WUPS

Even though ScanLine (covered in the next section) and nmap sufficiently address advanced port scanning and cover most conceivable operating systems, WUPS is worth a brief mention. WUPS is a companion to IpEye that scans UDP ports where the latter only covered TCP ports. It is available for download at http://ntsecurity.nu/toolbox/wups/.

Implementation

One nice thing about WUPS is that it has a graphical interface, as shown in Figure 4-3. As with other UDP scanners , packet filters that filter out "port unreachable" messages and the like can return a lot of false positives for the scan. Another drawback of WUPS is that it cannot scan a range of IP addresses. Figure 4-3 shows a UDP scan on 10.0.1.1 from port 1 to 1024 with a delay of 100 milliseconds between port probes. We would guess that 10.0.1.1 is a Windows system because of the UDP services on ports 137 and 138 (NetBIOS) as well as 445 (SMB over IP, also referred to as the Microsoft-DS service).


Figure 4-3: WUPS port scanner in action


Anti-Hacker Tool Kit
Anti-Hacker Tool Kit, Third Edition
ISBN: 0072262877
EAN: 2147483647
Year: 2006
Pages: 175

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net