How it works...
The previously shown command is designed for detecting common ports used by ICS SCADA protocols. Host discovery is disabled (-Pn) as it uses specially crafted SYN, ACK, and ICMP packets and a single full connection TCP probe is preferred (-sT). As we have mentioned before, ICS SCADA devices are very fragile and you must never scan them aggressively (--scan-delay 1s --max-parrallelism 1). There have been reports that OS, version, and aggressive NSE scanning and even ping sweeps have caused adverse effects on the devices. The port list specified (-p<port list>) covers the most common ports used by different ICS SCADA vendors and if possible, we must reduce the list to target only known vendors. Remember that many of these systems ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access