Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: Nessus reports all ports open

Subject: Re: Nessus reports all ports open
Date: Sat, 22 Dec 2007 16:21:16 +0200
Dear Michel

Thank you for your help, I was able to identify the cuplrit..I am running
the latest nessus on my Ubuntu laptop. The other computer on the network are
all mine.

Laptop <----------Wireless Medium-----192.168.0.0/24----->LinkSys Wireless
Router (Wan Port)<--------192.168.10.024---Eth Cable--->XP + ICS

The problem was with the LinkSys Wireless router, I have no fancy config on
it and no firewall, however whatever host I scan behind the linksys router
would turn all ports as open. I disabled routing on the router and used it
as a wireless access point and pluged the cable to the ICS computer into a
switch port that way my gateway and natting device became the XP with ICS.
This solved the problem..it is weird though I dont know why the linksys
router would do that.

Thx

On Dec 22, 2007 11:38 AM, Michel Arboi <mikhail@nessus.org> wrote:

On Sat, 22 Dec 2007 02:31:10 +0200
"Ali Jawad" <alijawad1@gmail.com> wrote:

I tried the netstat scanner ..

There is no way that netstat can report all ports open, unless you
found a very odd bug (you'd be the first to see it).
However, if you select multiple port scanners, the results are
_merged_. If a portscanner is confused and reports all ports as open,
then the other scanners are useless.

Disable all scanners but nessus_tcp_scanner, and run Nessus against
127.0.0.1 (localhost). That way, we'll see if it is a mysterious bug or
not.

the nessus tcp scanner and I tried multiple hosts with the same results.

I think there is a Labrea or some facetious IPS on your network.
If the targets are on the same physical network, you can check who
sends the packets by sniffing the network traffic: look at the Ethernet
addresses.

By the way, when you scan a whole network, do you find all IP up or
only some of them?

You did not give any information on your configuration: OS, Nessus
version, etc.




-- 
-- 
With Regards
Ali Jawad System Administrator
Phone   : +961-01-559031
Mobile  : +961-03-041705


----------------------------------------------------


Confidentiality Notice: The contents of this E-mail are intended for the
named recipient only. It may contain confidential and privileged
information. If you received it in error, please notify us immediately and
then destroy it. Internet communications are not secure and therefore
I do we do not accept legal responsibility
for the contents of this message. Also, and though we provide every effort
to keep our network free from viruses, you would need to check this E-mail
and any attachments for viruses as we can take no responsibility for any
computer virus which might be transferred by way of this E-mail.
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus
<Prev in Thread] Current Thread [Next in Thread>