How To Install Nmap
Basic Nmap Scan
Scanning a single ip address:
- Scan an ip address:# nmap 192.168.100.1
Nmap Commands To Discover Your LAN
If you want to make a simple scan you can try scanning your LAN.
- Typeifconfigas root to know the broadcast ip address.
- Search the Bcast ip in the active interface, for example, wlan0
4. Make an nmap scan to the LAN:
Scanning multiple IP addresses With Nmap
- # nmap ip1 ip2 ip3
Working with Functional Options
- Detecting the OS
You must use the “A” option to detect the target’s operating system:
You must use the “sA” option to detect the target’s firewall:
You must make a ping scan with the “sP” option:
If you want a fast scan you can use the “F” option:
Use the “iflist” option:
Nmap Commands To Scan Ports
An application is actively accepting TCP connections, UDP datagrams or SCTP associations on this port.
A closed port is accessible (it receives and responds to Nmap probe packets), but there is no application listening on it.
Nmap cannot determine whether the port is open because packet filtering prevents its probes from reaching the port.
The unfiltered state means that a port is accessible, but Nmap is unable to determine whether it is open or closed.
5. open | filtered:
Nmap places ports in this state when it is unable to determine whether a port is open or filtered.
6. closed | filtered
This state is used when Nmap is unable to determine whether a port is closed or filtered. It is only used for the IP ID idle scan.
Port Scanning Techniques
-sS (TCP SYN scan)
It can be performed quickly, scanning thousands of ports per second on a fast network not hampered by restrictive firewalls. It is also relatively unobtrusive and stealthy since it never completes TCP connections.
-sT (TCP connect scan)
TCP connect scan is the default TCP scan type when SYN scan is not an option. This is the case when a user does not have raw packet privileges.
-sU (UDP scans)
While most popular services on the Internet run over the TCP protocol, UDP services are widely deployed. Because UDP scanning is generally slower and more difficult than TCP, some security auditors ignore these ports.
-sY (SCTP INIT scan)
SCTP is a relatively new alternative to the TCP and UDP protocols, combining most characteristics of TCP and UDP, and also adding new features like multi-homing and multi-streaming. It is mostly being used for SS7/SIGTRAN related services but has the potential to be used for other applications as well.
-sN, -sF, -sX (TCP NULL, FIN, and Xmas scans)
These three scan types exploit a subtle loophole in the TCP RFC to differentiate between open and closed ports.
-sA (TCP ACK scan)
It is used to map out firewall rulesets, determining whether they are stateful or not and which ports are filtered.
-sW (TCP Window scan)
Window scan is exactly the same as ACK scan except that it exploits an implementation detail of certain systems to differentiate open ports from closed ones, rather than always printing unfiltered when a RST is returned.
-sM (TCP Maimon scan)
This technique is exactly the same as NULL, FIN, and Xmas scans, except that the probe is FIN/ACK.
–scanflags (Custom TCP scan)
The –scanflags option allows you to design your own scan by specifying arbitrary TCP flags.
-sI <zombie host>[:<probeport>] (idle scan)
This advanced scan method allows for a truly blind TCP port scan of the target (meaning no packets are sent to the target from your real IP address).
-sO (IP protocol scan)
IP protocol scan allows you to determine which IP protocols (TCP, ICMP, IGMP, etc.) are supported by target machines.
- Open Zenmap as root
- Enter the target
- Choose a profile, also you can type the scan in the command field or create a new profile
- Click “Scan”
- With Zenmap you can see the ports, host details, and topology of the scan
- Also, you can save your scan as xml