Re: IPChains leak for UDP!?

From: Justin Nelson (bugtraq@jm4n.com)
Date: 10/31/01


Message-Id: <200110311838.f9VIcGl03014@localhost.localdomain>
From: Justin Nelson <bugtraq@jm4n.com>
To: focus-linux@securityfocus.com
Subject: Re: IPChains leak for UDP!?
Date: Wed, 31 Oct 2001 13:38:16 -0500

Hello,

> Q2) I tried blocking UDP ports 137-139 specifically right in the
> begging, and nmap shows that those ports are open! And when I block
> all UDP, nmap doesn't show any such message. (nmap was run from the
> localhost itself.)

I don't use PortSentry myself, but on one installation I saw,
PortSentry had set up a cron to flush any ipchains rules every hour.
This was on a RH 6.2 box with RackSpace, so it's possible some other
preinstalled tool had set this up...

The comments in the crontab mentioned flushing the rules so that
PortSentry could do its job without ipchians getting in its way.

I would double check and do an 'ipchians -L' to make sure the rules
are in fact still in place...

Also -- run your nmap from an outside box rather than on the same
machine...

- Justin



Relevant Pages

  • Re: Identifying Kernel 2.4.x based Linux machines using UDP
    ... > Linux Kernel 2.4.x has a bug with the UDP implementation which allows ... It also isn't specific to UDP -- you'll find ... Last year I added a feature to Nmap which automates this IPID ...
    (Bugtraq)
  • Re: how nmap can know my firewalled servers ?
    ... UDP or ICMP protocol), it will mark the port as closed. ... descrition, how NMAP determins, if the UDP port is open or closed. ... Try Webroot's Spy Sweeper Enterprisefor 30 days for FREE with no ...
    (Security-Basics)
  • Re: Disovering hosts using UDP services
    ... Often udp port scanning say with nmap -sU -pPort1,Port2,.. ... but will respond for good dns query. ... windows discovery ...
    (Pen-Test)
  • Re: nmap udp scan time
    ... The scan syntax used is as follows: ... Should a UDP scan take such a long time? ... Note that nmap adjusts the number of concurrent probes based on its performance. ... reasonably fast devices on a lightly-loaded local LAN. ...
    (Pen-Test)
  • Disovering hosts using UDP services
    ... Often udp port scanning say with nmap -sU -pPort1,Port2,.. ... At the same time utilities which send good packets getting ... windows discovery ...
    (Pen-Test)