Nmap Development mailing list archives

Re: IPv6 scan not correct ?


From: Fyodor <fyodor () insecure org>
Date: Fri, 7 May 2004 20:18:33 -0700

On Wed, Jun 25, 2003 at 05:05:02PM +0200, Ruediger Rissmann wrote:

I just run nmap against one of my IPv6 routers, and found that every port
was
reported to be open. I had a look into the router configureation and
found that every port is blocked by an acl and that all the packets
from my nmap scan were discarded. Instead the router send back an ICMPv6
destination unreachable type 1:
"communication with destination administratively prohibited" back wich
seems
to be not understood correctly by nmap.

I remove the access-list, and nmap reported the correct ports to be open,
so the problem seems to be only that specific icmpv6 message.

I debugged the problem in scan_engine.cc
and found that

Sorry it took me so long to respond.  I have applied your patch for the
next version of Nmap.

Cheers,
Fyodor

---------------------------------------------------------------------
For help using this (nmap-dev) mailing list, send a blank email to 
nmap-dev-help () insecure org . List archive: http://seclists.org



Current thread: