3 ms·
Not sure if I'd like to send anything into tested port just to tell if it is open. I'd rather stick with telnet or whatever is available. Also worth mentioning
by Snawoot 3y ago
Not sure if I'd like to send anything into tested port just to tell if it is open. I'd rather stick with telnet or whatever is available.
Also worth mentioning that bash also has network capabilities, you can check port like this:
: < /dev/tcp/google.com/80 && echo OK || echo ERROR
- edvinbesic 3y agoThis is very useful, will save me some hassle. Thanks!
- politelemon 3y agoThis is what I was trying to remember, I've seen this before but never understood it. What does the colon do?
- eMPee584 3y agoit makes the smiley face look very sad : < while giving an exit status of zero (in this case only if bash can resolve the input redirection by opening that tcp port)
- arp242 3y ago: is a special built-in that always succeeds and always returns an exit of 0. You typically use it when you need a command for syntax reasons, but don't actually need/want to run a command.
- matt-attack 3y agoExample?
- semi 3y agoit's equivalent to 'true'. It returns a successful value
- Eduard 3y ago> Not sure if I'd like to send anything into tested port just to tell if it is open. can you elaborate? From a stealth perspective, probing for a port will always reveal to the other side that they are being probed
- winrid 3y agoCould crash the server if it's badly written
- Snawoot 3y agoIt's not about stealth, it's about a bad habit of sending some bytes without thinking how it will be interpreted. Examples: - Syslog-ng server will interpret it as valid log messages - HP JetDirect on port 9100 will print HTTP request: https://twitter.com/AviKivity/status/1405147699557638145 https://twitter.com/AviKivity/status/1405147699557638145 - What if service is protected by fail2ban and accounting protocol errors? After all, sending anything was not my intention, so I won't send.
- void-star 3y agoYour concern about not wanting to send bytes is totally valid. As it happens (if memory serves) telnet can send some bytes on connection also, in attempting to negotiate terminal settings with the remote “telnet server”. That said the /dev/tcp trick is indeed great for bash though!
- keepamovin 3y agothat is so cool, my god! Bash is this awesome underrated thing (relative to how I perceive it being used). It's so cool that there's basically a virtual filesystem that maps the internet to your disk...haha. This even works on my Mac. But one issue I encountered was timeout. I just tried: : < /dev/tcp/google.com/8080 && echo OK || echo ERROR and it hung. So I asked ChatGPT and it suggested timeout 5 bash -c ': < /dev/tcp/google.com/8080' && echo OK || echo ERROR
- BenjiWiebe 3y agoThere isn't a virtual filesystem; bash just pretends there is. You can't use the /dev/tcp path in your own program as it doesn't exist.
- keepamovin 3y agoUnless...I program in bash! ^^ haha :) Yeah, I didn't know that. I definitely had a suspicion it was how you say, and "basically" was my fudge word, because I didn't know. I hadn't thought much about it, but I did not know for sure. Thanks for tellin me. I've thought about this idea: mapping the internet to the Unix filesystem, a la proc. I know TabFS, but I think the mapping could be better. I think it's an interesting problem to consider what a good mapping would be. But it's all tradeoffs I guess. I haven't thought that much about it. But it did seem interesting. Maybe not interesting enough to really commit to, because it seemed kinda like a big project. But definitely interesting to consider. What do you think? What kind of mapping would you do?