User manual

90
The Optional Sections are formatted to be read from beginning to end. The Appendices are not intended
to be read from start to finish; they are included as reference material.
7.1.1 Anomaly Detection
The Anomaly Detection section lists any anomalies that PhoneSweep found during checks on remote
modems. Anomalies are inconsistent responses from one call to the next; they often indicate an
unauthorized or misconfigured modem.
For example, two calls to the same phone number might yield a modem (Carrier) on the first call and
Voice on the second. This could be an unauthorized modem that is only activated some of the time.
Another phone number might connect with Carrier on most calls, but report Timeout one out of four
times. This may indicate a faulty modem.
The Anomaly Detection section may take a substantial amount of time to generate, since it is
crosschecking responses against each other, but it does not generate a lengthy section in the report. We
recommended that you include the Anomaly Detection section in most reports, because it often shows
serious problems with security or reliability.
The Anomaly Detection section is included by default. To exclude the Anomaly Detection section from
the report, click the check box to deselect it.
7.1.2 Penetrated Modem Responses
The Penetrated Modem Responses section of the PhoneSweep report prints the entire buffer received
from each modem that was successfully penetrated. These buffers contain useful information about what
computer system is connected to the penetrated modem. Unless PhoneSweep has managed to penetrate a
large number of modems, this section is likely to be reasonably short.
The Penetrated Modem Responses section is included by default. To exclude this section from the report,
click the check box to deselect it.
7.1.3 Appendix A: All Responses From Target Modems
Appendix A includes the full response buffer from every Carrier call. This appendix is useful for getting
information about systems that PhoneSweep was unable to identify.
If you have a large number of modems to test or a large username/password database, Appendix A can
easily run to hundreds of pages. Check the length of reports including Appendix A before sending them to
a printer.
Because of its potential length, Appendix A is excluded from the report by default. To include it, click
in the appropriate check box.
7.1.4 Appendix B: Phone Number Taxonomy
Appendix B lists PhoneSweep’s best guesses as to the nature of the system that answered each call. The
information is sorted by phone number. If a phone number responds in multiple different ways to multiple
calls, each response will be included in the list. If PhoneSweep was able to correctly guess any usernames
and passwords, they will be included in Appendix B with the phone number.
If there are systems that PhoneSweep does not identify, please contact Sandstorm. We are interested in
obtaining data so future versions of PhoneSweep can identify those systems. In many cases, the
appropriate section of Appendix A will contain all the information necessary for engineering PhoneSweep
to identify that system.
Appendix B is turned on by default.