HPING3
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
hping3 is a network tool that sends custom TCP/IP packets and displays replies. Used for firewall testing, port scanning, network testing, OS fingerprinting, traceroute, and packet crafting.
BASIC USAGE#
hping3 <target> # Default TCP ping to port 0 hping3 -S <target> # TCP SYN ping hping3 -1 <target> # ICMP mode (like ping) hping3 -2 <target> # UDP mode
PROTOCOL MODES#
hping3 -0 <target> # Raw IP mode hping3 -1 <target> # ICMP mode hping3 -2 <target> # UDP mode hping3 -8 <target> # Scan mode (port scanning) hping3 -9 <target> # Listen mode
TCP FLAG OPTIONS#
hping3 -S <target> # SYN flag hping3 -A <target> # ACK flag hping3 -F <target> # FIN flag hping3 -R <target> # RST flag hping3 -P <target> # PUSH flag hping3 -U <target> # URG flag hping3 -X <target> # XMAS (FIN+URG+PSH) hping3 -Y <target> # YMAS scan hping3 -SA <target> # SYN+ACK flags
PORT SCANNING#
hping3 -8 1-1024 -S <target> # SYN scan ports 1-1024 hping3 -8 80,443 -S <target> # Scan specific ports hping3 --scan 1-100 -S <target> # Scan port range hping3 --scan known -S <target> # Scan well-known ports
PORT OPTIONS#
hping3 -p 80 <target> # Set destination port hping3 -s 12345 <target> # Set source port hping3 -p ++1 <target> # Increment dest port each packet
TIMING & COUNT#
hping3 -c 5 <target> # Send 5 packets hping3 -i u10000 <target> # Interval: 10000 microseconds hping3 --fast <target> # Send 10 packets/sec hping3 --faster <target> # Send 100 packets/sec hping3 --flood <target> # Send as fast as possible
TTL & TRACEROUTE#
hping3 -t 1 --tr-stop <target> # Traceroute mode hping3 -T <target> # Set TTL (default 64) hping3 --traceroute <target> # Traceroute mode
IP OPTIONS#
hping3 -a <spoof_ip> <target> # Spoof source IP hping3 --rand-source <target> # Random source IP each packet hping3 --rand-dest <target> # Random destination hping3 -N <id> <target> # Set IP ID field hping3 -f <target> # Fragment packets hping3 -m <mtu> <target> # Set virtual MTU
DATA OPTIONS#
hping3 -d 100 <target> # Set data size (bytes) hping3 -E file.txt <target> # Fill packet data from file hping3 --sign "MSG" <target> # Add signature to packets
ICMP OPTIONS#
hping3 -1 -C 8 <target> # ICMP type 8 (echo request) hping3 -1 -C 13 <target> # ICMP timestamp request hping3 -1 -C 17 <target> # ICMP address mask request
FIREWALL TESTING#
# Test if port is filtered hping3 -S -p 80 -c 3 <target> # ACK scan to detect firewall hping3 -A -p 80 -c 3 <target> # Test with different TTL values hping3 -S -p 80 -t 10 <target>
OS FINGERPRINTING#
hping3 -S -p 80 -c 1 <target> # Check window size and TTL # Linux: TTL=64, Win=5840 # Windows: TTL=128, Win=65535 # Cisco: TTL=255
EXAMPLES#
# SYN scan port 80 hping3 -S -p 80 -c 3 192.168.1.1 # Port scan range 1-100 hping3 --scan 1-100 -S 192.168.1.1 # Traceroute with SYN packets hping3 -S -p 80 -T --tr-stop 192.168.1.1 # ICMP ping with custom data size hping3 -1 -d 120 -c 5 192.168.1.1 # Firewall ACK probe hping3 -A -p 22 -c 3 192.168.1.1 # Idle scan (spoofed source) hping3 -a <zombie_ip> -S -p 80 <target>
NOTES#
- Requires root privileges - Can be used for DoS testing (use responsibly) - Useful for testing firewall rules - Interactive mode supports Tcl scripting - SA response = port open (to SYN) - RA response = port closed (to SYN) - No response = port filtered (to SYN)