RE: Nmap/netwag problem.

ankush.kapoor_at_wipro.com
Date: 08/12/05

  • Next message: houseofdabus: "(MS05-039) Microsoft Windows Plug-and-Play Service Remote Overflow (Universal Exploit + no crash shellcode)"
    Date: Fri, 12 Aug 2005 17:22:36 +0530
    To: <al3ph.one@gmail.com>, <pen-test@securityfocus.com>
    
    

    Hping is a pretty good tool. If you seriously feel that the port is
    being filtered at a firewall, give firewalk a shot. The paper explaining
    it is also very informative ;)

    Ankush

    -----Original Message-----
    From: Paul J Docherty [mailto:PJD@portcullis-security.com]
    Sent: Thursday, August 11, 2005 8:38 PM
    To: Pete Herzog; Kaj Huisman
    Cc: Aleph One; pen-test@securityfocus.com; Security-Basics
    Subject: RE: Nmap/netwag problem.

    Whilst the points you are making are correct once you have discovered
    open ports, I think you have raced ahead of the question, which was I
    think, "which port scanner is giving the correct results?" As many
    others have elegantly answered use a packet sniffer and look at the raw
    data to see what's going on. You have raced ahead and are bordering
    service discovery rather than port status, as we know there can be any
    number of filtering devices between the two ends, however, within TCP,
    which is what we are talking about here, an open port will respond to a
    syn with a syn/ack.

    As for scan methods, I tend to use both syn and full (where time
    permits) if time is not the key, I prefer to syn scan first then TCP
    Connect.

    With regards answering the questions you could, if you are not happy
    with the sniffer options use something like hping2(3) and watch the
    flags ie

    Hping2 -n -V -S -p (port no.) IP_address

    Paul.

    Confidentiality Notice

    The information contained in this electronic message and any attachments to this message are intended
    for the exclusive use of the addressee(s) and may contain confidential or privileged information. If
    you are not the intended recipient, please notify the sender at Wipro or Mailadmin@wipro.com immediately
    and destroy all copies of this message and any attachments.

    ------------------------------------------------------------------------------
    FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't

    Learn the hacker's secrets that compromise wireless LANs. Secure your
    WLAN by understanding these threats, available hacking tools and proven
    countermeasures. Defend your WLAN against man-in-the-Middle attacks and
    session hijacking, denial-of-service, rogue access points, identity
    thefts and MAC spoofing. Request your complimentary white paper at:

    http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801
    -------------------------------------------------------------------------------


  • Next message: houseofdabus: "(MS05-039) Microsoft Windows Plug-and-Play Service Remote Overflow (Universal Exploit + no crash shellcode)"

    Relevant Pages

    • Re: Help! Can I do this for under $400?
      ... >firewall, and I have being so dissappointed about the crap they sell at ... >stores like Best Buy CANNOT do address filtering. ... >> B. Public to access any of the web servers using only port 80 or SSL ...
      (comp.security.firewalls)
    • Re: keeping ports open
      ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
      (microsoft.public.security)
    • Re: How to Maintain an IIS Server?
      ... > server running on a Windows 2000 server. ... before a firewall and antivirus have been installed]. ... open ports; however, this will not identify which program is using the port. ...
      (microsoft.public.inetserver.iis.security)
    • Re: CEICW fails at firewall config
      ... ISA Server prevents connection to a remote desktop when you connect through ... Remote Web Workplace on a Windows Small Business Server 2003-based computer ... Acceleration Server as a firewall. ... connection uses TCP port 4125. ...
      (microsoft.public.windows.server.sbs)
    • Re: Help! Can I do this for under $400?
      ... >filtering, is missing. ... According to the FAQ of a firewall group, ... >destination addresses and port numbers. ... We have 3 web servers on the LAN ...
      (comp.security.firewalls)

  • Quantcast