Syngress - Secrets of Network Cartography - Nmap Guide
基本信息
- 云盘路径:
/田浩然上传的资料/电子书/[安全盛典]Syngress安全丛书/Syngress - Secrets of Network Cartography - A Comprehensive Guide to Nmap - Complete.pdf - 文件大小: 1.5M
- 作者/机构: Nmap Guide
- 处理方式: pdf-inspector 文本提取
- 消化状态: 已完成
核心内容
CHAPTER 1: THE BASICS
r Internet Protocol r Transmission Control Protocol (TCP)
-
TCP Ports
-
The TCP Handshake r User Datagram Protocol (UDP)
-
UDP Ports
-
The Non-existent UDP Handshake r Internet Control Message Protocol (ICMP) r The Basics of nmap
-
The Nmap Scanning Process
-
Using nmap from the Command Line
-
Nmap Target Specifications
-
Privileged Access
-
Nmap Support Files
-
Locating the Support Files
-
Using the Support Files
-
nmap-mac-prefixes
-
nmap-os-fingerprints
-
nmap-protocols
-
nmap-rpc
-
nmap-service-probes
-
nmap-services
CHAPTER 2: NMAP SCANNING TECHNIQUES
r Nmap Scan Summary r TCP SYN Scan (-sS) r TCP connect() Scan (-sT) r Stealth Scanning – The FIN Scan (-sF), Xmas Tree Scan (-sX), and Null Scan (-sN)
-
The FIN Scan (-sF)
-
The Xmas Tree Scan (-sX)
-
The Null Scan (-sN)
-
Stealth Scanning Summary r Ping Scan (-sP) r Version Detection (-sV) r UDP Scan (-sU) r IP Protocol Scan (-sO) r ACK Scan (-sA) r Window Scan (-sW) r RPC Scan (-sR) r List Scan (-sL) r Idlescan (-sI <zombie host:[probeport]>)
-
How Idlescan REALLY Works
-
Idlescan Preparation
-
Deconstructing the Idlescan Process
-
Idlescan Summary r FTP Bounce Attack (-b)
-
FTP Bounce Attack Operation
-
FTP Bounce Attack Summary
CHAPTER 3: NMAP’S PING OPTIONS
r Ping Options
- ICMP Echo Request and TCP ACK Ping (-PB)
- ICMP Echo Request Ping (-PE)
- TCP ACK Ping ( -PA [portlist])
- TCP SYN Ping ( -PS [portlist])
- UDP Ping ( -PU [portlist])
- ICMP Timestamp Ping (-PP)
- ICMP Address Mask Ping (-PM)
- Don’t Ping Before Scanning (-P0)
- Require Reverse DNS (-R)
- Disable Reverse DNS (-n)
CHAPTER 4: OPERATING SYSTEM FINGERPRINTING
r Operating System Fingerprinting (-O) Operation
- The nmap-os-fingerprints Support File
- nmap-os-fingerprints: Fingerprint
- nmap-os-fingerprints: Class
- nmap-os-fingerprints: TSeq
- TSeq: The Class Attribute
- TSeq: The IPID Attribute
- TSeq: Timestamp Option Sequencing
- nmap-os-fingerprints: Test 1 (T1) through Test 7 (T7)
- The T1 to T7 Attributes
- nmap-os-fingerprints: The Port Unreachable Test (PU)
- The Operating System Fingerprinting Process
- Advantages of Operating System Fingerprinting
- Disadvantages of Operating System Fingerprinting
- When to use Operating System Fingerprinting r Limit Operating System Scanning (—osscan_limit) r More Guessing Flexibility (—osscan_guess, —fuzzy) r Additional, Advanced, and Aggressive (-A)
CHAPTER 5: HOST AND PORT OPTIONS
-
Exclude Targets (—exclude <host1 [,host2] [,host3]…>)
-
Exclude Targets in File (—excludefile <exclude_file>)
-
Read Targets from File (-iL
) -
Pick Random Numbers for Targets (-iR
) -
Randomize Hosts (—randomize_hosts, -rH)
-
No Random Ports (-r)
-
Source Port (—source_port or -g)
-
Specify Protocol or Port Numbers (-p
) -
Fast Scan Mode (-F)
-
Create Decoys (-D <decoy1 [,decoy2][,ME],…>)
-
The Danger of Decoy-Initiated SYN Floods
-
Source Address (-S<IP_address>)
-
Interface (-e
) -
CHAPTER 6: LOGGING OPTIONS
-
Normal Format (-oN
) -
XML Format (-oX
) -
Stylesheet (—stylesheet
) -
No Stylesheet (—no-stylesheet)
-
Grepable Format (-oG
) -
All Formats (-oA
) -
Script Kiddie Format (-oS
) -
HTML Format (-oH)
-
Resume Scan (—resume
) -
