Re: Banner Grabbing



On 22/12/06, Michael J Condon <mjc001@xxxxxxxxx> wrote:
What steps can be used to prevent "OS Banner Grabbing" by the client? Also,
what is the best method or "attack" to get to a banner on MS and non MS
Operating Systems?

[resend, bounced due to nonsubscribed address]

Banner grabbing: 'telnet victim.example.com <port>' will often get you
a banner. My favourite is 'nmap -sV victim.example.com' which will do
all the work for you.

To prevent banner grabbing, you can alter or hide banners for various
services, but since many exploits are automated and a lot of people
launch attacks blindly, I don't see this as a must-do item. There are
other ways of identifying services other than reading the welcome
banner, and it won't help you if your service is actually vulnerable.

cheers,
Jamie
--
Jamie Riden, CISSP / jamesr@xxxxxxxxxx / jamie.riden@xxxxxxxxx
NZ Honeynet project - http://www.nz-honeynet.org/



Relevant Pages

  • Re: Banner Grabbing
    ... what is the best method or "attack" to get to a banner on MS and non MS ... Operating Systems? ... You can have a look in irongeek's passive OS fingerprintig video. ...
    (Pen-Test)
  • Re: Banner Grabbing
    ... Michael J Condon a écrit: ... what is the best method or "attack" to get to a banner on MS and non MS Operating Systems? ...
    (Pen-Test)
  • Re: Banner Grabbing
    ... Michael J Condon a écrit: ... Subject: Banner Grabbing ... what is the best method or "attack" to get to a banner on MS and non MS Operating Systems? ... With a simple telnet client you can grab almost all banners, but netcat is the most recommended tool for this kind of job. ...
    (Pen-Test)
  • Re: Prevent banner grabbing
    ... >> How could I prevent a banner grabbing? ... > so that connecting clients can determine what protocol versions to ... The protocol requires the first part of the banner to be sent. ...
    (SSH)
  • Banner Grabbing
    ... What steps can be used to prevent "OS Banner Grabbing" by the client? ... what is the best method or "attack" to get to a banner on MS and non MS Operating Systems? ...
    (Pen-Test)

Quantcast