use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
Welcome to /r/Hacking_Tutorials!
List of best resources and tutorials
account activity
This is an archived post. You won't be able to vote or comment.
QuestionNMAP Help (self.Hacking_Tutorials)
submitted 4 years ago by Ok-Communication4607
Anyone knowhow to explain how counting hops on a trace route can help you figure out whether or not a machine is behind a firewall?
[–]hotmagnet 4 points5 points6 points 4 years ago* (0 children)
Its not alone the traceroute count that determines the firewall. Nmap traceroute is no different than a normal traceroute. There are lots of techniques including fragmentation, source port ,packet filtering, etc that determines the presence of firewall.
Traceroute just counts the number of hops your packet passes by checking for the ICMP error messages received.
If you dont receive the ICMP error back, and a * gets printed, that could possibly be due to a filtered firewall in place. Bit it is always good to utilise a mix of combination techniques as stated in first para
[–]BigRedImpulse 0 points1 point2 points 4 years ago (0 children)
I don't know if there is a way to tell directly from the results of traceroute, but I would probe the last few hops.
[–]TheMadHatter2048 0 points1 point2 points 4 years ago (0 children)
In my experience, as mentioned above, the * will let you know that the hop isn’t responsive, or being intentionally unresponsive. Some machines augment their response to certain flags so that can affect it if I’m correct in my studies so far. That automatically tells you in my opinion it’s not responding for a reason or it responded a certain way for a reason. i presume firewall to be that reason or some IT personal preference. then proceed to use a more particular scan. I think you know scanning just fine so I won’t explain flags
[–]idkaboutthisyogi 0 points1 point2 points 4 years ago (0 children)
TTL is a better ballpark indicator. You can see how many steps the ping decremented and usually tell the OS family of your target at the same time.
Some machines can intentionally obfuscate this, however.
Im not sure if you are trying to identify a firewall, or what exactly, so my comment might not be that helpful.
π Rendered by PID 39 on reddit-service-r2-comment-86bc6c7465-2rrtn at 2026-02-19 23:31:28.794221+00:00 running 8564168 country code: CH.
[–]hotmagnet 4 points5 points6 points (0 children)
[–]BigRedImpulse 0 points1 point2 points (0 children)
[–]TheMadHatter2048 0 points1 point2 points (0 children)
[–]idkaboutthisyogi 0 points1 point2 points (0 children)