Penetration Testing mailing list archives
Re: FW: RE Modem identification
From: olle <olle () nxs se>
Date: Wed, 26 Sep 2001 14:15:36 +0200
On Tue, Sep 25, 2001 at 10:01:01AM +0200, Dawes, Rogan (ZA - Johannesburg) wrote:
Re the prompting, one of the most common "Silent" modems seems to be Windows NT RAS. This sits there until you give it a particular string. I am intending to capture the initial string using PortMon, and replay it blindly whenever I get no initial characters. That should help identify a number of systems, I think.
NT RAS is just PP with MSCHAP authentication. pppd will suffice both to identify and bf NT RAS. /olle ---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/
Current thread:
- RE Modem identification Nate . King (Sep 21)
- <Possible follow-ups>
- FW: RE Modem identification Stephan Barnes (Sep 22)
- Re: FW: RE Modem identification Bikar Dude (Sep 23)
- RE: FW: RE Modem identification Stephan Barnes (Sep 25)
- RE: FW: RE Modem identification Dawes, Rogan (ZA - Johannesburg) (Sep 25)
- Re: FW: RE Modem identification olle (Sep 26)
- Re: FW: RE Modem identification Pawel Krawczyk (Sep 26)