nmap scan and vunerability ?

This question is based on the nmap scan below.

1. why did the nmap scan take so long?

Interesting ports on computer.sawyer.home (
(The 1666 ports scanned but not shown below are in state: filtered)
21/tcp closed ftp
22/tcp open ssh OpenSSH 4.3 (protocol 2.0)
25/tcp closed smtp
80/tcp open http Apache httpd 2.2.2 ((Fedora))
139/tcp open netbios-ssn Samba smbd 3.X (workgroup: NASQNT)
443/tcp closed https
445/tcp open netbios-ssn Samba smbd 3.X (workgroup: NASQNT)
631/tcp closed ipp
MAC Address: 000:B7:89:30:F8 (Intel)
Device type: general purpose
Running: Linux 2.4.X|2.6.X
OS details: Linux 2.4.18 - 2.4.27, Linux 2.4.21 (Suse, X86), Linux 2.4.22, Linux 2.4.6 - 2.4.26 o r 2.6.9, Linux 2.6.10, Linux 2.6.5 - 2.6.11, Linux 2.6.7, Linux 2.6.8 (Debian)
TCP Sequence Prediction: Class=random positive increments
Difficulty=2697477 (Good luck!)
IPID Sequence Generation: All zeros

Nmap finished: 1 IP address (1 host up) scanned in 1681.877 seconds
Raw packets sent: 1851 (82.266KB) | Rcvd: 1691 (121.716KB)
Well, the reason it took so long could be because of a multitude of things. I'll list a few:

1. Where were you scanning from? Nmap scans between machines on a local network will be faster than when an nmap scan has to travel across the internet.

2. Could've been some network congestion between where you were scanning from and where the scanned box was.

3. What nmap switches were you using? There are numerouse things you can have nmap do. You can have it scan on TCP ports, have it do a stealth scan to attempt to bypass firewalls and other security devices... Scans also depend on what (if any) firewalls between source and destination are doing with your scan attempt.

Keep in mind that the fact that it took so long isn't exactly a bad thing. Sometimes scans take awhile. Basically, there's no real definitive answer to your question. Are the Nmap results to your there anything in the results that set off red flags for you?

I'm gonna guess that you initiated this can inside your LAN, since port 139 and 445 are open on computer.sawyer.home. Most ISPs filter on those ports to protect their networks from worms based on those ports/services.

The command was: "nmap -v -A"

I don't think any congestion, all on the same local network.

How can that be shortened up?

I am planning on configuring this box to use as a firewall router. I would like for the external side to be tight.

- Dan