Append Output (—append_output)
-
CHAPTER 7: REAL-TIME INFORMATION OPTIONS
-
Verbose Mode (—verbose, -v)
-
Version Trace (—version_trace)
-
Packet Trace (—packet_trace)
-
Debug Mode (—debug, -d)
-
Interactive Mode (—interactive)
-
Noninteractive Mode (—noninteractive)
-
CHAPTER 8: TUNING AND TIMING OPTIONS
-
Nmap Packet Tuning
-
Time to Live (—ttl
) -
Use Fragmented IP Packets (-f, -ff)
-
Maximum Transmission Unit (—mtu
) -
Data Length (—data_length
) -
Nmap Timing Options
-
Host Timeout (—host_timeout
) -
Round Trip Time
-
Initial Round Trip Time Timeout (—initial_rtt_timeout)
-
Minimum Round Trip Time Timeout (—min_rtt_timeout)
-
Maximum Round Trip Time Timeout (—max_rtt_timeout)
-
Parallel Host Scanning
-
Maximum Parallel Hosts per Scan (—max_hostgroup)
-
Minimum Parallel Hosts per Scan (—min_hostgroup)
-
Parallel Port Scanning
-
Maximum Number of Parallel Scans (—max_parallelism)
-
Minimum Number of Parallel Scans (—min_parallelism)
-
Delay
-
Minimum Delay Between Probes (—scan_delay)
-
Maximum Delay Between Probes (—max_scan_delay)
-
Timing Policies (-T)
-
CHAPTER 9: WINDOWS-ONLY OPTIONS
-
Help for Windows (—win_help)
-
List All Network Interfaces (—win_list_interfaces)
-
Disable Raw Socket Support (—win_norawsock)
-
Try Raw Sockets Even on non-W2K Systems (—win_forcerawsock)
-
Disable WinPcap Support (—win_nopcap)
-
Test NT 4.0 Route Code (—win_nt4route)
-
Test Response to Lack of iphlpapi.dll (—win_noiphlpapi)
-
Trace Through Raw IP Initialization (—win_trace)
-
Skip Windows IP Initialization (—win_skip_winip_init)
-
CHAPTER 10: MISCELLANEOUS OPTIONS
-
Quick Reference Screen (—help, -h)
-
Nmap Version (—version, -V)
-
Data Directory (—datadir)
-
Quash Argument Vector (-q)
-
Define Custom Scan Flags (—scanflags[flagval])
-
(Uriel) Maimon Scan (-sM)
-
IPv6 Support (-6)
-
CHAPTER 11: USING NMAP IN THE “REAL WORLD”
-
Identifying the Remnants of a Virus Outbreak or Spyware Infestation
-
Vulnerability Assessments
-
Security Policy Compliance Testing
-
Asset Management
-
Firewall Auditing
-
Perpetual Network Auditing
Chapter 1: The Basics
To understand how nmap works, one must also understand the fundamentals of TCP/IP. Nmap uses TCP/IP protocols to query workstations and the responses are interpreted into useful security information. All of the wonderful information that nmap discovers is related to these intricate conversations between nmap and the remote devices.
All computers using the TCP/IP family of protocols follow standard processes when initiating network conversations. Ideally, these processes would be identical regardless of operating system, software version, or hardware manufacturer. In the networking world, however, not every system works exactly the same way. Although these minor differences would usually be considered problematic, nmap takes advantage of these anomalies to provide additional information about the remote system.
The TCP/IP protocols aren’t difficult to understand, but each protocol is unique and has its own set of rules and procedures. Once the basics of these protocols are understood, the fundamental operation of nmap becomes much easier to follow. If you’re new to networking, don’t skip this section!
Internet Protocol
For data to move across the Internet, each device must have an Internet Protocol (IP) address. At its
most basic level, IP is a truck-for-hire that carries data shipments across the roads of the network. IP doesn’t care what’s in the … (内容较长已截断) …