Nmap Development mailing list archives

Nmap does not perform reliable scans on Solaris 11


From: Giovanni Schmid <giovanni.schmid () na icar cnr it>
Date: Mon, 16 May 2011 20:46:06 +0200

 Hi,

I tested Nmap 5.21 on Oracle Solaris 11 and found that it only apparently works. Actually, many different scan sessions (with different options and targets) got wrong results. For ex., the following scan is related to a host with 22/tcp (SSH) and 111/tcp (rpcbind) open; however the two services are not detected. Morever, turning off the -PN option results in
an host apparently blocking up ping probes. This is not the case, instead.

# nmap -A 172.16.3.42

Starting Nmap 5.21 ( http://nmap.org/ ) at 2011-05-16 20:13 CEST
Note: Host seems down. If it is really up, but blocking our ping probes, try -PN
Nmap done: 1 IP address (0 hosts up) scanned in 3.60 seconds

# nmap -PN -A 172.16.3.42

Starting Nmap 5.21 ( http://nmap.org/ ) at 2011-05-16 20:14 CEST
Nmap scan report for 172.16.3.42
Host is up.
All 1000 scanned ports on 172.16.3.42 are filtered
Too many fingerprints match this host to give specific OS details

TRACEROUTE (using proto 1/icmp)
HOP RTT    ADDRESS
1   ... 30

# nmap -PN -sS 172.16.3.42

Starting Nmap 5.21 ( http://nmap.org/ ) at 2011-05-16 20:34 CEST
Nmap scan report for 172.16.3.42
Host is up.
All 1000 scanned ports on 172.16.3.42 are filtered

Nmap done: 1 IP address (1 host up) scanned in 201.16 seconds


Nmap was downloaded and installed through IPS and the official sw repositories for
Solaris

# pkg info nmap
          Nome: diagnostic/nmap
     Riepilogo: nmap - Network Mapper
   Descrizione: nmap - Network exploration tool and security / port scanner
                (5.21)
     Categoria: System/Administration and Configuration
         Stato: Installato
     Publisher: solaris
      Versione: 5.21
 Release della build: 5.11
          Ramo: 0.151.0.1
Data del packaging: 05 novembre 2010 05.39.10
    Dimensione: 8.92 MB
FMRI: pkg://solaris/diagnostic/nmap@5.21,5.11-0.151.0.1:20101105T053910Z

I hope this can help.

Sincerely,

--
Giovanni Schmid, PhD.
National Research Council
Italy

Contact Information:
High Performance Computing and Networking Institute (ICAR)
Via Pietro Castellino 111, I-80131 Naples, Italy
voice: +39-081-6139529; fax: +39-081-6139531
e-mail: giovanni.schmid () na icar cnr it
mobile: 3316916011


_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: