Re: Spoof IP otption synthax misleading

From: Tim (tim-pentest@sentinelchicken.org)
Date: Thu Feb 16 2006 - 17:08:25 EST


> is this the correct synthax of -S option ? ...I can't manage it to work
> properly because it gives me different results from a normal -sS option
> scan.
>
> nmap -vv -P0 -T4 -S xxx.xxx.xxx.xxx ( spoofed ) -e eth0 xxx.xxx.xxx.50 (
> target IP )

Hello again,

If you are spoofing a scan, what makes you think nmap will be able to
see the reply packets coming back from your target?

In some network configurations it can, but it sounds like you aren't in
one of those...

tim

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
futile against web application hacking. Check your website for vulnerabilities
to SQL injection, Cross site scripting and other web attacks before hackers do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:55:32 EDT