A security analyst is analyzing packet captures and notices a large number of packets with the FIN, PSH, and URG flags set. This is a common signature for what type of port scan?
Correct Answer: Xmas scan
Explanation: An Xmas scan sets the FIN, PSH, and URG flags in a TCP packet header. If the port is open, the target's operating system drops the packet. If the port is closed, the system sends an RST packet back. It's called an "Xmas" scan because the flags are "all lit up."
Correct Answer: Xmas scan
Explanation: An Xmas scan sets the FIN, PSH, and URG flags in a TCP packet header. If the port is open, the target's operating system drops the packet. If the port is closed, the system sends an RST packet back. It's called an "Xmas" scan because the flags are "all lit up."