Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 140 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 140
Topic #: 1
[All 312-49v10 Questions]

If an attacker's computer sends an IPID of 31400 to a zombie computer on an open port in IDLE scanning, what will be the response?

  • A. The zombie will not send a response
  • B. 31402
  • C. 31399
  • D. 31401
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Elb
6 months, 2 weeks ago
Selected Answer: B
B > Open ports increments by 2
upvoted 1 times
...
Elb
6 months, 2 weeks ago
Open port increments by 2 No open port increments by 1 The answer depends whether the port is open or not.
upvoted 1 times
...
torabi123
1 year ago
If the attacker's computer sends an IPID of 31400 to the zombie computer on an open port during IDLE scanning, the response from the zombie would typically not result in any change in the IPID value on the zombie. This is because the open port scenario doesn't generate an RST response, so the IPID remains the same on the zombie computer. The attacker can then use this information to deduce that the target port is open based on the lack of a change in the IPID value. --> The zombie will not send a response
upvoted 1 times
...
Malko59
1 year, 3 months ago
Selected Answer: B
The response is A IPID=31402 But the question is very very very badly worded! In a Idle scan, the attacker's send a SYN/ACK to a Zombie (but we don't care about the attacker IPID) and the Zombie reply to the attacker with its own IPID which is interresting! The Idle scan has 3 steps: 1) Attacker sends a SYN/ACK to the Zombie. The Zombie responds to attacker with a RST and IPID=31400. 2) Attacker forges a SYN packet to the victim spoofing the IP of the Zombie machine. The victime responds to the Zombie with SYN/ACK. The Zombie responds to the victim with a RST and IPID+1=31401. 3) Same as 1) Attacker sends a new SYN/ACK to the Zombie. The Zombie responds to the attacker with a RST with IPID+1=31402. So if the Zombie IPID is increased by 2 the attacker can conclude that the victimes port is open. The response is IPID=31402 I think the question is more for CEH than for CHFI
upvoted 1 times
Malko59
1 year, 3 months ago
Sorry, I mean answer is B IPID=31402
upvoted 2 times
...
...
vcloudpmp
2 years, 8 months ago
Answer is A, 31402.
upvoted 3 times
...
vcloudpmp
2 years, 8 months ago
Every IP packet on the Internet has a fragment identification number (IP ID). Since many operating systems simply increment this number for each packet they send, probing for the IPID can tell an attacker how many packets have been sent since the last probe. An increase of one indicates that the zombie hasn't sent out any packets, except for its reply to the attacker's probe. This lack of sent packets means that the port is not open (the target must have sent the zombie either a RST packet, which was ignored, or nothing at all). An increase of two indicates that the zombie sent out a packet between the two probes. This extra packet usually means that the port is open (the target presumably sent the zombie a SYN/ACK packet in response to the forged SYN, which induced a RST packet from the zombie).
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...