June 22, 2004

Windows XP SP2 and Nmap

I’ve been building some XP images for our lab at work and figured I would throw the release candidate of Service Pack 2 onto them.

As one might expect, the networking components are severely disrupted, resulting in nmap syn scans coming back as all filtered. TCP connect scans come back fine, however. I tried to figure it out using different versions of winpcap (but later versions require an unreleased version of nmap to work) and digging into some of the firewall options on sp2. It’s not just the firewall, though, as I can disable it completely and still have nmap not work.

For now, I guess I have to drop back to SP1. Too bad, I kind of liked the firewall in sp2…much more configurable!

3 Comments so far
Leave a comment

That stinks. Oh well… can’t wait to get the image, though!

Seems like support for raw sockets were removed.

http://seclists.org/lists/nmap-dev/2004/Apr-Jun/0077.html

Dana Epp’s Weblog comments on this lost functionality, as well as some other stuff:
http://silverstr.ufies.org/blog/archives/000669.html

Fyodor has made an SP2 build available, which should be rolled into an official release if all goes well:
http://seclists.org/lists/nmap-dev/2004/Jul-Sep/0030.html



Leave a comment
Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>