What Is hping3? Packet Crafting Commands for Firewall Testing and Diagnostics

Explore the Hping3 tool in detail—an advanced TCP/IP packet crafter for firewall testing, port scanning, and network diagnostics. Learn its features, installation steps, commands, and use cases in ethical hacking.

Jun 18, 2025 - 10:56
Updated: 23 hours ago
112k
What Is hping3? Packet Crafting Commands for Firewall Testing and Diagnostics

Quick answer: hping3 is a free, command-line packet crafting tool for Linux. Unlike ping, which only sends ICMP, it can build TCP, UDP, ICMP and raw IP packets with any flags, ports and TTL you choose, and show how the target or a firewall responds. Network engineers use it to test firewall rules, trace paths and diagnose filtering. Use it only on networks you own or are authorised to test.

Key takeaways

  • hping3 crafts and sends individual packets and reads the replies. Nmap scans many hosts and ports at once. They complement each other.
  • Its best everyday use is diagnosing firewalls: is this port blocked, closed or open, and where is the packet being dropped?
  • It needs root privileges because it writes raw packets.
  • hping3 can also generate high volumes of traffic, which is a denial-of-service technique. That belongs only in an authorised lab test of your own infrastructure's resilience, never against a system you do not own. Unauthorised use is an offence under India's IT Act, 2000.

What is hping3?

hping3 is an open-source command-line tool that assembles TCP/IP packets from options you give it, sends them, and prints what comes back. The name comes from "ping" and the idea of a ping that works with more than ICMP.

A normal ping asks "are you alive?" using ICMP echo. Many firewalls block ICMP, so a host that is up can look dead. hping3 can ask the same question with a TCP SYN to port 443, which is usually allowed, and it tells you much more: whether the port is open, closed or filtered, what TTL the reply had, and how long the round trip took.

How does hping3 work?

It lets you set fields in the packet headers directly. The ones you will change most often are:

  • the protocol (TCP is the default; -2 for UDP, -1 for ICMP, -0 for raw IP),
  • destination port (-p) and source port (-s),
  • TCP flags: SYN (-S), ACK (-A), FIN (-F), RST (-R), PUSH (-P) and URG (-U),
  • TTL (-t), fragmentation, packet size and payload,
  • how many packets to send (-c) and how fast (-i).

Then it reads each reply and prints a line per packet. How the target answers is the diagnostic. For a TCP SYN probe, the common outcomes are:

ReplyMeaning
Flags SA (SYN and ACK)The port is open and a service accepted the connection attempt.
Flags RA (RST and ACK)The port is closed. The host is reachable, but nothing is listening.
No replyA firewall is probably dropping the packet, or the host is down.
ICMP "unreachable" messageA router or firewall actively rejected the traffic.

How do you install hping3?

On Debian, Ubuntu and Kali Linux:

sudo apt update
sudo apt install hping3

On Fedora or RHEL-family systems, hping3 may be in an extra repository, so check your distribution's package search. Run it with sudo, because crafting raw packets needs root. Kali Linux already includes it. Check the version with hping3 --version.

hping3 commands worth knowing

Run these against a lab VM or a machine you own. The addresses below are examples on a private lab network.

Check if a TCP port is reachable

sudo hping3 -S -p 80 -c 3 192.168.56.101

This sends three SYN packets to port 80. A typical open-port reply shows flags=SA. A closed port replies with flags=RA.

Tell a firewall drop from a closed port

Send the probe and compare. Open ports answer SA. Closed ports answer RA. Filtered ports stay silent. If a port you expected to be closed gives no answer at all, a firewall is dropping the packet before the host sees it, which is exactly the information a firewall audit needs.

Map firewall statefulness with ACK probes

sudo hping3 -A -p 80 -c 3 192.168.56.101

An ACK packet that arrives with no existing connection is unusual. A stateful firewall drops it. A simple packet filter lets it through, and the host replies with RST. The difference between the two outcomes shows whether your firewall tracks connection state or only filters by port.

Trace the path with TCP instead of ICMP

sudo hping3 --traceroute -V -S -p 443 your-own-server.example

This works like traceroute but uses TCP to port 443, so it follows the path real web traffic takes, even where ICMP is filtered along the way. The hop where replies stop is often where a rule drops the packet.

Measure latency to a specific service

sudo hping3 -S -p 443 -c 10 -i u200000 192.168.56.101

This sends ten SYN probes, one every 200 milliseconds, giving round-trip times to the actual service rather than just to the host.

What about flood mode and spoofing?

hping3 can send packets as fast as possible (--flood) and can set a false source address (--spoof). These exist because testing how a server or firewall copes under heavy traffic, and whether source-address filtering is configured, are legitimate parts of a resilience or configuration review. They are also, used against a system you do not control, a denial-of-service attack and address spoofing, both serious offences.

If your work requires this kind of testing, run it only inside an isolated lab against infrastructure you own, under a written test plan, ideally during a maintenance window with the team that owns the system aware in advance. This article does not provide a ready-to-run flood command, because the same syntax used against your own lab is indistinguishable from an attack used against someone else's server; look it up in hping3's own manual page once you have that authorisation in place, and review the rate limiting, SYN cookies and connection-table tuning on the system you are protecting.

hping3 vs Nmap

hping3Nmap
PurposeCraft and send individual, fully customised packetsDiscover hosts and scan many ports and services
Best forFirewall diagnosis, path tracing, protocol-level testingInventory, service and OS fingerprinting, vulnerability scripts
ScaleOne target, deep controlMany targets, broad coverage
Typical pairingUse after Nmap to dig into one surprising resultUse first to find what to investigate further

In practice, scan with Nmap first, then reach for hping3 when a result needs a closer, hand-crafted look. The Nmap reference guide covers scanning in depth.

Where to practise

Build a small lab: a hypervisor on your laptop, a Kali Linux VM, and a target VM such as Metasploitable, connected on a host-only network with no route to the internet or your home devices. Run the commands above against the target, then open Wireshark on the same network to see the exact packets hping3 built and the replies it received. Seeing the handshake and the flags in Wireshark is what turns the command output into real understanding.

Next steps

To go deeper into scanning and host discovery, see our guide on Nmap vs Zenmap vs Angry IP Scanner vs hping3. For structured, lab-based training in these techniques, see WebAsha's Certified Ethical Hacking CEH v13 AI course.

Related reading

Frequently Asked Questions

hping3 crafts and sends custom TCP, UDP, ICMP or raw IP packets so you can see exactly how a target or firewall responds. It is mainly used to test firewall rules, trace network paths and diagnose whether a port is open, closed or filtered.

Standard ping only sends ICMP echo requests, which many firewalls block. hping3 can send TCP or UDP packets with chosen flags and ports instead, so it keeps working and gives far more detail even when ICMP is filtered.

hping3 builds and sends individual, fully customised packets for deep, one-target diagnosis. Nmap scans many hosts and ports at once and can fingerprint services and operating systems. Many testers use Nmap first and hping3 to investigate one result further.

Using hping3 on your own systems or lab is legal. Using it, especially flood or spoofing modes, against systems you do not own or have no written permission to test is unauthorised access or a denial-of-service attack under India's IT Act, 2000.

On Debian, Ubuntu or Kali Linux run sudo apt install hping3. Kali Linux includes it by default. It needs root privileges to run because it crafts raw packets, so commands are run with sudo.

SYN starts a TCP connection attempt. Sending a packet with only the SYN flag set and reading the reply (SYN-ACK for open, RST-ACK for closed, or silence for filtered) is the standard way to probe a port's state.

Yes, on a single port or a small set at a time, by sending SYN packets and reading the flags in the reply. For scanning many ports or hosts quickly, a dedicated scanner such as Nmap is the better tool.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.