thx instaman, now I actually understand this software some more...
frankly I didn't get what nis and ncc is or mean earlier or why this seperation exists in the first place (lol, i'm not the tech savviest around).
I didn't know NIS is enough to be harvesting. now I know
but I think many new users will just be running nis+ncc on default port. isn't that a real issue for the network? I mean you said if ncc can be accessed then nis can be crashed!? you guys should fix that somehow.
It is a problem but rather a small one

. Please view this youtube video-
https://www.youtube.com/watch?v=cbFiWeeMUDI. And then block the port 8989. This will ensure that nobody can remote access your NCC. Everybody should block the port 8989 in the inbound and outbound rules.