154
rtsp alternate port tcp/8554 detection
Enumeration
2004/09/06
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.1
Corrected the plugin structure and added the accuracy values in 1.1
tcp
8554
open|sleep|send \n|sleep|close|pattern_exists RTSP/
90
See also ATK plugin 153 for starting an attack on the port 554.
Real time stream server
Other solutions
Configuration
The remote host is running a Real Time stream server on the alternate port tcp/8554. These are using the Real Time Stream Control Protocol (rtsp). An attacker may use this information to start further enumeration or attacks.
The server should be deactivated or de-installed if not necessary. Try to prevent unwanted connection attempts by filtering traffic with firewalling.
Approx. 30 minutes
Maybe
Yes
Yes
Low
6
7
3
5
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.normos.org/rfc/rfc2326.txt