Table of Contents
Host Discovery (Discovery of Hosts and ping Sweeps)
The discovery of hosts allows us to determine which machines are activated and accessible to a network before performing more exhaustive port scans.
| Flag | Protocol | Technical description |
|---|---|---|
-sn |
Ping Sweep | Disables port scanning and only checks whether hosts are active. |
-PE |
ICMP Echo | He sends traditional ICMP eco applications (the typical ping). |
-PP / -PM |
ICMP Timestamp / Mask | Sends time mark or ICMP mask applications to avoid filters. |
-PS [portlist] |
TCP SYN Ping | Send TCP SYN packets to the specified ports (by default 80 and 443). |
-PA [portlist] |
TCP ACK Ping | He sends TCP ACK packets to force an RST response at firewalls with status monitoring. |
-PU [portlist] |
UDP Ping | He sends UDP probes (by default to port 40125) and expects an ICMP Port Unreachable message. |
-PR |
ARP Ping | It uses ARP applications on local Ethernet networks. That's the fastest and most undetectable method for host firewalls. |
-n: Never conduct DNS inverse resolution. It dramatically accelerates mass scans.-R: Always force DNS's inverse resolution for all goals.--dns-servers <servidor1,servidor2>: Specifies custom DNS servers to avoid local DNS login.