Network Security Assessment: From Vulnerability to Patch

| Note | No specific tools are implied or endorsed. No specific brands are implied or endorsed. CVE/CAN relation is strongly recommended. Tool versions are current as of the writing of this book. |
Tool Name: Nmap (v.3.81)
Developer: Fyodor (Insecure.org)
Platform/OS: UNIX, Linux, FreeBSD, NetBSD, OpenBSD, Solaris, OS X, Microsoft Windows, HP-UX, AIX, DigUX, Cray UNICOS
Commercial or Freeware? Freeware (GPL)
URL: www.insecure.org/nmap/
Notes: Microsoft Windows XP SP2 disabled the ability to use RAW sockets, it throttled the number of permitted outbound TCP connections, and disabled the ability to send spoofed UDP packets. This is fixed in Nmap version 3.55 and newer. Nmap is a tool that fits into more than one baseline activity. It can provide a wealth of information.
Tool Name: ScanLine (v.1.01)
Developer: McAfee (formerly FoundStone)
Platform/OS: Microsoft Windows
Commercial or Freeware? Freeware
URL: www.foundstone.com/resources/proddesc/scanline.htm
Notes: ScanLine is the replacement for Fscan. This is a command-line scanner for the MS Windows platform; it can handle scanning in a highly parallel fashion and provides more scanning capabilities than Fscan did.
Tool Name: Scanrand (part of paketto v.2.0p3)
Developer: Dan Kaminsky
Platform/OS: Compiles on Linux (RedHat, Mandrake, and Debian), FreeBSD, MinGW (on MS Windows)
Commercial or Freeware? Freeware
URL: www.doxpara.com
Notes: Libnet (v1.0.2) and libpcap are required.
Tool Name: SuperScan (v.4.0)
Developer: McAfee (formerly...