简介
NMap,也就是Network Mapper,是Linux下的网络扫描和嗅探东西包。文中均已Linux下Nmap
5.21为主,其他版本雷同。
成果包罗:
一是探测一组主机是否在线;
二是扫描 主机端口,嗅探所提供的网络处事;
三是揣度主机所用的操纵系统 [separator]
2.参数说明
1. 名目:nmap [Scan Type(s)] [Options]
{target specification}
(1)-sL:我们可以称之为蛮力扫描,它将方针ip一个一个扫描已往,期待回应,东莞电信服务器
河南电信服务器,不推荐
(2)-sP:回收ping模式扫描网段,arp获取MAC地点,结果不大抱负
(3)-PS:探测指定方针开放的端口,在方针开防火墙环境结果欠好
(4)-sS:SYN扫描,即半开放扫描,不是一个完全的TCP链接,执行效率高,隐蔽性较好。
(5)-sU:指定方针UDP端口开放环境
(6)-O/-A:探测处事器操纵系统范例
3.操纵应用
(1)查察该网段存在的主机,参数-sP (Linux区分巨细写,这里P大写)
1. sudo nmap -sP 192.168.8.0/24
说明:192.168.8.0是一个网段,24是子网页码位数,c类,返回功效如下:
1. Nmap scan report for bogon
(192.168.8.1)
2. Host is up (0.0036s latency).
3. MAC Address: 00:1F:33:BA:9A:EE
(Netgear) # 网关
4. Nmap scan report for bogon
(192.168.8.3)
5. Host is up (0.0069s latency).
6. MAC Address: 78:E4:00:27:3D:38
(Unknown) # 未知,一台装win7
7. Nmap scan report for bogon
(192.168.8.6)
8. Host is up (0.0089s latency).
9. MAC Address: 00:0D:56:FB:13:12 (Dell Pcba
Test) # dell主机,win2k3处事器
10. Nmap scan report for xiaoc-Studio-1458
(192.168.8.8)
11. Host is up.
12. Nmap scan report for bogon (192.168.8.9)
13. Host is up (0.032s latency).
14. MAC Address: B4:82:FE:BC:55:DE
(Unknown) # 未知,一台装winxp
15. Nmap scan report for bogon (192.168.8.10)
16. Host is up (0.077s latency).
17. MAC Address: 00:0D:56:FA:E9:C0 (Dell Pcba Test) #
dell主机,我用ubuntu搭建的
18. Nmap done: 256 IP addresses (6 hosts up) scanned in
5.13 seconds
总共开放了6台主机。
(2)查察自身打初步口
1. sudo nmap -sTU localhost
返回功效如下:
1. rDNS record for 127.0.0.1:
localhost.localdomain
2. Not shown: 1989 closed ports
3.
PORT
STATE
SERVICE
4. 22/tcp
open
ssh
# ssh长途打点
5. 80/tcp
open
http
# nginx的web处事
6. 139/tcp
open
netbios-ssn # 局域网共享
7. 445/tcp
open
microsoft-ds # 与window共享
8. 631/tcp
open
ipp
9. 3306/tcp
open
mysql
# mysql处事
10. 9000/tcp
open
cslistener # fcgi处事
11. 68/udp open|filtered
dhcpc
12. 137/udp
open
netbios-ns
13. 138/udp open|filtered netbios-dgm
14. 5353/udp open|filtered zeroconf
本机开放端口列表与对应处事列表
(3) 探测指定方针开放端口
1. sudo nmap -PS 192.168.8.10
返回功效: