Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. Salesforce
  3. Question
Salesforce

What's the purpose of DOS attack fin scan?

Asked by Andrew Jenkins Mar 24, 2022 4.7K views 2 answers
Share

About this question

 I've been having some weird issues with a home network, and it seems to me like I have some vulnerability I don't know about. To be honest, though, I'm not a big network/security guy and I kind of feel out of my depth. I'm hoping someone else can help me figure out what's going on.


For at least the last two months I have been seeing weird entries in my router logs. Basically, at least every few days, I see some entry in my router logs that says "Dos Attack" and "FIN Scan"/"Ack Scan" or "Smurf". Sometimes the remote IPs labeled as the attack source show up in whois as owned by Google, or an ad company called OpenX.


At first I thought, well, if my router only records the entries, then it must be blocking them, so it's fine. But I'm not so sure now. Take a look at a recent series of log entries for example:

[DoS attack: Smurf] attack packets in last 20 sec from ip [192.168.1.6], 15:56:22


[DHCP IP: (192.168.1.2)] to MAC address 33:33:33:33, 12:33:00

[DHCP IP: (192.168.1.2)] to MAC address 33:33:33:33, 12:32:49


[DoS attack: FIN Scan] attack packets in last 20 sec from ip [173.241.250.212], 10:45:25

[DoS attack: FIN Scan] attack packets in last 20 sec from ip [173.241.250.143], 10:45:25


[DHCP IP: (192.168.1.6)] to MAC address 22:22:22:222, 09:11:05

What concerns me about a log entry like this is that the "attack packets" change IP address -- not just to one in my internal network, but to the computer I had used earlier that night (I was asleep when the attack packets were logged, and my computer was supposedly asleep). That makes me think the "attack packets" somehow allowed someone access to my system or my network. What is even stranger to me is, while this has been happening for a while now, the most recent entries showing this kind of remote-to-local IP switch was for a Mac machine, whereas the previous ones were related to a physically different Windows machine.


Before this last entry I took some steps to protect my network just in case. On top of upgrading my router, all of the other machines on the network have been DBANd and had Windows reinstalled fresh, I upgraded my modem to it's newer version, I disabled wireless radio entirely on my router so there is no wireless network and no guest wireless network at all, and I also changed my external/public IP with my service provider.


Has anyone seen something like this before? Am I digging into a problem that doesn't exist, or is it possible I'm the target of some bot or attack?

Your answer

2 Answers

Ranjana Admin JanBask Expert Latest answer

Answered on Jun 10, 2024

A FIN scan is a type of network reconnaissance scan used by attackers to gather information about open ports on a target system. It's one of the many techniques used in the reconnaissance phase of a cyber attack, particularly for stealthy port scanning. Here's a detailed explanation of its purpose and how it works:

Purpose of a FIN Scan

1. Stealthiness:

The primary purpose of a FIN scan is to be stealthier than other types of scans like SYN or ACK scans. It aims to evade detection by firewalls and intrusion detection systems (IDS).

Many security systems are configured to detect and alert on SYN scans (which are more common), but may not be configured to detect FIN scans as effectively.

 2. Determining Open Ports:

A FIN scan helps identify open ports on a target system. Unlike SYN scans which initiate a connection, FIN scans send a packet with the FIN flag set, indicating the end of communication (as if it's part of a connection teardown).

3. Bypassing Firewalls and Filters:

Some firewalls and filtering systems might allow FIN packets through under the assumption that they are part of an ongoing, legitimate session. This can help the attacker map out open ports that would otherwise be hidden.

How a FIN Scan Works

Packet Structure:

A FIN scan sends TCP packets with only the FIN flag set. In normal TCP communication, the FIN flag is used to gracefully terminate a connection.

Response Analysis:

When a FIN packet is sent to a closed port, the target system should respond with an RST (reset) packet, indicating the port is closed.

If the port is open, the system is supposed to ignore the packet and not send any response. This lack of response is what the attacker uses to identify open ports.

Differences from Other Scans

SYN Scan:

Sends a SYN packet to initiate a connection. If the port is open, the target responds with a SYN-ACK, which the scanner then resets with an RST.

More likely to be detected by firewalls and IDS.

ACK Scan:

Sends an ACK packet to determine firewall rules, not necessarily to identify open ports. Responses vary based on firewall rules rather than port status.

Limitations and Countermeasures

Limitations:

Some modern IDS and firewalls are now capable of detecting FIN scans.

Not effective against all operating systems, as different OSes might handle FIN packets differently.

Countermeasures:

Firewalls and IDS can be configured to detect unusual patterns of FIN packets.

Implementing proper security policies and monitoring network traffic for anomalies.

In summary, the purpose of a FIN scan in the context of a Denial of Service (DoS) attack or reconnaissance is to stealthily identify open ports on a target system while attempting to evade detection by security systems. Understanding and detecting such scans is crucial for maintaining robust network security.

Was this helpful?

More Salesforce discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest Salesforce Blogs

Guides, tips and career advice on Salesforce from JanBask experts.