![]() |
Available news archives:
comp.lang.tcl
-
comp.lang.python
-
comp.security.firewalls
-
sci.crypt -
comp.lang.php -
comp.lang.javascript
|
|
comp.security.firewalls archiveRe: nmap inconsistent results - via intermedite router?
From: Moe Trin <ibuprofin@painkiller.example.tld>
Date: Tue Feb 28 2006 - 20:49:15 CET
On 27 Feb 2006, in the Usenet newsgroup comp.security.firewalls, in article
>Thanks for persisting.
Actually, it's not that hard
>SSH-ing into the remote machine (on the internet), I setup
>01:46:55.095342 IP source.2226 > dest.5190: S 4260908126:4260908126(0)
"Hello, I'd like to talk"
>01:46:55.095396 IP dest.5190 > source.2226: R 0:0(0) ack 4260908127 win
"<Hello???> Go away Kid, ya bother me"
In the first packet, the 'S' flag is the SYN of the contact initiation.
>On my local machine (behind the netgear router) I did this...
"Connect to that host on that port? Yeah, I can try that. Hang on..."
>Connected to dest.
"OK, I figured out how - let's see what they have to say"
>Connection closed by foreign host.
"The other end hung up the phone."
>I guess this is good - but not sure about the result. I do not have a
That's correct - no firewall, but also no server listening. The result is
OK, let's repeat this, but run tcpdump on the "local" machine. Look at
Old guy
|