Nmap Development mailing list archives

possibly a bug or MS voodoo


From: "Schmidt, Nathanael via dev" <dev () nmap org>
Date: Thu, 28 Oct 2021 10:15:39 +0000

Hello developer,

i have following Problem. I try to ping scan my local network using nmap, but it doesn't seem to find machines that are 
for sure alive. It responses to Windows ping but not to nmap ping scan. I searched the problem in the internet. I don't 
found a solution.

Results for ping (Transleted from German) :

Ping is executed for 172.27.97.21 with 32 bytes of data:
Reply from 172.27.97.21: Bytes=32 Time<1ms TTL=127
Reply from 172.27.97.21: Bytes=32 Time<1ms TTL=127
Reply from 172.27.97.21: Bytes=32 Time<1ms TTL=127
Reply from 172.27.97.21: Bytes=32 Time<1ms TTL=127

Ping statistics for 172.27.97.21:
   Packets: Sent = 4, Received = 4, Lost = 0.
    (0% loss),
Approx. times in millisec:
   Minimum = 0ms, Maximum = 0ms, Mean = 0ms

Results for Ping Capture:

921        18:51:13 11.10.2021      9.7150826          (2096)  194.113.123.243              172.27.97.21     ICMP     
ICMP:Echo Request Message, From 194.113.123.243 To 172.27.97.21
922        18:51:13 11.10.2021      9.7158972          (16876)             172.27.97.21              194.113.123.243    
        ICMP     ICMP:Echo Reply Message, From 172.27.97.21 To 194.113.123.243
962        18:51:14 11.10.2021      10.7188766       (2096)  194.113.123.243              172.27.97.21     ICMP     
ICMP:Echo Request Message, From 194.113.123.243 To 172.27.97.21
963        18:51:14 11.10.2021      10.7192058       (0)        172.27.97.21              194.113.123.243            
ICMP     ICMP:Echo Reply Message, From 172.27.97.21 To 194.113.123.243
1034     18:51:15 11.10.2021      11.7228086       (2096)  194.113.123.243              172.27.97.21     ICMP     
ICMP:Echo Request Message, From 194.113.123.243 To 172.27.97.21
1035     18:51:15 11.10.2021      11.7233874       (0)        172.27.97.21              194.113.123.243            ICMP 
    ICMP:Echo Reply Message, From 172.27.97.21 To 194.113.123.243
1098     18:51:16 11.10.2021      12.7274641       (2096)  194.113.123.243              172.27.97.21     ICMP     
ICMP:Echo Request Message, From 194.113.123.243 To 172.27.97.21
1099     18:51:16 11.10.2021      12.7278742       (0)        172.27.97.21              194.113.123.243            ICMP 
    ICMP:Echo Reply Message, From 172.27.97.21 To 194.113.123.243

Results for nmap -sn -PE:

Nmap done: 1 IP address (0 hosts up) scanned in 2.11 seconds

Results for nmap  -sn -PE Capture:

562        19:47:06 11.10.2021      3.5983423          (11480)              194.113.123.243            172.27.97.21     
TCP       TCP: [Bad CheckSum]Flags=CE....S., SrcPort=59137, DstPort=HTTP(80), PayloadLen=0, Seq=1643617409, Ack=0, 
Win=8192 ( Negotiating scale factor 0x8 ) = 8192
715        19:47:07 11.10.2021      4.5985142          (11480)              194.113.123.243            172.27.97.21     
TCP       TCP: [Bad CheckSum]Flags=CE....S., SrcPort=59138, DstPort=HTTP(80), PayloadLen=0, Seq=215975257, Ack=0, 
Win=8192 ( Negotiating scale factor 0x8 ) = 8192


I don't can disable Checksum Offload. It is a production System. When they do need it. I'll have to sit down in the 
evening and do that.

nmap -version
Nmap version 7.92 ( https://nmap.org )
Platform: i686-pc-windows-windows
Compiled with: nmap-liblua-5.3.5 openssl-1.1.1k nmap-libssh2-1.9.0 nmap-libz-1.2.11 nmap-libpcre-7.6 nmap-libdnet-1.12 
ipv6

Windows Version: Microsoft Windows Server 2012 R2 Standard

Where I'm most confused.

nmap -sn -PA 194.113.122.40
Starting Nmap 7.92 ( https://nmap.org ) at 2021-10-28 11:54 Mitteleuropõische Sommerzeit
Nmap scan report for 194.113.122.40
Host is up (1.00s latency).
Nmap done: 1 IP address (1 host up) scanned in 1.05 seconds

nmap -sn -PA 194.113.122.0/24
Starting Nmap 7.92 ( https://nmap.org ) at 2021-10-28 11:54 Mitteleuropõische Sommerzeit
...
Nmap scan report for xxx (194.113.122.38)
Host is up (0.00s latency).
Nmap scan report for xxx (194.113.122.39)
Host is up (0.00s latency).
Nmap scan report for 194.113.122.44
Host is up (0.00s latency).
...

If you need any more information, feel free to write me.

Mit freundlichen Grüßen

Nathanael Schmidt
Fachgruppe RZ

T  +49 351 857-1612 (Durchwahl)
nathanael.schmidt () dresden-it de
________________________________

Dresden-IT GmbH
Kleiststraße 10 c, 01129 Dresden

T   +49 351 857-1500 (Zentrale)
F   +49 351 857-1502
info () dresden-it de
https://www.dresden-it.de

[cid:image001.png@01D7CBF5.84A54A50]


Geschäftsführer: Dr. Ralf Weber | Aufsichtsratsvorsitzender: Dr. Peter Lames | Amtsgericht Dresden: HRB 20046

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/

Current thread: