RE: [LOGS] Summary of large-scale portscanning detec ts
Patrik Sternudd <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Barry, You wrote: > I can think of a number of reasons why he wouldn't want to do this. > > First, since these are firewall logs that would be a counter-scan. > Second, if the attacker were looking for a response, it could be > detected by the attacker and might bring interest to the network. > Third, if the system sending the p0f scan were the firewall > itself, it could expose information about the firewall. Sorry to contradict you, but p0f is a passive OS fingerprinting utility, hence no counter scan will be performed. Cheers, Patrik Sternudd _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions