27.06.2013 Views

6th European Conference - Academic Conferences

6th European Conference - Academic Conferences

6th European Conference - Academic Conferences

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Muhammad Naveed<br />

32768 Udp Open Rpcbind<br />

32769 Udp Open | filtered<br />

32772 Udp Open | filtered<br />

Port Protocol State Service<br />

48480 Udp Open | filtered<br />

54711 Udp Open | filtered<br />

57409 Udp Open | filtered<br />

63420 Udp Open | filtered<br />

Table 21: Aggressive OS scan results (most probable)<br />

OS Name and Version Type Vendor OS Family OS Generation Accuracy of result<br />

Linux 2.4.28 – 2.4.35 General Purpose Linux Linux 2.4.X 97%<br />

Table 22: Aggressive OS scan results (other)<br />

Type Vendor OS Family OS Generation Accuracy of result<br />

General Purpose Ubiquiti Linux 2.4.X 95%<br />

General Purpose Linux Linux 2.6.X 94%<br />

6.2 Commercial organizations<br />

For the commercial organization, the webserver scanned is of the organization providing the same<br />

services in Pakistan as AT&T provides in America. The organization have hundreds of millions of<br />

customers and was selected as this organization should be first to implement security. The scan<br />

reveals horrible results, even the telnet port is opened as well as SSH. The server is being used as<br />

ftp, telnet, ssh, mail (smtp, imap, pop3) and many other servers as shown by forth column of table 24.<br />

Many ports are found open on the server to provide the various services, although webserver is<br />

supposed to provide only web services and should not be used as any other server at least for such a<br />

big organization. The OS installed is a Prerelease version of FreeBSD, which is released to find bugs.<br />

The server should be installed with a stable OS.<br />

Table 23: Scan Details<br />

Scanned Web Server Hidden (because of Possible Objections)<br />

Scan Launching Time 2010-08-14 00:50 PKST<br />

Scan Type Slow Comprehensive Scan<br />

Scan Time 7589.54 seconds<br />

Raw packets sent 2387 (88.397KB)<br />

Raw packets received 2302 (112.940KB)<br />

Table 24: Port scan results<br />

Port Protocol State Service<br />

21 Tcp Open ftp<br />

22 Tcp Open Ssh<br />

23 Tcp Open telnet<br />

25 Tcp Open Smtp<br />

80 Tcp Open http<br />

106 Tcp Open Pop3pw<br />

110 Tcp Open Pop3<br />

143 Tcp Open Imap<br />

443 Tcp Open http<br />

587 Tcp Open Smtp<br />

993 Tcp Open Imap<br />

995 Tcp Open Pop3<br />

1720 Tcp Filtered H.323/Q.931<br />

3306 Tcp Open Mysql<br />

5060 Tcp Filtered Sip<br />

5190 Tcp Open Smtp<br />

196

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!