Nmap Development mailing list archives

Re: Diet Nmap v3.95 Released


From: uzy <uzy () isecurelabs com>
Date: Wed, 14 Dec 2005 00:58:33 +0100

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

Two question about idle scan :

Martin Mačok wrote:
...
== nmap-3.30-idle.patch ==

This patch allows a user to specify that SYN packets should be sent
to the Idle proxy to probe for IPID rather than the default SYN/ACK.
I can see hypothetical cases where this could be useful, but it is
pretty obscure.  Do you use this a lot?


When I scan through "stateful" firewall I often can't get SYN+ACK
through but I can get SYN through.

(I use it rarely in pentests and a little bit more often as an IDLE
scan demonstration during my occasional pentest lectures.)

What about using ICMP echo request/reply for IPID probing ?

Don't you think that should be less "aggressive" or visible than lots of
SYN packets ?

Regards,
uzy
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (MingW32)

iD8DBQFDn2ApESqHNCSDHZURAtbcAJ9tdryQ3tNqtx9ouw4gW8COTPPsFQCfZiq1
t4i0hFLgQxygQDK4D06CphI=
=nBXG
-----END PGP SIGNATURE-----



_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev


Current thread: