Jump to content
Nytro

Topera: invisible IPv6 TCP scanner to Snort

Recommended Posts

Posted

[h=2]Topera: invisible IPv6 TCP scanner to Snort[/h]

Topera is a brand new TCP port scanner under IPv6, with the particularity that these scans are not detected by Snort.

Snort is the most known IDS/IPS and is widely used in many different critical environments. Some commercial tools (Juniper or Checkpoint ones) use it as detection engine also.

Mocking snort detection capabilities could suppose a high risk in some cases.

All the community is invited to test it in any environment and we would be thankful if you send us any feedback.

We keep researching on the security implications that the "new" IPv6 protocol will have in different environments.

This tool was presented in the second edition of the Security Conference "Navaja Negra" (Navaja Negra Conference :: Albacete) by Daniel Garcia a.k.a cr0hn (@ggdaniel) and Rafa Sanchez (@r_a_ff_a_e_ll_o ).

If any provider/vendor needs further detailed information or is interested in testing its products please, don't hesitate to contact us

In next pictures you can see some executions screenshots:

topera_help.jpg

topera_execution.jpg

You can see an example of execution of Topera here:

Links:

http://code.google.com/p/topera/
http://www.iniqua.com/labs/topera-invisible-tcp-scanner/?lang=en

Via: Full Disclosure: "Topera" The new IPv6 TCP port scanner invisible to SNORT...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...