Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SCAN:NMAP:XMAS

Severity

Low

Recommended

No

Category

SCAN

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

SCAN: NMAP XMAS TCP Packet


This signature detects attempts to scan the system for ports using NMAP scanner. Attackers can send TCP URG and PUSH packets with some or no options set in the options byte and wait for a response. Open ports should not respond; if no service is running or if no daemon is listening, the port is closed and the system responds with a RST message.

Extended Description

A successful scan may expose information to assist an attacker in conducting further attacks. The impact depends on how a target system handles such attacks.

References

  • URL: http://www.insecure.org/nmap/
  • URL: http://svn.digium.com/view/cheops-ng/tags/deblah/nmap/docs/nmap_manpage.html?rev=7&view=markup

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out