Nessus
[Top] [All Lists]

Re: Scanning through Windows XP Firewalls

To: darko.gavrilovic@utoronto.ca
Subject: Re: Scanning through Windows XP Firewalls
From: "Doug Nordwall" <raleel@gmail.com>
Date: Mon, 11 Dec 2006 07:06:33 -0800
Cc: nessus@list.nessus.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: nessus@list.nessus.org
Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:references; b=JgJNR7NpVkqJNQvjiMQcTMnddb+8itJrlBOy0xW2+eDLKJ8ROdZLP3QwV+IXgGmgFfaQMPcG2lXCWSeA2HRgSM9M/L2WicbUyhdZADtqfzVmMQNdpHUX5GbGThOcxxig1GEEzaZ5C/YRRq/30V7mhaf23qU9yVicDP6lVLm7IZk=
In-reply-to: <005601c71d35$5cba64a0$ef3d968e@mobile>
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
References: <752305c00612110647i5e406493m8fcb227fd918f366@mail.gmail.com> <005601c71d35$5cba64a0$ef3d968e@mobile>
Sender: nessus-bounces@list.nessus.org
this combined with credentialed checks should find most stuff

On 12/11/06, Darko Gavrilovic <darko.gavrilovic@utoronto.ca > wrote:
You could do & deply a script to allow poke hole in firewall and restrice to your own subnet or scanning host. Type "netsh firewall add portopening /?" at command prompt.
 
Also, refer to this doc for what ports to open.
 
 
Usually all you need is 445 and 135 - 139.
 

cheers,
dg

UOFT/DUA
Tel: 416.978.7719

 


From: nessus-bounces@list.nessus.org [mailto:nessus-bounces@list.nessus.org] On Behalf Of Doug Nordwall
Sent: Monday, December 11, 2006 9:47 AM
To: Wolfgang Kantner
Cc: nessus@list.nessus.org
Subject: Re: Scanning through Windows XP Firewalls

http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/depfwset/wfsp2apa.mspx might give you some ideas on how to do it. I've not tested it though, as I don't have a windows machine handy.

On 12/11/06, Wolfgang Kantner <wolfgang.kantner@boku.ac.at> wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Hello!

We use nessus for network-scanning and are very satisfied, but:
Windows XP-Hosts with firewalls active are a problem.

Is there a registry-key or something thelike to open
host a for the scanning-host?
Or are there other solutions?


Greetings

Wolfgang Kantner

- --
secure by default
http://openbsd.org



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (OpenBSD)

iD8DBQFFfWLAgU6QtVOUt00RAjL3AKCnpJhjan0MHdwRk3l23t2Rk5HUAQCfRypN
eInaj809XsgsEO3jPcpSUcs=
=gFbc
-----END PGP SIGNATURE-----
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus



--
Doug Nordwall
Unix, Network, and Security Administrator
Noise proves nothing. Often a hen who has merely laid an egg cackles as if she laid an asteroid. -- Mark Twain

_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus




--
Doug Nordwall
Unix, Network, and Security Administrator
Noise proves nothing. Often a hen who has merely laid an egg cackles as if she laid an asteroid. -- Mark Twain
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus
<Prev in Thread] Current Thread [Next in Thread>