Finding real host in Nmap -D Scans

From: Ryan (ryan@packetwatch.net)
Date: 03/03/03

  • Next message: H D Moore: "Re: Finding real host in Nmap -D Scans"
    From: "Ryan" <ryan@packetwatch.net>
    To: <pen-test@securityfocus.com>, <nmap-dev@insecure.org>
    Date: Sun, 2 Mar 2003 18:25:29 -0600
    
    

    Hi All,

    I was wondering about the decoy scan in nmap. Is there a way to tell
    which host in a decoy scan is the real host? I found a post by Dug Song
    (http://www.geek-girl.com/ids/1999/0057.html), but these methods won't
    work anymore.

    First, as Dug Song said nmap now randomizes the ttl fields, and secondly
    you can't narrow it down to a host that can run nmap, because nmap can
    now be run on Windows systems as well.

    Ryan Spangler
    http://www.packetwatch.net

    ----------------------------------------------------------------------------
    <Pre>Do you know the base address of the Global Offset Table (GOT) on a Solaris 8 box?
    CORE IMPACT does.</Pre>
    <A href="http://www.securityfocus.com/core"> http://www.securityfocus.com/core>



    Relevant Pages

    • RE: Weird Nmap Behavior
      ... As nice as NMAP is, ... Host xxx.xxx.xxx.241 is up (0.0089s latency). ... Information Assurance Certification Review ...
      (Pen-Test)
    • Re: Weird Nmap Behavior
      ... host is up, it will just scan... ... I believe the default 'ping' behaviour with NMAP now is to send a tcp ... Information Assurance Certification Review Board ... Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. ...
      (Pen-Test)
    • Re: Weird Nmap Behavior
      ... If you only intend to just check whether the host are alive or not ... then try the host discovery switches in NMAP. ...
      (Pen-Test)
    • Re: Is it "legal" to nmap offending hosts?
      ... Is it "legal" to nmap offending hosts? ... Personally I would nmap an offending host. ... exploitable services or backdoors I know the host is not the one offending me ...
      (Security-Basics)
    • Re: setting up HP 4050 with network adapter
      ... to install a new one but Im not sure how to give the HP a IP. ... I installed nmap and this is the result: ... Note: Host seems down. ... All 1714 scanned ports on 192.168.0.3 are filtered ...
      (Ubuntu)

  • Quantcast