Nmap
In short: “Network Mapper” — a standard tool for scanning networks that can determine open ports, running services and sometimes even the operating system of a target system.
In more detail: Nmap sends packets specifically to one or more hosts and evaluates the responses to find out which ports are open, closed or filtered (e.g. by a firewall). System administrators use it to know their own attack surface (“which services are reachable from outside?”); pentesters use it in the reconnaissance phase of an authorised test. Scanning other people’s systems without permission is legally problematic.
In Depth
A simple Nmap scan and typical output:
$ nmap -sV 192.168.1.10
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9
80/tcp open http nginx 1.24.0
443/tcp open https nginx 1.24.0
3306/tcp filtered mysqlNmap supports various scanning techniques with different properties: a SYN scan (-sS, also a “half-open scan”) only sends a SYN packet and evaluates the response without fully establishing the connection — faster and less conspicuous than a complete three-way handshake. The -sV option additionally tries to determine a service’s exact software version via banner grabbing and behavioural analysis, and -O attempts operating system detection based on peculiarities in the TCP/IP stack.
From a defender’s point of view, a regular Nmap scan of your own systems is sensible practice: it shows objectively what attack surface a system actually offers from outside — administrators often find forgotten, unnecessarily open ports this way (e.g. a development service accidentally also reachable from outside) that would otherwise have gone unnoticed. From an attacker’s point of view, a port scan is usually the first step of a reconnaissance phase, before specifically looking for vulnerabilities in the services found.
Port states in detail
Nmap doesn’t just distinguish “open” and “closed”, but differentiates more precisely, which is important for troubleshooting in particular:
open - a service is actively listening on this port and answers
closed - the host is reachable, but no service is listening on this port
filtered - Nmap can't determine whether the port is open, because packets
are dropped by a firewall/packet filter (no response
instead of an active rejection)
unfiltered - the port is reachable, but Nmap can't determine whether it's
open or closed (rare, mostly with certain scanning techniques)
The difference between “closed” and “filtered” is equally revealing for attackers and defenders: a “closed” port reveals that the host is basically reachable and actively answers (it’s just that no service runs on this particular port) — a “filtered” port, on the other hand, points to an active firewall that silently drops packets without sending any response at all.
Reconnaissance as part of a larger attack sequence
A port scan is typically only the first step of multi-stage reconnaissance: after finding open ports, banner grabbing usually follows (determining the exact software version, see -sV), then matching the versions found against known vulnerability databases (e.g. the CVE database), before any concrete attack attempt takes place at all. Automated tools such as Shodan or Censys essentially carry out the same process continuously for the ENTIRE publicly reachable internet and make the results searchable — one reason why unpatched, unnecessarily open services today are often found and attacked automatically within hours to days of a new vulnerability becoming known.
Legal limits
Even a “harmless” port scan against someone else’s system without permission is, in Germany, in a legal grey area up to and including a criminal offence (depending on the exact circumstances and intent) — unlike merely calling up a public website, systematically scanning someone else’s infrastructure is no longer “normal” internet use. For legitimate security research, you therefore need, as with Hydra, the explicit permission of the system operator, in writing if in doubt.