ALL PASS, NO FAIL!

CEH v13 Module 3: Scanning Networks

This module covers active network scanning techniques used to discover live hosts, open ports, and services on a target network. You will learn nmap scan types, port scanning methods, vulnerability scanning, banner grabbing, and techniques for bypassing IDS and firewalls.

The CEHStudy app carries 10 flashcards for Module 3 across 3 sections — open the Module 3 deck and memorize each nmap flag with the packet it actually sends.

Key Topics Covered

Important Terms & Concepts

TCP SYN scan (-sS): Default and stealthiest Nmap scan — half-open scan that sends SYN packets and analyzes responses without completing the TCP three-way handshake. Requires raw socket access (root/administrator privileges).
TCP Connect scan (-sT): Completes the full TCP three-way handshake using the OS system call. More reliable but easier to detect than SYN scan; used when raw socket privileges are missing.
UDP scan (-sU): Scans UDP ports (DNS, DHCP, SNMP) — slower than TCP scanning because of ICMP port-unreachable analysis.
NULL scan (-sN): Sends a packet with no TCP flags set — closed ports reply RST, filtered ports stay silent. Can bypass simple firewalls.
FIN scan (-sF): Sends a FIN packet — non-listening ports respond with RST. Can bypass some firewalls.
Xmas Tree scan (-sX): Sets FIN, PSH, and URG flags like a Christmas tree. Named for the combination of flags set.

The -sN / -sF / -sX variants are stealth/evasion scans that manipulate TCP flags to bypass simple firewalls: a closed port must reply RST regardless of flags, while a filtered port silently drops the packet.

Ping scan (-sn): Disables port scanning and performs host discovery only (formerly -sP) — discovers live hosts on a network range.
No Ping / Skip Host Discovery (-Pn): Treats all targets as online and forces a port scan even when ICMP is blocked.
ARP Ping (-PR): Fast and reliable host discovery on local Ethernet networks using ARP instead of ICMP.
Service Version Detection (-sV): Probes open ports to determine the application name and version beyond just port status.
OS Detection (-O): Detects the remote operating system via TCP/IP stack fingerprinting (TTL, window size, option ordering).
Aggressive Scan (-A): Enables OS detection (-O), version detection (-sV), script scanning (-sC), and traceroute in a single flag.
Default Script Scan (-sC): Runs standard Nmap Scripting Engine (NSE) scripts for basic vulnerability checks without naming specific scripts.
Idlescan (-sI): Zombie-based stealthy port scan that uses a third-party system to avoid sending packets from your own IP.
FTP Bounce attack (-b): Uses a proxy FTP server to scan a target through the relay, hiding the true source.

nmap Port Specification & Timing Options

How to Study This Module

Frequently Asked Questions

Which nmap scan is most commonly used?
SYN scan (-sS) is the most popular because it is fast, widely available (requires root), and stealthy since it does not complete the TCP handshake.

What is the difference between a vulnerability assessment and port scanning?
Port scanning identifies open ports and services. Vulnerability assessment goes further by identifying known CVEs and weaknesses in those services.

Related Modules

What is Scanning Networks in Ethical Hacking?

Scanning Networks is a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers active scanning techniques for finding live hosts, open ports, running services, and vulnerabilities on target systems. The primary tool — Nmap — offers dozens of scan types, from half-open SYN scans to UDP sweeps, each trading speed, accuracy, and stealth against one another. Expect scenario questions on which scan fits a given situation. Module 3 accounts for about 8% of CEH v13 exam questions.

Key Concepts in Scanning Networks

Common Exam Mistakes in Module 3

Believing a SYN scan completes the connection: -sS is half-open by design: send a SYN, read the reply (SYN-ACK open, RST closed), tear down with RST. No session is established, so many logs record nothing — hence "stealth scanning".
Reading silence as "closed": A port that answers RST is closed; silence may just mean filtered by a firewall. OPEN, CLOSED, and FILTERED are distinct exam answers on packet traces; Nmap reports OPEN|FILTERED when it cannot decide between the two.
Picking a TCP scan for UDP services: SYN and Connect scans only see TCP — DNS, DHCP, and SNMP need -sU with ICMP port-unreachable analysis. For "is this firewall stateful or stateless?" questions, the answer is an ACK scan (-sA), not a version-detection run.

Tools Used in Network Scanning

The exam's scanning tools, by job:

Worked Example: Reading a Scan Result Line by Line

You run nmap -sS on an authorized test host and get three results: 443 replies SYN-ACK, 80 replies RST, and 53 gives no response.

Translation and follow-up: 443 is open with a service running; 80 is closed — host reachable, nothing listening; 53 is filtered — the probe was dropped, so you cannot call it closed. Re-probe with -sU to check UDP DNS, add -O to fingerprint the OS from initial TTL, window size, and TCP option ordering, then hand the confirmed open ports to a vulnerability scanner such as Nessus.

How to Study Scanning Networks for the CEH v13 Exam

To study Module 3:

  1. Memorize each Nmap scan flag and the packet it sends — expect packet-trace identification questions
  2. Understand the TCP/IP response for each scan type against open, closed, and filtered ports (use a matrix: scan type × port state)
  3. Set up a Metasploitable 2 VM in VirtualBox and run a full Nmap scan with -sV -sC -oA — document what each flag reveals and compare SYN vs connect results
  4. Review Module 4 (Enumeration) for protocol-specific discovery that builds on scanning, and Module 5 (Vulnerability Analysis) for what comes next

Frequently Asked Questions About Scanning Networks

Why is a SYN scan called a half-open scan?

A SYN scan completes only the first step of the TCP three-way handshake — it sends a SYN, gets a SYN-ACK (open) or RST (closed), and never sends the final ACK. No full connection means many systems don't log it — stealthier than a connect() scan. It requires raw socket access (root/administrator), so no non-privileged mode.

What is the difference between a filtered and a closed port?

A closed port actively rejects the connection — it sends back a RST (reset), meaning no service is listening. A filtered port gives no response — a firewall drops the packets before they reach the target. Closed means the host is up and the service is stopped; filtered means a firewall or security device is blocking access. Nmap labels ports "open," "closed," or "filtered" based on these responses.

Related CEH v13 Modules

Related Glossary Terms