update tool nmap

This commit is contained in:
2025-11-21 17:23:10 +01:00
parent 4cad18c2a5
commit a6375dde69
2 changed files with 43 additions and 31 deletions
+22 -22
View File
@@ -13,12 +13,12 @@
"state": { "state": {
"type": "markdown", "type": "markdown",
"state": { "state": {
"file": "Proof.md", "file": "Linux/Shell.md",
"mode": "source", "mode": "source",
"source": false "source": false
}, },
"icon": "lucide-file", "icon": "lucide-file",
"title": "Proof" "title": "Shell"
} }
} }
] ]
@@ -94,7 +94,7 @@
"state": { "state": {
"type": "backlink", "type": "backlink",
"state": { "state": {
"file": "Proof.md", "file": "Linux/Shell.md",
"collapseAll": false, "collapseAll": false,
"extraContext": false, "extraContext": false,
"sortOrder": "alphabetical", "sortOrder": "alphabetical",
@@ -104,7 +104,7 @@
"unlinkedCollapsed": true "unlinkedCollapsed": true
}, },
"icon": "links-coming-in", "icon": "links-coming-in",
"title": "Backlinks for Proof" "title": "Backlinks for Shell"
} }
}, },
{ {
@@ -164,8 +164,25 @@
"webpage-html-export:Export Vault to HTML": false "webpage-html-export:Export Vault to HTML": false
} }
}, },
"active": "7cefa59e3501848a", "active": "04550972536d9a99",
"lastOpenFiles": [ "lastOpenFiles": [
"Linux/portscanning.md",
"Linux/Perm.md",
"Linux/LFI.md",
"Linux/Crontab.md",
"Linux/Cap.md",
"Linux/_etc_passwd.md",
"Linux/Tunnel/sshuttle.md",
"Linux/Tunnel/ssh.md",
"Linux/Tunnel/Socat.md",
"Linux/Tunnel/chisel.md",
"Software/php/LFI.md",
"Tools/nmap.md",
"Tools/autorecon.md",
"Proof.md",
"Labs.md",
"2024-10-28.md",
"20 EoP - Leveraging Windows Services.md",
"Windows/WWW.md", "Windows/WWW.md",
"Windows/SMB.md", "Windows/SMB.md",
"Windows/Scheduled Tasks.md", "Windows/Scheduled Tasks.md",
@@ -175,23 +192,6 @@
"Windows/Tunnel/ligolo.md", "Windows/Tunnel/ligolo.md",
"Windows/Tunnel/chisel.md", "Windows/Tunnel/chisel.md",
"Windows/SMB/crackmapexec.md", "Windows/SMB/crackmapexec.md",
"Windows/Services/Unquoted Service Paths.md",
"Windows/Services/DLL Hijacking.md",
"Windows/Services/Binary Hijacking.md",
"Windows/Privesc/Juicypotato.md",
"Windows/Information Gathering/Username and Hostname.md",
"Windows/Information Gathering/Network.md",
"Windows/Information Gathering/Locate files.md",
"Windows/Information Gathering/Installed Program.md",
"Windows/Information Gathering/History.md",
"Windows/CMD/Power_Reboot.md",
"Windows/CMD/Permission.md",
"Windows/CMD/File Transfer.md",
"Windows/CMD/Backup.md",
"Windows/Active Directory for OSCP/NTDS.dir cracking with SYSTEM.md",
"Windows/Active Directory for OSCP/Mimikatz.md",
"Windows/Active Directory for OSCP/Enumeration.md",
"Windows/Active Directory for OSCP/We have User Name but no Password/Password Spray.md",
"Windows/unnamed_b656515f39144863bbdaa2d5851c417c.png", "Windows/unnamed_b656515f39144863bbdaa2d5851c417c.png",
"MindMap/AD Mindmap/AD - OSCP.canvas", "MindMap/AD Mindmap/AD - OSCP.canvas",
"MindMap/WiFi/WiFi Mindmap.canvas", "MindMap/WiFi/WiFi Mindmap.canvas",
+21 -9
View File
@@ -1,46 +1,58 @@
``` ```bash
nmap -p- -T5 <ip> nmap -p- -T5 <ip>
nmap -p 22,25,80 -A <ip> nmap -p 22,25,80 -A <ip>
``` ```
``` ``` bash
nmap -p- --min-rate 5000 <ip> nmap -p- --min-rate 5000 <ip>
``` ```
``` ```bash
nmap -sn 192.168.102.0/24 -T4 -oN discovery.nmap nmap -sn 192.168.102.0/24 -T4 -oN discovery.nmap
nmap -iL output.txt -T4 -sV -sC -p- -Pn -n --open -A -oN version.nmap nmap -iL output.txt -T4 -sV -sC -p- -Pn -n --open -A -oN version.nmap
``` ```
``` ```bash
nmap -sU -p- --min-rate 5000 <ip> nmap -sU -p- --min-rate 5000 <ip>
``` ```
- Conduct a full UDP port scan (may be all `open|filtered`) because open ports rarely respond to empty probes. No response --> open port or dropped by firewall. - Conduct a full UDP port scan (may be all `open|filtered`) because open ports rarely respond to empty probes. No response --> open port or dropped by firewall.
``` ```bash
nmap -A -sV -sC -sU 10.11.1.111 --script=*enum --top-ports 20 nmap -A -sV -sC -sU 10.11.1.111 --script=*enum --top-ports 20
``` ```
- When version scanning is enabled with -sV (or -A), it will send UDP probes to every `open|filtered` port. If any of the probes elicit a response from an `open|filtered`port, the state is changed to open. - When version scanning is enabled with -sV (or -A), it will send UDP probes to every `open|filtered` port. If any of the probes elicit a response from an `open|filtered`port, the state is changed to open.
``` ```bash
nmap script=vuln 192.168.193.211 nmap script=vuln 192.168.193.211
``` ```
- Nmap scripts location `/usr/share/nmap/scripts/` - Nmap scripts location `/usr/share/nmap/scripts/`
``` ```bash
proxychains nmap --top-ports=20 -sT -Pn 10.5.5.20 proxychains nmap --top-ports=20 -sT -Pn 10.5.5.20
``` ```
- SOCKS proxies require a TCP connection to be made and thus a half-open or SYN scan cannot be used with ProxyChains - SOCKS proxies require a TCP connection to be made and thus a half-open or SYN scan cannot be used with ProxyChains
Scans thru Socks proxy ## Scans thru Socks proxy
``` ```bash
nmap --proxies socks4://proxy-ip:8080 target-ip nmap --proxies socks4://proxy-ip:8080 target-ip
```
## SYN-Scan of a Filtered Port
```bash
sudo nmap 10.129.2.28 -p50000 -sS -Pn -n --disable-arp-ping --packet-trace
```
## SYN-Scan From DNS Port
```bash
sudo nmap 10.129.2.28 -p50000 -sS -Pn -n --disable-arp-ping --packet-trace --source-port 53
``` ```