以下几个示例带领你快速了解nmap的基本扫描方法,更多详情请查阅nmap手册。
1、Nmap 简单扫描
$ nmap <target ip address>
$ nmap 192.168.41.41
直接指定需要扫描的主机IP开始扫描,返回详细描述。
2、Nmap 扫描并输出详细信息
$ nmap <target ip address> -vv
$ nmap 192.168.41.41 -vv
3、Nmap 指定端口范围扫描
$ nmap -p(range) <target IP>
# (rangge)为要扫描的端口(范围),端口大小不能超过65535
# nmap 192.168.41.41 -p1-50
Starting Nmap 7.80 ( https://nmap.org ) at 2021-01-26 16:37 CST
Nmap scan report for bogon (192.168.41.41)
Host is up (0.0038s latency).
Not shown: 46 closed ports
PORT STATE SERVICE
5/tcp filtered rje
21/tcp filtered ftp
23/tcp open telnet
27/tcp filtered nsw-fe
MAC Address: 00:11:22:33:44:41 (Cimsys)
Nmap done: 1 IP address (1 host up) scanned in 7.99 seconds
4、Nmap 指定端口扫描
$ nmap -p(port1,port2,port3,...) <target ip>
$ nmap -p23 192.168.41.41
Starting Nmap 7.80 ( https://nmap.org ) at 2021-01-26 16:44 CST
Nmap scan report for bogon (192.168.41.41)
Host is up (0.0083s latency).
PORT STATE SERVICE
23/tcp open telnet
MAC Address: 00:11:22:33:44:41 (Cimsys)
Nmap done: 1 IP address (1 host up) scanned in 0.04 seconds
5、Nmap Ping 扫描
$ nmap -sP <target ip>
$ nmap -sP 192.168.41.41
Starting Nmap 7.80 ( https://nmap.org ) at 2021-01-26 16:45 CST
Nmap scan report for bogon (192.168.41.41)
Host is up (0.0064s latency).
MAC Address: 00:11:22:33:44:41 (Cimsys)
Nmap done: 1 IP address (1 host up) scanned in 0.02 seconds
6、Nmap路由跟踪
$ nmap --traceroute <target ip>
$ nmap --traceroute 119.29.29.29
Starting Nmap 7.80 ( https://nmap.org ) at 2021-01-26 16:50 CST
Nmap scan report for pdns.dnspod.cn (119.29.29.29)
Host is up (0.019s latency).
Not shown: 998 filtered ports
PORT STATE SERVICE
53/tcp open domain
80/tcp open http
TRACEROUTE (using port 80/tcp)
HOP RTT ADDRESS
1 1.99 ms bogon (192.168.6.1)
2 2.71 ms bogon (192.168.169.9)
3 2.71 ms bogon (192.168.169.1)
4 19.82 ms hn.kd.ny.adsl (123.14.80.1)
5 4.74 ms hn.kd.ny.adsl (125.40.240.77)
6 6.17 ms pc93.zz.ha.cn (61.168.37.93)
7 ... 8
9 44.19 ms no-data (125.39.198.178)
10 ... 19
20 19.46 ms pdns.dnspod.cn (119.29.29.29)
Nmap done: 1 IP address (1 host up) scanned in 10.55 seconds
7 Nmap 扫描某网段IP
CodeBlock Loading...
8、Nmap 探测操作系统类别
CodeBlock Loading...
9、Nmap 万能扫描
此选项设置包含了1-10000的端口ping扫描,操作系统扫描,脚本扫描,路由跟踪,服务探测。 命令语法:
CodeBlock Loading...
10、Nmap 命令混合式扫描
CodeBlock Loading...
参考文献
- Nmap基础教程:https://wooyun.js.org/drops/NMAP%20%E5%9F%BA%E7%A1%80%E6%95%99%E7%A8%8B.html
- 利用 Nmap 实现快速的网络发现与管理:https://developer.ibm.com/zh/articles/os-cn-nmap/
- Nmap 中文手册 - Nmap 中文网:http://www.nmap.com.cn/doc/manual.shtm#4