From: Francis Cianfrocca Date: 2007-04-17T00:12:56+09:00 Subject: Re: simple but fast port scanner ------=_Part_50329_26033622.1176736372198 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline On 4/16/07, mrpink wrote: > > hi, > I wanna write a simple and fast port scanner which scans one host for > some open ports. I need to do this in a SYN scan mode which is described > as follows: > > 'This technique is often referred to as half-open scanning, because you > don't open a full TCP connection. You send a SYN packet, as if you are > going to open a real connection and then wait for a response. A SYN/ACK > indicates the port is listening (open), while a RST (reset) is > indicative of a non-listener. If no response is received after several > retransmissions, the port is marked as filtered. The port is also marked > filtered if an ICMP unreachable error (type 3, code 1,2, 3, 9, 10, or > 13) is received.' > > But a simple question ;) How do I send a SYN packet ? Google didn't want > to drop a usefull answer for that question so I hope I can get here some > infos about that. > > greets > > Depends on what you're trying to do. If you only want to manage systems in your own environment, just do a full TCP connect. (There is a class in EventMachine that was designed exactly for this kind of test, and it's extremely fast.) If you're looking for open ports out in the internet that you intend to SYN-flood, you came to the wrong list. ------=_Part_50329_26033622.1176736372198--