pen-test
[Top] [All Lists]

Re: Port Scanning Issues

To: pen-test@securityfocus.com
Subject: Re: Port Scanning Issues
From: ebk_lists@hotmail.com
Date: 26 Jun 2007 13:20:56 -0000
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Tue, 26 Jun 2007 17:59:12 -0600 (MDT)
Resent-from: pen-test-return-1078484472@securityfocus.com
Resent-message-id: <20070626235912.97004144CE6@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Since you mention Superscan, I am going to assume that you are doing this on a 
windows system. Most likely a windows XP SP2 system. SP2 drastically changed 
the way the TCP/IP stack works in XP and thus created numerous problems with 
port scanning tools. I can't speak for the other tools you mention, having 
never run them from a windows XP box, but I know for a fact that Superscan 
results are unpredictable after installing SP2. You may want to try making your 
scan smaller, and running 'net stop shared services' before launching your 
scan. Sometimes, running Superscan twice will yield accurate results the second 
time. One last thing you may want to try is to use a full connect scan with 
superscan. This is very noisy, but the syn scan is flaky at best with SP2. 

I've reached the point where I no longer use superscan for these reasons, which 
is unfortunate, because it used to work really well. 

I'm sure others on the list can speak about running the other tools and getting 
better results from them.

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>