<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: stealth techniques &#8211; syn</title>
	<atom:link href="http://www.darknet.org.uk/2007/06/stealth-techniques-syn/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2007/06/stealth-techniques-syn/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 14 Feb 2012 00:17:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: backbone</title>
		<link>http://www.darknet.org.uk/2007/06/stealth-techniques-syn/#comment-59550</link>
		<dc:creator>backbone</dc:creator>
		<pubDate>Fri, 15 Jun 2007 09:36:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/stealth-techniques-syn/#comment-59550</guid>
		<description>in some cases you may be right shadow... but not everybody has an IDS/IPS... and believe me I infiltrated many hosts/website which haven&#039;t got protection at all... why waste my time? well if you didn&#039;t know darknet is based on the motto: &quot;share your knowledge&quot;... so then why not share it...</description>
		<content:encoded><![CDATA[<p>in some cases you may be right shadow&#8230; but not everybody has an IDS/IPS&#8230; and believe me I infiltrated many hosts/website which haven&#8217;t got protection at all&#8230; why waste my time? well if you didn&#8217;t know darknet is based on the motto: &#8220;share your knowledge&#8221;&#8230; so then why not share it&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shadow</title>
		<link>http://www.darknet.org.uk/2007/06/stealth-techniques-syn/#comment-59514</link>
		<dc:creator>shadow</dc:creator>
		<pubDate>Thu, 14 Jun 2007 17:54:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/stealth-techniques-syn/#comment-59514</guid>
		<description>Why even waste time explaining the techniques for xmas, null, and fin scans?  xmas scans = pulling the IDS/IPS fire alarm.  Null = another IDS/IPS fire alarm.  FIN scan = not gonna bypass any firewall worth a grain of salt, unless it was developed back during the Cold War.  All three should be known for historical reasons though.  IMHO, the only tcp based scanning techniques worth anything are full connection scans (extremely low and slow), and idle scanning with an intelligent script that can identify enough idle zombies to guarantee reliability.  Syn scans used to be worth something however a high number of syn packets with no follow up creates a telltale sign of reconnaissance activity; so if you are really trying to be sneaky you might as well just do a full connect scan so it at least appears to be normal connection attempts that suffered from some application error.  On the other hand if you&#039;re not worried about stealth and just want a quick scan use a syn scan (much faster when since you don&#039;t have to wait for 3-way handshake to complete.</description>
		<content:encoded><![CDATA[<p>Why even waste time explaining the techniques for xmas, null, and fin scans?  xmas scans = pulling the IDS/IPS fire alarm.  Null = another IDS/IPS fire alarm.  FIN scan = not gonna bypass any firewall worth a grain of salt, unless it was developed back during the Cold War.  All three should be known for historical reasons though.  IMHO, the only tcp based scanning techniques worth anything are full connection scans (extremely low and slow), and idle scanning with an intelligent script that can identify enough idle zombies to guarantee reliability.  Syn scans used to be worth something however a high number of syn packets with no follow up creates a telltale sign of reconnaissance activity; so if you are really trying to be sneaky you might as well just do a full connect scan so it at least appears to be normal connection attempts that suffered from some application error.  On the other hand if you&#8217;re not worried about stealth and just want a quick scan use a syn scan (much faster when since you don&#8217;t have to wait for 3-way handshake to complete.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: s1n</title>
		<link>http://www.darknet.org.uk/2007/06/stealth-techniques-syn/#comment-59472</link>
		<dc:creator>s1n</dc:creator>
		<pubDate>Wed, 13 Jun 2007 12:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/stealth-techniques-syn/#comment-59472</guid>
		<description>I recommend &quot;scapy&quot; as can be scripted and expanded on much easier:

http://www.google.co.uk/search?hl=en&amp;q=scapy&amp;btnG=Google+Search&amp;meta=</description>
		<content:encoded><![CDATA[<p>I recommend &#8220;scapy&#8221; as can be scripted and expanded on much easier:</p>
<p><a href="http://www.google.co.uk/search?hl=en&#038;q=scapy&#038;btnG=Google+Search&#038;meta" rel="nofollow">http://www.google.co.uk/search?hl=en&#038;q=scapy&#038;btnG=Google+Search&#038;meta</a>=</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: backbone</title>
		<link>http://www.darknet.org.uk/2007/06/stealth-techniques-syn/#comment-59434</link>
		<dc:creator>backbone</dc:creator>
		<pubDate>Tue, 12 Jun 2007 14:49:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/stealth-techniques-syn/#comment-59434</guid>
		<description>yes, i did mean waiting =)...</description>
		<content:encoded><![CDATA[<p>yes, i did mean waiting =)&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nTze</title>
		<link>http://www.darknet.org.uk/2007/06/stealth-techniques-syn/#comment-59421</link>
		<dc:creator>nTze</dc:creator>
		<pubDate>Tue, 12 Jun 2007 10:07:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/stealth-techniques-syn/#comment-59421</guid>
		<description>Thanks for that post dude, very good idea :)
Btw, did you mean &quot;waiting&quot;?

&quot;Now for the moment we all were [[ wainting ]] for:&quot;</description>
		<content:encoded><![CDATA[<p>Thanks for that post dude, very good idea :)<br />
Btw, did you mean &#8220;waiting&#8221;?</p>
<p>&#8220;Now for the moment we all were [[ wainting ]] for:&#8221;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

