pshows port numbers instead of names,-nskips name lookups, andgrep LISTENkeeps only the listening lines.What you should see: lines such as
ControlCe 512 you ... TCP *:7000 (LISTEN). The first column is the program, the second is the PID, the last column is address:port. -
Read the last column.
*:portmeans any network can connect.127.0.0.1:portorlocalhost:portmeans only this Mac. -
To see the full path of a program, use its PID (replace
512):ps -p 512 -o pid,comm -
Compare with the usual macOS list:
ControlCenteron ports 5000 and 7000 is the AirPlay Receiver,rapportdis Continuity and Handoff between your Apple devices, andsharingdis AirDrop and sharing. -
If you do not use AirPlay to your Mac, switch it off: System Settings → General → AirDrop & Handoff → AirPlay Receiver → Off. Run the command from step 15 again.
What you should see: ports 5000 and 7000 are no longer in the list.
Part 4 (Mac): Turn on and check the firewall
- Click the Apple menu → System Settings → Network → Firewall, and switch the firewall on. (On macOS Monterey or older: System Preferences → Security & Privacy → Firewall → Turn On Firewall.)
- Click Options… and switch on Enable stealth mode, so the Mac does not answer test messages such as ping from other devices on the network. Click OK.
-
Check from Terminal:
/usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstateWhat you should see:
Firewall is enabled. (State = 1).
Ravindra Bagale's Tip
Many students see 20 listening lines and panic: "my laptop is hacked!" Ghabru naka. Most of them are Windows or macOS itself. First find the program name and who signed it, then decide. And never kill System, lsass.exe or svchost.exe just because you don't recognise the name.
Ravindra Bagale's Tip – मराठी
बरेच students 20 listening lines बघून घाबरतात: "माझा laptop hack झाला!" घाबरू नका. त्यातल्या बहुतेक lines Windows किंवा macOS च्याच असतात. आधी program चं नाव आणि ते कोणी sign केलं ते शोधा, मग ठरवा. आणि नाव ओळखीचं नाही म्हणून System, lsass.exe किंवा svchost.exe कधीच बंद करू नका.
Ravindra Bagale's Tip – हिंदी
बहुत से students 20 listening lines देखकर डर जाते हैं: "मेरा laptop hack हो गया!" घबराओ मत। उनमें से ज़्यादातर Windows या macOS की अपनी होती हैं। पहले program का नाम और उसे किसने sign किया ये देखो, फिर तय करो। और नाम पहचान में नहीं आया इसलिए System, lsass.exe या svchost.exe को कभी बंद मत करो।
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
Running netstat -ano in a normal (non-admin) window and then using -b |
-b (show program names) fails with "requested operation requires elevation" |
Open Command Prompt with Run as administrator, or use tasklist /FI "PID eq ..." |
Forgetting sudo on the Mac |
lsof shows only your own programs, not system ones |
Run sudo lsof -i -P -n \| grep LISTEN |
Treating 127.0.0.1 lines as a risk |
You waste time on programs that only talk to your own laptop | Focus on 0.0.0.0, [::] and * lines |
| Ending system processes in Task Manager | Windows can freeze or restart | Look up the name and signature first; remove only apps you installed |
| Turning the firewall on for only the active network | The next Wi-Fi uses a profile that is still off | Make sure all three Windows profiles say Firewall is on |
| Marking café Wi-Fi as Private | Windows treats strangers' devices as trusted and may allow sharing | Use Public network for any Wi-Fi outside home |
Self-check checklist
0 of 6 done
Try-at-home challenge
See a listening port appear and disappear with your own eyes. If Python is installed on your laptop:
- Open a second Command Prompt or Terminal and run
python -m http.server 8000 --bind 127.0.0.1(on a Mac you may needpython3). - In the first window, run the listening-ports command again and find port 8000. Note that the address is
127.0.0.1. - Press Ctrl + C in the second window to stop it, then run it again without
--bind 127.0.0.1. - Check the address now. Did Windows show a firewall pop-up asking whether to allow Python on Public networks? Choose Cancel / do not allow on Public.
- Stop the server with Ctrl + C and confirm that port 8000 has gone from the list.
Write two lines in your notes: why 127.0.0.1 is safer for a test server, and what the firewall pop-up protected you from.
Samjla ka? Know your own doors first, then keep the guard awake. Aata pudhe jaauya: Chapter 3 explains how these connections are built, layer by layer.