Nmap Development mailing list archives

Re: Nmap -PU can't find any host available


From: Daniel Miller <bonsaiviking () gmail com>
Date: Mon, 31 Mar 2014 10:15:35 -0500

On 03/31/2014 09:45 AM, Anorpi Jia wrote:
Hi,
Thank you for your reply,and here is the result i run nmap -sn -n -PU -ddd X.X.X.X on my Windows XP[In the attachment is another file run on Centos6.5]:
This is quite strange. Nmap clearly sees the replies, but fails to match them to the probes. Do you have the same problem with older versions of Nmap? If at all possible, could you try checking out the latest source from Subversion (http://nmap.org/book/install.html#inst-svn) and trying that? We made some changes to ICMP probe matching in r31888, but I think they only affect responses to ICMP probes, not UDP probes.

One last idea: is there an IPS or firewall that may be stripping the encapsulated UDP probe from the ICMP replies, or otherwise changing it so that it doesn't match? You could examine the ICMP port-unreachable responses in Wireshark to see if it looks like there is a valid header there.

Dan
_______________________________________________
Sent through the dev mailing list
http://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/


Current thread: