Network mapping oddity

From: Yonatan Bokovza (Yonatan@xpert.com)
Date: 03/20/03

  • Next message: Patrick MacDanel: "Terminal Server brute force developemnts ?"
    Date: Thu, 20 Mar 2003 20:28:42 +0200
    From: "Yonatan Bokovza" <Yonatan@xpert.com>
    To: <pen-test@securityfocus.com>
    

    Hi all,
    During the network mapping phase of a penetration test
    I've run into something weird, and I'd like to hear
    more opinions on this matter.

    The target (xx.xx.xx.1) is a web server behind a
    firewall (xx.xx.xx.2), 21 hops away. Between both of them
    there is a filter that:
    1. Replies with RST+ACK to SYN with TTL=20. The RST+ACK
    source is of the tested target.
    2. Ignores the fact that the TCP-checksum is wrong.

    I'm aware of http://www.phrack.org/show.php?p=60&a=12
    suggesting this is a load-balancer. What do you think?

    At first I thought it might be an Air-Gap product, as
    they disassemble and reassemble the TCP session. I then
    found out a DNS server behind this filter, and I know
    Air-Gap products don't handle UDP by default.

    Please ignore the differences in TTL (in the first example,
    for instance, 21!=128-109). This client has a BGP
    connection and the incoming packets do not travel the same
    path as the outgoing packets.

    Best Regards,

    Yonatan Bokovza
    IT Security Consultant
    Xpert Systems

    Hping session follows:
    #> hping -S -c 1 -p 80 -t 21 xx.xx.xx.1
    HPING xx.xx.xx.1 (fxp0 xx.xx.xx.1): S set, 40 headers + 0 data bytes
    len=46 ip=xx.xx.xx.1 ttl=109 id=33493 sport=80 flags=SA seq=0 win=512 rtt=224.9 ms

    --- xx.xx.xx.1 hping statistic ---
    1 packets tramitted, 1 packets received, 0% packet loss
    round-trip min/avg/max = 224.9/224.9/224.9 ms
    #> hping -S -c 1 -p 80 -t 21 -b xx.xx.xx.1
    HPING xx.xx.xx.1 (fxp0 xx.xx.xx.1): S set, 40 headers + 0 data bytes
    len=46 ip=xx.xx.xx.1 ttl=109 id=64110 sport=80 flags=SA seq=0 win=512 rtt=190.8 ms

    --- xx.xx.xx.1 hping statistic ---
    1 packets tramitted, 1 packets received, 0% packet loss
    round-trip min/avg/max = 190.8/190.8/190.8 ms
    #> hping -S -c 1 -p 80 -t 20 -b xx.xx.xx.1
    HPING xx.xx.xx.1 (fxp0 xx.xx.xx.1): S set, 40 headers + 0 data bytes
    len=46 ip=xx.xx.xx.1 ttl=236 id=40067 sport=80 flags=RA seq=0 win=0 rtt=174.3 ms

    --- xx.xx.xx.1 hping statistic ---
    1 packets tramitted, 1 packets received, 0% packet loss
    round-trip min/avg/max = 174.3/174.3/174.3 ms
    #> hping -S -c 1 -p 80 -t 20 -b xx.xx.xx.1
    HPING xx.xx.xx.1 (fxp0 xx.xx.xx.1): S set, 40 headers + 0 data bytes

    --- xx.xx.xx.1 hping statistic ---
    1 packets tramitted, 0 packets received, 100% packet loss
    round-trip min/avg/max = 0.0/0.0/0.0 ms
    #> hping -S -c 1 -p 80 -t 19 xx.xx.xx.1
    HPING xx.xx.xx.1 (fxp0 xx.xx.xx.1): S set, 40 headers + 0 data bytes
    TTL 0 during transit from ip=xx.xx.xx.2 name=firewall.client.com

    --- xx.xx.xx.1 hping statistic ---
    1 packets tramitted, 1 packets received, 0% packet loss
    round-trip min/avg/max = 0.0/0.0/0.0 ms
    #>

    ----------------------------------------------------------------------------
    Did you know that you have VNC running on your network?
    Your hacker does. Plug your security holes now!
    Download a free 15-day trial of VAM:
    http://www2.stillsecure.com/download/sf_vuln_list.html


  • Next message: Patrick MacDanel: "Terminal Server brute force developemnts ?"

    Relevant Pages

    • Re: paket loss on freebsd router if (b)snmpd is running##SPAM
      ... T>> T>If bsnmpd is running and I'm doing a snmpwalk from a remote machine the ... I already have significant packet loss if bsnmpd is started. ... T>44 packets transmitted, 44 packets received, 0% packet loss ... You find this in the BEGEMOT-MIB2-MIB. ...
      (freebsd-net)
    • Assymetric results from iperf across gigabit link (long)
      ... Laptop is located some place we'll call Sproul Hall. ... that seems remotely strange is the number of out-of-order packets, ... PING 169.229.254.137: 1400 data bytes ... 1000 packets transmitted, 972 packets received, 2% packet loss ...
      (freebsd-net)
    • Re: paket loss on freebsd router if (b)snmpd is running##SPAM
      ... T>> T>If bsnmpd is running and I'm doing a snmpwalk from a remote machine the ... I already have significant packet loss if bsnmpd is started. ... T>44 packets transmitted, 44 packets received, 0% packet loss ... T> packets errs bytes packets errs bytes colls ...
      (freebsd-net)
    • suffering from poor network performance...
      ... I have a small home network with a PowerBook G4 and FBSD 4.9-STABLE ... In my limited knowledge I'm using ping from each host to the other. ... When I ping from one machine to the other I get nearly 60% packet loss ... 1000 packets transmitted, 500 packets received, 50% packet loss ...
      (freebsd-net)
    • Re: paket loss on freebsd router if (b)snmpd is running##SPAM
      ... T>average traffic is 300mbit/s (em interfaces with polling enabled). ... T>If bsnmpd is running and I'm doing a snmpwalk from a remote machine the ... I already have significant packet loss if bsnmpd is started. ... 44 packets transmitted, 44 packets received, 0% packet loss ...
      (freebsd-net)