Re: Hidden Ports

From: Geoff Beier (geoff_at_mollyandgeoff.com)
Date: 02/03/04

  • Next message: Jason Haith: "File Catching Firewall?"
    Date: Tue, 03 Feb 2004 15:21:25 -0500
    To: Eduardo Sorensen <ovo@osite.com.br>
    
    

    Eduardo Sorensen wrote:

    > Can a port scanner not see a port that is opened?
    >
    > The question is: can a backdoor be on a machine, and with nmap -p 1-,
    > for example, you couldn't see it?
    >
    A backdoor could certainly be constructed that way, though I'm not aware
    of any that are "out of the box". For example, I could build a backdoor
    that does not listen on any port until it detects connection attempts to
    closed ports 1026,1027,1029,1034,1026,1044 and 1035 in that sequence
    within 5 seconds, then listens on port 60006 for 10 seconds.

    Here's a site that describes the concept in more detail:
    http://www.portknocking.org/

    Like I said, though, I'm not aware of any specific backdoor (other than
    one I've seen built in a lab :-)) that does this.

    Regards,

    Geoff

    ---------------------------------------------------------------------------
    Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any
    course! All of our class sizes are guaranteed to be 10 students or less.
    We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention,
    and many other technical hands on courses.
    Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off
    any course!
    ----------------------------------------------------------------------------


  • Next message: Jason Haith: "File Catching Firewall?"

    Relevant Pages

    • Re: Hidden Ports
      ... >> Can a port scanner not see a port that is opened? ... > is received, then the backdoor isn't listening, and thus wouldn't show ... > David J. Bianco ... We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, ...
      (Security-Basics)
    • Re: Hidden Ports
      ... > Can a port scanner not see a port that is opened? ... certain trigger arrives via one of the already-open services. ... is received, then the backdoor isn't listening, and thus wouldn't show ... We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, ...
      (Security-Basics)
    • Re: increase of scans against port 1524
      ... this port as a backdoor for most automated attacks. ... to finding compromised systems. ...
      (Incidents)
    • RE: Hidden Ports
      ... like renaming their backdoor to winmgnt.exe, lsass.exe, svchost.exe etc. ... will try to connect from port 1 to 100, ... MS patch MS patches the correct way, rootkits patch the wrong ...
      (Security-Basics)
    • Re: ssh and ids
      ... NeVO 1.0 when the backdoor shell or high port SSH daemon was used. ... or encrypted sessions going to or from your servers. ...
      (Focus-IDS)