Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: firewalk meets nmap - TTL (fwd)

firewalk meets nmap - TTL (fwd)

From: Lance Spitzner <lance_at_spitzner.net>
Date: Sat, 4 Nov 2000 21:13:33 -0600 (CST)

I sent this off to the nmap-list, was wondering what
all the firewall weenies on board here thought. :0

-- 
Lance Spitzner
http://www.enteract.com/~lspitz
---------- Forwarded message ----------
Date: Thu, 2 Nov 2000 23:00:53 -0600 (CST)
From: Lance Spitzner <lance_at_spitzner.net>
To: nmap-hackers_at_insecure.org
Subject: firewalk meets nmap - TTL
I'm not sure if anyone has thought of this, but this
would be a REALLY cool feature for auditing firewall
rulebases.  Say you want to determine what ports a
firewall allows through, what ports are NOT filtered.
Have the option with nmap to set the TTL on the packets
it sends.  I set the TTL to be the same as the amount
of hops to the firewall I am scanning.  If the packet is
filtered by the firewall, then it is dropped and nothing
is sent back.
However, if the packet is accepted by the firewall (and
the port is not filtered), the firewall will attempt to
forward it.  However, the TTL will now be zero and the
firewall will respond with ICMP TTL expired error message.
You can now map what ports are passed through the firewall
(i.e not filtered) without a packet ever passing through the 
firewall.
firewalk meets nmap
thoughts?
-- 
Lance Spitzner
http://www.enteract.com/~lspitz
_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_nfr.com
http://www.nfr.com/mailman/listinfo/firewall-wizards
Received on Nov 06 2000
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]