Nmap Development mailing list archives
RE: decoy scan: no decoy packages
From: "Craig Humphrey" <Craig.Humphrey () chapmantripp com>
Date: Tue, 14 Dec 2004 12:22:47 +1300
I don't think 'traceroute' is going to tell you what packets made it to the target... 'tcpdump' perhaps? Or Ethereal? (or some other network sniffer). Is there anything between your scanning host and the target host? E.g. routers, firewalls, etc, which might filter out invalid/spoofed traffic. Hope that helps. Later'ish Craig
-----Original Message----- From: mgrd [mailto:subscriptions () gerdau freeshell org] Sent: Tuesday, December 14, 2004 12:14 PM To: nmap-dev () insecure org Subject: decoy scan: no decoy packages When running a decoy scan, shouldn't I see decoy host packages arriving on the target host? I ran: `nmap -sS <ip-decoy1>,<ip-decoy2>,ME <ip-target>' (where: `ME' is expanded to the own IP) Running `traceroute' on the target host, no decoy host IP packages arrived but only of the scanning host. nmap version : 3.75 (default compile) scanning host OS: linux 2.4.20 x86 target host OS : linux 2.4.20 x86
--------------------------------------------------------------------- For help using this (nmap-dev) mailing list, send a blank email to nmap-dev-help () insecure org . List archive: http://seclists.org
Current thread:
- decoy scan: no decoy packages mgrd (Dec 13)
- <Possible follow-ups>
- Re: decoy scan: no decoy packages mgrd (Dec 13)
- RE: decoy scan: no decoy packages Craig Humphrey (Dec 13)
- Re: decoy scan: no decoy packages mgrd (Dec 13)
- Re: decoy scan: no decoy packages Nils Magnus (Dec 13)
- Re: decoy scan: no decoy packages mgrd (Dec 13)
- Re: decoy scan: no decoy packages mgrd (Dec 13)
- RE: decoy scan: no decoy packages Craig Humphrey (Dec 13)
- RE: decoy scan: no decoy packages Gary Bunker (Dec 14)