SCAN: NMAP XMAS TCP Packet

This signature detects attempts to scan the system for ports using NMAP scanner. Attackers can send TCP URG and PUSH packets with some or no options set in the options byte and wait for a response. Open ports should not respond; if no service is running or if no daemon is listening, the port is closed and the system responds with a RST message.

Extended Description

A successful scan may expose information to assist an attacker in conducting further attacks. The impact depends on how a target system handles such attacks.

Short Name
SCAN:NMAP:XMAS
Severity
Warning
Recommended
False
Recommended Action
None
Category
SCAN
Keywords
NMAP Packet TCP XMAS
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown

Found a potential security threat?