Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: All tcp ports open? |
|---|---|
| Date: | Tue, 31 Aug 2004 10:11:33 +0100 |
I do not think this is the tool you've got in mind, but what I have done some
months ago is the following:
- download iptrap (www.jedi.claranet.fr),
- create a script that launches if on each port between, let's say,
1-1024
- then running an nmap or nessus or whatever more againt it, will give
all the ports open.
That's maybe not the smarter solution, but without spare time... :)
I am not a honeypot's guru, but maybe a honeypot as Specter, DTK or HoneyD can
do this, correct me if I am wrong...
-----Message d'origine-----
De : Beaty, Bryan [mailto:Bryan.Beaty@vector.com]
Envoyé : lundi 30 août 2004 20:18
À : Todd Towles; Don Parker; asp@webexc.com; pen-test@securityfocus.com
Objet : RE: All tcp ports open?
I know there is a hardware device that does this. I cannot for the life of me
remember the name but I have seen it used by several banks. It intentionally
shows all ports open making port scanning almost useless.
I would love to know the name of the appliance if anybody knows it.
-----Original Message-----
From: Todd Towles [mailto:toddtowles@brookshires.com]
Sent: Monday, August 30, 2004 8:15 AM
To: Don Parker; asp@webexc.com; pen-test@securityfocus.com
Subject: RE: All tcp ports open?
It is a proactive defense measure most likely. Hard to tell what services are
up and running if all the ports return SYN/ACK when scanned with a SYN scan.
This is talked about in "Hacking: The Art of Exploitation" by Jon Erickson.
Very good book. All of this was pointed out by another fellow member eariler.
-----Original Message-----
From: Don Parker [mailto:hydra291@hotmail.com]
Sent: Sunday, August 29, 2004 4:37 PM
To: asp@webexc.com; pen-test@securityfocus.com
Subject: RE: All tcp ports open?
Hello Ben, it makes absolutely no sense that there is a service listening on
every TCP port at all. Are you sure? Could you perhaps paste the hping o/p
here? Lastly if the handshake are not completed the connection may not be
handed to the internal network if there is a f/w in front of it, which
validates the handshake. More info as to what you are trying to get past O/S
wise as well as network topology would be most helpful.
Cheers,
Don
----------------------------------------
Don Parker, GCIA
Intrusion Detection Specialist
1.613.302.2910(c)
----------------------------------------
From: Ben Timby <asp@webexc.com> To: pen-test@securityfocus.com Subject: All tcp ports open? Date: Sun, 29 Aug 2004 02:04:08 -0500 I am not sure what is doing this, but I assume it is a software (or some kind of) firewall/hids, can anybody point me in the right
direction?
I am pen-testing a Windows webserver, and a port scan reveals ALL tcp ports open. hping also confirms that a SA is returned for any S packets
sent to any port I try. I can connect via netcat any of the ports, and send data, but nothing is returned. In order to verify services, I am required to connect and check for a banner or send appropriate protocol
commands to elicit a response. Has anyone seen this, or have any idea of what this is? Thanks. ----------------------------------------------------------------------- ------- Ethical Hacking at the InfoSec Institute. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one
interaction with one of our expert instructors. Check out our Advanced Hacking course, learn to write exploits and attack security infrastructure. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. http://www.infosecinstitute.com/courses/ethical_hacking_training.html ----------------------------------------------------------------------- --------
_________________________________________________________________ Take charge with a pop-up guard built on patented Microsoft(r) SmartScreen Technology. http://join.msn.com/?pgmarket=en-ca&page=byoa/prem&xAPID=1994&DI=1034&SU =http://hotmail.com/enca&HL=Market_MSNIS_Taglines Start enjoying all the benefits of MSN(r) Premium right now and get the first two months FREE*. ------------------------------------------------------------------------ ------ Ethical Hacking at the InfoSec Institute. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. Check out our Advanced Hacking course, learn to write exploits and attack security infrastructure. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. http://www.infosecinstitute.com/courses/ethical_hacking_training.html ------------------------------------------------------------------------ ------- ------------------------------------------------------------------------ ------ Ethical Hacking at the InfoSec Institute. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. Check out our Advanced Hacking course, learn to write exploits and attack security infrastructure. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. http://www.infosecinstitute.com/courses/ethical_hacking_training.html ------------------------------------------------------------------------ ------- ------------------------------------------------------------------------------ Ethical Hacking at the InfoSec Institute. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. Check out our Advanced Hacking course, learn to write exploits and attack security infrastructure. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. http://www.infosecinstitute.com/courses/ethical_hacking_training.html ------------------------------------------------------------------------------- ------------------------------------------------------------------------------ Ethical Hacking at the InfoSec Institute. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. Check out our Advanced Hacking course, learn to write exploits and attack security infrastructure. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. http://www.infosecinstitute.com/courses/ethical_hacking_training.html -------------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Test scripts for NIDS, Stong, Ian C. (Contractor) |
|---|---|
| Next by Date: | Craking Serv-u passwords stored in .ini file., [Arcangel] |
| Previous by Thread: | RE: All tcp ports open?, Beaty, Bryan |
| Next by Thread: | RE: All tcp ports open?, Altheide, Cory B. (IARC) |
| Indexes: | [Date] [Thread] [Top] [All Lists] |