Home page logo

nmap-dev logo Nmap Development mailing list archives

Re: Nmap says Host down when actually host is up.
From: Swapnali <swapnali2 () gmail com>
Date: Fri, 26 Oct 2007 08:27:51 -0500

Thanks for all your response. Unfortunately, I am unable to completely solve
this mystery. When I did a traceroute to, it infact ended at But because I do not have access on, I am unable
to see the configuration on it. might be configured as
anything on that. Will have to wait till I see the config.

Thanks again.

On 10/26/07, Fyodor <fyodor () insecure org> wrote:

On Fri, Oct 26, 2007 at 07:10:33AM +0000, Brandon Enright wrote:

I haven't given it more than 2 seconds of thought, but we could try
something TCP SYNCOOKIE inspired for our ICMP ECHO requests.

Hi Brandon.  The response already has enough information (e.g. ICMP
sequence and ID numbers) for us to recognize it.  But I think in most
cases where we get a response from a different IP than the target we
sent to, it is because the target host forwarded the request
(e.g. subnet-directed broadcast) to other machines, and one or more of
them answered.  In that case, for us to mark the target as up would be
a false postive.  For us to change that behavior and mark the host as
up, I would want some evidence that actual online hosts responding
with the wrong IP is a normal occurence.


Sent through the nmap-dev mailing list
Archived at http://SecLists.Org

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]