networking · intermediate · ~12 min · safe pentest lab
Probe one TCP port on localhost using the same pattern a sysadmin uses to check 'is my service up'.
A port checker interprets each connect() outcome. Implement the classifier:
int classify_probe(int rc, int err);
Return 0 (OPEN) when rc==0; 1 (CLOSED) for ECONNREFUSED; 2 (FILTERED) for ETIMEDOUT or EHOSTUNREACH; 3 (ERROR) for anything else.
The simplest 'is it alive?' check. Hard-coded to loopback so it's structurally incapable of misuse.
rc (0 = connected) and err (errno when rc != 0).
0/1/2/3 per the classification.
A successful connect is OPEN regardless of err. Only the listed errno values map to CLOSED/FILTERED.
#include <stddef.h>
/* Classify the outcome of a connect() probe from its return code and errno:
0 = OPEN (rc==0), 1 = CLOSED (ECONNREFUSED), 2 = FILTERED (ETIMEDOUT or
EHOSTUNREACH), 3 = ERROR (anything else). */
int classify_probe(int rc, int err){ (void)rc;(void)err; return 3; }
Leaking the fd. Treating every -1 as 'closed' instead of distinguishing ECONNREFUSED from real errors. Adding a host parameter (defeats the safety design).
Port 1 / port 65535 boundaries. A port that is open AND immediately closes the connection. Errno being clobbered by close() — save it first.
Solve this exercise in the browser editor — compile and run against the test harness, no setup required.