Re: Scanning - anyone got ball park timings?

From: linux seaq (linux_at_seaq.com.co)
Date: 05/30/03

  • Next message: Mark Squire: "Network Mapping/Discovery"
    Date: Thu, 29 May 2003 17:33:53 -0500
    
    

    Sometime ago "Pete Herzog" <pete@isecom.org> (exactly the Thu, 29 May
    2003 22:55:03 +0200), wrote:

    >
    > Rule of thumb for security testing enumeration-- straight out of
    > OSSTMM 2.5 RED--
    >

    Hi, right now i'm doing a nessus vuln scan with top20 in a ~3000 hosts /
    multiple subnets network (about 90 subnets) all of them about 1 max 2
    hops from me.

    First i search for online hosts, using nmap scanning for netbios ports
    and web ports, it took 2-3 hours without OS fingerprinting (it was done
    several times in 2 weeks, so i could get a somehow accurate map form the
    network). if i used OS fp it take from 6 to 10 hours to do the whole
    scan.

    Second i split the hosts detected by subnets (the most populated has
    about 200 hosts) and merge the subnets whose population were less than
    50 hosts (so i could get 100-200 blocks of ip)

    Third i started nessusd (yesterday, to be accurate) and for the first
    subnet with 180 hosts it took about 3 hours (2 hops from me).

    but today the next subnet (same size/hops) is taking 7 hours..

    i'll send you the timings after the process is completed.. (well i hope
    it would finish some day)

    hope this helps

    ---
    Andres Mauricio Mujica
    SEAQ SERVICIOS CIA LTDA
    www.seaq.com.co
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Mark Squire: "Network Mapping/Discovery"

    Relevant Pages

    • Re: [SLE] YaST Online Update
      ... Use the traceroute command to get an idea of how "far" a site is from you. ... It will show you how many hops (hosts through which packets must be ...
      (SuSE)
    • [HPADM] Clariion Issues continued...
      ... The HP hosts, and the Storage Processors, are on the SAME subnet. ... traceroute to the SP, and it reaches the max ttl of 30 hops, and dies. ...
      (HP-UX-Admin)
    • Re: Subnet Planning Question
      ... Leave the mask as is. ... Just add new subnets in the third octet, ... 254 hosts per each one, so two subnets will give you the 500 hosts you ... > My network is presently configured to use the 192.168 private ip address> range with a subnet mask of 255.255.255.0. ...
      (microsoft.public.win2000.networking)
    • Re: linux as router
      ... In the 1980s, our subnets were designed with a 255.255.252.0 mask, allowing ... 1000 hosts on a single collision domain. ...
      (comp.os.linux.networking)
    • Re: windows mem leak
      ... # Generate and add networks 192.168.1-255 to networks. ... # Generate and add hosts 1-254 to hosts. ... ## Add the 192.168.0 net list to the subnets list. ... print "There are", len, "class C network lists in the subnets list." ...
      (comp.lang.python)