Using hping3 to perform host discovery (layers 3/4)
An even more versatile discovery tool that can be used to perform host discovery in multiple different ways is hping3
. It is more powerful than fping
in the sense that it can employ multiple different types of discovery techniques but is less useful as a scanning tool because it can only be used to target a single host. However, this shortcoming can be overcome using bash scripting. This recipe will demonstrate how to use hping3
to perform layer 3 and layer 4 discovery on remote hosts.
Getting ready
Using hping3
to perform layer 3 discovery does not require a lab environment, as many systems on the Internet will reply to ICMP echo requests as well as both TCP and UDP traffic. However, it is highly recommended that you perform any type of network scanning exclusively in your own lab unless you are thoroughly familiar with the legal regulations imposed by any governing authorities to whom you are subject. If you wish to use this technique within...