Nmap Development mailing list archives

questions on packet trace


From: "Mike ." <dmciscobgp () hotmail com>
Date: Tue, 19 Jan 2016 19:01:42 +0000

ok. sorry for so many questions, but today nmap is making me about ready to pull my hair out! ok. first my setup--as 
simple as can be. one router/modem, one laptop, one net card. that's it. no wireless here. i  have been testing out 
some of the broadcast scripts today. i run windump and tshark alot next to nmap. i have noticed a few of these 
broadcast scripts WILL NOT show up as far as windump/tshark are concerned, but WILL in packet trace. why is this?????? 
is packet trace the more trusted when i am wondering "did that packet really get sent out"? the one script that seems 
to never show up at all in windump/tshark i ran today is the upnp-broadcast. as you can see---nmap sees it fine


NSE: UDP 0.0.0.0:0 > 239.255.255.250:1900 | 00000000: 4d 2d 53 45 41 52 43 48 20
 2a 20 48 54 54 50 2f M-SEARCH * HTTP/
00000010: 31 2e 31 0d 0a 48 6f 73 74 3a 32 33 39 2e 32 35 1.1  Host:239.25
00000020: 35 2e 32 35 35 2e 32 35 30 3a 31 39 30 30 0d 0a 5.255.250:1900
00000030: 53 54 3a 75 70 6e 70 3a 72 6f 6f 74 64 65 76 69 ST:upnp:rootdevi
00000040: 63 65 0d 0a 4d 61 6e 3a 22 73 73 64 70 3a 64 69 ce  Man:"ssdp:di
00000050: 73 63 6f 76 65 72 22 0d 0a 4d 58 3a 33 0d 0a 0d scover"  MX:3
00000060: 0a

and windump...nothing:

windump -n -t -v port 1900
windump: listening on \Device\NPF_{E6793762-9633-432B-B8A6-B4C2F6AA5179}.........(sits there silent)

i thought i knew networking fairly well. i am beyond bewildered here so someone point out what i am doing wrong so i 
can then look stupid...lol. thank you!


Mike




_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/

Current thread: