Penetration Testing mailing list archives

Re: Nmap/netwag problem.


From: Daniel Miessler <daniel () dmiessler com>
Date: Fri, 12 Aug 2005 00:44:04 -0400


On Aug 11, 2005, at 5:16 AM, Pete Herzog wrote:

I just would like to
point out that to determine a service on a port it is not enough just to complete a full TCP hand-shake and Telnet to it if there is a response.

I think the main focus of the comments were to determine which of two tools were right about whether or not a port was in fact open, and not anything beyond that. I think you're right about testing HTTP with HTTP interactions, etc, but the scope here was just figuring out if there was an open port.

I think that's why you got the response you did from the list.

--
Daniel R. Miessler
M: daniel () dmiessler com
W: http://dmiessler.com
G: 0x316BC712




Attachment: PGP.sig
Description: This is a digitally signed message part


Current thread: