You are having trouble obtaining accurate results while conducting a port scan against a target network. You check for the presence of any security devices between you and the target system. When both stealth and connect scans do not work, you decide to perform a NULL scan with NMAP. The first few systems scanned shows all ports open. Which one of the following statements is most probably true?
A.
The systems have all ports open
B.
The systems are running a host based IDS
C.
The systems are Web Servers
D.
The systems are running Windows
Explanation:
The null scan turns off all flags, creating a lack of TCP flags that should never occur in the real world. If the port is closed, a RST frame should be returned and a null scan to an open port results in no response. Unfortunately Microsoft (like usual) decided to completely ignore the standard and do things their own way. Thus this scan type will not work against systems running Windows as they choose not to response at all. This is a good way to distinguish that the system being scanned is running Microsoft Windows.
I choose D