Nmap Development mailing list archives

broken CRC


From: Ed3f <ed3f () antifork org>
Date: Sun, 11 Dec 2005 02:44:22 +0100


Near the end of 2002 I wrote something for Phrack* and discussed with Fyodor 
if those features could be included in nmap. That was not the right time, but 
things have changed, and recently Fyodor suggested me to post on this list to 
get ideas, and plan how to implement the broken CRC stuff.

* http://www.phrack.org/phrack/60/p60-0x0c.txt


There are a lot of ways and places to play with broken checksums, so I'm 
writing a couple of ideas...

1) BadTCP scan
2) BadUDP scan
3) add a TCP/UDP/ICMP/IP CRC test on OS detection engine
4) add a global CRC option that tells nmap to always use invalid CRC;
useful for host discovery, idle scan, spotting firewalls, and so on...


Some black boxes out there keep accepting broken CRC streams, or even better 
forward them via another TCP connection (proxy!), so we could be able to use 
nmap's version detection sending only invalid packets. Wunderbar!



_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev


Current thread: