Using nmap on a firewall

View: New views
1 Messages — Rating Filter:   Alert me  

Using nmap on a firewall

by russo :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi

I have a firewall but I'm not responsable for it.
I tryied nessus it sometimes gave me some information and other time no information, So I tryied nmap to scan it tryied some commands

I got this

 nmap -P0 -vv -sA -ff -r -n 195.XX.XX.XX

Starting Nmap 4.11 ( http://www.insecure.org/nmap/ ) at 2008-03-17 23:27 WET
Initiating ACK Scan against 195.XX.XX.XX [1680 ports] at 23:27
ACK Scan Timing: About 16.46% done; ETC: 23:30 (0:02:32 remaining)
The ACK Scan took 54.32s to scan 1680 total ports.
Host 195.XX.XX.XX appears to be up ... good.
Interesting ports on 195.XX.XX.XX:
Not shown: 1679 filtered ports
PORT     STATE      SERVICE
1723/tcp UNfiltered pptp

Nmap finished: 1 IP address (1 host up) scanned in 54.338 seconds


then I did this scan
 nmap -P0 -vv -sS -ff -r -n -p 1-65535 195.XX.XX.XX

Starting Nmap 4.11 ( http://www.insecure.org/nmap/ ) at 2008-03-18 00:44 WET
Initiating SYN Stealth Scan against 195.XX.XX.XX [65535 ports] at 00:44
SYN Stealth Scan Timing: About 0.42% done; ETC: 02:43 (1:58:12 remaining)
SYN Stealth Scan Timing: About 3.02% done; ETC: 01:17 (0:32:10 remaining)
SYN Stealth Scan Timing: About 5.66% done; ETC: 01:10 (0:25:01 remaining)
SYN Stealth Scan Timing: About 9.37% done; ETC: 01:07 (0:21:18 remaining)
SYN Stealth Scan Timing: About 27.15% done; ETC: 01:04 (0:14:56 remaining)
The SYN Stealth Scan took 1161.75s to scan 65535 total ports.
Host 195.XX.XX.XX appears to be up ... good.
All 65535 scanned ports on 195.XX.XX.XX are filtered

Nmap finished: 1 IP address (1 host up) scanned in 1161.813 seconds
               Raw packets sent: 262136 (8.388MB) | Rcvd: 4 (234B)


But I know that there are more ports open

What is the best command to see which ports are open?'