Why can't discover host in my LAN even though it responds over ARP?
Jacek Wielemborek <[email protected]>
| Newsgroups | gmane.comp.security.nmap.devel |
|---|---|
| Message-ID | <[email protected]> |
List,
Have a look at this output:
[11:30:43] ➜ .nmap % nmap 192.168.0.140 -PS22 -d9
Starting Nmap 7.50SVN ( https://nmap.org ) at 2017-07-08 11:30 CEST
Fetchfile found /home/d33tah/.nmap/nmap-services
PORTS: Using top 1000 ports found open (TCP:1000, UDP:0, SCTP:0)
The max # of sockets we are using is: 0
--------------- Timing report ---------------
hostgroups: min 1, max 100000
rtt-timeouts: init 1000, min 100, max 10000
max-scan-delay: TCP 1000, UDP 1000, SCTP 1000
parallelism: min 0, max 0
max-retries: 10, host-timeout: 0
min-rate: 0, max-rate: 0
---------------------------------------------
Fetchfile found /home/d33tah/.nmap/nmap-payloads
Initiating ARP Ping Scan at 11:30
Scanning 192.168.0.140 [1 port]
Packet capture filter (device wlp4s0): arp and arp[18:4] = 0xA434D9C5
and arp[22:2] = 0x6E4E
SENT (0.0819s) ARP who-has 192.168.0.140 tell 192.168.0.117
**TIMING STATS** (0.0820s): IP, probes
active/freshportsleft/retry_stack/outstanding/retranwait/onbench,
cwnd/ssthresh/delay, timeout/srtt/rttvar/
Groupstats (1/1 incomplete): 1/*/*/*/*/* 10.00/75/* 200000/-1/-1
192.168.0.140: 1/0/0/1/0/0 10.00/75/0 200000/-1/-1
Current sending rates: 21.62 packets / s, 908.15 bytes / s.
Overall sending rates: 21.62 packets / s, 908.15 bytes / s.
RCVD (0.2491s) ARP reply 192.168.0.242 is-at 00:26:B6:7C:28:44
SENT (0.2821s) ARP who-has 192.168.0.140 tell 192.168.0.117
**TIMING STATS** (0.2822s): IP, probes
active/freshportsleft/retry_stack/outstanding/retranwait/onbench,
cwnd/ssthresh/delay, timeout/srtt/rttvar/
Groupstats (1/1 incomplete): 1/*/*/*/*/* 10.00/75/* 200000/-1/-1
192.168.0.140: 1/0/0/2/0/0 10.00/75/0 200000/-1/-1
Current sending rates: 8.11 packets / s, 340.77 bytes / s.
Overall sending rates: 8.11 packets / s, 340.77 bytes / s.
**TIMING STATS** (0.4823s): IP, probes
active/freshportsleft/retry_stack/outstanding/retranwait/onbench,
cwnd/ssthresh/delay, timeout/srtt/rttvar/
Groupstats (1/1 incomplete): 0/*/*/*/*/* 10.00/75/* 200000/-1/-1
192.168.0.140: 0/0/0/2/1/0 10.00/75/0 200000/-1/-1
Current sending rates: 4.48 packets / s, 188.10 bytes / s.
Overall sending rates: 4.48 packets / s, 188.10 bytes / s.
ultrascan_host_probe_update called for machine 192.168.0.140 state
UNKNOWN -> HOST_DOWN (trynum 1 time: 202323)
Moving 192.168.0.140 to completed hosts list with 1 outstanding probe.
* ARP
Completed ARP Ping Scan at 11:30, 0.45s elapsed (1 total hosts)
Overall sending rates: 4.46 packets / s, 187.20 bytes / s.
pcap stats: 1 packets received by filter, 0 dropped by kernel.
mass_rdns: Using DNS server 127.0.0.53
Nmap scan report for 192.168.0.140 [host down, received no-response]
Read from /home/d33tah/.nmap: nmap-payloads nmap-services.
Note: Host seems down. If it is really up, but blocking our ping probes,
try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 0.53 seconds
Raw packets sent: 2 (56B) | Rcvd: 1 (28B)
[11:30:49] ➜ .nmap % arp -a
OpenWrt.lan (192.168.0.1) at c4:e9:84:7d:e2:f2 [ether] on wlp4s0
? (172.17.0.2) at <incomplete> on docker0
d33tah-pc-wifi.lan (192.168.0.140) at 74:31:70:c5:1b:8a [ether] on wlp4s0
d33tah-ao756-kodi.lan (192.168.0.242) at 00:26:b6:7c:28:44 [ether] on wlp4s0
What could be happening here?
Cheers,
d33tah
_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/
signature.asc
(application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJZYKbAAAoJEGlViymZXJRvBHgP/RonrZXM/2EXpkqxDa1Opn0D TLs8xKYqNzVBu3oEVi9mGw8djGh0WlUbTrMqB+shcRLDGo3CAHNKbtJIWnX+lvUr 9TDEesj/lNU63mbE2Q8KrhMeRJMQETe3PJSsJku2xiA5sWosWTw/DZPfRCODPcyX RcGl+iBEBM3Xw2PtSlfbrPXySgtqewVzcdNfvgz+5Hl9V7SEp12mJTZjNrOeEQ3b f19vi3wVNPcFPLM+FzKzGAjdeyAIzJWFCZZFo8PSt5uc7FreWp/GpGAi0bSK8P2W j0W5N2dE2BZ5jcLlAWCJy7Ntgvq5HacDhozn7W8yrLs2HsQizsF7+CvGn1odweyC Nqr28zUHgjZDPU/u8VSgKEftwiGotgC/UKNTXRxm47WivnwJy+/Q2rvV1+ZaZ+4u YRJ7Ll3vwWax9O2dm4Ba2XCfxEIh6VDaMolUd32+6z1f1/1EoCS4jRi6KAIkAtnK bDkfvG4W7QfHOQOTB0Coiztf0i9f/9tE6WOXxZS532j/HA9gYaiQgv3qeUroqCWb 2oQyqgeFjjPB1YUjMuFaMO30WadWYoqM1ejNJkbKCEl/xcBXGju8/JG2FzEYW/XR HCPRUi2NYR4s4jIzRDzlJhPRZ/zv8OvVtjSRVBKrJyyjz+dBCdZbiSbTkgr3Tp8D ugpzpj7SvMbqk//XrAMu =iR8i -----END PGP SIGNATURE-----