LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-04-2004, 02:09 AM   #1
chrisfirestar
Member
 
Registered: Sep 2003
Location: Adelaide, Australia
Distribution: Fedora/RH
Posts: 231

Rep: Reputation: 30
Question differences between scan packets and genuine


Hi I was thinking about security etc

Just wondering if their was any way to determine the difference between a genuine request for a service (eg HTTP on port 80) or a scan from say nmap?

is their anyway to seperate the two??

Chris
 
Old 03-04-2004, 05:04 AM   #2
SciYro
Senior Member
 
Registered: Oct 2003
Location: hopefully not here
Distribution: Gentoo
Posts: 2,038

Rep: Reputation: 51
no not realy, the only was see is only to listen, or respond so the requests that you are expecting, IE, if your broswing the web then youd expect incoming trafic thru and outgoing thru port 80, if there are no web browsers active, then anything thru port 80 could be a scan, but its less liky to be genuine (unless your runing a web server, or some server people conect to thru that port)

other then that, i have no clue about how to detect whats real and whats not, if nmap is half the program i think it is tehn you shoulent be able to tell the difrence, it would just seem odd that somone was sending you all this stuff
 
Old 03-04-2004, 01:46 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Just wondering if their was any way to determine the difference between a genuine request for a service (eg HTTP on port 80) or a scan from say nmap? is their anyway to seperate the two??
Yes, provided you use the right tools. A HTTP request is made and built following a defined structure. The minimum you should be able to ngrep packets payload for in a HTTP request is the "$REQUESTTYPE HTTP/$VERSION" header. An IDS like Snort is quite capable determining an Nmap scan from an urlencoded double backslash attack or a genuine request. Of course it does more than only grep for a string.
 
Old 03-04-2004, 07:20 PM   #4
chrisfirestar
Member
 
Registered: Sep 2003
Location: Adelaide, Australia
Distribution: Fedora/RH
Posts: 231

Original Poster
Rep: Reputation: 30
yeah just so everybody knows this is just a out of interest kind of post. What about other ports? say ssh or email ports? hmmm
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Genuine Windows Validation microsoft/linux General 1 10-11-2005 10:43 PM
To SCAN or not to SCAN? HP750xi Suse 9.2 Pro newtwolinux Linux - Hardware 4 06-22-2005 04:02 PM
Genuine AMD xowl Linux - Hardware 4 03-03-2005 02:42 AM
Buy genuine linux mrhyde Linux - Newbie 25 01-03-2004 01:29 AM
genuine pentium or celeron? versaulis Linux - Software 3 10-21-2003 10:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration