This module covers active network scanning techniques used to discover live hosts, open ports, and services on a target network. You will learn nmap scan types, port scanning methods, vulnerability scanning, banner grabbing, and techniques for bypassing IDS and firewalls.
The CEHStudy app carries 10 flashcards for Module 3 across 3 sections — open the Module 3 deck and memorize each nmap flag with the packet it actually sends.
Key Topics Covered
Scanning vs footprinting: active vs passive information gathering
Vulnerability scanning and network discovery procedures
TCP scan types: SYN (-sS), connect (-sT), FIN (-sF), Xmas (-sX), NULL scans
nmap timing options: -T0 through -T5 (default -T3 Normal)
nmap port selection: -p <range> and --top-ports <number>
nmap output formats: Normal, XML, Grepable, All (-oA)
Banner grabbing and TCP/IP fundamentals
Bypassing IDS and firewalls during scanning
Important Terms & Concepts
TCP SYN scan (-sS): Default and stealthiest Nmap scan — half-open scan that sends SYN packets and analyzes responses without completing the TCP three-way handshake. Requires raw socket access (root/administrator privileges).
TCP Connect scan (-sT): Completes the full TCP three-way handshake using the OS system call. More reliable but easier to detect than SYN scan; used when raw socket privileges are missing.
UDP scan (-sU): Scans UDP ports (DNS, DHCP, SNMP) — slower than TCP scanning because of ICMP port-unreachable analysis.
NULL scan (-sN): Sends a packet with no TCP flags set — closed ports reply RST, filtered ports stay silent. Can bypass simple firewalls.
FIN scan (-sF): Sends a FIN packet — non-listening ports respond with RST. Can bypass some firewalls.
Xmas Tree scan (-sX): Sets FIN, PSH, and URG flags like a Christmas tree. Named for the combination of flags set.
The -sN / -sF / -sX variants are stealth/evasion scans that manipulate TCP flags to bypass simple firewalls: a closed port must reply RST regardless of flags, while a filtered port silently drops the packet.
Ping scan (-sn): Disables port scanning and performs host discovery only (formerly -sP) — discovers live hosts on a network range.
No Ping / Skip Host Discovery (-Pn): Treats all targets as online and forces a port scan even when ICMP is blocked.
ARP Ping (-PR): Fast and reliable host discovery on local Ethernet networks using ARP instead of ICMP.
Service Version Detection (-sV): Probes open ports to determine the application name and version beyond just port status.
OS Detection (-O): Detects the remote operating system via TCP/IP stack fingerprinting (TTL, window size, option ordering).
Aggressive Scan (-A): Enables OS detection (-O), version detection (-sV), script scanning (-sC), and traceroute in a single flag.
Default Script Scan (-sC): Runs standard Nmap Scripting Engine (NSE) scripts for basic vulnerability checks without naming specific scripts.
Idlescan (-sI): Zombie-based stealthy port scan that uses a third-party system to avoid sending packets from your own IP.
FTP Bounce attack (-b): Uses a proxy FTP server to scan a target through the relay, hiding the true source.
nmap Port Specification & Timing Options
-p <range> Ports to scan (e.g., -p 80,443 for specific ports, -p- for all 65,535 ports)
--top-ports <number> Scans the most common X ports (e.g., --top-ports 100)
-T5 Insane (75s timeout, 0.3s per probe) — fastest
How to Study This Module
Memorize each nmap scan type flag and its mechanism (-sS, -sT, -sF, -sX, etc.)
Understand when to use each scan type (stealth vs reliability)
Know the timing options and their trade-offs between speed and stealth
Practice with nmap in a lab environment if possible
Frequently Asked Questions
Which nmap scan is most commonly used? SYN scan (-sS) is the most popular because it is fast, widely available (requires root), and stealthy since it does not complete the TCP handshake.
What is the difference between a vulnerability assessment and port scanning? Port scanning identifies open ports and services. Vulnerability assessment goes further by identifying known CVEs and weaknesses in those services.
Scanning Networks is a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers active scanning techniques for finding live hosts, open ports, running services, and vulnerabilities on target systems. The primary tool — Nmap — offers dozens of scan types, from half-open SYN scans to UDP sweeps, each trading speed, accuracy, and stealth against one another. Expect scenario questions on which scan fits a given situation. Module 3 accounts for about 8% of CEH v13 exam questions.
Key Concepts in Scanning Networks
TCP Three-Way Handshake & Half-Open Scanning: A full handshake (SYN → SYN-ACK → ACK) identifies open ports but is easily logged. Half-open SYN scanning sends only the initial SYN and reads the response — SYN-ACK open, RST closed — without completing the connection, which is why -sS beats -sT on speed and stealth.
