Home page logo
/

pen-test logo Penetration Testing mailing list archives

Re: nmap results
From: Brian Smith-Sweeney <bsmithsweeney () nyu edu>
Date: Sun, 11 Sep 2005 21:55:29 -0400

Mohamed Abdel Kader wrote:
Hello All,
I have recently been doing some scans and in some cases nmap returns many
ports to be open. the weird thing is that the ports are sequential.
i know many of you might be tempted to say its a honeypot but i know for a
fact its not. does anyone know why does this happen and how?
Thanks in advance.


Need more information. What type of nmap scan are you running (syn, connect, UDP, etc.)? What OS are you running it from? Can you give examples of some of the targets? What type of gear is between you and the targets? Have you run a sniffer on at least the source side of the scan, and preferably the destination side as well (assuming you have permission to be pen-testing these networks)? If not, do that. If so, what are the results? Does what your seeing match up with what nmap is reporting?

The $10k question you need to be asking yourself is "what causes nmap to report a port as open for the type of scan I'm running?" Then you can try to figure out why that condition may be occurring in this situation. Answers to the questions above should help you figure that out.

Cheers,
Brian

--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Brian Smith-Sweeney
Sr. Network Security Analyst
ITS Technology Security Services, New York University
bsmithsweeney () nyu edu
http://www.nyu.edu/its/security
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault