官术网_书友最值得收藏!

How it works...

The ACK scan sends an acknowledgment packet instead of a SYN packet. The firewall does not create logs of ACK packets as it will treat ACK packets as the response of the SYN packets. It is mostly used to map the type of firewall being used.

The scan results of filtered and unfiltered ports depend on whether the firewall being used is stateful or stateless. A stateful firewall checks whether an incoming ACK packet is part of an existing connection or not. It blocks it if the packets are not part of any requested connection, and so the port will show up as filtered during the scan, whereas in the case of a stateless firewall, it will not block the ACK packets and the ports will show up as unfiltered.

 An idle scan works on the basis of a predictable IPID or IP Fragmentation ID of the zombie host. First, the IPID of the zombie host is checked and then a connection request is spoofed from that host to the target host. If the port is open, an acknowledgment is sent back to the zombie host, which resets (RST) the connection so that it has no history of opening such a connection.

Next, the attacker checks the IPID on the zombie host again. If it has changed by one step, it implies that a RST was received from the target. However, if the IPID has changed by two steps, it means that the packet was received by the zombie host from the target host, and there was an RST on the zombie host, which implies that the port is open.

主站蜘蛛池模板: 利津县| 加查县| 石狮市| 偏关县| 石门县| 开封市| 鄂伦春自治旗| 潜江市| 井冈山市| 呼和浩特市| 墨脱县| 保靖县| 鹤山市| 夏邑县| 灵武市| 望江县| 宜君县| 麻江县| 东山县| 波密县| 阜南县| 囊谦县| 章丘市| 清丰县| 榆社县| 扎兰屯市| 大化| 长春市| 屯昌县| 余干县| 周至县| 英德市| 永川市| 雅安市| 陇南市| 巴马| 隆林| 库尔勒市| 永清县| 新源县| 建德市|