networking · intermediate · ~12 min · safe pentest lab

Classify a probe result

Probe one TCP port on localhost using the same pattern a sysadmin uses to check 'is my service up'.

Challenge

A port checker interprets each connect() outcome. Implement the classifier:

int classify_probe(int rc, int err);

Return 0 (OPEN) when rc==0; 1 (CLOSED) for ECONNREFUSED; 2 (FILTERED) for ETIMEDOUT or EHOSTUNREACH; 3 (ERROR) for anything else.

Why this matters

The simplest 'is it alive?' check. Hard-coded to loopback so it's structurally incapable of misuse.

Input format

rc (0 = connected) and err (errno when rc != 0).

Output format

0/1/2/3 per the classification.

Constraints

A successful connect is OPEN regardless of err. Only the listed errno values map to CLOSED/FILTERED.

Starter code

#include <stddef.h>
/* Classify the outcome of a connect() probe from its return code and errno:
   0 = OPEN (rc==0), 1 = CLOSED (ECONNREFUSED), 2 = FILTERED (ETIMEDOUT or
   EHOSTUNREACH), 3 = ERROR (anything else). */
int classify_probe(int rc, int err){ (void)rc;(void)err; return 3; }

Common mistakes

Leaking the fd. Treating every -1 as 'closed' instead of distinguishing ECONNREFUSED from real errors. Adding a host parameter (defeats the safety design).

Edge cases to handle

Port 1 / port 65535 boundaries. A port that is open AND immediately closes the connection. Errno being clobbered by close() — save it first.

Background lessons

Up next

Solve this exercise in the browser editor — compile and run against the test harness, no setup required.