RE: Fingerprinting PIX with nmap



I got the following result while using nmap, the scan of port 25 gives the
firewall brand, what should be the
recommendation to disable that PIX fingerprinting?

Why would you recommend that they do anything about the fact that a port
scanner can identify the version of firewall that they're running? I mean,
aside from the obvious answer that you have no higher severity findings to
report.


I guess disabling the mail guard "fixup smtp" on the pix is not a good
idea.

Not for the sole purpose of avoiding detection by NMap. Know why? Because
the next time you run that scan, NMap will identify the mail server sitting
behind it instead of the PIX proxy. And as recon goes, identifying
OS/app/version of an internal server is more valuable than identifying the
brand (but not specific version) of the border firewall.

PaulM



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • RE: how nmap can know my firewalled servers ?
    ... Are you running Nmap from a machine inside your firewall? ... I know that "nmap" can show open ports. ...
    (Security-Basics)
  • Re: Is my home computer at risk knowing that nmap says...
    ... Not only the firewall, but everything else - yeah, that would not be good. ... as nmap report to me: ... ssh xxx.xxx.xxx.xxx ... I don't _know_ that they have proxy servers, ...
    (comp.os.linux.security)
  • AW: Re: nmap -sS SYN-SCAN does not find all open Ports?
    ... that there is actually no problem with nmap. ... I have a frontend fierwall watchguard and a backend firewall isa. ... in my opinion both -sT and -sS should state all closed ports as filtered. ... Information Security. ...
    (Security-Basics)
  • Re: how nmap can know my firewalled servers ?
    ... How about UDP, if an udp port firewalled, how does NMAP know it? ... Dropping traffic at a firewall violates RFC and makes it ... Try Webroot's Spy Sweeper Enterprisefor 30 days for FREE with no ...
    (Security-Basics)
  • Re: nmap on firewall machine.
    ... I have two NICs in the machne and trying to test how firewall rules work on ... I assume that the source IP would be my firewall IP ... source port for trafic generated by nmap. ... >> ports are open use netstat, to check the firewall functionality invoce ...
    (comp.os.linux.security)