FIREWALK
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Firewalk is an active reconnaissance tool that determines which protocols a firewall or gateway will pass. It sends TCP/UDP packets with TTL values designed to expire one hop past the firewall, revealing open ports in the ACL.
BASIC USAGE#
firewalk -S<port_start>-<port_end> <gateway_ip> <target_ip>
# Scan port range through gateway
firewalk -pTCP <gateway_ip> <target_ip>
# Use TCP protocol (default)
firewalk -pUDP <gateway_ip> <target_ip>
# Use UDP protocol
SCAN OPTIONS#
firewalk -S1-1024 <gw> <tgt> # Scan ports 1-1024
firewalk -S80,443,8080 <gw> <tgt>
# Scan specific ports
firewalk -S1-65535 <gw> <tgt> # Full port range scan
firewalk -n <gw> <tgt> # Do not resolve hostnames
PROTOCOL OPTIONS#
firewalk -pTCP <gw> <tgt> # TCP scan (default) firewalk -pUDP <gw> <tgt> # UDP scan
TIMING & NETWORK#
firewalk -t <timeout> <gw> <tgt>
# Set packet timeout (ms)
firewalk -d <port> <gw> <tgt> # Set initial destination port
firewalk -r <gw> <tgt> # Strict RFC adherence
firewalk -T 1-2 <gw> <tgt> # Set initial/ramped TTL
NETWORK INTERFACE#
firewalk -i eth0 <gw> <tgt> # Specify network interface firewalk -s <port> <gw> <tgt> # Set source port
EXAMPLES#
# Scan common web ports through firewall firewalk -S80,443,8080,8443 192.168.1.1 10.0.0.1 # Full TCP port scan firewalk -pTCP -S1-1024 192.168.1.1 10.0.0.1 # UDP scan for DNS, SNMP, TFTP firewalk -pUDP -S53,161,69 192.168.1.1 10.0.0.1 # Scan with specific interface firewalk -i eth0 -S1-100 192.168.1.1 10.0.0.1
HOW IT WORKS#
# Phase 1: Ramping # - Determines hop count to the gateway (like traceroute) # - Sends packets with incrementing TTL values # - Identifies the exact TTL needed to reach the gateway # Phase 2: Scanning # - Sends packets with TTL = gateway_hops + 1 # - If firewall allows the traffic: ICMP TTL exceeded from next hop # - If firewall blocks the traffic: no response (filtered)
INTERPRETING RESULTS#
# "A" = ACL allows the port (open/forwarded) # "F" = Filtered (firewall blocks the port) # "T" = Timed out (no response, likely filtered)
NOTES#
- Requires root privileges - Gateway IP = firewall/router you want to test - Target IP = host beyond the firewall - Works best when there is exactly one hop past the gateway - May trigger IDS/IPS alerts - Some firewalls detect and block firewalk scans - Stateful firewalls may give inaccurate results