nist special publication 800-41
-security guideline recommending that you block incoming ping traffic
malicious ping
-attackers can observe the ttl values in ping replies to identify operating systems
juniper ttl value
64
linux 2.4 ttl value
255
red hat ttl value
64
mac ttl value
64
windows ttl value
128
netstat
-used to determine if a particular service is listening on a network interface
nslookup
-resolves hostnames to test dns
nmap
- used to fingerprint services on open ports
nmap scan types
nmap -sS
nmap -sT
nmap -sU
nmap options
network traffic traveling through a windows firewall can be allowed or blocked based on
windows firewall profiles
domain windows firewall profile
- used for corporate networks
private windows firewall profile
- used for home networks
public windows firewall profile
- used for public networks
netfilter
iptables
- used to configure and view tables of packet filter rules
iptables parts
iptables rule match characteristics