Term
| Full (TCP Connect), initial flag sent |
|
Definition
|
|
Term
| Half Open (Stealth / SYN Scan), initial flag sent |
|
Definition
|
|
Term
|
Definition
|
|
Term
|
Definition
|
|
Term
|
Definition
|
|
Term
|
Definition
|
|
Term
| Full (TCP Connect), Open Port Response |
|
Definition
|
|
Term
| Half Open (Stealth / SYN Scan), Open Port Response |
|
Definition
|
|
Term
|
Definition
|
|
Term
|
Definition
|
|
Term
|
Definition
|
|
Term
|
Definition
|
|
Term
| Full (TCP Connect), Closed Port Response |
|
Definition
|
|
Term
| Half Open (Stealth / SYN Scan), Closed Port Response |
|
Definition
|
|
Term
| XMAS, Closed Port Response |
|
Definition
|
|
Term
| FIN, Closed Port Response |
|
Definition
|
|
Term
| NULL, Closed Port Response |
|
Definition
|
|
Term
| ACK, Closed Port Response |
|
Definition
|
|
Term
| Full (TCP Connect), special characteristic |
|
Definition
| Noisiest but most reliable. |
|
|
Term
| Half Open (Stealth / SYN Scan), special characteristic |
|
Definition
No completion of three way handshake. Designed for stealth but may be picked up on IDS sensors. |
|
|
Term
| XMAS, special characteristic |
|
Definition
| Does not work on Windows Machines |
|
|
Term
| FIN, special characteristic |
|
Definition
| Does not work on Windows Machines |
|
|
Term
| NULL, special characteristic |
|
Definition
| Does not work on Windows Machines |
|
|
Term
| ACK, special characteristic |
|
Definition
| Used in firewall filter tests |
|
|