From owner-freebsd-security@FreeBSD.ORG Fri Jun 18 14:55:49 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D219C16A4CE for ; Fri, 18 Jun 2004 14:55:49 +0000 (GMT) Received: from ox.eicat.ca (ox.eicat.ca [66.96.30.35]) by mx1.FreeBSD.org (Postfix) with ESMTP id 85C3243D49 for ; Fri, 18 Jun 2004 14:55:49 +0000 (GMT) (envelope-from dgilbert@daveg.ca) Received: by ox.eicat.ca (Postfix, from userid 66) id 0EA6DC11C; Fri, 18 Jun 2004 10:54:48 -0400 (EDT) Received: by canoe.dclg.ca (Postfix, from userid 101) id 6E47E1D26A8; Fri, 18 Jun 2004 10:54:47 -0400 (EDT) From: David Gilbert MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Message-ID: <16595.567.380998.969679@canoe.dclg.ca> To: Zoran Kolic In-Reply-To: <20040618062557.GA616@kolic.net> References: <20040617120329.8AA7216A4D5@hub.freebsd.org> <20040618062557.GA616@kolic.net> X-Mailer: VM 7.17 under 21.5 (beta15) "celery" XEmacs Lucid X-Mailman-Approved-At: Wed, 07 Jul 2004 16:02:47 +0000 cc: freebsd-security@freebsd.org Subject: Re: nmap not scanning networks? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Date: Fri, 18 Jun 2004 14:55:49 -0000 X-Original-Date: Fri, 18 Jun 2004 10:54:47 -0400 X-List-Received-Date: Fri, 18 Jun 2004 14:55:49 -0000 >>>>> "Zoran" == Zoran Kolic writes: >> nmap -sT -p 21 '172.19.17.*' Zoran> Have you tried without "'"? Or 172.19.17.1-254? Nmap works Zoran> for me. Maybe port 21? I've noticed that nmap on FreeBSD is particularly lame at scanning the local network. If the majority of the addresses on the local network are unoccupied, then it will pause with a 'no buffer space available' message and pause for 15 or 20 seconds each. This seems to be due to it wanting to send a number of packets to the same addresses and when the arp is not resolved we're putting a negative entry in the routing table. ... or at least that was the behaviour. Recent -CURRENTS don't even seem to try to send arp entries as the arp table isn't full of incomplete entries as it was before. Dave. -- ============================================================================ |David Gilbert, Independent Contractor. | Two things can only be | |Mail: dave@daveg.ca | equal if and only if they | |http://daveg.ca | are precisely opposite. | =========================================================GLO================