Penetration Testing mailing list archives
Re: nmap results
From: Brian Smith-Sweeney <bsmithsweeney () nyu edu>
Date: Sun, 11 Sep 2005 21:55:29 -0400
Mohamed Abdel Kader wrote:
Hello All, I have recently been doing some scans and in some cases nmap returns many ports to be open. the weird thing is that the ports are sequential. i know many of you might be tempted to say its a honeypot but i know for afact its not. does anyone know why does this happen and how?Thanks in advance.
Need more information. What type of nmap scan are you running (syn, connect, UDP, etc.)? What OS are you running it from? Can you give examples of some of the targets? What type of gear is between you and the targets? Have you run a sniffer on at least the source side of the scan, and preferably the destination side as well (assuming you have permission to be pen-testing these networks)? If not, do that. If so, what are the results? Does what your seeing match up with what nmap is reporting?
The $10k question you need to be asking yourself is "what causes nmap to report a port as open for the type of scan I'm running?" Then you can try to figure out why that condition may be occurring in this situation. Answers to the questions above should help you figure that out.
Cheers, Brian -- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Brian Smith-Sweeney Sr. Network Security Analyst ITS Technology Security Services, New York University bsmithsweeney () nyu edu http://www.nyu.edu/its/security ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ------------------------------------------------------------------------------Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at:
http://www.securityfocus.com/sponsor/pen-test_050831 -------------------------------------------------------------------------------
Current thread:
- nmap results Mohamed Abdel Kader (Sep 11)
- Re: nmap results Tim (Sep 12)
- <Possible follow-ups>
- Re: nmap results Christine Kronberg (Sep 12)
- RE: nmap results Bill Louis (Sep 12)
- Re: nmap results King Fuddler (Sep 12)
- Re: nmap results Fósforo (Sep 12)
- Re: nmap results Brian Smith-Sweeney (Sep 12)
