Hands-On Ethical Hacking and Network Defense, Third Edition 5-1
Chapter 05
Port Scanning
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Key Terms
Technical Notes for Activities
Hands-On Ethical Hacking and Network Defense, Third Edition 5-2
Lecture Notes
Overview
This chapter presents an overview of port scanning and its different types. Students will learn
about various tools used for port scanning. The purpose of ping sweeps is also explained.
Finally, students will learn about scripting and its role in automating security tasks.
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Describe port scanning and types of port scans
Teaching Tips
Introduction to Port Scanning
1. Explain what port scanning is and how it can be used by attackers. Port scanning is a
technique that allows you to find out what services a network host offers. Every service
Security
Tip
SuperScan is a powerful free port scanning tool available at:
http://www.sofotex.com/SuperScan-download_L14815.html.
2. Describe what kind of information port scanning programs report, including:
a. Open ports
Hands-On Ethical Hacking and Network Defense, Third Edition 5-4
Teaching
Tip
Download Nessus plug-ins from http://cgi.nessus.org/plugins/.
Quick Quiz 1
1. True or False: Port scanning is also referred to as service scanning.
2. What term is used to describe the process of scanning a range of IP addresses to
determine what services are running on a network?
3. Which port scanning tool was originally written for Phrack magazine in 1997 by
Fyodor?
A. OpenVAS
B. Nmap
C. Greenbone Security Assistant
D. Nessus
4. True or False: The Nessus port scanning tool is now known as Greenbone Security
Assistant?
5. Which port scanning tool includes plug-ins that can determine what vulnerabilities are
associated with services running on a port?
A. OpenVAS
B. Nmap
C. Greenbone Security Assistant
D. Nessus
Conducting Ping Sweeps
1. Explain that port scanners can be used to conduct ping sweeps of a large network to
identify which IP addresses belong to active hosts. Ping sweeps sends ICMP Echo
Requests messages to all IP addresses within the range. An active host normally
Hands-On Ethical Hacking and Network Defense, Third Edition 5-5
Fping
1. Use Figures 5-5 and 5-6 to illustrate the use of Fping, a command-line tool that allows
you to ping multiple IP addresses simultaneously. Fping can accept a range of IP
Hping
1. Explain the use of Hping for ping sweeping. It is important to note that Hping allows
2. Emphasize that security professionals should spend some time learning and
Crafting IP Packets
1. Describe the advantages of crafting packets when trying to find out information about a
network host and its running services. Packets contain fields for source IP addresses,
Understanding Scripting
1. Define a script as a customized computer program that automates otherwise time
Scripting Basics
1. Explain that scripting is similar to DOS batch programming. A script or batch file is a
text file containing a multiple commands that can be executed by just providing the
name of the script (or batch) file. Good candidates for scripting are repetitive tasks
involving several commands.
Security
Tip
Check out http://www.freeos.com/guides/lsst/ for a Linux shell scripting tutorial.
Hands-On Ethical Hacking and Network Defense, Third Edition 5-6
Quick Quiz 2
1. True or False: Ping sweeping tools send ICMP Echo Requests messages to identify
active hosts.
2. Port scanners can also be used to conduct a test on a large network in order to identify
which IP addresses belong to active hosts. What is the test called?
3. True or False: You cannot craft any type of IP packet you like.
4. A computer program that automates tasks that take too much time to perform manually
is known as which of the following?
A. sweep
B. ping
C. script
Class Discussion Topics
1. What are the main advantages and disadvantages of each port scanning tool? Compare
2. Is it really important for a security professional to be familiar with scripting techniques?
Why or why not?
Additional Projects
2. Although this chapter has discussed the most important open source port scanning tools,
there are several commercial options as well. Ask your students to find information
about these tools using the Internet. Are commercial tools better than open source tools?
Additional Resources
1. Understanding the ICMP Protocol (Part I):
2. Understanding the ICMP Protocol (Part II):
4. Security Analysis Tool for Analyzing Networks (SATAN):
5. Mastering the VI Editor:
Key Terms
See Glossary for definitions of Key Terms.
closed ports
filtered ports
open ports
OpenVAS
ping sweep
port scanning
Hands-On Ethical Hacking and Network Defense, Third Edition 5-8
Technical Notes for Activities
Activity 5-1: This activity requires a classroom Linux CD and an Internet connection.
Activity 5-2: This activity requires a classroom Linux CD and an Internet connection.