Penetration Testing mailing list archives

Re: Some unusual network features


From: "Nathan R. Valentine" <nathan () nathanvalentine org>
Date: Tue, 13 Jan 2004 15:22:30 -0500

I've got some theories, but I'm not sure how much I'm jumping to 
conclusions.

My guesses: 

1) A tarpit. 
2) Hosts behind a firewall with some kind of Layer 7 inspecting proxy.
3) A firewall with a munged NAT configuration.
4) Some combination of the above. 

Have you tried fingerprinting the IP stack? I wouldn't be surprised to
find a homebrew *nix security box or a Symantec box. 

-- 
Nathan R. Valentine <nathan () nathanvalentine org>

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: