Re: Nmap issues...? or router?

From: Alex Butcher (alex@s3.integralis.co.uk)
Date: 10/08/01


Message-ID: <3BC19E95.7050600@s3.integralis.co.uk>
Date: Mon, 08 Oct 2001 13:39:49 +0100
From: Alex Butcher <alex@s3.integralis.co.uk>
To: bluefur0r bluefur0r <bluefur0r@drea.ms>
Subject: Re: Nmap issues...? or router?

bluefur0r bluefur0r wrote:
> After just completeing an audit for a company that has a DS-3 connection (shared) and a cisco router (2015), One of the first issues that was found was this: When nmaping using -sS and all ports, 1 nmap scan nmaping 1 host at a time appeared to completely destroy their bandwidth... Has anyone heard of this? Could this be a Router or ISP problem??? It took very long to complete because i needed to use the -T Polite option. I'm just curious if anyone else has ever encountered nmap using up all network resources for such a high volume connection. Any help would be appreciated so this never happens again. *Luckily I started after hours*
> blue

I've seen similar; some firewalls (e.g. WatchGuard) start blocking
connections from hosts that generate 'x' policy violations in a
given time.

Bleh.

Best Regards,
Alex.

-- 
Alex Butcher                                      PGP/GnuPG Key IDs:
Consultant, S3 Systems Security Services          alex@s3       B7709088
PGP: http://www.s3.integralis.co.uk/pgp/alex.pgp  alex.butcher@ 885BA6CE

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • Re: faster scans? (nmap)
    ... one host using nmap for syn scans in burst mode with the ... >>>This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: pen test help please asap
    ... > Machine A on client site makes a configurable encrypted OUTBOUND ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: ettercap help
    ... Anyways have never tried Ettercap for VNC. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: ettercap help
    ... > I can get it to sniff telnet, ftp, pop, smb, but no vnc. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Wardialing
    ... >>> achieving the connection with the modem. ... >>This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)

Quantcast