Great Circle Associates Firewalls
(May 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: TIS portscan against a cisco
From: reh @ cs . UMD . EDU (Richard Huddleston)
Date: Fri, 6 May 1994 10:57:00 -0400
To: firewalls @ greatcircle . com

I was using the TIS Toolkit's portscan the other day, within my employer's
domain, just to verify general tightness, when it occured to me to run it 
against an interface on my cisco 4000.  I made sure that I ran it from an 
IP address that the cisco will ignore TELNET SYNs from.  IP, RIP, Vines 
and IEEE bridging are enabled on the router, but only RIP and IP are active 
on the particular interface, with RIP neighbors defined.  The IP subnet 
I ran the test from, however, is generally "trusted" by the router. 

I expected the first three results, but the last five have made me curious.  
I'm hunting it down now, but thought it an interesting enough result to bring 
to general attention in the meantime.  The only other routers that I can test 
against are Wellfleets and a Morning Star Express; haven't done it yet, though. 

I can apparently make a TCP connection on those numbered ports. 

Things that make you go "hmmmm"... although it's probably something trivial
-- which I'll discover only minutes after sending this message out ;). 

echo
discard
finger
1993
2006
4006
6006
9006

Richard

Indexed By Date Previous: help
From: larryl @ hpubvwa . nsr . hp . com
Next: Password Aging
From: ken @ cameron . East . Sun . COM (Ken Harford - Network Architecture Consultant)
Indexed By Thread Previous: help
From: Manjuka Herath <hem @ cairo . anu . edu . au>
Next: Password Aging
From: ken @ cameron . East . Sun . COM (Ken Harford - Network Architecture Consultant)

Google
 
Search Internet Search www.greatcircle.com