Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: What is this situation???

Subject: Re: What is this situation???
Date: Tue, 8 Apr 2008 16:28:58 -0400

A SYN scan is a "half open" scan:

http://www.google.com/search?hl=en&q=nessus+syn+scan+half+open&btnG=Google+Search
http://www.edgeos.com/nessuskb/results.cgi?gui_section=&kw=generate&nessusrc_section=

From the scond URL, under SYN:

"This technique is often referred to as "half-open" scanning, because you do not open a full TCP connection. You send a SYN packet, as if you are going to open a real connection and you wait for a response. A SYN|ACK indicates the port is listening. A RST is indicative of a non- listener. If a SYN|ACK is received, a RST is immediately sent to tear down the connection (actually our OS kernel does this for us). The primary advantage to this scanning technique is that fewer sites will log it."




On Apr 8, 2008, at 4:13 PM, francesco sottini wrote:

How can i set the SYN scan "half open"?
remember that i am using the nessus server...

thanks!

On Tue, Apr 8, 2008 at 7:07 PM, Michel Arboi <mikhail@nessus.org> wrote:
Le Tue, 8 Apr 2008 18:06:35 +0200,
"francesco sottini" <francesco.sot@gmail.com> a écrit :


> Nmap with Xmas tree scan setted,  i obtain that whatever port number
> i scan, it is open and no other information.

That's normal if the machine is unresponsive.
Xmas Tree portscan is useless for a vulnerability audit. Use SYN "half
open" scan or full TCP scan.



--
Francesco S. _______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus
<Prev in Thread] Current Thread [Next in Thread>