hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

night^man
how to check barner on a sepsific port ?
sorry for bad english ;P
help me
EXPLOiTED
Easy. to check the banner you a scanning tool. xScan or scan500...tons of Banner options
Jeeve5
QUOTE (night^man @ Jan 26 2004, 02:09 PM)
how to check barner on a sepsific port ?
sorry for bad english ;P
help me

check out amap. is recognizes which service is running on the other end even if its not on the default port.
flashb4ck
hier a little list of good bannerscanner!

xray
xscan
fluyax
languard networks scanner
perhabs brutus (not sure)
google 4 "sl.exe" its another good tool
SFBF WIN v.2.5


info 4 SFBF WIN v.2.5
:
Very fast server banner scanner for windows. Up to 1024 sockets!
logs results to the file "LOG" in the same directory. Use grep to find what your looking for.

Usage
--------------
./sfbfwin <-p port> <-t threads> <[-f file] | [-r startip-endip]> <mode>
modes:
-banner: Get Banner.(ftp servers,etc.)
-httphead: Get Http header.
-httpserver: Get http server.
-real: Get Real server header.
-raw <file>: Send the contents of <file> and log returns.

About -raw:
--------------
With this mode you can scan other services not supported by sfbf.
-raw raw.txt, where raw.txt contains: "HEAD / HTTP/1.0

",
would do the same thing as -httphead.


hf
night^man
k will try
10xall
jubbly
u wanna check out the downloads section cos there has been quite a few tools for that posted recently smile.gif
nmcog
New feature in NMAP:
nmap -sV

from man page:
" -sV Version detection: Afer TCP and/or UDP ports are discovered
using one of the other scan methods, version detection communi-
cates with those ports to try and determine more about what is
actually running. A file called nmap-service-probes is used to
determine the best probes for detecting various services and the
match strings to expect. Nmap tries to determine the service
protocol (e.g. ftp, ssh, telnet, http), the application name
(e.g. ISC Bind, Apache httpd, Solaris telnetd), the version num-
ber, and sometimes miscellaneous details like whether an X
server is open to connections or the SSH protocol version). If
Nmap was compiled with OpenSSL support, it will connect to SSL
servers to deduce the service listening behind the encryption.
When RPC services are discovered, the Nmap RPC grinder is used
to determine the RPC program and version numbers. Note that the
Nmap -A option also enables this feature. For a much more
detailed description of Nmap service detection, read our paper
at http://www.insecure.org/nmap/versionscan.html . There is a
related --version_trace option which causes Nmap to print out
extensive debugging info about what version scanning is doing
(this is a subset of what you would get with --packet_trace)."
barty32
Try NMAP, it's a great biggrin.gif

I'm very satisfied with it wink.gif
tyler.durden
QUOTE (barty32 @ Feb 12 2004, 04:18 PM)
Try NMAP, it's a great biggrin.gif

I'm very satisfied with it wink.gif

yes, I agree nmap is a good one... wink.gif
rasmichael
is there a nmap for win?

does nmap support bannerchecking?

*confused*

...pls explain
yuliang11
yeah of course. there's an nmap for windows.
banner checking ? yeah i think so. even telnet can support banner grabbing
eXist
You could try with scanline and grab banners on specific ports.
Search around on google for it.
For instance:

-------------------------------------------------------------------------------
4.x.x.x
Responds with ICMP unreachable: No
TCP ports: 4000


TCP 4000:
[4.11.5 G [ ^r ~ N D B| (; ' / ' Oe Xb 5 7 4E ^ P mH m + VRK KY }sf " bEJ ." 7)# 0 R A9( @ u7 z w,l < P b4O W K 5 J]

-------------------------------------------------------------------------------
Tyrano
yeah the new nmap version will grab banners and identify the version of the service they are running, regardless of what port. i'd say about 85% accurate, but thats just me. i will have to try out some of of these other tools you guys have mentioned though blink.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.