RE: All tcp ports open?

From: Mike Sues (msues_at_rigelksecurity.com)
Date: 08/30/04

  • Next message: Andy Cuff: "Re: EC-Counsil (Book Review) Can we wrap this thread up?"
    To: "'Varun Pitale'" <varun.pitale@gmail.com>, "'Ben Timby'" <asp@webexc.com>, <pen-test@securityfocus.com>
    Date: Mon, 30 Aug 2004 08:24:32 -0400
    
    

    Hello,

    just to confirm someone else's posting, the Milkyway
    firewall, Blackhole, later named to SecureIT does respond
    in this way too. I also saw old versions of the Raptor
    firewall respond with all open ports.

    Did you try a fragmented SYN scan? I have seen SecureIT
    respond differently to the fragmented SYN scan. That is,
    all ports are reported closed but rsh is reported open.

    This would be a possible way to fingerprint the firewall.

    --------------------------------------------
    Mike Sues, GCIH
    Ethical Hack Specialist
    Rigel Kent Security & Advisory Services Inc
    http://www.rigelksecurity.com
    voice:613.233.HACK
    fax :613.233.1788
    toll
    free :1.877.777.H8CK
    --------------------------------------------

    -----Original Message-----
    From: Varun Pitale [mailto:varun.pitale@gmail.com]
    Sent: Sunday, August 29, 2004 6:36 PM
    To: Ben Timby; pen-test@securityfocus.com
    Subject: Re: All tcp ports open?

    I have seen a solaris box which was acting as a load balancer act this
    way too, so it might be a loadbalancer thing. All ports seem to be
    open, but they do not give any response . If you could post what kinds
    of machines they are, it would be good..

    On Sun, 29 Aug 2004 02:04:08 -0500, Ben Timby <asp@webexc.com> wrote:
    > I am not sure what is doing this, but I assume it is a software (or
    > some kind of) firewall/hids, can anybody point me in the right
    > direction?
    >
    > I am pen-testing a Windows webserver, and a port scan reveals ALL tcp
    > ports open. hping also confirms that a SA is returned for any S
    > packets sent to any port I try. I can connect via netcat any of the
    > ports, and send data, but nothing is returned. In order to verify
    > services, I am required to connect and check for a banner or send
    > appropriate protocol commands to elicit a response.
    >
    > Has anyone seen this, or have any idea of what this is?
    >
    > Thanks.
    >
    > ----------------------------------------------------------------------
    > --------
    > Ethical Hacking at the InfoSec Institute. All of our class sizes are
    > guaranteed to be 12 students or less to facilitate one-on-one
    interaction
    > with one of our expert instructors. Check out our Advanced Hacking
    course,
    > learn to write exploits and attack security infrastructure. Attend a
    course
    > taught by an expert instructor with years of in-the-field pen testing
    > experience in our state of the art hacking lab. Master the skills of
    an
    > Ethical Hacker to better assess the security of your organization.
    >
    > http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    > ----------------------------------------------------------------------
    > ---------
    >
    >

    -- 
    Regards, 
       Varun
       (704)-548-8793 --(Home)
       (704)-241-0092 --(Mobile)
       mailto: varun.pitale_(at)_gmail_(dot)_com
    ------------------------------------------------------------------------
    ------
    Ethical Hacking at the InfoSec Institute. All of our class sizes are
    guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Check out our Advanced
    Hacking course, learn to write exploits and attack security
    infrastructure. Attend a course taught by an expert instructor with
    years of in-the-field pen testing experience in our state of the art
    hacking lab. Master the skills of an Ethical Hacker to better assess the
    security of your organization.
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ------------------------------------------------------------------------
    -------
    ------------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. All of our class sizes are
    guaranteed to be 12 students or less to facilitate one-on-one interaction
    with one of our expert instructors. Check out our Advanced Hacking course,
    learn to write exploits and attack security infrastructure. Attend a course
    taught by an expert instructor with years of in-the-field pen testing
    experience in our state of the art hacking lab. Master the skills of an
    Ethical Hacker to better assess the security of your organization.
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    -------------------------------------------------------------------------------
    

  • Next message: Andy Cuff: "Re: EC-Counsil (Book Review) Can we wrap this thread up?"

    Relevant Pages

    • Re: All tcp ports open?
      ... This is not a safe assumption, many services do not respond with a banner. ... Subject: All tcp ports open? ... > Ethical Hacking at the InfoSec Institute. ... > learn to write exploits and attack security infrastructure. ...
      (Pen-Test)
    • Re: All tcp ports open?
      ... All ports seem to be ... > Ethical Hacking at the InfoSec Institute. ... Check out our Advanced Hacking course, learn to write exploits and attack security infrastructure. ...
      (Pen-Test)
    • Re: All tcp ports open?
      ... ports with banners will be the ones you should pen-test. ... > Ethical Hacking at the InfoSec Institute. ... > learn to write exploits and attack security infrastructure. ...
      (Pen-Test)
    • Re: Strange response from network
      ... My guess is that hop 7 is home of a firewall of some sort. ... Regarding the port number, my guess is that port 2443 is the 2nd SSL ... Ethical Hacking at the InfoSec Institute. ... learn to write exploits and attack security infrastructure. ...
      (Pen-Test)
    • Re: All tcp ports open?
      ... "hacking: the art of exploitation" by jon erickson only on a linux machine. ... Subject: All tcp ports open? ... > learn to write exploits and attack security infrastructure. ... > experience in our state of the art hacking lab. ...
      (Pen-Test)