OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
RE: Disovering hosts using UDP services

From: TURPIN Marc IT&Lbs (IT&Lbs)
Date: Fri Sep 05 2008 - 02:19:23 CDT


For windows detection you can use DFind

http://heapoverflow.com/f0rums/projects/tools/20-dfind-port-scanner/

Tiny multi-threaded port scanner.

Marc TURPIN
Security Consultant / Consultant Sécurité
Consulting Services, rue de la chataigneraie, BP51766, 35513 CESSON SEVIGNE,
FRANCE
www.orange-business.com

 

-----Message d'origine-----
De : listbouncesecurityfocus.com [mailto:listbouncesecurityfocus.com] De
la part de Gleb Paharenko
Envoyé : jeudi 4 septembre 2008 21:33
À : pen-testsecurityfocus.com
Objet : Disovering hosts using UDP services

Dear list.

Often udp port scanning say with nmap -sU -pPort1,Port2,.. does not
give results as UDP services tends do not respond to malformed
packets. At the same time utilities which send good packets getting
results and allows to enumerate hosts on the net. For example
ike-scan usually give you the VPN endpoints, while nmap will not be
able to do this. Another example - dns server, it will not respond to
nmap UDP packet, but will respond for good dns query.

I'm looking for tools which will allow enumerate
 - dns 53
 - snmp discover 161
 - windows discovery (135,139,138,445,137)
 - ntp discovery 123
 - ms sql 1434

I'm interested on your thoughts about advanced discovery techniques as well.

--
Best regards.
Gleb Pakharenko.
http://gpaharenko.livejournal.com
http://www.linkedin.com/in/gpaharenko

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes in
Securing Web Applications
Get 45 Min Video and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------


  • application/x-pkcs7-signature attachment: smime.p7s