Unit 3: Port Scanning 3.1 Port Scanning ACK Scan

You might be wondering if there's a way to get further
insight to a port that's being flagged as open or filtered. The
answer is yes. The purpose of the ACK scan is simply to
identify if a port is filtered or unfiltered. The beauty of
this very simple scan is that it lets you know if there's a
firewall between you and the destination, which is very
important information to have. The ACK scan sends a TCP segment
with the ACK flag raised to a destination IP address and port.
If there is no reply or an ICMP destination unreachable message
comes back, there's a firewall filtering your traffic. If an
RST comes back from the destination, there is obviously
no filter dropping your traffic. So think back to an Null, FIN,
or Xmas scan that was classified as either open or filtered. We
want to know, is that port open or filtered? If nothing comes
back from the ACK scan, we can say that the port is filtered.
If an RST comes back with the ACK scan, we can say that the
port is open on a non-Windows system. If the Null, FIN, Xmas
scans got an RST from a Windows system, we know the port is not
filtered. Therefore, after getting an RST back from the ACK
scan, it could mean either a Windows open port or a Windows
closed port, Which doesnt really help. Windows systems
response to Null, FIN and Xmas scans with an RST, regardless if
a port is open or closed. This is a great example of how
certain scans can be used in tandem for reconnaissance by
both the hackers and cybersecurity specialists.

转载于:https://www.cnblogs.com/sec875/articles/10028382.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值