From 28a64a848f378369f4f1cf30775d4eec444771ca Mon Sep 17 00:00:00 2001 From: Slava Bacherikov Date: Sun, 11 Jan 2026 11:29:52 +0200 Subject: [PATCH] nping: add docs about --badsum for ICMP --- nping/docs/nping-man.xml | 17 +++++++++++++++++ nping/docs/nping-usage.txt | 1 + nping/docs/nping.1 | 7 +++++++ 3 files changed, 25 insertions(+) diff --git a/nping/docs/nping-man.xml b/nping/docs/nping-man.xml index 2f1d73c66..9aa0c4b9c 100644 --- a/nping/docs/nping-man.xml +++ b/nping/docs/nping-man.xml @@ -1049,6 +1049,23 @@ SENT (4.0330s) TCP 192.168.0.21 > 3.3.3.3:139 + + + (Invalid Checksum) + (Nping option) + + + + Asks Nping to use an invalid ICMP checksum for the packets sent to + target hosts. Since virtually all host IP stacks properly drop these + packets, any responses received are likely coming from a firewall or + an IDS that didn't bother to verify the checksum. For more + details on this technique, see + . + + + + diff --git a/nping/docs/nping-usage.txt b/nping/docs/nping-usage.txt index 3e0cfca29..f621829c8 100644 --- a/nping/docs/nping-usage.txt +++ b/nping/docs/nping-usage.txt @@ -39,6 +39,7 @@ ICMP PROBE MODE: --icmp-orig-time : Set originate timestamp. --icmp-recv-time : Set receive timestamp. --icmp-trans-time : Set transmit timestamp. + --badsum : Use a random invalid checksum. ARP/RARP PROBE MODE: --arp-type : Type: ARP, ARP-reply, RARP, RARP-reply. --arp-sender-mac : Set sender MAC address. diff --git a/nping/docs/nping.1 b/nping/docs/nping.1 index dbb75605b..31af3a817 100644 --- a/nping/docs/nping.1 +++ b/nping/docs/nping.1 @@ -131,6 +131,7 @@ ICMP PROBE MODE: \-\-icmp\-orig\-time : Set originate timestamp\&. \-\-icmp\-recv\-time : Set receive timestamp\&. \-\-icmp\-trans\-time : Set transmit timestamp\&. + \-\-badsum : Use a random invalid checksum\&. ARP/RARP PROBE MODE: \-\-arp\-type : Type: ARP, ARP\-reply, RARP, RARP\-reply\&. \-\-arp\-sender\-mac : Set sender MAC address\&. @@ -678,6 +679,12 @@ This option sets the Transmit Timestamp in ICMP Timestamp messages\&. The Transm is as with \fB\-\-icmp\-orig\-time\fR\&. .RE +.PP +\fB\-\-badsum\fR (Invalid Checksum) +.RS 4 +Asks Nping to use an invalid ICMP checksum for the packets sent to target hosts\&. Since virtually all host IP stacks properly drop these packets, any responses received are likely coming from a firewall or an IDS that didn\*(Aqt bother to verify the checksum\&. For more details on this technique, see +\m[blue]\fB\%https://nmap.org/p60-12.html\fR\m[]\&. +.RE .SS "ICMP Types" .PP These identifiers may be used as mnemonics for the ICMP type numbers given to the