Nessus
[Top] [All Lists]

RE: Scanning through Windows XP Firewalls

To: <nessus@list.nessus.org>
Subject: RE: Scanning through Windows XP Firewalls
From: "Darko Gavrilovic" <darko.gavrilovic@utoronto.ca>
Date: Mon, 11 Dec 2006 10:02:22 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: nessus@list.nessus.org
In-reply-to: <752305c00612110647i5e406493m8fcb227fd918f366@mail.gmail.com>
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
Organization: University of Toronto
Reply-to: darko.gavrilovic@utoronto.ca
Sender: nessus-bounces@list.nessus.org
Thread-index: AccdM2GF2vkvYRHdSRO5SXRXA+6f3gAAMxIg
You could do & deply a script to allow poke hole in firewall and restrice to your own subnet or scanning host. Type "netsh firewall add portopening /?" at command prompt.
 
Also, refer to this doc for what ports to open.
 
 
Usually all you need is 445 and 135 - 139.
 

cheers,
dg

UOFT/DUA
Tel: 416.978.7719

 


From: nessus-bounces@list.nessus.org [mailto:nessus-bounces@list.nessus.org] On Behalf Of Doug Nordwall
Sent: Monday, December 11, 2006 9:47 AM
To: Wolfgang Kantner
Cc: nessus@list.nessus.org
Subject: Re: Scanning through Windows XP Firewalls

http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/depfwset/wfsp2apa.mspx might give you some ideas on how to do it. I've not tested it though, as I don't have a windows machine handy.

On 12/11/06, Wolfgang Kantner <wolfgang.kantner@boku.ac.at> wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Hello!

We use nessus for network-scanning and are very satisfied, but:
Windows XP-Hosts with firewalls active are a problem.

Is there a registry-key or something thelike to open
host a for the scanning-host?
Or are there other solutions?


Greetings

Wolfgang Kantner

- --
secure by default
http://openbsd.org



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (OpenBSD)

iD8DBQFFfWLAgU6QtVOUt00RAjL3AKCnpJhjan0MHdwRk3l23t2Rk5HUAQCfRypN
eInaj809XsgsEO3jPcpSUcs=
=gFbc
-----END PGP SIGNATURE-----
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus



--
Doug Nordwall
Unix, Network, and Security Administrator
Noise proves nothing. Often a hen who has merely laid an egg cackles as if she laid an asteroid. -- Mark Twain
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus
<Prev in Thread] Current Thread [Next in Thread>