RE: nmap showing port 21 (ftp) open, but port is actually closed

From: Drage, Nick (nick.drage_at_eds.com)
Date: 09/16/05

  • Next message: Omar A. Herrera: "RE: root kit detection/penetration"
    Date: Fri, 16 Sep 2005 12:43:58 +0100
    To: <pen-test@securityfocus.com>
    
    

    >Is it 'closed' or firewalled? A firewalled port will show as
    >filtered since it will not receive the response reporting that
    >it is closed.
    >Therefore, it cannot be distinguished between open/filtered.

    I presume that you're referring to UDP scans, whereas for this FTP
    related issue its likely that TCP is being used. If not please explain,
    because I'm missing something if that's the case.

    -- 
    Nick Drage
    EDS UK Penetration Testing Team
    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner: 
    Hackers are concentrating their efforts on attacking applications on your 
    website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
    futile against web application hacking. Check your website for vulnerabilities 
    to SQL injection, Cross site scripting and other web attacks before hackers do! 
    Download Trial at:
    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------
    

  • Next message: Omar A. Herrera: "RE: root kit detection/penetration"

    Relevant Pages

    • Re: nmap showing port 21 (ftp) open, but port is actually closed
      ... > Has anyone ever seen this before, nmap is showing port 21 to be open on ... Firewalls often make port 21 appears to be opened. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: NAT is present?
      ... Some firewalls act as proxies as well, ... >PORT STATE SERVICE ... >Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: VOIP Security
      ... where each of has own specific vulnerabilities. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ... login pages, dynamic content etc. Firewalls, SSL and locked-down servers are ...
      (Pen-Test)
    • Re: Tools/Software Toolkits
      ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... > login pages, dynamic content etc. Firewalls, SSL and locked-down servers are ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • RE: nmap results
      ... Is these sequential ports udp or tcp, and if u r scaning against a firewall? ... Audit your website security with Acunetix Web Vulnerability Scanner: ... login pages, dynamic content etc. Firewalls, SSL and locked-down servers are ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)

  • Quantcast