mirror of
https://github.com/nmap/nmap.git
synced 2026-08-03 22:29:06 +00:00
Update the refguide (man page) to note our new (soon-to-be) support for TCP simultaneous-open/split-handshake connections
This commit is contained in:
parent
58e1d664a6
commit
77ef606d52
2 changed files with 9 additions and 8 deletions
|
|
@ -1132,9 +1132,9 @@ scans.</para>
|
|||
|
||||
<para>SYN scan is the default and most popular scan option for good
|
||||
reasons. It can be performed quickly, scanning thousands of ports per
|
||||
second on a fast network not hampered by restrictive firewalls. SYN scan
|
||||
is relatively unobtrusive and stealthy, since it never completes TCP
|
||||
connections. It also works against any compliant TCP stack rather
|
||||
second on a fast network not hampered by restrictive firewalls. It is also
|
||||
relatively unobtrusive and stealthy since it never completes TCP
|
||||
connections. SYN scan works against any compliant TCP stack rather
|
||||
than depending on idiosyncrasies of specific platforms as Nmap's
|
||||
FIN/NULL/Xmas, Maimon and idle scans do. It also allows clear,
|
||||
reliable differentiation between the <literal>open</literal>,
|
||||
|
|
@ -1148,7 +1148,7 @@ response. A SYN/ACK indicates the port is listening (open), while a
|
|||
RST (reset) is indicative of a non-listener. If no response is
|
||||
received after several retransmissions, the port is marked as
|
||||
filtered. The port is also marked filtered if an ICMP unreachable
|
||||
error (type 3, code 1, 2, 3, 9, 10, or 13) is received.</para>
|
||||
error (type 3, code 1, 2, 3, 9, 10, or 13) is received. The port is also considered open if a SYN packet (without the ACK flag) is received in response. This can be due to an extremely rare TCP feature known as a simultaneous open or split handshake connection (see <ulink url="http://nmap.org/misc/split-handshake.pdf"/>).</para>
|
||||
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue