This repository provides a high-performance, containerized version of hping3, an advanced command-line oriented TCP/IP packet assembler and analyzer. This image is heavily optimized for Layer 4 (Transport Layer) stress testing, such as SYN floods, firewall benchmarking, and network stack limit testing.
When generating millions of packets per second, your own host machine's firewall will likely crash before the target does. To achieve maximum throughput on modern Linux hosts (like Ubuntu 24.04), you must bypass the kernel's Connection Tracking (conntrack) engine.
Run these commands on your physical host before launching the container:
# 1. Disable conntrack globally for outgoing and incoming test traffic
sudo iptables -t raw -A OUTPUT -j NOTRACK
sudo iptables -t raw -A PREROUTING -j NOTRACK
# 2. Increase the kernel's internal packet queue limit
sudo sysctl -w net.core.netdev_max_backlog=5000
To unleash the full speed of hping3, the Docker container must be granted raw network access and elevated file limits.
docker run -it --rm \
--privileged \
--net=host \
--ulimit nofile=65535:65535 \
--add-host target.example.local:192.168.1.52 \
jhasensio/hping3:latest \
-S -p 443 --flood --rand-source target.example.local
| Docker Flag | Purpose for Performance |
|---|---|
--privileged | Required. Grants the container kernel-level permission to craft raw TCP/IP frames. |
--net=host | Bypasses Docker's internal virtual bridge (NAT). Grants direct, zero-latency access to the host's NIC. |
--ulimit nofile=65535 | Prevents the container process from crashing due to "Too many open files" when generating massive socket loads. |
--add-host | Injects FQDN resolution directly into the container's /etc/hosts (useful for targeting specific virtual hosts by IP). |
Once your testing is complete, it is highly recommended to restore your host machine's stateful firewall to ensure standard security.
Run this on your Linux host:
#!/bin/bash
# Flush the raw table to re-enable connection tracking
sudo iptables -t raw -F
# Restore the packet backlog to default
sudo sysctl -w net.core.netdev_max_backlog=1000
echo "โ
Connection tracking re-enabled. Security state restored."
This tool is intended for professional, authorized security testing and network benchmarking only. Using this image to conduct Denial of Service (DoS) attacks against infrastructure you do not own or do not have explicit, written permission to test is illegal and strictly prohibited.
Content type
Image
Digest
sha256:9e5de3113โฆ
Size
28.7 MB
Last updated
7 months ago
docker pull jhasensio/hping3