Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Penetration Testing: Re: [PEN-TEST] Firewalking

Re: [PEN-TEST] Firewalking

From: Tom Vandepoel <tom.vandepoel_at_UBIZEN.COM>
Date: Tue, 6 Mar 2001 21:31:52 +0100

Pepijn Vissers wrote:
>
> Hi all,
>
> What would be the best way to determine what kind of firewall is running on
> a server? Especially one that does not give out any banners.
> TCP-fingerprinting is not possible because there are no obvious open ports.
>

But sometimes there are. Firewall-1 by default opens several ports (e.g.
256/tcp). Some firewalls (Raptor) have several ports open, that are
immediately closed upon connecting to them (tcp-wrapper like).
It's also important to look closely at the responses you get back: if
you're seeing icmp unreach - admin prohibited by filter, you're probably
dealing with IOS acl's.
If you can query snmp on a router in front of the firewall, you can get
the ARP table; from that you can get the ethernet vendor code of the
firewall, which often gives away a lot.

Ofcourse, a firewall that's configured well will not respond to anything
at all and just swallow all your probe packets.

Tom.

--
Tom Vandepoel                 Ubizen
Sr. Security Engineer         We Secure e-Business
Phone   +32 16 28 70 00       http://www.ubizen.com
Fax     +32 16 28 71 00       http://www.securitywatch.com

Received on Mar 06 2001
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos