EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium
An ethical hacker is performing an internal penetration test and has gained access to a workstation. They want to identify other active hosts on the local network segment without sending any packets that would leave the local subnet and trigger network-based intrusion detection systems (NIDS). Which of the following Nmap host discovery techniques would be most suitable for this scenario?
- AUDP Ping (-PU)
- BARP Ping (-PR)
- CTCP SYN Ping (-PS)
- DICMP Echo Ping (-PE)
Show answer & explanationAnswer & explanation
Correct answer: B. ARP Ping (-PR)
ARP Ping (-PR) uses ARP requests to discover hosts on the local network segment. ARP traffic does not traverse routers, making it ideal for host discovery within a local subnet without sending packets that would leave the local network and potentially trigger NIDS.
Why the other options are wrong
- A. UDP Ping sends UDP packets to common ports, which can cross subnets and may trigger NIDS.
- C. TCP SYN Ping sends TCP SYN packets, which can cross subnets if routing allows and may trigger NIDS.
- D. ICMP Echo Ping sends ICMP packets, which can cross subnets and are commonly monitored by NIDS.
Nmap ARP Ping (-PR)
An Nmap host discovery method that sends ARP requests to identify live hosts on a local Ethernet network. It operates at Layer 2 and does not traverse routers.
- Operates at Layer 2 (Data Link Layer).
- Does not cross subnet boundaries.
- Effective for local network host discovery.
- Less likely to trigger NIDS compared to Layer 3 pings.
Memory trick: Pings are like knocking; ARP is like asking your neighbor directly.