Nmap Development mailing list archives

Re: Nmap Scans via Socks Proxy? (OSX)


From: "DePriest, Jason R." <jrdepriest () gmail com>
Date: Fri, 7 Sep 2007 13:14:02 -0500

On 9/7/07, Dario Ciccarone (dciccaro) <> wrote:
Does that even work? I would assume SYN scan would become a "connect"
scan, just because it's being proxied. And FIN/XMAS wouldn't work at
all. And kiss OS detection goodbye.

I haven't tried the scenario - but knowing how a proxy works, it looks
like the only possible outcome.

Dario



I would suspect the results would be wildly inaccurate, but no worse
than scanning through a simple NAT.  Mostly because SOCKS5 doesn't do
any special application or protocol specific mangling, it just passes
stuff back and forth and manages the IP addresses.  It's been a while
since I look at a SOCKS packet capture, so I am not sure.

Now I'm all excited and I can't wait to test it out when I'm back at
work (next week).

-Jason

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org


Current thread: