Nmap Development mailing list archives

Nmap for Windows problem in scanning (result is always filtered even it doesn't with filtered) and doesn't ping


From: "Michael" <egold_offers () yahoo co uk>
Date: Mon, 14 Feb 2005 05:21:33 +0330

Hi and thanks for your efforts in making this real great useful software
 
 
I recently installed the nmap 3.81 for windows 
 
and this is my system details
a normal system: P4 2.8 (Cache 1mb),Ram 512MB,...
 
Software and related hardwares:
 Windows xp pro sp1
 Winpcap (3.1 beta4)
 DVB card (Skystar 2)
 Virtual machine (VMware)
 Dialup Connection (56KB)
 
when I want to scan a host (my ISP that isn't behind a firewall) I
always get the following result:
 
 
nmap.exe -P0 -sS -p 80 195.146.38.10
 
Starting nmap 3.81 ( http://www.insecure.org/nmap ) at 2005-02-14 04:59
Iran Sta
ndard Time
Interesting ports on 195.146.38.10:
PORT   STATE    SERVICE
80/tcp filtered http
 
Nmap finished: 1 IP address (1 host up) scanned in 19.766 seconds
 
But when I scan it with SuperScan 3.0 port 80 is open and this IP
response to the ping (I even have to disable the ping)
 
I also when I use ported HPing 2 for windows (It doesn't work too) I got
the following Result:
 
 
hping2.exe 195.0.0.1    
1. \Device\NPF_GenericNdisWanAdapter (Generic NdisWan adapter)
 
2. \Device\NPF_{9B3F5AED-2763-4931-BF27-AD204512A007} (B2C2 Broadband
Receiver P
 
CI Adapter (Microsoft's Packet Scheduler) )
 
3. \Device\NPF_{BC14C488-85E8-43DC-AB5A-3A87C9D3693E} (WAN (PPP/SLIP)
Interface)
 
4. \Device\NPF_{56DA5A31-5A1B-4D3F-B30A-0A5380C70531} (VMware Virtual
Ethernet A
 
dapter)
 
5. \Device\NPF_{71BA705C-90A3-44B5-9C22-D56D37A16DCF} (VMware Virtual
Ethernet A
 
dapter)
 
HPING 195.0.0.1 (ppp0 195.0.0.1): NO FLAGS are set, 40 headers + 0 data
bytes
 
not presented
 
 
 
RemoteIP=195.0.0.1
 
RemotePort=11111
 
[send_ip] sendto: No error
 
I thought that it may be cause of that nmap can't recognize my ethernet
adapter (adapter for WinPcap) so I tried the
every of below commands and got the same following result:
 
nmap.exe "-e \Device\NPF_GenericNdisWanAdapter" -S 81.91.134.186 -sS -p
80 195.146.38.10
nmap.exe -e NPF_GenericNdisWanAdapter -S 81.91.134.186 -sS -p 80
195.146.38.10
nmap.exe "-e \Device\NPF_GenericNdisWanAdapter (Generic NdisWan
adapter)" -S 81.91.134.186 -sS -p 80 195.146.38.10
 
Result:
 
WARNING:  If -S is being used to fake your source address, you may also
have to
use -e <iface> and -P0 .  If you are using it to specify your real
source addres
s, you can ignore this warning.
 
Starting nmap 3.81 ( http://www.insecure.org/nmap ) at 2005-02-14 05:13
Iran Sta
ndard Time
my_pcap_open_live: invalid device (null)
 
QUITTING!
 
This is how that it does. 
 
Thanks again for your efforts in making nmap and thanks for your
patience in hearing and solving other 
people problems
 
Regards,
Mandy Spears 
 
 

Current thread: