Zmap Focus on host scanning, port scanning Namp features more, in the official site, we can find it all parameters Http://nmap.orgnmap use nmap+ scan type + Type OPTION + Destination address
-SL list Scan, do not send any requests, and then come out of the results do not have any effect, just listed
-SP sends pings to see if the host is alive, but some hosts ' firewalls make it impossible to ping or return some of the wrong data
-p0 no ping, even if there is no host to detect, the result is not generally slow, is very slow.
-ps can pass in a port after someone is 80
-N without domain name parsing,-r resolves the domain name for all targets,multiple scan modes can be specified at the same timeNmap-pe 103.20.87.1-255 using SYN ping scan
NMAP-PS80 103.20.87.1-255 is also a SYN ping scan specified on port 80, which hosts discovery on this network segment
NMAP-PR 103.20.87.1-255 A detailed scan of the local area network.
NMAP-PN IP does not use ping scan, more suitable for the internet
NMAP-SN parameters, scan only surviving hosts, do not scan for additional information
NMAP-PN-SN IP plus-sn parameter, detect the detection time is slow, longer, because to scan other information
Nmap-ss IP or IP segment nmap-st IP connection-oriented NMAP-SU IP is scanned for a non-connected nmap-su-p 80,445 IP designated port for faster reaction times
Nmap-st-v IP Boot Detail mode
Nmap-o Operating system detection Nmap--osscan-limit to set targets for operating system detection Nmap--osscan-guess;--fuzzy speculated on the results of operating system detection
Nmap-st-o IP Operating system version of his detection, scanning the comparison of all, but relatively slow, compared to the efficiency is relatively high nmap-st-p 3390-o--osscan-linit IP only the host opened 3390 for operating system detection
Nmap-sa-o IP ACK mode detection operating system, sweep out the results seem to have nothing to use
The Service program detects the scan port of the NMAP-SA-SV IP ACK mode, and can see all the scanning information
NMAP-ST-SV IP TCP scan namp-sv-p 22,ip detection for open 22 port service The speed of the open 22,445 port is relatively fast.
Some advanced usage nmap-e mac IP specify mac and IP address nmap--iflist view local Routing and interface information
NMAP-D specifies multiple IP addresses (fake) ME real IP (address decoy) NMAP-SV--spoof-mac mac (fake) virtual one plus IP address nmap-p1-25.80,512-515,2001,4001,6001,9001 etc. IP Segment Scan Cisco router nmap-su-p 69-nvv IP Scan route tftp protocol, upload something according to the vulnerability, carry out traffic hijacking nmap-o-f-n IP segment, fast scan (-f) nmap-ir 100000-ss-ps80-p 45-og Nmap. TXT random scan 45 port put to Nmap. TXT in nmap--script=brute IP violence hack reference drops.woyun.org/tips/2188 script explanation
Zmap uses ZMAP scans faster than Zmap Http:////zmap.io/github.com/zamp/zmap
Installation of Zmap
Use of Zmap
Zmap-b 20m-p 80-n 10000000-o result.txt-b identified bandwidth-p port number-n random 10 million IP address-O to result. TXT in zmap-b 20m-p 80-n 10000000-o result.txt-b. Etc/zmap/blacklist.conf Use blacklist
From for notes (Wiz)
The use of Nmap and Zmap