Comprehensive and Detailed Explanation:
An Xmas scan is a type of stealth TCP scan that sets the FIN, PSH, and URG flags. According to RFC 793:
If the port is closed, the target responds with a TCP RST (Reset) packet.
If the port is open or filtered, there is no response.
Thus, receiving a RST response indicates a closed port.
From CEH v13 Courseware:
[Reference:CEH v13 Study Guide – Module 3: Xmas, Null, and FIN ScansRFC 793 – Transmission Control Protocol Specification, ==================================================================, ]
Submit