LostInSpace wrote: Then again, web servers are more commonly hacked than internal file servers anyway...and you could scan those./quote]Yes, and that's why companies really shouldn't attach webservers to their LAN or WAN unless they have a really good reason. Placing it at a decent host is often much safer. Usually any type of internal access will have to be done with some sort of social engineering. If you can port scan a companies internal machines, they are just asking for it. Yeah, with a decent firewall (i.e. PIX or Checkpoint) configured by a competent professional you have a lot less to worry about attackers using the front door to enter, by technical means.
Usually any type of internal access will have to be done with some sort of social engineering. If you can port scan a companies internal machines, they are just asking for it.
/usr wrote: After all this studying, I'm feeling dumb. The whole CEH book assumes you can scan the pc, find out info, etc...but if the pc is behind a router which performs NAT (which almost all do now) then that whole concept goes out the window, right? So what do you do...?
Ten9t6 wrote: A lot of devices now come with a ingress filter for internal addresses.......