Linux Netfilter discussions
 help / color / mirror / Atom feed
* Defeating NMAP Null scans (and Nessus scans).
@ 2005-06-22 12:28 Jason Ziemba
  2005-06-22 12:52 ` Jan Engelhardt
  0 siblings, 1 reply; 17+ messages in thread
From: Jason Ziemba @ 2005-06-22 12:28 UTC (permalink / raw)
  To: netfilter

I am attempting to secure a new machine and thought I did until I ran NMAP's
Null scan (which sends no TCP flags).  NMAP was able to determine just about
every port running on the machine, and Nessus found more (even though a
standard TCP Connect and SYN scan found exactly what I wanted). 

I tried a number of TCP Flag combination rules in IPTables attempting to
filter out these scans and was unsuccessful.  Does anybody know how to
successful conceal your machine from these scans (while still allowing the
ports that 'should' be open to function correctly)?



^ permalink raw reply	[flat|nested] 17+ messages in thread

end of thread, other threads:[~2005-07-09 10:30 UTC | newest]

Thread overview: 17+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-06-22 12:28 Defeating NMAP Null scans (and Nessus scans) Jason Ziemba
2005-06-22 12:52 ` Jan Engelhardt
2005-06-22 16:47   ` R. DuFresne
2005-06-22 16:59     ` Jan Engelhardt
2005-06-22 19:26       ` R. DuFresne
2005-06-23 11:07         ` Jan Engelhardt
2005-06-24 15:17           ` R. DuFresne
2005-06-29 19:37             ` Kirk
2005-06-30  9:47             ` Kirk
2005-07-06 19:54           ` curby .
2005-07-07  7:13             ` Jörg Harmuth
2005-07-09 10:30             ` Jan Engelhardt
2005-06-22 20:26       ` Taylor, Grant
2005-06-22 20:37         ` Alexey Toptygin
2005-06-22 20:47           ` R. DuFresne
2005-06-22 21:18             ` Alexey Toptygin
2005-06-23 11:01               ` Jan Engelhardt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox