What Is hping3? Packet Crafting Commands for Firewall Testing and Diagnostics
Explore the Hping3 tool in detail—an advanced TCP/IP packet crafter for firewall testing, port scanning, and network diagnostics. Learn its features, installation steps, commands, and use cases in ethical hacking.
Quick answer: hping3 is a free, command-line packet crafting tool for Linux. Unlike ping, which only sends ICMP, it can build TCP, UDP, ICMP and raw IP packets with any flags, ports and TTL you choose, and show how the target or a firewall responds. Network engineers use it to test firewall rules, trace paths and diagnose filtering. Use it only on networks you own or are authorised to test.
Key takeaways
- hping3 crafts and sends individual packets and reads the replies. Nmap scans many hosts and ports at once. They complement each other.
- Its best everyday use is diagnosing firewalls: is this port blocked, closed or open, and where is the packet being dropped?
- It needs root privileges because it writes raw packets.
- hping3 can also generate high volumes of traffic, which is a denial-of-service technique. That belongs only in an authorised lab test of your own infrastructure's resilience, never against a system you do not own. Unauthorised use is an offence under India's IT Act, 2000.
What is hping3?
hping3 is an open-source command-line tool that assembles TCP/IP packets from options you give it, sends them, and prints what comes back. The name comes from "ping" and the idea of a ping that works with more than ICMP.
A normal ping asks "are you alive?" using ICMP echo. Many firewalls block ICMP, so a host that is up can look dead. hping3 can ask the same question with a TCP SYN to port 443, which is usually allowed, and it tells you much more: whether the port is open, closed or filtered, what TTL the reply had, and how long the round trip took.
How does hping3 work?
It lets you set fields in the packet headers directly. The ones you will change most often are:
- the protocol (TCP is the default;
-2for UDP,-1for ICMP,-0for raw IP), - destination port (
-p) and source port (-s), - TCP flags: SYN (
-S), ACK (-A), FIN (-F), RST (-R), PUSH (-P) and URG (-U), - TTL (
-t), fragmentation, packet size and payload, - how many packets to send (
-c) and how fast (-i).
Then it reads each reply and prints a line per packet. How the target answers is the diagnostic. For a TCP SYN probe, the common outcomes are:
| Reply | Meaning |
|---|---|
| Flags SA (SYN and ACK) | The port is open and a service accepted the connection attempt. |
| Flags RA (RST and ACK) | The port is closed. The host is reachable, but nothing is listening. |
| No reply | A firewall is probably dropping the packet, or the host is down. |
| ICMP "unreachable" message | A router or firewall actively rejected the traffic. |
How do you install hping3?
On Debian, Ubuntu and Kali Linux:
sudo apt update
sudo apt install hping3
On Fedora or RHEL-family systems, hping3 may be in an extra repository, so check your distribution's package search. Run it with sudo, because crafting raw packets needs root. Kali Linux already includes it. Check the version with hping3 --version.
hping3 commands worth knowing
Run these against a lab VM or a machine you own. The addresses below are examples on a private lab network.
Check if a TCP port is reachable
sudo hping3 -S -p 80 -c 3 192.168.56.101
This sends three SYN packets to port 80. A typical open-port reply shows flags=SA. A closed port replies with flags=RA.
Tell a firewall drop from a closed port
Send the probe and compare. Open ports answer SA. Closed ports answer RA. Filtered ports stay silent. If a port you expected to be closed gives no answer at all, a firewall is dropping the packet before the host sees it, which is exactly the information a firewall audit needs.
Map firewall statefulness with ACK probes
sudo hping3 -A -p 80 -c 3 192.168.56.101
An ACK packet that arrives with no existing connection is unusual. A stateful firewall drops it. A simple packet filter lets it through, and the host replies with RST. The difference between the two outcomes shows whether your firewall tracks connection state or only filters by port.
Trace the path with TCP instead of ICMP
sudo hping3 --traceroute -V -S -p 443 your-own-server.example
This works like traceroute but uses TCP to port 443, so it follows the path real web traffic takes, even where ICMP is filtered along the way. The hop where replies stop is often where a rule drops the packet.
Measure latency to a specific service
sudo hping3 -S -p 443 -c 10 -i u200000 192.168.56.101
This sends ten SYN probes, one every 200 milliseconds, giving round-trip times to the actual service rather than just to the host.
What about flood mode and spoofing?
hping3 can send packets as fast as possible (--flood) and can set a false source address (--spoof). These exist because testing how a server or firewall copes under heavy traffic, and whether source-address filtering is configured, are legitimate parts of a resilience or configuration review. They are also, used against a system you do not control, a denial-of-service attack and address spoofing, both serious offences.
If your work requires this kind of testing, run it only inside an isolated lab against infrastructure you own, under a written test plan, ideally during a maintenance window with the team that owns the system aware in advance. This article does not provide a ready-to-run flood command, because the same syntax used against your own lab is indistinguishable from an attack used against someone else's server; look it up in hping3's own manual page once you have that authorisation in place, and review the rate limiting, SYN cookies and connection-table tuning on the system you are protecting.
hping3 vs Nmap
| hping3 | Nmap | |
|---|---|---|
| Purpose | Craft and send individual, fully customised packets | Discover hosts and scan many ports and services |
| Best for | Firewall diagnosis, path tracing, protocol-level testing | Inventory, service and OS fingerprinting, vulnerability scripts |
| Scale | One target, deep control | Many targets, broad coverage |
| Typical pairing | Use after Nmap to dig into one surprising result | Use first to find what to investigate further |
In practice, scan with Nmap first, then reach for hping3 when a result needs a closer, hand-crafted look. The Nmap reference guide covers scanning in depth.
Where to practise
Build a small lab: a hypervisor on your laptop, a Kali Linux VM, and a target VM such as Metasploitable, connected on a host-only network with no route to the internet or your home devices. Run the commands above against the target, then open Wireshark on the same network to see the exact packets hping3 built and the replies it received. Seeing the handshake and the flags in Wireshark is what turns the command output into real understanding.
Next steps
To go deeper into scanning and host discovery, see our guide on Nmap vs Zenmap vs Angry IP Scanner vs hping3. For structured, lab-based training in these techniques, see WebAsha's Certified Ethical Hacking CEH v13 AI course.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0