pen-test
[Top] [All Lists]

Re: Port Scanning Issues

To: crumdub12@gmail.com
Subject: Re: Port Scanning Issues
From: Vijay <zion.den@gmail.com>
Date: Tue, 26 Jun 2007 18:24:48 +1000
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:user-agent:mime-version:to:cc:subject:references:in-reply-to:content-type:content-transfer-encoding; b=PHQ1KYungDuvC+5qE2mGOVJmk+d2dBVFOPJyD7VRwX1ZG/XJNkbFzrArGCpPLnbgrY4JsV3kH84R9oUVQkbbBMihpnaVfZW07z3EneCvmonzVBVNd8+wPol4YYu1aPUaaoaNZGyz1J43We86L3pKMm0QsLm3K64ty3Bic/tbAW0=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:user-agent:mime-version:to:cc:subject:references:in-reply-to:content-type:content-transfer-encoding; b=BeUwn7dY+bOU3ehCSqDjAiHnCi4yEG3ob1JN5nsOihYdLS6UEEb2hBHTzPglNeoNJzyN8X63NywTDzZpW0mfkEQr097xRMtoZLZoj3TYW0SLURd75JRqtRMYf3sjDwMMLujwpLnjo3njYTAWv/Uo4/+aLC9phjWEcgikKm5dbJI=
In-reply-to: <20070625215958.25364.qmail@securityfocus.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <20070625215958.25364.qmail@securityfocus.com>
Resent-date: Tue, 26 Jun 2007 17:58:21 -0600 (MDT)
Resent-from: pen-test-return-1078484469@securityfocus.com
Resent-message-id: <20070626235821.2188C1442EA@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Thunderbird 2.0.0.4 (X11/20070617)
Hi Chaidre,

You could use the Connect scan option in nmap to get a more reliable scan. saying that i just realize that there are firewalls/load balancers that will respond with a SYN-ACK for every port, in that case i would say only when you send a data part of the connection after the ACK will you know if the port is really open. (people correct me if i am wrong). Hope it was of some help.

Regards
Vijay

crumdub12@gmail.com wrote:
A Chairde,


   Havin, some issues with scanning stacks on my system.


1. Using Superscan4 , I scan stack UDP-TCP 1-65534 , Sometimes I
get no ports open , another time I get 49159 UDP Ports open, only get port 
report, no attempt made to open any ports ... , when get open ports , I always 
get 49159 UDP Ports ...... , use the scanner at 250msecs , takes around 16 
hours to finish.


2. Using Languard, Nessus and Retina , get different scans from each tool, any 
ideas why, how do I find out real ports open.. differences can be 10,000 ports



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>