Continuing Port Scan
SYN scan (-sS):
- Makes a scan by sets the SYN flag.
- SYN scan is a fast scan because only one packet is sent to ports.
- Often used to evade firewall, IPS and does not leave traces in the logs, because three-way handshake not completed.
nmap -sS 192.168.1.18
data:image/s3,"s3://crabby-images/eecf6/eecf6455507669f65c63c09b2b659eba29377153" alt="SYN scan"
TCP connect scan (-sT):
- Three-way handshake completed.
- Leaves traces in the logs.
- Is a slow scan.
nmap -sT 192.168.1.18
UDP scan (-sU):
- Uses UDP packets.
- Is a slow scan because the three-way handshake not completed.
nmap -sU 192.168.1.18
TCP NULL/FIN/Xmas scan (-sN/-sF/-sX):
- NULL Scan: The packet is sent to the destination without setting flags
- FIN Scan: The packet is sent to the destination by setting the FIN flag,
- Xmas scan: The packet is sent to the destination by setting FIN-URG-PSH flags,
You can see that bits set as in the figure below with tcpdump.
nmap -sN 192.168.1.18
data:image/s3,"s3://crabby-images/d271d/d271dc9e993e9adb826eccd932d3201742d66faa" alt="Null Scan"
nmap -sF 192.168.1.18
data:image/s3,"s3://crabby-images/c69a5/c69a52c22e91b7729d2ad481dc2cee1f3885443a" alt="Fin Scan"
nmap -sX 192.168.1.18
data:image/s3,"s3://crabby-images/a1c41/a1c41f69e85ee9c28aa6fe991962d6ed3bb58b3e" alt="Xmas Scan"
TCP ACK Scan (-sA) :
- Makes a scan by sets ACK flag.
- Used for firewall detection.
nmap -sA 192.168.1.18