Nmap Development mailing list archives
Why can't discover host in my LAN even though it responds over ARP?
From: Jacek Wielemborek <d33tah () gmail com>
Date: Sat, 8 Jul 2017 11:32:42 +0200
List, Have a look at this output: [11:30:43] ➜ .nmap % nmap 192.168.0.140 -PS22 -d9 Starting Nmap 7.50SVN ( https://nmap.org ) at 2017-07-08 11:30 CEST Fetchfile found /home/d33tah/.nmap/nmap-services PORTS: Using top 1000 ports found open (TCP:1000, UDP:0, SCTP:0) The max # of sockets we are using is: 0 --------------- Timing report --------------- hostgroups: min 1, max 100000 rtt-timeouts: init 1000, min 100, max 10000 max-scan-delay: TCP 1000, UDP 1000, SCTP 1000 parallelism: min 0, max 0 max-retries: 10, host-timeout: 0 min-rate: 0, max-rate: 0 --------------------------------------------- Fetchfile found /home/d33tah/.nmap/nmap-payloads Initiating ARP Ping Scan at 11:30 Scanning 192.168.0.140 [1 port] Packet capture filter (device wlp4s0): arp and arp[18:4] = 0xA434D9C5 and arp[22:2] = 0x6E4E SENT (0.0819s) ARP who-has 192.168.0.140 tell 192.168.0.117 **TIMING STATS** (0.0820s): IP, probes active/freshportsleft/retry_stack/outstanding/retranwait/onbench, cwnd/ssthresh/delay, timeout/srtt/rttvar/ Groupstats (1/1 incomplete): 1/*/*/*/*/* 10.00/75/* 200000/-1/-1 192.168.0.140: 1/0/0/1/0/0 10.00/75/0 200000/-1/-1 Current sending rates: 21.62 packets / s, 908.15 bytes / s. Overall sending rates: 21.62 packets / s, 908.15 bytes / s. RCVD (0.2491s) ARP reply 192.168.0.242 is-at 00:26:B6:7C:28:44 SENT (0.2821s) ARP who-has 192.168.0.140 tell 192.168.0.117 **TIMING STATS** (0.2822s): IP, probes active/freshportsleft/retry_stack/outstanding/retranwait/onbench, cwnd/ssthresh/delay, timeout/srtt/rttvar/ Groupstats (1/1 incomplete): 1/*/*/*/*/* 10.00/75/* 200000/-1/-1 192.168.0.140: 1/0/0/2/0/0 10.00/75/0 200000/-1/-1 Current sending rates: 8.11 packets / s, 340.77 bytes / s. Overall sending rates: 8.11 packets / s, 340.77 bytes / s. **TIMING STATS** (0.4823s): IP, probes active/freshportsleft/retry_stack/outstanding/retranwait/onbench, cwnd/ssthresh/delay, timeout/srtt/rttvar/ Groupstats (1/1 incomplete): 0/*/*/*/*/* 10.00/75/* 200000/-1/-1 192.168.0.140: 0/0/0/2/1/0 10.00/75/0 200000/-1/-1 Current sending rates: 4.48 packets / s, 188.10 bytes / s. Overall sending rates: 4.48 packets / s, 188.10 bytes / s. ultrascan_host_probe_update called for machine 192.168.0.140 state UNKNOWN -> HOST_DOWN (trynum 1 time: 202323) Moving 192.168.0.140 to completed hosts list with 1 outstanding probe. * ARP Completed ARP Ping Scan at 11:30, 0.45s elapsed (1 total hosts) Overall sending rates: 4.46 packets / s, 187.20 bytes / s. pcap stats: 1 packets received by filter, 0 dropped by kernel. mass_rdns: Using DNS server 127.0.0.53 Nmap scan report for 192.168.0.140 [host down, received no-response] Read from /home/d33tah/.nmap: nmap-payloads nmap-services. Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn Nmap done: 1 IP address (0 hosts up) scanned in 0.53 seconds Raw packets sent: 2 (56B) | Rcvd: 1 (28B) [11:30:49] ➜ .nmap % arp -a OpenWrt.lan (192.168.0.1) at c4:e9:84:7d:e2:f2 [ether] on wlp4s0 ? (172.17.0.2) at <incomplete> on docker0 d33tah-pc-wifi.lan (192.168.0.140) at 74:31:70:c5:1b:8a [ether] on wlp4s0 d33tah-ao756-kodi.lan (192.168.0.242) at 00:26:b6:7c:28:44 [ether] on wlp4s0 What could be happening here? Cheers, d33tah
Attachment:
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Sent through the dev mailing list https://nmap.org/mailman/listinfo/dev Archived at http://seclists.org/nmap-dev/
Current thread:
- Why can't discover host in my LAN even though it responds over ARP? Jacek Wielemborek (Jul 08)
- Message not available
- Re: Why can't discover host in my LAN even though it responds over ARP? Jacek Wielemborek (Jul 09)
- Message not available
