Defense against port scans
So far, we have learned how to use port scanning techniques to discover and detect information about remote hosts. Let's try to understand that any services/hosts will be vulnerable to port scans, which are exposed to users through some sort of connectivity. This might include an enterprise WAN or the internet. Port scanning is also not classed as illegal activity unless information is used to exploit systems.
The amount of information that should be exposed to the outside world is down to the system administrator. Any IP scanning starts with an ICMP, and you can block all incoming ICMPs on an enterprise edge device. This will make Ping ineffective and will filter ICMP unreachable messages to block Traceroute as ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access