Mike Leone on Tue, 26 Feb 2002 15:30:21 +0100


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] fire wall question(s)


> Now this is useful.  What can be done with simply an open port number?

If nothing is listening on that port, not a lot, I think, since the traffic would come to the port, but nothing would process the traffic. Conside the IDENT (or AUTH) port (113). I know people who open that port on their firewall, but never run an IDENT daemon. So, to the other side, it's a timeout .. and not a direct REJECT, which some places don't like.

I suppose it could be made into a DOS.

> Also, is there software I can get for my Linux box that I can use to port
> scan my Windows box?  What about a packet sniffer (?) to watch all traffic
> on and into/out of my network?

nmap is available for Linux and for Windows; it's pretty much a standard port-scanner. And Ethereal is a free Windows-based packet sniffer, altho it doesn't handle all types of packets (no PPPOE, I'm told, amongst other kinds).




______________________________________________________________________
Philadelphia Linux Users Group       -      http://www.phillylinux.org
Announcements-http://lists.phillylinux.org/mail/listinfo/plug-announce
General Discussion  -  http://lists.phillylinux.org/mail/listinfo/plug