Nmap Development mailing list archives

Nmap Question


From: IndianZ <indianz () indianz ch>
Date: Sun, 2 May 2004 21:49:43 +0200

Hi List

Is the attached table correct? It's about the answers of packets (when meeting 
open/closed/filtered ports) by scanning them with nmap. And can you tell why 
it's different (or detected different) when scanning port <1024 or >1024?

                                <1024                                   >1024   
                UDP                     TCP                     UDP                     TCP

OPEN    Nothing or      syn/ack         Response        syn/ack
                Response

CLOSED  ICMP Port       Reset           ICMP Port       Reset
                Unreachable                             Unreachable     

FILTER  Admin prohib    Nothing or      Nothing         Nothing or
                or ICMP Host    Admin prohib                            Admin prohib
                Unreachable                     

GreetZ from IndianZ

mailto:indianz () indianz ch
http://www.indianz.ch

---------------------------------------------------------------------
For help using this (nmap-dev) mailing list, send a blank email to 
nmap-dev-help () insecure org . List archive: http://seclists.org



Current thread: