Nessus
[Top] [All Lists]

Re: Port scan

To: "Scott Pate" <spate@Spohncentral.com>
Subject: Re: Port scan
From: Michel Arboi <mikhail@nessus.org>
Date: Tue, 23 Jan 2007 22:44:36 +0100
Cc: Nessus@list.nessus.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: Nessus@list.nessus.org
In-reply-to: <C565AB59099A9645ACBEA5E7D52CAB5A706100@EX.spohn.central>
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
Organization: Compilo ergo sum
References: <C565AB59099A9645ACBEA5E7D52CAB5A706100@EX.spohn.central>
Sender: nessus-bounces@list.nessus.org
On Tue, 23 Jan 2007 07:45:55 -0600
"Scott Pate" <spate@Spohncentral.com> wrote:

> I ran into this problem the other day running a port scan (1-65535)
> on a firewall (which dropped all packets - no open or closed ports)

Considering what happened, I suspect that your firewall does not "drop"
packets but rather "rejects" them with ICMP messages.

> When using nessus_tcp_scan, the 'portscan' status bar for the host
> would get all the way to the end, and then start over from the
> beginning.

Yes, that's normal. In some cases, nessus_tcp_scanner runs additionnal
passes.

> It did this for about 4 hours until I stopped it.

Mmmhhhh... Disappointing :(

> Is this expected behavior from these scanners? 

If this target IP really _drops_ all packets, definitely not. I'll
double check and keep you in touch anyway.
If it answers with ICMP messages which are often limited (8 / s on
Linux), the scanners can be awfully slow.
 
Any idea on the remote host OS and packet filter?
Which was the value of max_check?
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>