I rarely use Nmap for windows but I was forced to while educating a friend. In the process, I found a bug (or so I believe) so if anyone would like to test this before I submit it to Insecure.org, I'd appreciate it.
SOFTWARE
====================================
WinXP Pro SP1
Nmap for Windows v1.3.1
Winpcap v3.0
SETTINGS
====================================
SYN Stealth scan against any IP you like (other than your own)
Select Port Range and use 1-65535
Select Bounce Scan and enter the IP of the host you are currently using.
Hit "Scan" NOTE: This will cause the box to reboot.
EFFECT
====================================
While I don't think that the scan type or port range have anything to do with it, when you hit "scan" you get a blue screen along with a bunch of error messages that post for about a half second and the box immediately reboots. It also seems that bootup takes awhile longer than normal after you execute the scan.
Oh yeah, I do realize you are not supposed to put your IP in the Bounce field but then again, most of the bugs I find have nothing to do with how software is "supposed" to work/be used in the first place. ;)
Anyway, any other confirmation would be appreciated.
--TH13
