![]() | ![]() |
[29]This problem could have been lessened if both had been running NTP. NTP is discussed in Chapter 11, "Miscellaneous Tools".It is best to deal with such potential problems in advance by clearly stating what you will be doing and why. If you can't justify it, then perhaps you should reconsider exactly why you are doing it. A number of sites automatically block networks or hosts they receive scans from. And within some organizations, unauthorized scanning may be grounds for dismissal. You should consider developing a formal policy clearly stating when and by whom scanning may and may not be done. This leads to an important point: you really should have a thorough understanding of how scanning tools work before you use them. For example, some SNMP tools have you enter a list of the various SNMP passwords (community strings) you use on your network. In the automatic discovery mode, it will probe for SNMP devices by trying each of these passwords in turn on each machine on the network. This is intended to save the network manager from having to enter this information for each individual device. However, it is a simple matter for scanned machines to capture these passwords. Tools like dsniff are designed specifically for that purpose. I strongly recommend watching the behavior of whatever scanning tools you use with a tool like tcpdump or ethereal to see what it is actually doing. Unfortunately, some of the developers of these tools can't seem to decide whether they are writing for responsible users or crackers. As previously noted, some tools include questionable features, such as support stealth scans or forged IP addresses. In general, I have described only those features for which I can see a legitimate use. However, sometimes there is no clear dividing line. For example, forged IP addresses can be useful in testing firewalls. When I have described such features, I assume that you will be able to distinguish between appropriate and inappropriate uses.
![]() | ![]() | ![]() |
6.5. Mapping or Diagramming | ![]() | 6.7. Microsoft Windows |
Copyright © 2002 O'Reilly & Associates. All rights reserved.