# Network Security: Nmap Live Host Discovery (TryHackMe)

This article will cover the [Nmap Live Host Discovery](https://tryhackme.com/room/nmap01) write-up under the Web Fundamentals on THM.

## Introduction

When we want to target a network, we want to find an efficient tool to help us handle repetitive tasks and answer the following questions:

1. Which systems are up?
    
2. What services are running on these systems?
    

The tool that we will rely on is Nmap. The first question about finding live computers is answered in this room. This room is the first in a series of four rooms dedicated to Nmap. The second question about discovering running services is answered in the next Nmap rooms that focus on port-scanning.

This room is the first of four in this Nmap series. These four rooms are also part of the Network Security module.

1. [Nmap Live Host Discovery](https://tryhackme.com/room/nmap01)
    
2. [Nmap Basic Port Scans](https://tryhackme.com/room/nmap02)
    
3. [Nmap Advanced Port](https://tryhackme.com/room/nmap03) [Scans](https://tryhackme.com/room/nmap04)
    
4. [Nmap Post Port Scans](https://tryhackme.com/room/nmap04)
    

This room explains the steps that Nmap carr[ies out to discover t](https://tryhackme.com/room/nmap01)[he s](https://tryhackme.com/room/nmap02)[ystems that are onlin](https://tryhackme.com/room/nmap01)[e before port-scannin](https://tryhackme.com/room/nmap02)[g.](https://tryhackme.com/room/nmap04) [Th](https://tryhackme.com/room/nmap03)[is stage is crucial b](https://tryhackme.com/room/nmap01)[ecause trying to port](https://tryhackme.com/room/nmap02)\-sc[an offline systems w](https://tryhackme.com/room/nmap03)[ill only waste time](https://tryhackme.com/room/nmap04) and create unnecessary noise on the network.

We present the different approaches that Nmap uses to discover live hosts. In particular, we cover:

1. ARP scan: This scan uses ARP requests to discover live hosts
    
2. ICM[P scan: This scan use](https://tryhackme.com/room/nmap01)[s ICMP requests to id](https://tryhackme.com/room/nmap02)ent[ify live hosts](https://tryhackme.com/room/nmap03)
    
3. [TC](https://tryhackme.com/room/nmap03)[P/UDP ping scan: Thi](https://tryhackme.com/room/nmap04)s scan sends packets to TCP ports [and UDP ports to det](https://tryhackme.com/room/nmap01)[ermine](https://tryhackme.com/room/nmap02) [live hosts.](https://tryhackme.com/room/nmap01)
    

[We als](https://tryhackme.com/room/nmap01)[o in](https://tryhackme.com/room/nmap02)[troduce two scanners,](https://tryhackme.com/room/nmap01) [`arp-sc`](https://tryhackme.com/room/nmap02)[`an` and `masscan`, and e](https://tryhackme.com/room/nmap01)[xpl](https://tryhackme.com/room/nmap02)[ain how they overlap](https://tryhackme.com/room/nmap01) [with part of Nmap’s h](https://tryhackme.com/room/nmap02)[ost](https://tryhackme.com/room/nmap04) [discovery.](https://tryhackme.com/room/nmap03)

[As alre](https://tryhackme.com/room/nmap03)[ady mentioned, start](https://tryhackme.com/room/nmap04)ing with this room, we will use Nmap to discover systems and services actively. Nmap was created by Gordon Lyon (Fyodor), a network security expert and open sour[ce programmer. It was](https://tryhackme.com/room/nmap01) [released in 1997. Nm](https://tryhackme.com/room/nmap02)ap, [short for Network M](https://tryhackme.com/room/nmap03)[apper, is free, open](https://tryhackme.com/room/nmap04)\-source software r[eleased under GPL lic](https://tryhackme.com/room/nmap01)[ense. Nmap is an indu](https://tryhackme.com/room/nmap02)str[y-standard tool for](https://tryhackme.com/room/nmap03) [mapping networks, id](https://tryhackme.com/room/nmap01)[entifying live hosts,](https://tryhackme.com/room/nmap02) an[d discovering runnin](https://tryhackme.com/room/nmap03)[g](https://tryhackme.com/room/nmap04) [services. Nmap’s scr](https://tryhackme.com/room/nmap01)[ipting engine can fur](https://tryhackme.com/room/nmap02)the[r extend its functio](https://tryhackme.com/room/nmap03)[nality, from fingerp](https://tryhackme.com/room/nmap04)rinting servi[ces to exploiting vul](https://tryhackme.com/room/nmap01)[nerabilities. A Nmap](https://tryhackme.com/room/nmap02) sca[n usually goes throu](https://tryhackme.com/room/nmap03)[gh the steps shown i](https://tryhackme.com/room/nmap04)n the figure below, although many a[re optional and depen](https://tryhackme.com/room/nmap01)[d on the command-line](https://tryhackme.com/room/nmap02) ar[guments you provide.](https://tryhackme.com/room/nmap03)

