RE: Auditing boxes with predictable IP Sqeuence(s)

From: Aleksander P. Czarnowski (alekc@avet.com.pl)
Date: 02/26/02


Date: Tue, 26 Feb 2002 10:14:37 +0100
From: "Aleksander P. Czarnowski" <alekc@avet.com.pl>
To: <pen-test@securityfocus.com>


> I came up with a bunch of hosts which nMap classifies as
> 'unknown', but with predictable TCP Sqeuence(s).
Try passive OS fingerprinting. Personally I like siphon (although it's
OS database is a bit outdated, but you can easily add new OSes) but
there are other tools. Also run sniffer and look for connection to you
hosts. If you find one consider hijacking it. This will also reveal some
open ports.
nmap can be very flexible in port scanning - try packet fragmentation
and source port options (-f and -g). Also try rpc and null scans.
Just my two cents.
Regards,
Alex Czarnowski
AVET INS

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: Identify OS?
    ... The first thing that struck me was port 6112/dtspc. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: Raptor Firewall 6.5 Config
    ... Raptor as a firewall also has another side feature that can confuse ... This is the whole keep a port open PNAT idea. ... Once raptor has a standard proxy or GSP enabled, it 'opens' that ... >>This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Digital UNIX 5.60 recourses
    ... Find out what is running on what port (use of netcat, nmap, ... >> Subject: Digital UNIX 5.60 recourses ... >This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Config cisco switches against arpspoofing
    ... switch won't let traffic through unless source MAC address is the one it ... At the interface config option issue "port secure" command, ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: DENY x REJECT
    ... >The best way to differ between a port which the firewall is configured ... a Destination Port Unreachable message should be ... >This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)