Basically, the objective of this research was to see how Windows 2012 and CentOS 6.5 respond when a specific TCP packet is sent to it.
Stimulus
| Response | |||
| Windows 2012 | Linux CentOS 6.5 | |||
| 80 (Listening) | 81 (Not listening) | 80 (Listening) | 81 (Not listening) | |
| FIN | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| SYN | SYN-ACK | RST-ACK | SYN-ACK | RST-ACK |
| RST | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| ACK | RST | RST | RST | RST |
| PSH | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| URG | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| FIN-SYN | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| RST-PSH | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| ACK-URG | RST | RST | RST | RST |
| URG-FIN | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| URG-SYN | SYN-ACK | RST-ACK | SYN-ACK | RST-ACK |
| URG-RST | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| URG-PSH | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| ACK-PSH | RST | RST | RST | RST |
| ACK-RST | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| SYN-ACK | RST | RST | RST | RST |
| FIN-ACK | RST | RST | RST | RST |
| PSH-SYN | SYN-ACK | RST | SYN-ACK | RST |
| PSH-FIN | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| RST-SYN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| RST-FIN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| SYN-FIN | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| URG-ACK-PSH | RST | RST | RST | RST |
| URG-ACK-RST | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| URG-ACK-SYN | RST | RST | RST | RST |
| URG-ACK-FIN | RST | RST | RST | RST |
| FIN-SYN-RST | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| FIN-SYN-PSH | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| FIN-SYN-ACK | RST | RST | RST | RST |
| FIN-SYN-URG | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| SYN-RST-PSH | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| SYN-RST-ACK | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| SYN-RST-URG | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| PSH-RST-ACK | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| PSH-ACK-SYN | RST | RST | RST | RST |
| PSH-FIN-SYN | RST-ACK | RST-ACK | Silent Discard | RST-ACK |
| PSH-RST-SYN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| RST-ACK-SYN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| RST-FIN-SYN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| RST-URG-FIN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| RST-PSH-FIN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| URG-ACK-PSH-RST | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| URG-ACK-PSH-SYN | RST | RST | RST | RST |
| URG-ACK-PSH-FIN | RST | RST | RST | RST |
| ACK-PSH-RST-SYN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| ACK-PSH-RST-FIN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| PSH-RST-SYN-FIN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| URG-ACK-SYN-FIN | RST | RST | RST | RST |
| PSH-ACK-URG-FIN | RST | RST | RST | RST |
| URG-ACK-PSH-RST-SYN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| URG-ACK-PSH-RST-FIN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
| ACK-PSH-RST-SYN-FIN | Silent Discard | Silent Discard | Silent Discard | Silent Discard |
Developed by Abdul Kittana and Nik Alleyne for securitynik.blogspot.ca
| Blackhole | ||||||
| Identifies the same response | ||||||
| Identifes Difference in response for listening ports | ||||||
Enjoy!
No comments:
Post a Comment