Hi List
Is the attached table correct? It's about the answers of packets (when meeting
open/closed/filtered ports) by scanning them with nmap. And can you tell why
it's different (or detected different) when scanning port <1024 or >1024?
<1024 >1024
UDP TCP UDP TCP
OPEN Nothing or syn/ack Response syn/ack
Response
CLOSED ICMP Port Reset ICMP Port Reset
Unreachable Unreachable
FILTER Admin prohib Nothing or Nothing Nothing or
or ICMP Host Admin prohib Admin prohib
Unreachable
GreetZ from IndianZ
mailto:indianz_at_indianz.ch
http://www.indianz.ch
---------------------------------------------------------------------
For help using this (nmap-dev) mailing list, send a blank email to
nmap-dev-help@insecure.org . List archive: http://seclists.org
Received on May 02 2004