Re: ftp server question



TwistyCreek wrote:

Rick Merrill <rick0.merrill@xxxxxxxxxxxxxxx> wrote:


Maybe you can tell us HOW these attackers find the IP numbers of
systems that are running FTP (or others services) ???


Too easy. Nmap is more than capable of scanning huge chunks of the net
for specific services and spitting out nicely formatted lists. And I'd
wager there's specialized software for people who are too script kiddie
to figure out nmap.

The standard practice as I understand it is to run your scans and sit
on the results for a while, or trade them with your buddies. Then some
time later or from another location launch your "attack" so that it's
harder to figure out where it's really coming from.

That innocent looking port scan you see in your firewall today could
very likely be the precursor to the attack you're going to experience
next month.


So anyone running an open FTP server has probably already been 'found out' but not everyone runs a log and even fewer probably check it!

THe only account they have tried Does Not Exist!

Is a VPN the only way to protect against this scanning?
.



Relevant Pages

  • Re: ftp server question
    ... Nmap is more than capable of scanning huge chunks of the net ... time later or from another location launch your "attack" so that it's ...
    (alt.computer.security)
  • Re: Advice on Fastest NMAP Scan
    ... when I try nmap scanning within Nessus, it just take ages to finish the ... initial scanning process. ... or just a local network? ...
    (Security-Basics)
  • Evading and profiling nmap filters.
    ... No matter what options I try nmap says that the remote host is turned off or is filtrating ICMP requests. ... When I'm scanning from machines that are on a different AS I have no problems. ...
    (Pen-Test)
  • Nmap 3.00 Released -- http://www.insecure.org/
    ... I am pleased to announce the immediate, free availability of the Nmap ... scanning techniques (determine what services the hosts are offering), ... o Added ICMP Timestamp and Netmask ping types. ...
    (Bugtraq)
  • Re: XP SP2 nmap incompatibility
    ... > the just-released Microsoft Windows SP2. ... When an Nmap user asked MS why security tools ... in between scanning subnets here on the network, ... nmap correctly identified the open ports and what OS it was running. ...
    (NT-Bugtraq)

Quantcast