If an attacker’s computer sends an IPID of 24333 to a zombie (Idle Scanning) computer on a
closed port, what will be the response?
A.
The zombie computer will respond with an IPID of 24334.
B.
The zombie computer will respond with an IPID of 24333.
C.
The zombie computer will not send a response.
D.
The zombie computer will respond with an IPID of 24335.
Explanation:
But in 312-50 (CEH v7) , the answer is C.The zombie computer will not send a response
A is the right Ans.
Correct answer is A. Add 1 to the sending IPID.
Since the zombie had to send the RST packet it will increment its IPID. This is how an attacker would find out if the targets port is open. The attacker will send another packet to the zombie. If the IPID is incremented only by a step then the attacker would know that the particular port is closed.