RE: Simple Scan

From: Brandon Enright (bmenrigh_at_ucsd.edu)
Date: 02/18/05

  • Next message: Jonathan Glass: "Re: RealVNC / Windows 2000 Security"
    To: "'Paul Selibas'" <gotiex@yahoo.com>, <security-basics@securityfocus.com>
    Date: Thu, 17 Feb 2005 21:06:41 -0800
    
    

    With nmap <www.insecure.org>:

    nmap -P0 -p 3321 AAA.BBB.CCC.DDD/MM

    So -P0 says don't ping. -p 3321 says probe only that port. You may want to
    turn on verbose mode with -v. If you aren't root/administrator you'll only be
    able to run a TCP Connect. If you are root/administrator you can run a
    half-open TCP scan. If you want to probe for UDP ports use -sU. UDP can have
    unpredictable results depending on the target OS.

    Hosts that are down/firewalled will come back with port filtered status.

    -----------------------
    Brandon Enright
    ACS/Network Operations
    bmenrigh@ucsd.edu

    > -----Original Message-----
    > From: Paul Selibas [mailto:gotiex@yahoo.com]
    > Sent: Tuesday, February 15, 2005 11:14 PM
    > To: security-basics@securityfocus.com
    > Subject: Simple Scan
    >
    > Greetings all...
    >
    > I am looking for a way to check which hosts are up
    > and have port 3321 open on my network. But i dont
    > want to ping, is there no way of just probing port
    > 3321 and reporting back if it is open or not?
    >
    > Many Thanks
    >
    >
    >
    >
    >
    > __________________________________
    > Do you Yahoo!?
    > Yahoo! Mail - Find what you need with new enhanced search.
    > http://info.mail.yahoo.com/mail_250


  • Next message: Jonathan Glass: "Re: RealVNC / Windows 2000 Security"

    Relevant Pages

    • re: Port 1025 - Network Blackjack
      ... > I need some info on a Port 1025 UDP and TCP which is ... > registered to network blackjack. ... > I simply couldn't find anything on this port. ... Do You Yahoo!? ...
      (Security-Basics)
    • Re: excessive TCP dulplicate acks revisted
      ... The tcp duplicate ACK attack is back. ... there was a thread on duplicate TCP acks in -CURRENT. ... TCP STREAM TEST from localhost port 0 AF_INET to greenhouse- george.18clay.com port 0 AF_INET ... Socket Socket Message Elapsed ...
      (freebsd-current)
    • excessive TCP dulplicate acks revisted
      ... The tcp duplicate ACK attack is back. ... there was a thread on duplicate TCP acks in -CURRENT. ... TCP STREAM TEST from localhost port 0 AF_INET to greenhouse- george.18clay.com port 0 AF_INET ... Socket Socket Message Elapsed ...
      (freebsd-current)
    • Re: How to tell if a firewall alert is suspicious or not
      ... > WHY this SBCGlobal DNS server would be contacting Adobe Acrobat on port ... They have to parts, a kernel and the userland, in which programs, which are ... With Internet Protocol and TCP it is so, that any network interface in the ... To initiate a TCP connection, first the server has to "listen" on a port. ...
      (comp.security.firewalls)
    • RE: Configure Hardware Firewall for SBS 2003
      ... the corresponding ports to the SBS box. ... When a router is deployed at the SBS end, you must forward the port numbers ... TCP 110 This port is used for POP3 mail clients. ... TCP 1723 PPTP VPN connection ...
      (microsoft.public.windows.server.sbs)