update tool nmap
This commit is contained in:
Vendored
+22
-22
@@ -13,12 +13,12 @@
|
|||||||
"state": {
|
"state": {
|
||||||
"type": "markdown",
|
"type": "markdown",
|
||||||
"state": {
|
"state": {
|
||||||
"file": "Proof.md",
|
"file": "Linux/Shell.md",
|
||||||
"mode": "source",
|
"mode": "source",
|
||||||
"source": false
|
"source": false
|
||||||
},
|
},
|
||||||
"icon": "lucide-file",
|
"icon": "lucide-file",
|
||||||
"title": "Proof"
|
"title": "Shell"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
@@ -94,7 +94,7 @@
|
|||||||
"state": {
|
"state": {
|
||||||
"type": "backlink",
|
"type": "backlink",
|
||||||
"state": {
|
"state": {
|
||||||
"file": "Proof.md",
|
"file": "Linux/Shell.md",
|
||||||
"collapseAll": false,
|
"collapseAll": false,
|
||||||
"extraContext": false,
|
"extraContext": false,
|
||||||
"sortOrder": "alphabetical",
|
"sortOrder": "alphabetical",
|
||||||
@@ -104,7 +104,7 @@
|
|||||||
"unlinkedCollapsed": true
|
"unlinkedCollapsed": true
|
||||||
},
|
},
|
||||||
"icon": "links-coming-in",
|
"icon": "links-coming-in",
|
||||||
"title": "Backlinks for Proof"
|
"title": "Backlinks for Shell"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -164,8 +164,25 @@
|
|||||||
"webpage-html-export:Export Vault to HTML": false
|
"webpage-html-export:Export Vault to HTML": false
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"active": "7cefa59e3501848a",
|
"active": "04550972536d9a99",
|
||||||
"lastOpenFiles": [
|
"lastOpenFiles": [
|
||||||
|
"Linux/portscanning.md",
|
||||||
|
"Linux/Perm.md",
|
||||||
|
"Linux/LFI.md",
|
||||||
|
"Linux/Crontab.md",
|
||||||
|
"Linux/Cap.md",
|
||||||
|
"Linux/_etc_passwd.md",
|
||||||
|
"Linux/Tunnel/sshuttle.md",
|
||||||
|
"Linux/Tunnel/ssh.md",
|
||||||
|
"Linux/Tunnel/Socat.md",
|
||||||
|
"Linux/Tunnel/chisel.md",
|
||||||
|
"Software/php/LFI.md",
|
||||||
|
"Tools/nmap.md",
|
||||||
|
"Tools/autorecon.md",
|
||||||
|
"Proof.md",
|
||||||
|
"Labs.md",
|
||||||
|
"2024-10-28.md",
|
||||||
|
"20 EoP - Leveraging Windows Services.md",
|
||||||
"Windows/WWW.md",
|
"Windows/WWW.md",
|
||||||
"Windows/SMB.md",
|
"Windows/SMB.md",
|
||||||
"Windows/Scheduled Tasks.md",
|
"Windows/Scheduled Tasks.md",
|
||||||
@@ -175,23 +192,6 @@
|
|||||||
"Windows/Tunnel/ligolo.md",
|
"Windows/Tunnel/ligolo.md",
|
||||||
"Windows/Tunnel/chisel.md",
|
"Windows/Tunnel/chisel.md",
|
||||||
"Windows/SMB/crackmapexec.md",
|
"Windows/SMB/crackmapexec.md",
|
||||||
"Windows/Services/Unquoted Service Paths.md",
|
|
||||||
"Windows/Services/DLL Hijacking.md",
|
|
||||||
"Windows/Services/Binary Hijacking.md",
|
|
||||||
"Windows/Privesc/Juicypotato.md",
|
|
||||||
"Windows/Information Gathering/Username and Hostname.md",
|
|
||||||
"Windows/Information Gathering/Network.md",
|
|
||||||
"Windows/Information Gathering/Locate files.md",
|
|
||||||
"Windows/Information Gathering/Installed Program.md",
|
|
||||||
"Windows/Information Gathering/History.md",
|
|
||||||
"Windows/CMD/Power_Reboot.md",
|
|
||||||
"Windows/CMD/Permission.md",
|
|
||||||
"Windows/CMD/File Transfer.md",
|
|
||||||
"Windows/CMD/Backup.md",
|
|
||||||
"Windows/Active Directory for OSCP/NTDS.dir cracking with SYSTEM.md",
|
|
||||||
"Windows/Active Directory for OSCP/Mimikatz.md",
|
|
||||||
"Windows/Active Directory for OSCP/Enumeration.md",
|
|
||||||
"Windows/Active Directory for OSCP/We have User Name but no Password/Password Spray.md",
