Re: Does a security scanning program needs to know the OS's of the machines being scanned?

From: Lassi Hippeläinen (lahippel_at_ieee.orgies.invalid)
Date: 05/25/04


Date: Tue, 25 May 2004 09:10:04 GMT

Ricardo wrote:
>
> Does a security scanning program needs to know the operating systems
> of the machines being scanned? In other words, does the security
> scanning program perform different security tests depending on the
> operating system of the machine being scanned?

Yes. Actually, one of the first things a scanner does is to figure out
the OS. Most of them leak the information in plain text in plain text,
including version number and distribution source. Otherwise you can test
specific features, e.g. how it handles TCP errors (number of
retransmits, their timing, etc.).

-- Lassi



Relevant Pages

  • Does a security scanning program needs to know the OSs of the machines being scanned?
    ... Does a security scanning program needs to know the operating systems ... of the machines being scanned? ...
    (comp.security.misc)
  • Re: the exploit that wasnt
    ... The other Mac Book Pro? ... brought Microsoft into a security discussion about Mac OS X. ... The number of security patches, ... if you were to scan random machines on the internet for a week, how many Unix machines do you believe you would hit? ...
    (comp.sys.mac.advocacy)
  • Re: Cryptogram Comment
    ... Or had to go through setting up basic security for their ... > bother me with Windows questions. ... > machines are broken. ... and Linux and other open OS's make all patches FREE to redistribute. ...
    (sci.crypt)
  • Re: Temporary Ban On Links In Posts To SRI
    ... understand that there is a risk when clicking ... low)" in the general case does not apply to SRI. ... implement the security measures recommended. ... update" even with machines that are restricted to only applications ...
    (soc.religion.islam)
  • Re: the exploit that wasnt
    ... The other Mac Book Pro? ... brought Microsoft into a security discussion about Mac OS X. ... The number of security patches, ... if you were to scan random machines on the internet for a week, ...
    (comp.sys.mac.advocacy)