← All cheat sheets

HPING3

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

hping3 is a network tool that sends custom TCP/IP packets and
displays replies. Used for firewall testing, port scanning, network
testing, OS fingerprinting, traceroute, and packet crafting.

BASIC USAGE#

hping3 <target>                  # Default TCP ping to port 0
hping3 -S <target>               # TCP SYN ping
hping3 -1 <target>               # ICMP mode (like ping)
hping3 -2 <target>               # UDP mode

PROTOCOL MODES#

hping3 -0 <target>               # Raw IP mode
hping3 -1 <target>               # ICMP mode
hping3 -2 <target>               # UDP mode
hping3 -8 <target>               # Scan mode (port scanning)
hping3 -9 <target>               # Listen mode

TCP FLAG OPTIONS#

hping3 -S <target>               # SYN flag
hping3 -A <target>               # ACK flag
hping3 -F <target>               # FIN flag
hping3 -R <target>               # RST flag
hping3 -P <target>               # PUSH flag
hping3 -U <target>               # URG flag
hping3 -X <target>               # XMAS (FIN+URG+PSH)
hping3 -Y <target>               # YMAS scan
hping3 -SA <target>              # SYN+ACK flags

PORT SCANNING#

hping3 -8 1-1024 -S <target>    # SYN scan ports 1-1024
hping3 -8 80,443 -S <target>    # Scan specific ports
hping3 --scan 1-100 -S <target> # Scan port range
hping3 --scan known -S <target> # Scan well-known ports

PORT OPTIONS#

hping3 -p 80 <target>            # Set destination port
hping3 -s 12345 <target>         # Set source port
hping3 -p ++1 <target>           # Increment dest port each packet

TIMING & COUNT#

hping3 -c 5 <target>             # Send 5 packets
hping3 -i u10000 <target>        # Interval: 10000 microseconds
hping3 --fast <target>           # Send 10 packets/sec
hping3 --faster <target>         # Send 100 packets/sec
hping3 --flood <target>          # Send as fast as possible

TTL & TRACEROUTE#

hping3 -t 1 --tr-stop <target>  # Traceroute mode
hping3 -T <target>               # Set TTL (default 64)
hping3 --traceroute <target>     # Traceroute mode

IP OPTIONS#

hping3 -a <spoof_ip> <target>   # Spoof source IP
hping3 --rand-source <target>    # Random source IP each packet
hping3 --rand-dest <target>      # Random destination
hping3 -N <id> <target>          # Set IP ID field
hping3 -f <target>               # Fragment packets
hping3 -m <mtu> <target>         # Set virtual MTU

DATA OPTIONS#

hping3 -d 100 <target>           # Set data size (bytes)
hping3 -E file.txt <target>      # Fill packet data from file
hping3 --sign "MSG" <target>     # Add signature to packets

ICMP OPTIONS#

hping3 -1 -C 8 <target>          # ICMP type 8 (echo request)
hping3 -1 -C 13 <target>         # ICMP timestamp request
hping3 -1 -C 17 <target>         # ICMP address mask request

FIREWALL TESTING#

# Test if port is filtered
hping3 -S -p 80 -c 3 <target>

# ACK scan to detect firewall
hping3 -A -p 80 -c 3 <target>

# Test with different TTL values
hping3 -S -p 80 -t 10 <target>

OS FINGERPRINTING#

hping3 -S -p 80 -c 1 <target>   # Check window size and TTL
# Linux: TTL=64, Win=5840
# Windows: TTL=128, Win=65535
# Cisco: TTL=255

EXAMPLES#

# SYN scan port 80
hping3 -S -p 80 -c 3 192.168.1.1

# Port scan range 1-100
hping3 --scan 1-100 -S 192.168.1.1

# Traceroute with SYN packets
hping3 -S -p 80 -T --tr-stop 192.168.1.1

# ICMP ping with custom data size
hping3 -1 -d 120 -c 5 192.168.1.1

# Firewall ACK probe
hping3 -A -p 22 -c 3 192.168.1.1

# Idle scan (spoofed source)
hping3 -a <zombie_ip> -S -p 80 <target>

NOTES#

- Requires root privileges
- Can be used for DoS testing (use responsibly)
- Useful for testing firewall rules
- Interactive mode supports Tcl scripting
- SA response = port open (to SYN)
- RA response = port closed (to SYN)
- No response = port filtered (to SYN)