[Subject Prev][Subject Next][Thread Prev][Thread Next][Subject Index][Thread Index]

Re: Re: [LIP] How to identify a Unix machine....




>Nah, don't bother with running nmap, you may get caught.  Just use
>nslookup to list out all the domains using one of TIL's DNS servers.

nmap half syn attack can not be detected unless kernel is patched to detect
ack / syn packets.
>
>Yes, they permit zone transfers from unauthorised hosts.  No, they're
>not the only ones -- 80% of the ISP's I tried zone transfers and other
>stuff on happily gave me their IP's, their dial-up IP's, public SNMP
>responses from their routers, fingers on their RAS's, the works.


Some routers have default password of cisco, and yes most routers do bother
to ask username also.
>
>I guess it won't take more than an hour or so to get r00t on any of
>their servers either.

yes, very true.

>
>Security?  What's that?
>
>/me's clue-o-meter reads below zero.

because the mostly server are managed by mouse clickers only.

>
>Regards,
>
>-- Raju
>