Stealth Scan Variants (FIN, Xmas, NULL): These exploit a gap in older TCP/IP stacks where stateless firewalls only check for SYN packets. FIN (-sF) sets only the FIN flag; no response means likely filtered. Xmas (-sX) sets FIN, PSH, and URG; NULL sends no flags at all. Modern OSes RST all closed ports regardless of flags, but these scans can still bypass poorly configured stateless firewalls.
Nmap Timing & Performance Options: The -T0 through -T5 timing templates control how aggressively Nmap sends packets and waits for responses. -T3 is the default; -T4 suits most engagements on modern networks; -T5 is fastest but may trigger IDS alerts. Know when to drop to paranoid/sneaky settings.
Vulnerability Scanning vs Port Scanning: Port scanning identifies open ports and the services on them. Vulnerability scanning (Nessus, OpenVAS, Qualys) goes further, matching running services against known-CVE databases to find specific exploitable weaknesses.
Common Exam Mistakes in Module 3
Believing a SYN scan completes the connection: -sS is half-open by design: send a SYN, read the reply (SYN-ACK open, RST closed), tear down with RST. No session is established, so many logs record nothing — hence "stealth scanning".
Reading silence as "closed": A port that answers RST is closed; silence may just mean filtered by a firewall. OPEN, CLOSED, and FILTERED are distinct exam answers on packet traces; Nmap reports OPEN|FILTERED when it cannot decide between the two.
Picking a TCP scan for UDP services: SYN and Connect scans only see TCP — DNS, DHCP, and SNMP need -sU with ICMP port-unreachable analysis. For "is this firewall stateful or stateless?" questions, the answer is an ACK scan (-sA), not a version-detection run.
Tools Used in Network Scanning
The exam's scanning tools, by job:
Nmap: the industry-standard scanner — SYN/Connect/FIN/Xmas/NULL/Idle flags, OS detection from TCP/IP stack fingerprints, and ping-sweep host discovery with -sn
NSE (Nmap Scripting Engine): Lua scripts that extend Nmap beyond port status into service interrogation and quick vulnerability checks
Masscan: internet-scale port scanning at extreme speed; the exam's pick for huge address spaces
ZMap: stateless high-speed scanner in the same bulk-discovery category as Masscan
Angry IP Scanner / Advanced IP Scanner / Superscan: GUI ping-sweep utilities for finding live hosts on a LAN before detailed scanning; PingPlotter adds continuous path monitoring
Netcat (nc): swiss-army socket tool for banner grabbing — connect straight to an open port and read the service banner
Nessus (Tenable): the commercial vulnerability scanner that takes port-scan results and matches services against CVE databases
OpenVAS (Greenbone): Nessus's open-source counterpart, commonly paired with it in exam questions
Worked Example: Reading a Scan Result Line by Line
You run nmap -sS on an authorized test host and get three results: 443 replies SYN-ACK, 80 replies RST, and 53 gives no response.
Translation and follow-up: 443 is open with a service running; 80 is closed — host reachable, nothing listening; 53 is filtered — the probe was dropped, so you cannot call it closed. Re-probe with -sU to check UDP DNS, add -O to fingerprint the OS from initial TTL, window size, and TCP option ordering, then hand the confirmed open ports to a vulnerability scanner such as Nessus.
How to Study Scanning Networks for the CEH v13 Exam
To study Module 3:
Memorize each Nmap scan flag and the packet it sends — expect packet-trace identification questions
Understand the TCP/IP response for each scan type against open, closed, and filtered ports (use a matrix: scan type × port state)
Set up a Metasploitable 2 VM in VirtualBox and run a full Nmap scan with -sV -sC -oA — document what each flag reveals and compare SYN vs connect results
Frequently Asked Questions About Scanning Networks
Why is a SYN scan called a half-open scan?
A SYN scan completes only the first step of the TCP three-way handshake — it sends a SYN, gets a SYN-ACK (open) or RST (closed), and never sends the final ACK. No full connection means many systems don't log it — stealthier than a connect() scan. It requires raw socket access (root/administrator), so no non-privileged mode.
What is the difference between a filtered and a closed port?
A closed port actively rejects the connection — it sends back a RST (reset), meaning no service is listening. A filtered port gives no response — a firewall drops the packets before they reach the target. Closed means the host is up and the service is stopped; filtered means a firewall or security device is blocking access. Nmap labels ports "open," "closed," or "filtered" based on these responses.
Related CEH v13 Modules
Module 4: Enumeration — digs into SMB, SNMP, and LDAP to extract user lists, shares, and group memberships