Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: Discovering network topology

Subject: Re: Discovering network topology
Date: 15 Feb 2007 16:10:01 -0000
Hello Jeremy,

Discovering a network totally depends on the factor from where you are 
discovering it i.e. within the network (inside) or outside the network. 
Off-course discovering network from within the network is far more accurate as 
compared to the external ones. 

If you are absolutely sure that all the computers within the network are 
utilizing Microsoft Windows OS, then a tool called MBSA with Visio connector 
from Microsoft, could help you out in discovering the network topology 
(provided you have Microsoft Visio installed on your system). However third 
party tools like GFI Languard, Superscan or any network security scanner, can 
also help easily to discover the network. Off-course Nmap has always been an 
indispensable tool for network discovery.

Now-a-days scanners and discovery tools are so sophisticated and accurate that 
we can rely on the outputs of these tools without much hesitation. This is 
because the rate of false-positive outputs from these tools has been reduced 
drastically. However for our satisfactions, we could just verify by ourselves 
that the outputs are correct and are not false positives, by manually doing 
telnet to the IP Address and port. 

Besides traceroute (Windows tracert), Windows XP and above OS supports a 
built-in command called pathping which is basically an integration of two 
commands: tracert and ping. The advantages of pathping over ping and tracert 
are that each node is pinged as the result of a single command, and that the 
behaviour of nodes is studied over an extended time period, rather than the 
Ping's default sample of four messages or tracert's default single route trace.

Reference:
MBSA with Visio Connector: 
http://www.microsoft.com/technet/security/tools/mbsavisio.mspx 

GFI Languard: http://www.gfi.com/lannetscan/ 

SuperScan: 
http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/proddesc/superscan.htm
 

Nikhil Wagholikar
Security Analyst

NII Consulting
Web: www.niiconsulting.com

<Prev in Thread] Current Thread [Next in Thread>