[TOOL] Malloc() FWScrape, Filtering Characteristics Analyzer

From: support@securiteam.com
Date: 02/15/03

  • Next message: support@securiteam.com: "[TOOL] YAPH - Yet Another Proxy Hunter"
    From: support@securiteam.com
    To: list@securiteam.com
    Date: 15 Feb 2003 22:05:39 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    Beyond Security would like to welcome Tiscali World Online
    to our service provider team.
    For more info on their service offering IP-Secure,
    please visit http://www.worldonline.co.za/services/work_ip.asp
    - - - - - - - - -

      Malloc() FWScrape, Filtering Characteristics Analyzer
    ------------------------------------------------------------------------

    DETAILS

    Malloc() FWScrape is a tool used to analyze the filtering characteristics
    of a specific host, Gateway(router) and/or Firewall. This tool performs a
    series of test and checks to determine the filtering rules of a host.

    Current tests:
     * TCP Traffic Testing
    Sends TCP packets to open/closed services and checks if the target host
    generates a response.

     * TCP Broken CRC Testing
    Sends TCP packets to open/closed services with invalid checksums and
    checks if the target host generates a response.

     * UDP Traffic Test
    Sends UDP packets to a closed UDP service and checks if the target sends
    back any response.

     * ICMP Traffic Test
    Sends ICMP packets to a host and checks if the target host sends back a
    response.

     * ICMP Broken CRC Test
    Sends ICMP packets to a host with a invalid checksum and checks if the
    host responds.

    ADDITIONAL INFORMATION

    The tool can be downloaded from:
     <http://mfwscrape.sourceforge.net> http://mfwscrape.sourceforge.net

    The information has been provided by <mailto:tek@superw00t.com> Dr. Tek.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



    Relevant Pages

    • Re: Do I Have A Firewalled LAN Run By ISP In Between?
      ... from that host while at host ... running a layer within a layer, with a complex network address translation ... application called "Internet Connection Sharing". ... what those packets are for, ...
      (comp.security.firewalls)
    • Re: IP over RS232 serial port under QNX6 (devn-fd.so)
      ... Now i can 'ping' and receive correct answers from the remote host. ... Now i want to setup the TCP/IP stack on top of the serial port. ... When i 'ping' to the destination endpoint 10.0.0.185 from the source ... These packets were correct ARP-Broadcasts ...
      (comp.os.qnx)
    • Re: Duplicate Echo Replies with Channel Bonding
      ... In this mode both interfaces receive packets, ... >When both eth0 and eth1 are up and I ping from Host C to Host A I get ... >The destination network 192.168.120.0/24 exists on both Router A and ... Switch B does not have the MAC address in its MAC address table ...
      (RedHat)
    • Re: Ip spoof from 0.0.0.0
      ... - A passive spoofed portscan with the attacker on the local ... segment watching the response packets go out to the default ... If a host responds to the syn packet sourced from 0.0.0.0 with an ack, ... it goes to the router either with the destination IP address rewritten ...
      (Incidents)
    • Re: Yet another thread on the legality of port scanning
      ... Which portthe packets are sent to is ... If I do a "nice", normal portscan on a host - via TCP, UDP or ICMP I am ... This sort of behavior is ... If I try to flood your host with abnormally LARGE ICMP packets endlessly ...
      (Security-Basics)