RE: pre-scanning for vulnerability scans?

From: Lyal Collins (lyal.collins@key2it.com.au)
Date: Mon Jan 09 2006 - 15:30:20 EST


Not sure about cable modems, but many DSL modem/switch/firewall devices have
more or less hard limits on the number of 'routes' (src IP, port, dest IP,
port) due to limited memory, thus limited ip_conntrack pools. Exhaust the
ip_conntrack pool and packet log/queuing/dropping becomes a dominating
factor for speed and accuracy.

Using a USB DSL modem and a PC-based linux box as the router and or test
machine may increase this threshold substantially, otherwise I've found
tweaking your DSL modem to increase the ip_conntrack pool to the devices
memory limits, and reduce the timeout settings so as to release used
ip_conntracks quicker will somewhat increase your scanning speed to around
the '-T polite' setting on nmap.

Unicornscan also needs to be throttled down on NATed DSL modems, in my
experience, to a few dozen to 100pps or so.

Patience in recon scanning pays off later, in my view.

Lyal

-----Original Message-----
From: offset [mailto:offset@core.svcroot.net]
Sent: Monday, 9 January 2006 4:48 PM
To: pen-test@securityfocus.com
Subject: pre-scanning for vulnerability scans?

Greetings,

My goal is to determine ways to speed up network vulnerability scans on a
number of /20 networks (but not at the expense of accuracy)

Given the goal above, anyone have experience testing accuracy and speed for
host detection and full port scans using various network scanners (ie,
unicorn versus nmap)?

Do you find that bandwidth is the limiting factor to negate differences
between scanners? Assuming source is typical broadband (dsl, cable) around
1Mbps upload speed.

Looking to find most efficient methods of the following, assume stealth is
not the goal, but accuracy is 1. host up detection (detecting ports (ie, 80,
443)), mark for followup later (queue for full scan) 2. full port SYN scan
on detected hosts (TCP only) 3. vulnerability analysis based on host/port
information

Regards

----------------------------------------------------------------------------

--
Audit your website security with Acunetix Web Vulnerability Scanner: 
Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
futile against web application hacking. Check your website for
vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers
do! 
Download Trial at:
http://www.securityfocus.com/sponsor/pen-test_050831
----------------------------------------------------------------------------
---
------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 
Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:
http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:55:20 EDT