Hey Guys, Can anyone tell me if its possible to hack a server with all incoming ports closed?
Keep in mind, that there is more in the world of networks besides TCP+UDP, for example ARP, ICMP, DHCP, ...
They don't run over IP, so they don't care about your IP-port-related settings.
In addition: Your machine IS talking to the outside. And you say that you are relying on SSL to provide confidentiality, integrity and authenticity.
Is your SSL-library bullet-proof? Can you trust your domain name resolution? Are you validating SSL certificates at all? How secure is your certificate verification mechanism? When did you update that system and fetched the latest certificates and do you know, that they really were not tampered?
And what about physical access to the machine? Is it a virtual machine? How secure is the host? Is it hosted by a different company? What about their access-restrictions for administration purposes?
And don't limit the meaning of "hacking". Think of an attack that can crash your whole system, or block it due to DoS-attacks. Everything "hurts", what makes your business lose money.
...