Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. Cyber Security
  3. Question
Cyber Security

How to bypass tcpwrapped with nmap scan?

Asked by Al German Sep 23, 2022 16.5K views 3 answers
Share

About this question

I ran a scan with

nmap -n -vv -A x.x.x.x --min-parallelism=50 --max-parallelism=150 -PN -T2 -oA x.x.x.x

With the following result:

Host is up (0.032s latency).
Scanned at 2012-10-25 16:06:38 AST for 856s
PORT      STATE SERVICE    VERSION
1/tcp     open  tcpwrapped
3/tcp     open  tcpwrapped
4/tcp     open  tcpwrapped
.
.
19/tcp    open  tcpwrapped
20/tcp    open  tcpwrapped
21/tcp    open  tcpwrapped
22/tcp    open  tcpwrapped
23/tcp    open  tcpwrapped
.
.
64623/tcp open  tcpwrapped
64680/tcp open  tcpwrapped
65000/tcp open  tcpwrapped
65129/tcp open  tcpwrapped
65389/tcp open  tcpwrapped
Scan methodology was

I'm sure that this is a firewall or load balancer's game. I tried many ways, such as changing source port, source IP, fragmentation, etc..

Do you have any idea/suggestion to bypass this case?

On another hand, do you know how to do that in a firewall policy (on any firewall)?

Your answer

3 Answers

Ranjana Admin JanBask Expert Latest answer

Answered on Jan 27, 2025

When performing an Nmap scan, encountering tcpwrapped means that the target system has refused the connection attempt, often due to security configurations or firewall rules. While there is no guaranteed way to bypass this, there are techniques to improve your chances of gathering more information.

Steps to Bypass tcpwrapped:

1. Use a Full Connect Scan:

A SYN scan (-sS) may trigger tcpwrapped if the target drops connections after a SYN-ACK. Using a TCP Connect scan forces a complete connection:

  nmap -sT 

2. Try Version Detection:

Adding version detection can sometimes reveal information about the service:

  nmap -sV 

3. Spoof Source IP or Port:

Some systems apply restrictions based on the source IP or port. Spoofing can help bypass this:

To scan from a common port (e.g., 80 or 443):

  nmap --source-port 443 

4. Fragment Packets:

Fragmenting packets can bypass basic firewalls:

  nmap -f 

5. Increase Stealth with Timing Options:

Use a slower scan to avoid detection or throttling:

  nmap -T2 

6. Use Alternate Scans:

Combine TCP with UDP scans to gather more data:

  nmap -sS -sU 

Important Notes:

  • Ethical Use: Ensure you have permission to scan the target. Unauthorized scanning may be illegal or violate policies.
  • tcpwrapped often indicates deliberate security measures, so bypassing it may still yield limited information.
  • Experiment with different scan types and flags based on the system's configuration.

With these techniques, you can increase the effectiveness of your Nmap scans while respecting ethical guidelines.

Was this helpful?

Ranjana Admin JanBask Expert

Answered on Apr 25, 2024

Attempting to bypass a TCP wrapped service using Nmap is not recommended and could potentially be illegal or unethical, as it may involve attempting to circumvent network security measures without proper authorization. TCP wrapping is a security feature that restricts access to network services based on IP address, hostname, or other criteria, and attempting to bypass it without proper authorization could lead to legal consequences.


If you have legitimate reasons to access a TCP wrapped service and believe that you have the necessary authorization to do so, it's best to contact the network administrator or owner of the system to request access. Engaging in unauthorized scanning or bypass attempts could result in severe penalties, including legal action and loss of reputation.

In any case, it's essential to adhere to ethical hacking guidelines and obtain proper authorization before attempting any security assessments or penetration tests on network systems. Unauthorized scanning or bypass attempts can cause disruption to network operations and compromise the security and privacy of systems and data.

Was this helpful?

More Cyber Security discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest Cyber Security Blogs

Guides, tips and career advice on Cyber Security from JanBask experts.