Module 3: Scanning and Enumeration Flashcards

1
Q

Scanning and Enumerations is the process of identifying

A

hosts, ports and services within the network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the three types of scanning?

A

Network Scanning
Port Scanning
Vulnerability Scanning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

TCP Flags

SYN

A

synchronise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

TCP Flags

ACK

A

Acknowledge the SYN flag

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

TCP Flags

RST

A

Reset - forces a termination of the circuit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

TCP Flags

FIN

A

Finish - orderly tear down of the circuit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

TCP Flags

PSH

A

Push -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

TCP Flags

URG

A

Urgent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Well-known Port Numbers

A

0-1023

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Registered Port Numbers

A

1024-49151

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Dynamic Port Numbers

A

49152-65535

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

IPv4 Broadcast address subnet

A

255.255.255.255

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

IPv6 Broadcast address subnet

A

FFFF.FFFF.FFFF.FFFF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ICMP Type 8

A

Echo-Request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ICMP Type 0

A

Echo Reply

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ICMP Type 3

A

Destination unreachable

17
Q

ICMP Type 3 - Code 0

A

The route is missing

18
Q

ICMP Type 3 - Code 1

A

the host is down

19
Q

ICMP Type 3 - Code 13

A

The firewall is stopping the ICMP

20
Q

What is a full connect scan

A

This is a TCP Connect scan - that performs the full three-way handshake - easy to detect

21
Q

What is a stealth scan

A

this is a half open scan or SYN scan. Only sends the first part of the handshake

22
Q

What is the XMAS scan type

A

all the flags on the tcp header are set. PSH, URG, FIN

23
Q

Syntax for Nmap is

A

nmap

24
Q

4 Evasion Methods

A
  1. Fragmenting Packets
  2. Spoof your IP Address
  3. IP Source Routing
  4. Use Proxies
25
Q

What is a vulnerability scanning tool

A

Nessus