Nmap Development mailing list archives

Re: Portscanning through HTTP proxy?


From: MadHat <madhat () unspecific com>
Date: Mon, 6 Dec 2004 16:33:11 -0600

On Dec 6, 2004, at 3:58 PM, Mark Lachniet wrote:
Is there a decent way, similar to the FTP bounce approach, to do
portscanning through an insecure HTTP proxy using CONNECT verbs?  For
example, say I find a dual-homed host that has unrestricted proxy, and am
too lazy to telnet to the proxy and type:

'CONNECT http://10.1.1.1:25 HTTP/1.1'

and manually iterate it a hundred times.

there is not an easy way right now built into nmap that I know of, but it should be easy to make a patch for it.


---------------------------------------------------------------------
For help using this (nmap-dev) mailing list, send a blank email to nmap-dev-help () insecure org . List archive: http://seclists.org



Current thread: