Re: Discrepancies in port scanning = trouble?

From: Thor Kottelin (thor_at_anta.net)
Date: 09/20/03


Date: Sat, 20 Sep 2003 22:54:23 +0300


LRW wrote:

> I used www.grc.com 's Shields Up port scanner, and it found all my
> ports in stealth mode, except 113 visible but closed.
> That worries me.
>
> But even moreso, I used SuperScan by foundstone to do a portscan of my
> IP, I suppose similar to what a scriptkiddie would do, and it found
> ports 25, 80, 110, 2468, 5678, and 6688.

I don't know those scanners, but here's a bunch of wild guesses:

The first scanner found your own system. You like to chat on IRC, so you run
an ident server.

The second scanner found a web proxy. Your ISP is a small-time operation
that uses that same box for mail and other stuff as well.

Some or all of the above is probably wrong, but at least we have a starting
point to discuss from. :-)

Follow-ups narrowed.

Thor

-- 
http://thorweb.anta.net/


Relevant Pages

  • Re: Discrepancies in port scanning = trouble?
    ... > But even moreso, I used SuperScan by foundstone to do a portscan of my ... The first scanner found your own system. ...
    (comp.security.misc)
  • Re: port 12345 windows95/nt
    ... better, format and reinstall everything from scratch, including a virus ... scanner). ... > Sorry for the very basic question. ... > Using superscan I found this port open on my computer. ...
    (Security-Basics)
  • Re: How to locate MSDE installations
    ... I think that Roger has ... tunable scanner for such things, I thank you for reinforcing that point. ... > listening on the SQLSRV port. ... > fscan and superscan, both free from the ...
    (microsoft.public.security)
  • Re: SP2 and Vulnerability Scanners
    ... > Foundstone and they told us their scanner wouldn't work because of ... > the way SP2 firewall works. ... > other network administrator was setting up his new laptop. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: [Full-Disclosure] Another Low Blow From Microsoft: MBSA Failure!
    ... Foundstone and Qualys tools ... > confusing; one would think an assessment tool released by the original ... across scanner reports, it would be real easy to load your network ...
    (Full-Disclosure)