Hi,
> What would be the best way to determine what kind of firewall is running on
> a server? Especially one that does not give out any banners.
> TCP-fingerprinting is not possible because there are no obvious open ports.
depends, I'd say. If they pass in (and let out) some ICMP types /
codes, you might be able to fingerprint them on that. I think it
was either Dragos Riu or Clayton Fiske, but one of them wrote an
excellent paper about ICMP fingerprinting.
Cheers, Jan
--
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther_at_radio.hundert6.de
Received on Mar 07 2001