Nmap Development mailing list archives

Re: nmap-3.7x MUCH slower than nmap-3.55 against firewalled hosts


From: Martin Mačok <martin.macok () underground cz>
Date: Thu, 16 Dec 2004 14:00:55 +0100

On Thu, Dec 16, 2004 at 01:22:32PM +0100, Martin Mačok wrote:

If you have time to scan such a class C again, how does Nmap 3.78
do with "-T4 --min_hostgroup 256 --max_scan_delay
0 --max_rtt_timeout XXX" (where XXX is about double the average
ping time against hosts on the target network).  How does that
compare to 3.55?

Nmap-3.78 wins here but generates much more traffic. When scanning
less than 25 hosts paralelly, nmap-3.55 wins.

Correction - nmap-3.78 looses in all cases when ICMP rate-limit is
implemented C-wide - e.g., there is a single firewall in front of the
whole C block. Paralelisation doesn't help here.

Martin Mačok
IT Security Consultant

---------------------------------------------------------------------
For help using this (nmap-dev) mailing list, send a blank email to 
nmap-dev-help () insecure org . List archive: http://seclists.org



Current thread: