Nmap Development mailing list archives

Re: still confused


From: maillist <maillist () securityoveride com>
Date: Sun, 11 Jan 2009 18:08:04 -0500

Interesting Thank you 



On Sun, 2009-01-11 at 17:53 -0500, Michael Pattrick wrote:
On Sun, Jan 11, 2009 at 4:56 PM, maillist <maillist () securityoveride com> wrote:
First of thank you to everyone for taking you time to answer my
questions and being so helpful

after some further investigation into port 80 on my host
securityoveride.com i discovered that the port would change from open to
filtered just by doing a bunch of scans one right after each other
i also followed this on wireshark and could see that a [SYN,ACK] was
sent back for every [SYN] even the ones that said filtered.
So im still confused

-snip-

Hey,

I could not reproduce this, after scanning securityoveride.com on port
80 five times consecutively nmap reported port 80 open all five times.
This discrepancy may be caused by a firewall on the scanning host, or
a bug in nmap that requires a very specific set of circumstances to be
triggered.

You may want to retry the scans from a different host.



_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org


Current thread: