EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium
A penetration tester is tasked with identifying the operating systems running on a target's internal network hosts. They have already performed a basic port scan and identified several open ports. To accurately determine the OS, which Nmap scan type would be most appropriate and effective without being overly intrusive?
- ANmap -O (OS detection scan)
- BNmap -sN (Null scan)
- CNmap -sA (ACK scan)
- DNmap -sS (SYN stealth scan)
Show answer & explanationAnswer & explanation
Correct answer: A. Nmap -O (OS detection scan)
The Nmap -O option is specifically designed for operating system detection. It analyzes various TCP/IP stack characteristics to fingerprint the target OS, which directly addresses the objective.
Why the other options are wrong
- B. Null scan (-sN) is a stealthy port scan method that exploits TCP flag behavior, not for OS detection.
- C. ACK scan (-sA) is used to map firewall rulesets and determine if a port is filtered, not for OS detection.
- D. SYN stealth scan (-sS) is primarily for port scanning with stealth, not for OS detection.
Nmap OS Detection
Nmap's OS detection feature uses a series of TCP and UDP probes to analyze responses and infer the operating system running on a target host.
- Activated with the -O option.
- Analyzes TCP/IP stack implementation details (e.g., initial sequence numbers, TCP window sizes, IP ID fields).
- Can be less accurate if firewalls or network devices modify responses.
Memory trick: Nmap's many maps, each for a different task, know your purpose.