Re: [SLUG] nmap and ID'ing open ports

From: bill triplett (btt@nethouse.com)
Date: Mon Sep 10 2001 - 21:44:19 EDT


On Sun, Sep 09, 2001 at 07:16:32PM -0400, Russell Hires wrote:
> Okay, I think I have it all figured out. Port 3059 is for kde, for some
> reason. I'll have to research that. Port 8021 is ID'ed as a python process,
> but it really belongs to Zope, as its ftp service. (8080 is normally the zope
> default http port, so 8021 for ftp...only makes sense.)
>
> The interesting thing for me lately is that whether my firewall is up or not,
> nmap shows me the same ports. So I'm sort of puzzled by that. OTOH, maybe
> that just means I'm nice and secure?

> > > Starting nmap V. 2.54BETA22 ( www.insecure.org/nmap/ )
> > > Interesting ports on poet (127.0.0.1):

It may be because in /etc/hosts or whatever DNS method is used,
poet is mapped to 127.0.0.1 which is usually 'localhost', on the
loopback interface (lo).

I think alot of firewalls just allow anything to and from localhost
because loopback traffic doesn't travel outside of the machine that
generated it. So any rules in the firewall to affect lookback would
never match any packets coming 'off the wire'.



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 19:04:40 EDT