網路安全系列之二十九 NMAP的使用

來源:互聯網
上載者:User

標籤:style   blog   http   io   ar   os   使用   sp   strong   

Nmap是一款網路掃描和主機檢測的非常有用的工具,適用於Winodws和Linux系統,支援多種掃描技術。

NMAP主要是在Linux環境下使用,RHEL中預設並沒有安裝,在配置好yum源之後,安裝NMAP。

[[email protected] ~]# yum install nmap

NMAP文法:

nmap <掃描類型> <掃描參數> <IP地址與範圍>

操作示範:

(1)探測網路中的存活主機

nmap -sP 192.168.80.0/24

“-sP”選項表示以ping方式進行掃描,不做進一步測試(如連接埠掃描或者作業系統探測),非常適用於探測網路中的存活主機。

[[email protected] ~]# nmap -sP 192.168.80.0/24

Starting Nmap 4.11 ( http://www.insecure.org/nmap/ ) at 2014-10-21 13:29 CST

Host 192.168.80.1 appears to be up.

MAC Address: 00:50:56:C0:00:08 (VMWare)

Host 192.168.80.2 appears to be up.

MAC Address: 00:50:56:F6:C1:1A (VMWare)

Host 192.168.80.128 appears to be up.

MAC Address: 00:0C:29:3D:B0:4E (VMware)

Host 192.168.80.130 appears to be up.

Host 192.168.80.254 appears to be up.

MAC Address: 00:50:56:FB:E4:16 (VMWare)

Nmap finished: 256 IP addresses (5 hosts up) scanned in 9.069 seconds

(2)掃描某台特定主機

nmap –sS –O 192.168.80.128

“-sS”選項表示執行SYN掃描,-O選項,表示識別遠程作業系統。

[[email protected] ~]# nmap -sS -O 192.168.80.128

Starting Nmap 4.11 ( http://www.insecure.org/nmap/ ) at 2014-10-21 14:54 CST

Interesting ports on 192.168.80.128:

Not shown: 1674 closed ports

PORT STATE SERVICE

80/tcp open http

135/tcp open msrpc

139/tcp open netbios-ssn

445/tcp open microsoft-ds

1025/tcp open NFS-or-IIS

3389/tcp open ms-term-serv

MAC Address: 00:0C:29:3D:B0:4E (VMware)

Device type: general purpose

Running: Microsoft Windows 2003/.NET

OS details: Microsoft Windows 2003 Server SP1

Nmap finished: 1 IP address (1 host up) scanned in 5.384 seconds

(3)掃描開放指定連接埠的主機

隨意在公網中尋找一個位址區段,掃描哪些主機開放了3389連接埠。

nmap –sS –p 3389 –oG – 221.0.90.0/24 | grep open

“-p”選項指定連接埠,“-oG”選項表示以一種易於檢索的格式記錄資訊,即每台主機都以單獨的行來記錄所有資訊。

[[email protected] ~]# nmap -sS -p 3389 -oG - 221.0.90.0/24 | grep open

Host: 221.0.90.34 () Ports: 3389/open/tcp//ms-term-serv///

Host: 221.0.90.51 () Ports: 3389/open/tcp//ms-term-serv///

Host: 221.0.90.57 () Ports: 3389/open/tcp//ms-term-serv///

Host: 221.0.90.100 () Ports: 3389/open/tcp//ms-term-serv///

Host: 221.0.90.109 () Ports: 3389/open/tcp//ms-term-serv///

Host: 221.0.90.167 () Ports: 3389/open/tcp//ms-term-serv///

Host: 221.0.90.200 () Ports: 3389/open/tcp//ms-term-serv///

Host: 221.0.90.204 () Ports: 3389/open/tcp//ms-term-serv///

Host: 221.0.90.221 () Ports: 3389/open/tcp//ms-term-serv///

在nmap的掃描結果中,每個連接埠的狀態可能有:open、filtered、unfiltered。

  • open狀態意味著連接埠開放;

  • filtered狀態表示連接埠被防火牆或網路安全軟體掩蓋了,禁止nmap探測其是否開啟。

  • unfiltered表示連接埠關閉。

nmap的用法非常多,功能也很強大,這裡只是拋磚引玉。另外nmap在Windows中也可以使用,但功能感覺不如Linux中強大。

如在Windows中利用nmap掃描特定主機

650) this.width=650;" style="border-bottom:0px;border-left:0px;border-top:0px;border-right:0px;" title="clip_image002" border="0" alt="clip_image002" src="http://img1.51cto.com/attachment/201411/7/70821_1415345283bhyH.jpg" height="213" />

掃描結果

650) this.width=650;" style="border-bottom:0px;border-left:0px;border-top:0px;border-right:0px;" title="clip_image002[5]" border="0" alt="clip_image002[5]" src="http://img1.51cto.com/attachment/201411/7/70821_1415345286dbdm.jpg" height="387" />

本文出自 “一壺濁酒” 部落格,轉載請與作者聯絡!

網路安全系列之二十九 NMAP的使用

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.