Presentation on theme: "Scanning Determining if the system is alive IP Scanning Port Scanning War Dialing."— Presentation transcript:
Scanning Determining if the system is alive IP Scanning Port Scanning War Dialing
PING Sweeps PING is used to send ICMP Echo type 8 packets to determined if a Type 0 reply is received indicating the system is alive. Type 0 Echo Reply Type 3 Destination unreachable Type 4 Source Quench Type 8 Echo Type 11 Time exceeded Type 13 Timestamp Reply Type 15 Info Request Type 16 Info Reply
FPING Fping for unix systems, can read the contents of a file listing a range of IP addresses Fping –a –f in.txt
Port Scanning Determining what services are running or listening by connecting to TCP and UDP ports
Scan Types TCP Connect (full three way hand shake SYN, SYN/ACK, ACK) TCP SYN (half open scan SYN/ACK listening state, RST/ACK not listening) TCP FIN (UNIX, if closed a RST is replied) TCP xmas tree FIN, URG and PUSH if closed a RST is replied) TCP Null (if closed a RST is replied) TCP Ack (Firewall rule sets, stateful firewalls) TCP Windows (detects open and filter ports) TCP RPC (Unix, detect RPC ports) UDP (connectionless, used to receive an ICMP unreachable message for closed ports) SYN SYN/ACK ACK Server Client
Your consent to our cookies if you continue to use this website.