RE: Data Interpretation
- From: "David Gillett" <gillettdavid@xxxxxxxx>
- Date: Thu, 19 Mar 2009 17:43:06 -0700
On 2009-03-17 David Gillett wrote:
Neither of these things is happening, and nmap can't tell why not.received back,
SOMETHING must be listening, since no ICMP packet was
but clearly it's not a normal process. The most likely scenario isSYN packet
that a firewall or other security measure is dropping the
without deigning to respond.
Packet filters aren't really listening (at least not in the
TCP sense of the word).
Agreed, although I'd say that this is closer to the English definition
of listen than the TCP sense which carries additional implications.
This is, in fact, exactly what you want.
I have to disagree. What you actually want in a situation
like that is the firewall to respond with a RST.
I'm aware of arguments for and against sending an RST; I considered
them beyond the scope of the present question. But certainly if these
services were merely unsupported and not actively hostile, sending an
RST would be the correct and polite thing to do.
And that would tell nmap that the port was actively being blocked....
David Gillett
------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute
Find the source of cybercrime! Almost every crime today involves a computer or mobile device. Learn how to become a Computer Forensics Examiner in InfoSec Institute's hands-on Computer Forensics Course. Up to three industry recognized certs available, online computer forensics training available.
http://www.infosecinstitute.com/courses/computer_forensics_training.html
------------------------------------------------------------------------
- Follow-Ups:
- Re: Data Interpretation
- From: Ansgar Wiechers
- Re: Data Interpretation
- References:
- Data Interpretation
- From: Michael Lynch
- Re: Data Interpretation
- From: τ∂υƒιφ *
- RE: Data Interpretation
- From: David Gillett
- Re: Data Interpretation
- From: Ansgar Wiechers
- Data Interpretation
- Prev by Date: RE: Placing Test Server in DMZ
- Next by Date: Re: Judge orders defendant to decrypt PGP-protected laptop - CNET News
- Previous by thread: Re: Data Interpretation
- Next by thread: Re: Data Interpretation
- Index(es):
Relevant Pages
|