Re: nessus report



--On December 19, 2008 11:32:51 PM -0600 Richard Yang <kusanagiyang@xxxxxxxxx> wrote:


hi,
when i ran nessus against my bsd box, nessus can detect "the remote host
is
up".
i don't understand how nessus can detect it...
does anyone know how it is done?
thanx


There are several ways to detect if a host is up. Responses to icmp packets is one. Almost all hosts will respond to pings unless they're prevented by a firewall.

Another way is the type of response to a probe of a port. Sometimes services will respond differently if they're firewalled than if they're not listening on a particular port. Also, very few computers have no ports at all listening. For example, most unix boxes will be running syslogd and listening on port udp/514. That is the default for that daemon. Unless you reconfigured syslogd to listen on localhost only, it will respond to probes.

Sometimes a host will respond to a problem with RSETs. It's very, very hard to configure a box in such a way that it's impossible to detect that it's up and running.

Run sockstat and look at what's listening on your computer. Then see if you can figure out how to get it to stop listening on those ports.

Paul Schmehl (pauls@xxxxxxxxxxxx)
Senior Information Security Analyst
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/


Relevant Pages

  • Re: REMOTE DESKTOP NOT WORKING ANY LONGER PLEASE HELP!
    ... Yes the host is listening on port 3389 the default and I verified this. ... Try connecting again. ...
    (microsoft.public.windows.terminal_services)
  • Re: Need Help Fast.......
    ... to host... ... I checked the port 3389 is listening and open. ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: How to get connection to remote host
    ... To check if a server is listening at a particular port or not - you ... The remote host is listening on the port you are trying to connect ... The host you are connecting to is reachable from the host you are ...
    (comp.lang.java.programmer)
  • Re: SSH attacks?
    ... Nessus does this, as do a host of other scanners. ... I believe changing to a different port ...
    (Incidents)
  • Re[2]: Still trying to get my site up!
    ... $>listening on it, or there is no port forwarding on your gateway. ... $>> redirect to an alias using port 9545. ... Unable to connect to remote host. ...
    (freebsd-questions)