mailing list archives
TCP Split Handshake and Nmap
From: jah <jah () zadkiel plus com>
Date: Thu, 03 Jun 2010 01:19:15 +0100
Has anybody read "The TCP Split Handshake: Practical Effects on Modern
Network Equipment" published in the Macrothink Network Protocols and
Algorithms journal ? I thought section 8 regarding port scan
detection of a split handshake was particularly interesting and reckon
Nmap could easily handle a SYN or an ACK in response to a SYN probe in
order to mark a port as open.
If this was something we'd like to do, would we add ER_SYN and ER_ACK to
Related: what is ER_INITACK? it doesn't seem to be referenced anywhere...
 - http://www.macrothink.org/journal/index.php/npa/article/view/285
Sent through the nmap-dev mailing list
Archived at http://seclists.org/nmap-dev/
- TCP Split Handshake and Nmap jah (Jun 03)