Penetration Testing mailing list archives

Re: Interesting challenge


From: wjnorth <wjnorth () earthlink net>
Date: Fri, 30 Jan 2004 09:38:44 -0800

Are you testing externally or internally? Have you performed a syn scan or a full TCP connect scan, or a fragmented packet scan? Also, are you scanning from behind a local firewall?

-Wes

At 11:42 AM 1/30/2004 -0500, Sanjay K. Patel wrote:



We are doing a pen test for a client and have run into a interesting
situation. The client has a server running IIS and Exchange we can get to it
through a browser but when we try to run Nessus or Eeye Retina against it,
neither product can find the server. The client is not running any IDS
system has a simple firewall. A port scan revels no open port though port 80
is open since the server is serving pages.


SKP



---------------------------------------------------------------------------
----------------------------------------------------------------------------


---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: