Re: Raw sockets vs connect() scanning on windows/linux



On Sun, 2007-10-14 at 18:45 -0700, Erin Carroll wrote:
On the linux side, anyone know which scanners modify the raw socket packet
creation to craft 60 byte packets to mimic exactly the typical connect()
packet to get around products which are smart enough to tell the difference
and change behaviors accordingly?

Unicornscan implements the -W option to mimic different OS's TCP stack
characteristics. It supports sending as a Cisco Router, openbsd,
WindowsXP, FreeBSD, nmap, or Linux stacks by default.

Robert

--
Robert E. Lee
Chief Security Officer
Outpost24 - One Step Ahead
http://www.outpost24.com

SE Phone: +46 40-627-1650
US Phone: +1 801-924-5902
email: robert@xxxxxxxxxxxxx


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: firewall and UDP packets, and errocode 10004
    ... Did you tried to uninstall/install TCP stack, ... Arkady Frenkel wrote: ... MSAFD TCPIP TCP/IP ... I have an application that sends UDP packets. ...
    (microsoft.public.win32.programmer.networks)
  • Re: seeing strange values for tcp sk_rmem_alloc
    ... Might be because you use loopback device? ... After a while, tcp stack performs skb ... Looks like this is indeed the case, changing the loopback mtu to 8K ... will start dropping packets. ...
    (Linux-Kernel)
  • Re: solaris 9 IPQoS examples?
    ... I'm just saying, if I change the TCP stack on the local machine, ... No matter who initiated the ... it's still the remote end that is sending packets ...
    (comp.unix.solaris)
  • Re: solaris 9 IPQoS examples?
    ... > I'm just saying, if I change the TCP stack on the local machine, ... No matter who initiated the ... it's still the remote end that is sending packets ...
    (comp.unix.solaris)
  • Crafting IP packets with DNS queries .........newbie
    ... im looking for some code that can capture the IP packets from my system ... and craft them so that im able to put lots of DNS requests in them and ... is it possible and will the DNS server takes it for legal DNS request ...
    (comp.lang.python)