Re: Interesting challenge

From: David Barroso (dbarroso_at_s21sec.com)
Date: 01/30/04

  • Next message: Serhan Sevim: "RE: Interesting challenge"
    Date: Fri, 30 Jan 2004 20:28:44 +0100 (CET)
    To: "Sanjay K. Patel" <sanjay.patel@rexwire.com>
    
    

    > We are doing a pen test for a client and have run into a interesting
    > situation. The client has a server running IIS and Exchange we can get to
    > it
    > through a browser but when we try to run Nessus or Eeye Retina against it,
    > neither product can find the server. The client is not running any IDS
    > system has a simple firewall. A port scan revels no open port though port
    > 80
    > is open since the server is serving pages.
    >

    Sanjay,
    perhaps an additional layer of security is implemented, which silently
    drops all packets received from a specific host, if it detects a portscan
    from that host, and accepts a normal traffic flow if it does not detect
    any 'attack'. This countermeasure could be installed in your client's
    site, or, on the other hand, maybe your egress traffic is being filtered.

    David

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Serhan Sevim: "RE: Interesting challenge"

    Relevant Pages

    • Re: Unable to print to networked printer - get access denied messa
      ... Check the permissions on the server assuming the client has a true RPC ... How is the Standard TCP/IP port configured for the device? ...
      (microsoft.public.windowsxp.print_fax)
    • Re: interfaces lo:1 lo:2 lo:3? (for remote ssh tunnels)
      ... That's the problem tunneling (port forwarding) solves. ... >>can't get past the client firewall. ... > I don't understand why the server would be making the ... server initiates another connection to the client -- in this ...
      (Debian-User)
    • Re: Remote Connection Issue
      ... through port number 3389 and a workstation on the LAN through port number ... I understand that you want to allow a LAN client ... and you have configured server publishing rule ... > By default Terminal Server and Windows 2000 Terminal Services uses TCP ...
      (microsoft.public.windows.server.sbs)
    • Re: RealVNC
      ... Default listening port for RealVNC server that runs on the machine on which ... Then there is default Java listening port on port 5800 on the client machine ...
      (microsoft.public.windows.server.sbs)
    • Re: Redirecting data sent to a local printer to another host and port on the network
      ... All client workstations have access to the ... simply redirecting netcat traffic on port 9100 to port 515 on ... Only LPR clients talk to LPD print server daemons. ... >workstation at the branch site where the print job originated. ...
      (comp.unix.sco.misc)