RE: [LOGS] Summary of large-scale portscanning detec ts

Patrik Sternudd <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Barry,

You wrote:

> I can think of a number of reasons why he wouldn't want to do this.
> 
> First, since these are firewall logs that would be a counter-scan.  
> Second, if the attacker were looking for a response, it could be 
> detected by the attacker and might bring interest to the network.  
> Third, if the system sending the p0f scan were the firewall 
> itself, it could expose information about the firewall.

Sorry to contradict you, but p0f is a passive OS fingerprinting
utility, hence no counter scan will be performed.

Cheers,
Patrik Sternudd



_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.