CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester is performing an internal network assessment. They use `nmap` to scan a subnet and receive the following output for a specific host: ``` Nmap scan report for 192.168.1.100 Host is up (0.002s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0) 80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) 3389/tcp filtered ms-wbt-server ``` Based on this `nmap` output, which of the following is the MOST accurate conclusion regarding the `3389/tcp` port?

  1. AThe port is closed, and RDP is not running on the host.
  2. BThe port is being actively blocked by a firewall, preventing `nmap` from determining its state or service.
  3. CThe port is open, and RDP is running, but `nmap` could not identify the version.
  4. DThe port is open, but the service is being blocked by a firewall.
Show answer & explanation

Correct answer: B. The port is being actively blocked by a firewall, preventing `nmap` from determining its state or service.

The `filtered` state in `nmap` output indicates that a firewall, filter, or other network obstacle is blocking the port, preventing `nmap` from determining if the port is open or closed. It doesn't mean the port is necessarily closed, nor does it mean it's open and just blocking the service version; it means the probe didn't reach the port to get a definitive response.

Why the other options are wrong

  • A. A 'closed' state would explicitly indicate the port is not listening. 'Filtered' implies a block.
  • C. If it were 'open' but the version unknown, it would likely show 'open unknown' or 'open service?' not 'filtered'.
  • D. An 'open' state would mean the port is listening. 'Filtered' implies a block preventing state determination.

Nmap Port States

`nmap` reports various states for ports (e.g., open, closed, filtered, unfiltered, open|filtered, closed|filtered) to describe their accessibility and the presence of services.

  • Open: Application is actively accepting TCP connections/UDP datagrams.
  • Closed: Port is accessible, but no application is listening.
  • Filtered: Firewall or network device is blocking probes, state is unknown.

Memory trick: Open door, Closed door, Filtered to a mystery.

More Attacks and Exploits questions