Skip to contentExploitQuest

Lesson 1 of 2 in nmap · 2 min left in this chapter

Reading the Output, Not the Flags

Three port states, and the one everybody misreads.

1 min read

Not yet reviewed

Most nmap tutorials are a list of flags. The flags are the easy part — you can look them up. What takes practice is reading the output, and in particular knowing what the tool is telling you when it says a port is filtered.

Three states, and they mean different things

What nmap prints

22/tcp   open      ssh
80/tcp   closed    http
3306/tcp filtered  mysql

What actually happened

open      something answered and completed a handshake
closed    the host answered, and said nothing is listening
filtered  nothing came back at all

closed and filtered are not degrees of the same thing. Closed is an answer — the host is up and that port is empty. Filtered is silence, and silence has several causes.

That distinction is the whole lesson. A closed port tells you the machine is alive and reachable. A filtered port tells you that something between you and it dropped the packet, and you do not know whether the port is open, closed, or the host does not exist.

Note

"Filtered" is a statement about the path, not about the service. A firewall dropping traffic, a cloud security group, a network ACL, or your own outbound rules all produce it identically.

Trying it

Your turn

Scan the host gateway.internal and find the one service that is answering on a non-standard port. Print the scan output.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.