As i mention earlier BETA version [4.737] show to much (IMHO) info when someone starts a scan from the internet. A easy way to test this is to use the site www.grc.com (old ladies scan but hey it works!). With version 4 every port come up in stealth mode even when it's open (great!!!). With version 5 however all open port reported as 'open' and could be investigate more by an attacker. It's even getting worst when one is using more sophisticated scanners like nmap or nessus..... These tools are also able to guess the software versions used or read the banners....
I assume that IPS (Snort that is) is the one to blame

Afterall, you should listen on lets say port 80 to analyze the packets and therefore port 80 will be reported as open...
What's your opion about this?
Regards,
Ezteok