Forums: Scan From Inside A Firewalled Host - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Scan From Inside A Firewalled Host

#1 User is offline   Fareway 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 47
  • Joined: 20-December 03

Posted 15 August 2004 - 01:32 PM

Hi guys,

i was just thinking about a opportunity to scan from inside a firewalled host for ports which are allowed to connect from the ouside but are not occupied by a daemon. Sometimes firewalls are bad configed so that some ports are still allowed in both directions but the programm which should use them is deinstalled or not activ.

Mostly i used nmap to scan the host from ouside but i can only find those ports which are used by programms.
0

#2 User is offline   TRi 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 155
  • Joined: 06-March 04

Posted 15 August 2004 - 02:05 PM

I know this problem, always wondered if there is something comfortable to this but I was always lazy to find something.

From the inside i'm not really sure how to do, but from the outside:
Did you ever try to connect with any kind of client (browser, ftp, etc) to a specific port? Usually when the port gives you a timeout it's filtered by a firewall, if it gets your refused means either its an open port or you have to handle with a badly configured (or badly portstealthing) firewall.

Hope that helps you a bit..
0

#3 User is offline   Fareway 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 47
  • Joined: 20-December 03

Posted 15 August 2004 - 02:23 PM

TRi you're absolutly right, i always search for easy methods because that's what saves a lot of time. However i heared of a tool which does the trick from inside. I was wondering if anybody knows a bit more about such a method.
0

#4 User is offline   brOmstar 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 353
  • Joined: 12-January 04

Posted 15 August 2004 - 04:08 PM

Is it possible to bind a range of x ports in a little cmdline-program?

Because when this is possible we can create a proggie which binds every unused port and when a connection is made it simple logs the connection. After a portscan we should have any open port on the box.

Is somebody interested to create something like this or give me some info how this can be done i tried something but i need the info how i can open more then one port at one time.
0

#5 User is offline   Terminal 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 536
  • Joined: 21-February 04

Posted 16 August 2004 - 12:10 AM

Yeah man this is a prob . I am not able to ping even any website . My isp is blocking them so i cant scan outer ranges :( . In between for some days i was gettin reply when i ping websites but now again blocked :(
0

#6 User is offline   Fareway 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 47
  • Joined: 20-December 03

Posted 16 August 2004 - 03:08 AM

brOmstar that would be worth a try but the problem is to synconize the client and the server side. The server side binds for example 100 ports and the client side try's to connect to each port. If a connections is made there is a mark in a log file.
0

#7 User is offline   brOmstar 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 353
  • Joined: 12-January 04

Posted 16 August 2004 - 04:40 AM

i will try to find some info's about and code something like this..
0

#8 User is offline   ehsan_sfd 

  • Private
  • Icon
  • Group: Members
  • Posts: 9
  • Joined: 02-December 03

Posted 17 August 2004 - 11:56 PM

if u cant get the right informatins by scanning a host,almost there are 2 possibilities: ICMP in the router ACL's is blocked,either from where u get service or on the host u r scanning it
in this case Retina's Force Scan capability can really help u , it gathers more useful information . look if icmp is blocked u cant ping or trace the host,so scanner shows u that the host cant be found. using retina surely helps u, if u r interested i can give an article about the scanning structures,it will help u to have a wide aspect of the process.
0

#9 User is offline   Terminal 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 536
  • Joined: 21-February 04

Posted 18 August 2004 - 06:44 AM

ehsan_sfd, on Aug 18 2004, 01:26 PM, said:

if u cant get the right informatins by scanning a host,almost there are 2 possibilities: ICMP in the router ACL's is blocked,either from where u get service or on the host u r scanning it
in this case Retina's Force Scan capability can really help u , it gathers more useful information . look if icmp is blocked u cant ping or trace the host,so scanner shows u that the host cant be found. using retina surely helps u, if u r interested i can give an article about the scanning structures,it will help u to have a wide aspect of the process.

oh good tip their will try retina :)
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting