Penetration Testing A - Z: Vulnerability Security and Tools by V. Ayres Walter
Author:V. Ayres, Walter [V. Ayres, Walter]
Language: eng
Format: epub, pdf
Publisher: UNKNOWN
Published: 2020-10-18T16:00:00+00:00
Normally, we begin our Nmap port scans with a SYN stealth scan looking for selected ports and using OS identification option. By using the stealth scan feature and confining our scan to a few choice ports, we obtain valuable information while significantly improving the chances of remaining undetected. We begin by scanning for ports that support services that we know provide valuable information or that we may be able to exploit. We have
developed a list of some of these ports (seeTable 13-1 ). You should add and delete ports from this list based on what you find to be
successful and the type of systems you are targeting.
The syntax for this stealth scan can be confusing at first. Here is the command you could use to execute the SYN stealth scan we just described (remember, UNIX is case sensitive):
#nmap â sS â O â P0 â f â p 7,9,13,21,25,135-139,5800,etc. outputfile.txt 10.10.10.10-10.10.10.100
Table 13-1. Sample Ports to Scan
Port Service
7 Echo
9 Discard
13 Daytime
19 Character generator
21 FTP
22 SSH
23 telnet
25 SMTP
37 Time
42 Wins hostname server
53 DNS
69 TFTP
79 Finger
80 HTTP
110 POP
111 SUN RPC
135â139 NT services NetBIOS
143 IMAP
161â162 SNMP
256â258 Check Point Firewall
443 SSL
512â515 r services
2049 NFS
2301 Compaq
5800 VNC
5900 VNC
6000â6023 X Windows
12345 Netbus
32760â32785 RPC services
65301 pcAnywhere
There are several options included in this command.-sS specifies a SYN stealth scan.-O enables OS
identification.-P0 indicates that Nmap should not attempt to ping the target.-P0 is a very important option; if this option is not used, Nmap will attempt to ping the target, and if the target does not respond to ping, Nmap will not scan it.
Therefore, if you want to scan only hosts that respond to ping do not use-P0 , but be aware that you may miss hosts that have disabled or filtered ping. Using-P0 will enable you to scan hosts that do not
respond to ping. The scan will take longer since Nmap will attempt to scan the specified ports on every address even if the host is not active.-f indicates that the scan should be fragmented into small packets to help avoid detection.-p specifies the ports to be scanned. Follow the-p with your list of ports, as demonstrated in the example on page 232. Note that in our example we used âetcâ to signify that you could continue to add specific ports. If you do not specify the-p option Nmap will scan its default list of ports.-v indicates the verbose setting, which will display all output on the screen. We recommend using the verbose option so that you can examine the output as it is produced and catch problems early.-o allows you to specify an output file so that you can analyze the results later. Finally, enter the IP address range of the systems to be scanned. In our example, we are scanning
10.10.10.10 through 10.10.10.100. We could have easily added another range or individual hosts by adding a comma after each range or host.
Nmap offers some more advanced options that increase the functionality of the tool. Before we start
discussing these options and
providing examples, one word of warning. The decoy option,-D
Download
Penetration Testing A - Z: Vulnerability Security and Tools by V. Ayres Walter.pdf
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Personalized inhaled bacteriophage therapy for treatment of multidrug-resistant Pseudomonas aeruginosa in cystic fibrosis by unknow(180827)
CONSORT 2025 statement: updated guideline for reporting randomized trials by unknow(89283)
Critical evaluation of the ProfiLER-02 study design and outcomes by Vivek Subbiah & Razelle Kurzrock(88893)
Cardiac gene therapy makes a comeback by Oliver J. Müller & Susanne Hille & Anca Kliesow Remes(88648)
Whisky: Malt Whiskies of Scotland (Collins Little Books) by dominic roskrow(74451)
Unveiling the design rules for tunable emission in graphene quantum dots: A high-throughput TDDFT and machine learning perspective by Şener Özönder & Mustafa Coşkun Özdemir & Caner Ünlü(50904)
A yeast-based oral therapeutic delivers immune checkpoint inhibitors to reduce intestinal tumor burden by unknow(40273)
Covalent hitchhikers guide proteins to the nucleus by Alexander F. Russell & Madeline F. Currie & Champak Chatterjee(40219)
Meet the Authors: Christopher R. Mansfield and Emily R. Derbyshire by Christopher R. Mansfield & Emily R. Derbyshire(40103)
Alkaline-earth metals promote propane dehydrogenation with carbon dioxide through geometric effects: Altering the reaction pathway by unknow(32740)
Induced iron vacancies boosting FeOOH loaded on sustainable Fenton-like collagen fiber membrane for efficient removal of emerging contaminants by unknow(32521)
Efficient electric-field-assisted photochemical conversion of methane to n-propanol exclusively over penetrated TiO2Ti hollow fibers by Guanghui Feng(32460)
Bi2SiO5 nanosheets as piezo-photocatalyst for efficient degradation of 2,4-Dichlorophenol by Hangyu Shi & Yifu Li & Lishan Zhang & Guoguan Liu & Qian Zhang & Xuan Ru & Shan Zhong(32400)
A novel NDIPTA organic heterojunction photocatalyst with built-in electric field for efficient hydrogen production by Jiahui Yang & Baojun Ma & Yongfa Zhu(32370)
Enhanced conversion of methane to liquid-phase oxygenates via hollow ferrite nanotube@horseradish peroxidase based photoenzymatic catalysis by Jun Duan & Shiying Fan & Xinyong Li & Shaomin Liu(32337)
Ordered macroporous superstructure of defective carbon adorned with tiny cobalt sulfide for selective electrocatalytic hydrogenation of cinnamaldehyde by Xiao-Shi Yuan & Sheng-Hua Zhou & San-Mei Wang & Wenbo Wei & Xiaofang Li & Xin-Tao Wu & Qi-Long Zhu(32262)
What's Done in Darkness by Kayla Perrin(27155)
Topological analysis of non-conjugated ethylene oxide cored dendrimers decorated with tetraphenylethylene: Insights from degree-based descriptors using the polynomial approach by A Theertha Nair & D Antony Xavier & Annmaria Baby & S Akhila(26539)
Investigation of mechanical and self-healing properties of hydroxyl-terminated polybutadiene functionalized with 2-ureido-4-pyrimidinone by Mohsen Kazazi & Mehran Hayaty & Ali Mousaviazar(26467)