Techware Labs Header

Forums have moved

See this announcement for more details, or just go directly there.

  #1  
Old 06-03-2003, 08:22 PM
Prometheus Prometheus is offline
Chronique Technique
Lab Master Techie
 
Join Date: Sep 2002
Location: Bellingham,WA
Posts: 3,058
Send a message via AIM to Prometheus
Default Portscanning?

How do I go about doing a port scan on a website?

Omega showed me that my schools site is pretty insecure

ftp, smtp, http, pop3, netbios-ns, netbios-dgm, netbios-ssn, imap2, ldap, timbuktu, fcp, and ppp (21, 23, 25, 80, 110, 137, 138, 139, 143, 389, 407, 510, and 3000) and telnet

so im curious to look around on the site
Reply With Quote
  #2  
Old 06-03-2003, 08:46 PM
Uranium-235's Avatar
Uranium-235 Uranium-235 is offline
Administrator
 
Join Date: Nov 2001
Location: Mansfield, TX
Posts: 2,469
Send a message via ICQ to Uranium-235 Send a message via AIM to Uranium-235
Default

well, port scanning on a website, might not be the actual web server. many companies have a port forewarding setup on a internet gateway box so if anybody sends requests @ port 80 (http) it will foreward the packets to the webserver inside the lan, and the server will respond and those packets will get sent back into the internet.


Now if you want to scan ports on a computer inside your network (or school network). Keep in minds net admins will be able to detect it and you might get in serious trouble. Hence the term "Scan my network and die"
Reply With Quote
  #3  
Old 06-03-2003, 09:50 PM
Prometheus Prometheus is offline
Chronique Technique
Lab Master Techie
 
Join Date: Sep 2002
Location: Bellingham,WA
Posts: 3,058
Send a message via AIM to Prometheus
Default

I am aware of the risks

But isnt port scanning legal until you do something bad

oh christ now this is going to become a ethics thread hah

But how do I do the actual scanning
Reply With Quote
  #4  
Old 06-03-2003, 10:04 PM
Uranium-235's Avatar
Uranium-235 Uranium-235 is offline
Administrator
 
Join Date: Nov 2001
Location: Mansfield, TX
Posts: 2,469
Send a message via ICQ to Uranium-235 Send a message via AIM to Uranium-235
Default

http://www.google.com/search?hl=en&i...=Google+Search
Reply With Quote
  #5  
Old 06-04-2003, 01:42 AM
xMerCLorDx
 
Posts: n/a
Default

i've been using this since i first touched unix:

http://www.insecure.org/


nmap is what you're looking for.
Reply With Quote
  #6  
Old 06-06-2003, 02:21 AM
Omega Omega is offline
Administrator
 
Join Date: Nov 2001
Location: Minneapolis, MN, USA
Posts: 957
Send a message via ICQ to Omega Send a message via AIM to Omega Send a message via MSN to Omega Send a message via Yahoo to Omega
Default

Yup. I ran an nmap -v -sS -O -P0 xxx.xxx.xxx.xxx on the box in question. I believe they do have a port to Windows, if you don't have a *nix box at your disposal.
Reply With Quote
  #7  
Old 06-06-2003, 02:44 PM
vee_ess's Avatar
vee_ess vee_ess is offline
Super Moderator
 
Join Date: Aug 2001
Location: Phoenix, Arizona
Posts: 2,781
Send a message via ICQ to vee_ess Send a message via AIM to vee_ess Send a message via MSN to vee_ess Send a message via Yahoo to vee_ess
Default

The fastest one I have used for Windows is Blue's Port Scanner. It's a small file that you don't have to setup, so you can run it on user profiles with limited access (where you can't install others).

I am neither implying nor condoning misuse of any policies by the contents of this message.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 12:25 AM. Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Forum style by ForumMonkeys.