Dealing with stuck hosts

Unfortunately, when dealing with large blocks of IP addresses—which is a very common occurrence if you're scanning a large enterprise, whether for internal security purposes or as a client engagement—it isn't uncommon to deal with stuck hosts.

When a host gets stuck, it means that something is stopping the scan from completing at a normal rate. This could be caused by something benign such as a network hiccup on either end of the connection, or something more intentional such as a security software that is intentionally making the target host respond very slowly or inconsistently—effectively breaking the scan.

For the purposes of demonstration, I am going to start a ping agnostic (-Pn) scan against a host that doesn't exist ...

Get Nmap Essentials now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.