EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium
An ethical hacker is performing a black-box penetration test. They need to identify open ports and services on a target network without triggering intrusion detection systems (IDS) that are highly sensitive to full TCP handshakes. Which Nmap scan type is most suitable for this objective?
- AXmas Scan (-sX)
- BSYN Stealth Scan (-sS)
- CTCP Connect Scan (-sT)
- DUDP Scan (-sU)
Show answer & explanationAnswer & explanation
Correct answer: B. SYN Stealth Scan (-sS)
The SYN Stealth Scan (-sS) is designed to be stealthy by not completing the full TCP 3-way handshake. It sends a SYN packet and if a SYN/ACK is received, it sends an RST, preventing the target from logging a full connection, which makes it less likely to be detected by IDS.
Why the other options are wrong
- A. Xmas Scan can be stealthy, but it's often used to determine port states (open/closed/filtered) by manipulating TCP flags, and not specifically for avoiding full TCP handshakes like the SYN scan.
- C. TCP Connect Scan completes the full TCP 3-way handshake and is easily detectable by IDS.
- D. UDP Scan is for UDP ports, not for avoiding TCP handshake detection, and can be slow/unreliable for open port detection.
SYN Stealth Scan (-sS)
An Nmap scan technique that sends a SYN packet and, upon receiving a SYN/ACK, immediately sends an RST packet to avoid completing the TCP handshake, making it less detectable.
- Does not complete TCP 3-way handshake
- Less likely to be logged by target systems
- Requires raw packet privileges
Memory trick: SYN is stealthy because it doesn't say 'hello' all the way.