Skip to main content

Scan Live hosts using Netdiscover in Kali Linux

Scan Live hosts using Netdiscover in Kali Linux

Netdiscover is a simple tool to use.It uses (ARP)Address Resolution Protocol to find live hosts.Netdiscover discovers live hosts on a network but you must be connected to that network. 

Netdiscover not only finds the live hosts also returns mac addresses and hostname.

netdiscover is an active/passive arp reconnaissance tool, initially developed to gain information about wireless networks without dhcp servers in wardriving scenarios.

 It can also be used on switched net‐ works. Built on top of libnet and libpcap, it can passively detect online hosts or search for them by sending arp requests.

Start Netdiscover

With the below command you can see all the options that we can use with netdiscover.

root@seven:~# netdiscover -h

 Netdiscover 0.3-pre-beta7 [Active/passive arp reconnaissance tool] -
 i device: your network device

 -r range: scan a given range instead of auto scan.

 -l file: scan the list of ranges contained into the given file

 -p passive mode: do not send anything, only sniff

 -m file: scan the list of known MACs and host names

 -F filter: Customize pcap filter expression (default: "arp")

 -s time: time to sleep between each arp request (miliseconds)

 -n node: last ip octet used for scanning (from 2 to 253)

 -c count: number of times to send each arp requests 

 -f enable fastmode scan, saves a lot of time, recommended for auto

 -d ignore home config files for autoscan and fast mode


As soon as you start netdiscover it starts sending arp requests over network and prints out the result if it finds any live host. You can specify range too. 

root@seven:~# netdiscover _____________________________________________________________________________ IP At MAC Address Count Len MAC Vendor / Hostname ----------------------------------------------------------------------------- 00:50:56:c0:00:08 1 60 VMware, Inc. 00:50:56:ec:30:74 1 60 VMware, Inc. 00:50:56:e2:92:e5 1 60 VMware, Inc.

Scan with range

In order to scan a specific range you must give -r option to netdiscover.Below command will scan for all the live hosts on a network. It scans for all the ip addresses(254) and only prints live hosts on screen.

root@seven:~# netdiscover -r

A quick scan

When you do autoscan it is always good idea to give -f option to it.It saves time.
root@seven:~# netdiscover -f


Popular posts from this blog

Difference Between POP3 and IMAP

Difference Between POP3 and IMAP POP3 and IMAP are the protocols that are used to retrieve mail from the mailbox at the mail server to the recipient’s computer. Both are message accessing agents (MAA). The two protocols POP3 and IMAP are used when both the sender and recipient of mail are connected to the mail server by WAN or LAN .  SMTP protocol transfers the mail from client’s computer to the mail server and from one mail server to another mail server.POP3 has a limited functionality whereas, the IMAP has extra features over POP3. The basic difference between POP3 and IMAP is that using POP3 ; the user has to download the email before checking its content whereas, the user can partially check the content of mail before downloading it, using IMAP . Let us check out some more differences between POP and IMAP with the help of comparison chart. Content: POP3 Vs IMAP Comparison Chart Definition Key Differences Conclusion Comparison Chart Basis for Comparison POP...

Find Identifying Information from a Phone Number Using OSINT Tools

Find Identifying Information from a Phone Number Using OSINT Tools Phone numbers often contain clues to the owner's identity and can bring up a lot of data during an OSINT investigation. Starting with a phone number, we can search through a large number of online databases with only a few clicks to discover information about a phone number. It can include the carrier, the owner's name and address, and even connected online accounts. While a phone number may not seem like much information to give out, an OSINT researcher can quickly discover information that ties a phone number to a variety of other clues. The data can be used to detect whether a phone number is a throwaway VoIP number used to hide the owner's identity or a cell phone belonging to a real person. In the event of buying something online or replying to an apartment ad,...

How to use hping3 in kali Linux(Performing dos attack)

How to use hping3 in kali Linux (Performing dos attack) What is hping3 hping3 is a network tool able to send custom TCP/IP packets and to dis‐ play target replies like ping program does with ICMP replies. hping3 handle fragmentation, arbitrary packets body and size and can be used in order to transfer files encapsulated under supported protocols. Hping3 is extremely powerful you can do following things with hping3 Test firewall rules Advanced port scanning Test net performance using different protocols, packet size, TOS (type of service) and fragmentation. Path MTU discovery Transferring files between even really fascist firewall rules. Traceroute-like under different protocols. Firewalk-like usage. What is dos Attack Dos stands for denial of service. Dos attack shuts down Webservers/systems and completely makes them inaccessible to users. Dos attack floods target network with excess ...