Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GPEN Topic 7 Question 69 Discussion

Actual exam question for GIAC's GPEN exam
Question #: 69
Topic #: 7
[All GPEN Questions]

You work as a Penetration Tester for the Infosec Inc. Your company takes the projects of security auditing. Recently, your company has assigned you a project to test the security of the we-aresecure. com Web site. For this, you want to perform the idle scan so that you can get the ports open in the we-are-secure.com server. You are using Hping tool to perform the idle scan by using a zombie computer. While scanning, you notice that every IPID is being incremented on every query, regardless whether the ports are open or close. Sometimes, IPID is being incremented by more than one value. What may be the reason?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

Lynelle
1 months ago
Zombie computer, huh? Sounds like this penetration test is more like a haunted house than an audit.
upvoted 0 times
...
Yuette
1 months ago
Hping not doing idle scanning? That's like saying a screwdriver can't screw in screws. I'm pretty sure that's not the issue here.
upvoted 0 times
Tammara
3 days ago
A) The zombie computer is the system interacting with some other system besides your computer.
upvoted 0 times
...
Theresia
4 days ago
B) The firewall is blocking the scanning process.
upvoted 0 times
...
Diane
13 days ago
A) The zombie computer is the system interacting with some other system besides your computer.
upvoted 0 times
...
...
Maryann
1 months ago
Wait, so the zombie computer isn't even connected to the target server? That's a pretty big problem for the idle scan to work. Gotta be option C.
upvoted 0 times
Douglass
1 days ago
Looks like we need to make sure the zombie computer is properly connected to the we-are-secure.com server for the idle scan to be effective.
upvoted 0 times
...
Rosalia
10 days ago
That's true, option C seems to be the most likely reason for the IPID incrementing regardless of open ports.
upvoted 0 times
...
Rhea
18 days ago
Yeah, if the zombie computer isn't connected to the target server, then the idle scan won't work.
upvoted 0 times
...
...
Izetta
2 months ago
Nah, the firewall blocking the scan wouldn't cause the IPID to increment in that way. I think you're on the right track with the zombie computer being the issue.
upvoted 0 times
Wenona
5 days ago
A) The zombie computer is the system interacting with some other system besides your computer.
upvoted 0 times
...
Bette
10 days ago
B) The firewall is blocking the scanning process.
upvoted 0 times
...
Lettie
12 days ago
A) The zombie computer is the system interacting with some other system besides your computer.
upvoted 0 times
...
...
Felix
2 months ago
But what if the firewall is blocking the scanning process? Could that also be a reason?
upvoted 0 times
...
Charlette
2 months ago
Hmm, if the IPID is incrementing even for closed ports, it sounds like the zombie computer is interacting with something else besides the target server. I'd go with option A.
upvoted 0 times
Elliot
1 months ago
No, I don't think the firewall is the issue here.
upvoted 0 times
...
Lonna
1 months ago
Maybe the firewall is blocking the scanning process.
upvoted 0 times
...
Sabina
2 months ago
Yeah, that could be the reason for the IPID incrementing.
upvoted 0 times
...
Jackie
2 months ago
I think the zombie computer is interacting with another system.
upvoted 0 times
...
...
Yoko
2 months ago
I agree with Avery. It makes sense that the IPID is being incremented because of that.
upvoted 0 times
...
Avery
3 months ago
I think the reason could be that the zombie computer is interacting with another system.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77