วันอาทิตย์ที่ 18 มกราคม พ.ศ. 2552

A New Evolution in Hack Attacks:

Types of Port Scanning

There are several scanning techniques:
· Vanilla: The scan attempts to connect to all 65,535 ports.
fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46
© SANS Institute 2003, As part of GIAC practical repository. Author retains full rights.
Kelley Ealy Page 10 of 17
· Strobe: Only a few ports are scanned, those ports that are well-known for
being exploitable.
· Stealth-scan: Techniques such as SYN or FIN scans are used so the
scanned computer cannot log the port scanning activities.
· FTP bounce scan: The scanner goes through an FTP server so that the
scanning source cannot be determined.
· Fragmented packets: Fragmented packets are sent by the scanner to
penetrate simple packet filter firewalls.
· UDP: UPD ports are scanned to see if they are open.
· Sweep: One port is scanned on multiple systems.
Types of Distributed Port Scanning Tools
At this writing, a number of different port scanning tools are available, including
the following:
· NMAP. NMAP is one of the most popular scanning tools available. It
offers a variety of scanning techniques, such as UDP, TCP SYN, FTP
Proxy, ICMP, and Null scan, among others. It also provides remote OS
detection, fingerprinting, stealth scanning, decoy scanning, and port
detection filtering.
· NetScan Tools Pro 2000. Considered to have one of the best Windowsbased
port scanners available, Netscan also does a lot more than mere
port scanning. It offers several utilities like DNS queries, ping sweeps,
whois, SNMP walks, and even multitasks between systems so a port scan
can be run on one system and a ping sweep can be run on another.
· SuperScan. This TCP scanner is fast and flexible. Like Netscan,
SuperScan allows for flexible specification of target IPs and port lists. In
addition, it comes with some very extensive port lists.
· ISS Internet Scanner. This commercial scanner provides several
scanning techniques, including TCP, ICMP, and UDP. It offers NETBIOS
and DNS utilities, identifies operating systems, and performs
fingerprinting.
Port Scanning Prevention
“Federal law enforcement officials are generally in agreement that port scanning
is not a crime” [15]. However, there is a fine line between port scanning and
hacking. At this point, the best defense against distributed port scanning is to
Key fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46
© SANS Institute 2003, As part of GIAC practical repository. Author retains full rights.
Kelley Ealy Page 11 of 17
disable all unneeded services on users’ systems. Users should be familiar with
the programs and applications running on their systems and configure their
systems specifically to that environment’s needs. Also, network administrators
should make sure Intrusion Detection System and Intrusion Prevention System
signatures deployed in their environment are up-to-date.

ไม่มีความคิดเห็น:

แสดงความคิดเห็น