View previous topic :: View next topic |
Author |
Message |
Joseph_sys Advocate

Joined: 08 Jun 2004 Posts: 2719 Location: Edmonton, AB
|
Posted: Sun Jan 08, 2006 4:30 am Post subject: nmap accuracy |
|
|
I scan my IP address externally with "nmap + IP" and it only showed three ports opened 80, 443, 1024 (as it suppose to).
However, when I scan my IP address externally from some kind of Ethernet cafe (I was given some kind of bare-bone machine, without hard-drive) using Knoppix and nmap, I was surprised to see some additional ports opened: 389, 1002, 1072
In addition the scan took several minutes on slow DSL connection.
When I go back (I tried to investigate) so I did external scan again on my IP-address and these ports didn't whowed up as open.
Why did I see additional open ports when I scan my IP? |
|
Back to top |
|
 |
kadeux Tux's lil' helper

Joined: 21 Nov 2005 Posts: 103
|
Posted: Sun Jan 08, 2006 2:13 pm Post subject: |
|
|
If you are using a hardware dsl router to connect to the internet, it might be that the router had these ports open.
Ports 389 and 1002 are used by LDAP/OpenLDAP and/or NetMeeting, port 1072 is assigned to cardax (cardax offers hardware and software for access control and alarm monitoring management, I guess that you are not using their enterprise level hardware at home). But of course all ports could be used by any other application which ignores the port number assignments by the IANA.
Did you scan your machine at home from another machine ? If you try to scan the machine locally from the same machine given the external IP, the ethernet driver will send the packages to the "lo" interface, your router will not be "touched" by the scan. (That's a feature, not a bug. Really! Routing loops are bad!)
If you have a hardware DSL router with an integrated DSL modem, it's hard to test the external connection of your router in its final running configuration without connecting over the internet. If you have a DSL router that connects to the DSL modem over a pppoe interface, you can set up a pppoe server on a second machine and run penetration tests offline.
So if you are using a DSL router, I recommend first check (and change) the configuration of this router (and then repeat the scan over the internet). |
|
Back to top |
|
 |
Joseph_sys Advocate

Joined: 08 Jun 2004 Posts: 2719 Location: Edmonton, AB
|
Posted: Sun Jan 08, 2006 4:33 pm Post subject: |
|
|
Thank you for explanation.
I have two Internet connection DSL and Cable and both are behind software type routers (old boxes running freesco).
So I scan externally from one connection to another and did not find any additional ports open (besides the ones I'm aware) The scan that I perform was from IP: 202.138.167.235 and "nmap -P0" showed no ports open. Though it seems to me they have a hardware type router. |
|
Back to top |
|
 |
kadeux Tux's lil' helper

Joined: 21 Nov 2005 Posts: 103
|
Posted: Sun Jan 08, 2006 9:18 pm Post subject: |
|
|
I don't know whoever you mean with "they" when you said " .. it seems to me they have a hardware type router". I assume the following situation:
Code: |
+------------+ +------------+
| SW-Router1 |-----| Blackbox1 |
+------------+ |------------|
| | Cablemodem |----+
|(A) +------------+ |
+-------+ |
| Comp1 | |
+-------+ iiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiii
iiiii INTERNET iiiii
iiiiiiiiiiiiiiiiiiiiiiiiii
+-------+ iiiiiiiiiiiiiiiiiiiiii
| Comp2 | (B)| |
+-------+ | |
| +-----------+ |
| | DSL-Modem | |
+------------+ |-----------| +---+
| SW-Router2 |-----| Blackbox2 | | ? |
+------------+ +-----------+ +---+
|
|(C)
+------------+
| Comp3 (ext)|
+------------+
|
If a scan from Comp3 against Comp2 shows more open ports than a scan from Comp1 against Comp2, then someone between Point (A) and Point (B) is blocking the scans of these additional open ports (maybe your cable provider or the firewall rules of your software router), because the route between Point (B) and Comp2 is the same for both scans. If a scan of the public IP of Comp2 shows open ports, "something" on the internal side of Point (B) that is reachable under your public IP listens on these ports. That alone do not mean that you are vulnerable, maybe it is a management port for blackbox2 (which may be leased by your provider) which requires authentication. I don't know. But I do not think that any router between Point (C) and Point (B) is responsible for additional open ports on your internal side of Point (B). |
|
Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|