EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesHard
A penetration tester is evaluating the security posture of an organization's network. They want to identify active hosts on the network segments without generating significant network traffic or triggering easily detectable alerts. The network administrators have configured firewalls to drop ICMP echo requests. Which Nmap host discovery technique would be most effective and stealthy in this scenario?
- AUDP Ping Scan (-PU)
- BTCP SYN Ping Scan (-PS)
- CARP Ping Scan (-PR)
- DTCP ACK Ping Scan (-PA)
Show answer & explanationAnswer & explanation
Correct answer: D. TCP ACK Ping Scan (-PA)
Since ICMP echo requests are blocked, standard ping scans are ineffective. TCP ACK Ping Scan (-PA) sends an ACK packet to a specified port. Most hosts will respond with an RST if the port is closed, or nothing if the port is open and the ACK is out of sequence. This can bypass firewalls that only block SYN packets or ICMP, and is less likely to be logged as a full connection attempt.
Why the other options are wrong
- A. UDP Ping Scan sends UDP packets; while it can be stealthy, it's often less reliable for host discovery than TCP-based methods, especially if UDP ports are filtered.
- B. TCP SYN Ping Scan sends a SYN, which many firewalls are configured to detect and block.
- C. ARP Ping Scan is only effective on the local subnet and doesn't work across routers or for external scans.
TCP ACK Ping Scan (-PA)
An Nmap host discovery method that sends TCP ACK packets to target hosts. It's effective for bypassing firewalls that block ICMP or SYN packets, as it doesn't attempt to establish a connection.
- Sends ACK packets to a specified port (default 80)
- Target responds with RST if port is closed, or nothing if filtered
- Good for firewall bypass, especially for ICMP/SYN blocking
Memory trick: ACKing bypasses the firewall's ICMP and SYN guards.