![](https://tryhackme-images.s3.amazonaws.com/user-uploads/5f04259cf9bf5b57aed2c476/room-content/f1b4ede255e008646e425038d709c9b6.png align="left")

## Subnetworks

Let's review a couple of terms before we move on to the main tasks. A *network segment* is a group of computers connected using a shared medium. For instance, the medium can be the Ethernet switch or WiFi access point. In an IP network, a *subnetwork* is usually the equivalent of one or more network segments connected together and configured to use the same router. The network segment refers to a physical connection, while a subnetwork refers to a logical connection.

In the following network diagram, we have four network segments or subnetworks. Generally speaking, your system would be connected to one of these network segments/subnetworks. A subnetwork, or simply a subnet, has its own IP address range and is connected to a more extensive network via a router. There might be a firewall enforcing security policies depending on each network.

![](https://tryhackme-images.s3.amazonaws.com/user-uploads/5f04259cf9bf5b57aed2c476/room-content/aa787518e856e0094cb40da8399be0f3.png align="left")

The figure above shows two types of subnets:

* Subnets with `/16`, which means that the subnet mask can be written as `255.255.0.0`. This subnet can have around 65 thousand hosts.
    
* Subnets with `/24`, which indicates that the subnet mask can be expressed as `255.255.255.0`. This subnet can have around 250 hosts.
    

You might want to refer to Task 2 in the [Intro to LAN](https://tryhackme.com/room/introtolan) room if you need to learn more about subnetting.

As part of active reconnaissance, we want to discover more information about a group of hosts or about a subnet. If you are connected to the same subnet, you would expect your scanner to rely on ARP (Address Resolution Protocol) queries to discover live hosts. An ARP query aims to get the hardware address (MAC address) so that communication over the link-layer becomes possible; however, we can use this to infer that the host is online. (We revisit link-layer in Task 4.)

If you are in Network A, you can use ARP only to discover the devices within that subnet (10.1.100.0/24). Suppose you are connected to a subnet different from the subnet of the target system(s). In that case, all packets generated by your scanner will be routed via the default gateway (router) to reach the systems on another subnet; however, the ARP queries won’t be routed and hence cannot cross the subnet router. ARP is a link-layer protocol, and ARP packets are bound to their subnet.

Click on the “View Site” button to start the network simulator. We will use this simulator to answer the questions in tasks 2, 4, and 5.

### Answer the questions below

Send a packet with the following:

![](https://tryhackme-images.s3.amazonaws.com/user-uploads/5f04259cf9bf5b57aed2c476/room-content/65a1bdee53403520174388d9de6410ba.png align="left")

* From computer1
    
* To computer1 (to indicate it is broadcast)
    
* Packet Type: “ARP Request”
    
* Data: computer6 (because we are asking for computer6 MAC address using ARP Request)
    

1. How many devices can see the ARP Request? `4`
    
2. Did computer6 receive the ARP Request? (Y/N) `N`  
    
    Send a packet with the following:
    
    ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/5f04259cf9bf5b57aed2c476/room-content/818d1c5a3a96a9962dde71069f9e1ee8.png align="left")
    

* From computer4
    
* To computer4 (to indicate it is broadcast)
    
* Packet Type: “ARP Request”
    
* Data: computer6 (because we are asking for computer6 MAC address using ARP Request)
    

3. How many devices can see the ARP Request? `4`
    
4. Did computer6 reply to the ARP Request? (Y/N) `Y`
    

Thank you for reading my article. Please leave any questions or comments on improving my learning journey and the Lab THM challenges.
