Jing An Telescope Factory (JATF): A network security case study, The
Journal of Information Systems Education, Fall 2003 by White, Doug, Rea, Alan
It is also worth noting that NMAP is available with add-ons, such as NMAPFE, which provide graphical interfaces for using NMAP. There also is a Windows version available. A simple self-scan from NMAP can be performed any number of ways, but a basic scan might look like this:
nmap -sT -vv -O localhost (assuming localhost is defined as the loopback address of 127.0.0.1)
Related Results
Figure 1 provides the return of the scan for this basic machine. The scan reveals a great deal of information about this system. It illustrates two things: 1) what the system looks like when a would-be intruder scans the system; 2) any unusual or unneeded services that may be running. Even though this system is firewalled off, there are still ports open that may be attacked from users inside the firewall. (Appendix B in the Teaching Notes provides a list of well-known ports and what they are typically used for.) It's important to know each port's function so that you can identify which system services are running at each open port. Conversely, you should know when a port should not be open.
The most critical information provided by the scan is the examination of open ports. In this case, the machine has eight open ports that may be running services that are in use, or perhaps the administrator has simply failed to disable unused services that are set up by default.
6.3.2 Working with the Ports: All of these ports can be Trojans or other hacking tools in disguise. NMAP simply reports the most common usage of the ports. The fact that NMAP says "printer" does not necessarily mean this is actually a printer port, it merely means that this is the most common usage of port 515. Many Trojans intentionally use common ports to avoid detection through misdirection. The best rule is to disable any service you are not using. If the corporate network administrator feels uncomfortable with this approach, the next best approach would be to log all activity on the port and see how and if the port is being used.
The remainder of the NMAP scan provides some information about the operating system. As Figure 1 illustrates, NMAP is always trying to collect fingerprint information to better discern which operating system is being run. This is useful only in regard to the failure of NMAP to identify the operating system and the warning that IPID (Internet Protocol Identification) scanning is possible (this is a subtle form of systems probing for information).
Creating a script to automate the scan on a regular basis is a very good means of keeping an update on your servers. You can create scripts that email you a scan of all your servers once a week. You will quickly develop a "feel" for what your servers are running and a change should be obvious without a great deal of scanning of logs.
6.3.3 Ethernet Sniffing: Ethernet sniffing has declined in popularity with the rise of switched as opposed to hubbed networks. Unlike hubs, which broadcast all packets across the network, switches usually filter broadcasts so sniffing is only a useful tactic for hackers if they can get close access to devices they wish to sniff.
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Reference Articles
- A Maryland state trooper gave Erik Bonstrom an $80 ticket for driving too slowly
- In California, postal worker Dean Hudson has been found guilty
- Alec Loorz, the 15-year-old founder of Kids vs. Global Warming and recent Brower Youth Award recipient, went to Congress in November for a press conference with Senators Barbara Boxer and John Kerry, who are championing legislation to stabilize US greenho
- Foreign exchange
- The buzz on bees
Most Recent Reference Publications
Most Popular Reference Articles
- Credit card debt on college campuses: causes, consequences, and solutions
- 9 questions to ask your new lover: what you were afraid to ask, but always wanted to know
- How Tyler Perry rose from homelessness to a $5 million mansion
- Rejoice anyway - Zephaniah 3:14-20, Philippians 4:4-7 - Living by the Word - Column
- Living by the word


