OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Open ports

From: Todd Haverkos (infosechaverkos.com)
Date: Fri Aug 15 2008 - 17:34:50 CDT


skynetonsecuritygmail.com writes:

> Hi Guys,
>
> I am doing pen-testing for pool of IP's, During pen-test I observed
> that some IP's are giving all ports open i.e. 65535 in NMAP
> result & Nessus is giving empty result.
>
> What could be the reason for this?

More than likely, a firewall between you and the targets.

What options are you handing to nmap?

Fyodor's (nmap's lead author) very useful nmap presentation is at
http://insecure.org/presentations/BHDC08/ and svn links to the latest
version of it are in the presentation.

The --reason flag is rather useful in solving some of these
mysteries. You also might be interested in the difference in how
various discovery methods vary against stateful firwealls and
non-stateful packet filtering firewalls (slides 8 and 9).

Best Regards,
--
Todd Haverkos, LPT MsCompE
http://haverkos.com/

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes in
Securing Web Applications
Get 45 Min Video and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------