|
|
||||||
"Windows/unnamed_b656515f39144863bbdaa2d5851c417c.png",
|
"Windows/unnamed_b656515f39144863bbdaa2d5851c417c.png",
|
||||||
"MindMap/AD Mindmap/AD - OSCP.canvas",
|
"MindMap/AD Mindmap/AD - OSCP.canvas",
|
||||||
"MindMap/WiFi/WiFi Mindmap.canvas",
|
"MindMap/WiFi/WiFi Mindmap.canvas",
|
||||||
|
|||||||
+21
-9
@@ -1,46 +1,58 @@
|
|||||||
```
|
```bash
|
||||||
nmap -p- -T5 <ip>
|
nmap -p- -T5 <ip>
|
||||||
nmap -p 22,25,80 -A <ip>
|
nmap -p 22,25,80 -A <ip>
|
||||||
```
|
```
|
||||||
|
|
||||||
```
|
``` bash
|
||||||
nmap -p- --min-rate 5000 <ip>
|
nmap -p- --min-rate 5000 <ip>
|
||||||
```
|
```
|
||||||
|
|
||||||
```
|
```bash
|
||||||
nmap -sn 192.168.102.0/24 -T4 -oN discovery.nmap
|
nmap -sn 192.168.102.0/24 -T4 -oN discovery.nmap
|
||||||
nmap -iL output.txt -T4 -sV -sC -p- -Pn -n --open -A -oN version.nmap
|
nmap -iL output.txt -T4 -sV -sC -p- -Pn -n --open -A -oN version.nmap
|
||||||
```
|
```
|
||||||
|
|
||||||
```
|
```bash
|
||||||
nmap -sU -p- --min-rate 5000 <ip>
|
nmap -sU -p- --min-rate 5000 <ip>
|
||||||
```
|
```
|
||||||
|
|
||||||
- Conduct a full UDP port scan (may be all `open|filtered`) because open ports rarely respond to empty probes. No response --> open port or dropped by firewall.
|
- Conduct a full UDP port scan (may be all `open|filtered`) because open ports rarely respond to empty probes. No response --> open port or dropped by firewall.
|
||||||
|
|
||||||
|
|
||||||
```
|
```bash
|
||||||
nmap -A -sV -sC -sU 10.11.1.111 --script=*enum --top-ports 20
|
nmap -A -sV -sC -sU 10.11.1.111 --script=*enum --top-ports 20
|
||||||
```
|
```
|
||||||
|
|
||||||
- When version scanning is enabled with -sV (or -A), it will send UDP probes to every `open|filtered` port. If any of the probes elicit a response from an `open|filtered`port, the state is changed to open.
|
- When version scanning is enabled with -sV (or -A), it will send UDP probes to every `open|filtered` port. If any of the probes elicit a response from an `open|filtered`port, the state is changed to open.
|
||||||
|
|
||||||
|
|
||||||
```
|
```bash
|
||||||
nmap script=vuln 192.168.193.211
|
nmap script=vuln 192.168.193.211
|
||||||
```
|
```
|
||||||
|
|
||||||
- Nmap scripts location `/usr/share/nmap/scripts/`
|
- Nmap scripts location `/usr/share/nmap/scripts/`
|
||||||
|
|
||||||
```
|
```bash
|
||||||
proxychains nmap --top-ports=20 -sT -Pn 10.5.5.20
|
proxychains nmap --top-ports=20 -sT -Pn 10.5.5.20
|
||||||
```
|
```
|
||||||
|
|
||||||
- SOCKS proxies require a TCP connection to be made and thus a half-open or SYN scan cannot be used with ProxyChains
|
- SOCKS proxies require a TCP connection to be made and thus a half-open or SYN scan cannot be used with ProxyChains
|
||||||
|
|
||||||
|
|
||||||
Scans thru Socks proxy
|
## Scans thru Socks proxy
|
||||||
|
|
||||||
```
|
```bash
|
||||||
nmap --proxies socks4://proxy-ip:8080 target-ip
|
nmap --proxies socks4://proxy-ip:8080 target-ip
|
||||||
|
```
|
||||||
|
|
||||||
|
## SYN-Scan of a Filtered Port
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo nmap 10.129.2.28 -p50000 -sS -Pn -n --disable-arp-ping --packet-trace
|
||||||
|
```
|
||||||
|
|
||||||
|
## SYN-Scan From DNS Port
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo nmap 10.129.2.28 -p50000 -sS -Pn -n --disable-arp-ping --packet-trace --source-port 53
|
||||||
```
|
```
|
||||||
Reference in New Issue
Block a user