EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium

A penetration tester needs to perform a comprehensive port scan on a target network, but the client has strict requirements to minimize the chances of detection by network monitoring tools. The tester decides to use a scan that is known for its ability to bypass some firewalls and IDS by setting specific TCP flags. Which Nmap scan type fits this description and typically involves FIN, PSH, and URG flags?

  1. ANull Scan (-sN)
  2. BXmas Scan (-sX)
  3. CWindow Scan (-sW)
  4. DMaimon Scan (-sM)
Show answer & explanation

Correct answer: B. Xmas Scan (-sX)

The Xmas Scan (-sX) sets the FIN, PSH, and URG flags in the TCP header. When a port is open on a Linux/Unix system, it typically sends no response to such a packet. If the port is closed, it sends an RST. This behavior, especially the lack of response for open ports, can bypass some firewalls and IDS.

Why the other options are wrong

  • A. Null Scan (-sN) sends packets with no TCP flags set. It's stealthy but doesn't set FIN, PSH, and URG flags.
  • C. Window Scan (-sW) examines the TCP window size to determine port state, not by setting FIN, PSH, and URG flags.
  • D. Maimon Scan (-sM) is another stealthy scan that sends FIN/ACK and expects no response for open ports, but it's not characterized by setting FIN, PSH, and URG specifically as the Xmas scan.

Xmas Scan (-sX)

An Nmap scan technique that sets the FIN, PSH, and URG flags in the TCP header to probe ports. It can be stealthy as open ports on some OSes may not respond, while closed ports send an RST.

  • Sets FIN, PSH, URG flags
  • Open ports (Unix/Linux) often send no response
  • Closed ports send RST
  • Can bypass some firewalls/IDS

Memory trick: Xmas lights (FIN, PSH, URG) blink to reveal hidden ports.

More Reconnaissance Techniques questions