Nmap Development mailing list archives

Re: Unnecessary TCP retries ?


From: Martin Mačok <martin.macok () underground cz>
Date: Thu, 16 Jun 2005 11:33:38 +0200

On Tue, Jun 14, 2005 at 02:25:27PM -0400, Gerard Fowley wrote:

The problem is that I am seeing repeated probes for ports that have
already been determined to be open or closed. Here are tcpdump
outputs taken from the source host...

Just a *blind*, quick and dirty guess: it may be caused by Nmap's
internal rate-limit detector (rld* stuff in scan_engine.cc). (Though
it could be a bug too...)

Martin Mačok
ICT Security Consultant


_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev


Current thread: