A penetration tester is attempting to scan an internal corporate network from the internet without alerting the border sensor. Which is the most efficient technique should the tester consider using?
While the question says the pen tester is trying to scan the internal network from the internet (let's assume static nat or something), then this is the correct answer: https://nmap.org/book/man-bypass-firewalls-ids.html
-f (fragment packets); --mtu (using the specified MTU)
The -f option causes the requested scan (including ping scans) to use tiny fragmented IP packets. The idea is to split up the TCP header over several packets to make it harder for packet filters, intrusion detection systems, and other annoyances to detect what you are doing
An already established connection in the network is needed first.
https://isc.sans.edu/forums/diary/Tunneling+scanners+or+really+anything+over+SSH/24286/
But since the question says, "penetration tester" and not a hacker, it means he might already been given the access.
upvoted 1 times
...
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
pindarots
Highly Voted 4 years, 9 months agobic3p
Most Recent 2 months, 3 weeks agoRouter
1 year, 9 months agosalei
1 year, 12 months agoswetty
2 years agoGoki_28
2 years, 5 months agoGoki_28
2 years, 5 months agoHacker100
3 years, 2 months agobrider
4 years, 7 months agovirus9
4 years, 1 month agovirus9
4 years, 1 month ago