PrepAway - Latest Free Exam Questions & Answers

What does this suggest?

An Nmap scan shows the following open ports, and nmap also reports that the OS guessing
results to match too many signatures hence it cannot reliably be identified:
21 ftp
23 telnet
80 http
443 https
What does this suggest?

PrepAway - Latest Free Exam Questions & Answers

A.
This is a Windows Domain Controller

B.
The host is not firewalled

C.
The host is not a Linux or Solaris system

D.
The host is not properly patched

Explanation:
If the answer was A nmap would guess it,it holds the MS signature database,the
host not being firewalled makes no difference.The host is not linux or solaris,well it very well could
be. The host is not properly patched? That is the closest; nmaps OS detection architecture is
based solely off the TCP ISN issued by the operating systems TCP/IP stack,if the stack is
modified to show output from randomized ISN’s or if your using a program to change the ISN then
OS detection will fail. If the TCP/IP IP ID’s are modified then os detection could also fail,because
the machine would most likely come back as being down.

2 Comments on “What does this suggest?


Leave a Reply