Nmap syn scan problem with Windows 2003 Server

From: Bill Crenshaw (bcrenshaw99_at_yahoo.com)
Date: 01/28/05

  • Next message: Andrew Aris: "RE: IIS6 Security and other web servers"
    Date: Thu, 27 Jan 2005 23:40:52 -0800 (PST)
    To: security-basics@lists.securityfocus.com
    
    

    Hi
     
    I'm having the following problem. When I do a tcp
    connect portscan to a remote host using the following:

    nmap -sT xxx.xxx.xxx.xxx -P0 -p 80

    .... I get the the right response:
     
    Starting nmap V. 3.75 ( www.insecure.org/nmap )
    Interesting ports on (xxx.xxx.xxx.xxx):
    Port State Service
    80/tcp open http
     
    Port shows open...no problems..so far so good
     

    Now when I try to do a syn scan using the following:

    nmap.exe -sS xxx.xxx.xxx.xxx -P0 -p 80

    I get a response saying the port is filtered.
     
    Starting nmap V. 3.75 ( www.insecure.org/nmap )
    Interesting ports on (xxx.xxx.xxx.xxx):
    Port State Service
    80/tcp filtered http
     

    I'm running the same version of nmap on my winxp
    workstation and have no problems. Both the win2003
    server and my workstation are behind the same firewall
    hitting the same ruleset. Also, the win2003 server has
    the lastest updates from MS along with my workstation
    including SP2.
     
    Any ideas or suggestions would be most appreciated.
     
    Thanks in advance
     
    Bill Crenshaw

                    
    __________________________________
    Do you Yahoo!?
    Meet the all-new My Yahoo! - Try it today!
    http://my.yahoo.com
     


  • Next message: Andrew Aris: "RE: IIS6 Security and other web servers"

    Relevant Pages

    • Re: Best Plan of action for 2 forest.......
      ... PortQry reports the status of a port in one of the following ways: ... ..LISTENING This response indicates that a process is listening on the target ...
      (microsoft.public.windows.server.active_directory)
    • RE: MBSA and MSs attempts at "security"
      ... >the port status of TCP and UDP ports on a computer you choose. ... you can also query an LDAP service. ... LDAP query and interpret an LDAP server's response to ...
      (Focus-Microsoft)
    • RE: Using a dynamic request - response port
      ... Saravana Kumar ... I don't have any direct experience working with WSS adapter, ... You need to make sure, you are getting some response back from Sharepoint ... May be its worth investigating using a static solict-response send port ...
      (microsoft.public.biztalk.general)
    • Re: Cant connect to Mailserver
      ... chance yet to dig into the server and find out why. ... When I telnet to port 25 I should get a response from your exchange ... Are the correct ports open in the router? ...
      (microsoft.public.windows.server.sbs)
    • Re: how to set timeout for read command
      ... >> The shell will attempt to connect to that TCP port, get an error response, ... The desired behavior of the program is to ... in response to the refusal to open the connection. ... The remote machine has something listening on the port, ...
      (comp.unix.shell)