Re: powned.



On Fri, 14 Apr 2006 05:12:25 +0000, Sycho took a five-minute break from
flipping burgers to boot the etch-a-sketch and scribble out:

<snip>

Starting nmap V. 3.00 ( www.insecure.org/nmap )
Host p7w16.geo.re4.yahoo.com (216.39.58.67) appears to be up ... good.
Initiating SYN Stealth Scan against p7w16.geo.re4.yahoo.com
(216.39.58.67)
Skipping host p7w16.geo.re4.yahoo.com (216.39.58.67) due to host
timeout
Nmap run completed -- 1 IP address (1 host up) scanned in 75 seconds
-------
N-Stealth HTTP Security Scan detects the server as "(null)".


Interesting that the server came up as null. I had gotten the following.
(I ran it again just to be sure.) I knew that Roy used Yahoo, since
his FTP and whois both pointed to a Y! server. What I didn't know - and
suprised me - was that Yahoo used FreeBSD. I pegged them for
using Windows Workstation 2003 and IIS. Unless - of course - the
detection was wrong.

--------
Interesting ports on p7w15.geo.re4.yahoo.com (216.39.58.66):
(The 1661 ports scanned but not shown below are in state: filtered)
PORT STATE SERVICE
80/tcp open http
443/tcp open https
Device type: general purpose
Running: FreeBSD 4.X|5.X
OS details: FreeBSD 4.3 - 4.4PRERELEASE, FreeBSD 4.9 - 5.1, FreeBSD 5.1-CURRENT (June 2003) on Sparc64
Uptime 22.373 days (since Wed Mar 22 18:52:18 2006)
TCP Sequence Prediction: Class=truly random
Difficulty=9999999 (Good luck!)
IPID Sequence Generation: Busy server or unknown class

Nmap finished: 1 IP address (1 host up) scanned in 35.394 seconds
Raw packets sent: 3348 (134KB) | Rcvd: 202 (8260B)
----------


--
k
.



Relevant Pages

  • Re: DNSReport w/ Hosting Your Own DNS
    ... Thing is, I'm aware of the risks, monitor the server daily, patch as soon as ... I wouldn't dream of attempting to run public DNS. ... While it is permissible on an SBS server to host a website directly ... I've seen that point of ports being open a risk a lot with hardly a reason ...
    (microsoft.public.windows.server.sbs)
  • Re: RPC over HTTP - one server scenario no ISA
    ... If you have verified that your "Valid Ports" key is set correctly, ... You should get a 403.2 HTTP Error, this means that you are accessing the ... I've been able to connect to the server from an XP ...
    (microsoft.public.exchange.connectivity)
  • Re: Media services - cannot connect to media from internet
    ... If I disable HTTP and RTSP on the server, and only have MMS enabled, then I ... open for both UDP and TCP, no ports are being blocked outbound. ...
    (microsoft.public.windowsmedia)
  • Re: Dropping syn+fin replies, but not really?
    ... Now we're required to run external security scans on some of the hosts, and they constantly come back with a "high" or "medium" severity problem: The host replies to TCP packets with SYN+FIN set. ... Since when did "pound ssl proxy" equal "aladdin web server"? ... You can let tcpdump only show specific ports and source/destination ...
    (FreeBSD-Security)
  • Re: Kerberos error KDC_ERR_BADOPTION
    ... Ran the same test again using the IP instead of the host name and got this: ... Reusing existing connection \n ... Server: Microsoft-IIS/6.0\r\n ... I suggest you use webfetch to perform a test and trace the rawdata of http ...
    (microsoft.public.inetserver.iis.security)