Re: All tcp ports open?

From: Jack Burton (dreawn@gmail.com)
Date: Mon Aug 30 2004 - 14:47:34 EDT


I've seen any scan from some cable providers (comcast in particular)
exhibit this behavior.

On Sun, 29 Aug 2004 18:36:18 -0400, Varun Pitale <varun.pitale@gmail.com> wrote:
> I have seen a solaris box which was acting as a load balancer act this
> way too, so it might be a loadbalancer thing. All ports seem to be
> open, but they do not give any response . If you could post what kinds
> of machines they are, it would be good..
>
>
>
>
> On Sun, 29 Aug 2004 02:04:08 -0500, Ben Timby <asp@webexc.com> wrote:
> > I am not sure what is doing this, but I assume it is a software (or some
> > kind of) firewall/hids, can anybody point me in the right direction?
> >
> > I am pen-testing a Windows webserver, and a port scan reveals ALL tcp
> > ports open. hping also confirms that a SA is returned for any S packets
> > sent to any port I try. I can connect via netcat any of the ports, and
> > send data, but nothing is returned. In order to verify services, I am
> > required to connect and check for a banner or send appropriate protocol
> > commands to elicit a response.
> >
> > Has anyone seen this, or have any idea of what this is?
> >
> > Thanks.
> >
> > ------------------------------------------------------------------------------
> > Ethical Hacking at the InfoSec Institute. All of our class sizes are
> > guaranteed to be 12 students or less to facilitate one-on-one interaction
> > with one of our expert instructors. Check out our Advanced Hacking course,
> > learn to write exploits and attack security infrastructure. Attend a course
> > taught by an expert instructor with years of in-the-field pen testing
> > experience in our state of the art hacking lab. Master the skills of an
> > Ethical Hacker to better assess the security of your organization.
> >
> > http://www.infosecinstitute.com/courses/ethical_hacking_training.html
> > -------------------------------------------------------------------------------
> >
> >
>
>
> --
> Regards,
> Varun
> (704)-548-8793 --(Home)
> (704)-241-0092 --(Mobile)
> mailto: varun.pitale_(at)_gmail_(dot)_com
>
>
>
> ------------------------------------------------------------------------------
> Ethical Hacking at the InfoSec Institute. All of our class sizes are
> guaranteed to be 12 students or less to facilitate one-on-one interaction
> with one of our expert instructors. Check out our Advanced Hacking course,
> learn to write exploits and attack security infrastructure. Attend a course
> taught by an expert instructor with years of in-the-field pen testing
> experience in our state of the art hacking lab. Master the skills of an
> Ethical Hacker to better assess the security of your organization.
>
> http://www.infosecinstitute.com/courses/ethical_hacking_training.html
> -------------------------------------------------------------------------------
>
>

-- 
"... yes sir, the check is in the mail!"
--Jack Burton of the Pork Chop Express
------------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. All of our class sizes are
guaranteed to be 12 students or less to facilitate one-on-one interaction
with one of our expert instructors. Check out our Advanced Hacking course,
learn to write exploits and attack security infrastructure. Attend a course
taught by an expert instructor with years of in-the-field pen testing
experience in our state of the art hacking lab. Master the skills of an
Ethical Hacker to better assess the security of your organization.
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
-------------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:54:02 EDT