Nmap Development mailing list archives

Re: Diet Nmap v3.95 Released


From: Martin Mačok <martin.macok () underground cz>
Date: Wed, 14 Dec 2005 10:37:52 +0100

On Wed, Dec 14, 2005 at 12:58:33AM +0100, uzy wrote:

What about using ICMP echo request/reply for IPID probing ?

Don't you think that should be less "aggressive" or visible than
lots of SYN packets ?

Yes, it could be less visible in some scenarious but not in others ...
Personally, I find ICMP packets generally rarer in traffic so I take
them as more conspicuous. Also, if the zombie host is, say, a mail server
then SYN packets to port 25 are almost invisible (hidden in normal
traffic) ... but it is definitely good idea to implement something
like --ipid_probe_with (icmp_echo|icmp_ts|syn|synack) ...

Another argument is that (IIRC) some hosts reveal their IP ID
sequence in SYN+ACK packets (ie. responses to SYN probe) and not in
RST packets (ie. responses to SYN+ACK probes). Maybe vice versa, can't
remember exactly now...

Martin Mačok
ICT Security Consultant


_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev


Current thread: