A penetration tester is performing an internal assessment. They have compromised a Windows workstation and want to quickly identify other active hosts on the same local subnet. They need a command that leverages the Windows operating system's native capabilities for host discovery. Which command is most effective for this purpose?
- Aping -n 1 -w 100 <target_ip>
- Bfor /L %i in (1,1,254) do @ping -n 1 -w 100 192.168.1.%i | findstr "Reply from"
- Carp -a
- Dnmap -sn <target_subnet>
Show answer & explanationAnswer & explanation
Correct answer: B. for /L %i in (1,1,254) do @ping -n 1 -w 100 192.168.1.%i | findstr "Reply from"
The `for /L %i in (1,1,254) do @ping -n 1 -w 100 192.168.1.%i | findstr "Reply from"` command is a native Windows command-line technique for performing a ping sweep across a local subnet. It iterates through IP addresses (1-254 in the last octet) and pings each one, then filters the output to show only replies, effectively identifying active hosts.
Why the other options are wrong
- A. `ping -n 1 -w 100 <target_ip>` pings a single host, not an entire subnet.
- C. `arp -a` displays the local ARP cache, which only shows hosts the system has recently communicated with, not all active hosts on the subnet.
- D. Nmap is a third-party tool, not a native Windows capability, though it can be installed.
Windows Command Line Ping Sweep
A native Windows command-line technique to perform host discovery (a ping sweep) across a local subnet. It uses a `for` loop to iterate through a range of IP addresses, sending an ICMP echo request (ping) to each and filtering the output to identify active hosts.
- Uses `for /L` loop for iteration.
- Leverages `ping` command for ICMP echo requests.
- Filters output with `findstr` to show only replies.
- Native to Windows, no external tools required.
- Useful for quick host discovery on a local subnet.
Memory trick: The 'for' loop pings through the network, finding replies like treasure.