Port identification methodology

From: Erik Norman (erik.normanat_private)
Date: Mon Jul 02 2001 - 03:13:35 PDT

  • Next message: h0pperat_private: "Re: Nortel Security"

    Hi all,
    
    I have a question regarding methodology while performing a 
    PT. It concerns identifying programs/services.
    
    Imagine a full nmap scan has been performed. A handfull 
    of open ports was found on a particular server. The 
    usual 25, 53, 80 etc are identified, but one or two ports 
    stand out from the crowd. Looking in various 'common ports' 
    files does not provide a hint what the port is used for.
    
    Connecting with telnet yields no text, and a tcpdump 
    dump does not provide any text (in clear anyway).
    
    
    Now what!???
    
    How should one approach this?
    
    
    /Erik
    
    --------------------------------------------------------------------------------------
    
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service
    For more information on SecurityFocus' SIA service which automatically alerts you to 
    the latest security vulnerabilities please see:
    
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Mon Jul 02 2001 - 09:50:42 PDT