EG Information

Main Index
EG Manual
Disclaimer
Legal Information
Hall of Fame
Hall of Shame
Member Rankings
Members List
Meet the Staff
Hacker's Home Page

Training Missions

Read Me First
Basic Skills
Realistic Scenarios
Cryptography
Software Cracking
Linux ELF Binary Cracking
Logical Thinking
Programming
Captcha Cracking
Patching
Steganography
Deface This Wall
/dev/null
/dev/urandom
/dev/extra

Knowledge Bank

Discussion Forums
Exploit Database New
PasteBin New
RSS Feeds RSS
Articles / Tutorials
Videos
Online EG MP3 Player Radio
Downloads
Tools

Code Resources

Submit Code
Ajax
ASM
Bash
C
CPP
Csharp
Delphi
Haskell
Java
Javascript
Jython
Lisp
mIRC
MySQL
Perl
PHP
Python
QBASIC
VisualBasic

Pimp Us Out!

Review enigmagroup.org on alexa.com

Has Enigma Group Helped You? Then Help Us By Advertising For Us. Place One Of The Following Images On Your Site And Create A Link Back To Enigma Group.

Enigma Group

Enigma Group

Enigma Group

Enigma Group

 

Affiliates

hackhound.org

suck-o.com

hack.org.za

flyninja.net

 

Enigma Group's Articles



Return to Category Selection

Basics of Nmap - Submitted By: ishkur88 2008-08-19 11:57:49
(this article is going to deal with the console version of Nmap)

As you may or may not know, Nmap is one of, if not the best tool available for network scanning (along with Nessus.) Nmap can be used to uncover a lot of information about a remote host, and that in turn may open the door to bigger and better things.

First off, you're going to need a copy of the program. You can get that at the Official website (http://insecure.org), or if you are running Linux, you can install via the command line. For Debian based distros the string is "sudo apt-get install nmap".

Once you have the app installed and looking alright, you can begin trying it out. For a basic test run, just scan a host. You can easily do that by just running "nmap enigmagroup.org". That should take a few minutes, and you'll get a list of "interesting ports".


Next, a slightly more "advanced" string would be to scan multiple hosts at random. To do that, you need to open nmap and enter "nmap -v -iR 1 -P0 -p 80"

here's the output of that command:
--------------------
ishkur@linuxbox:~$ nmap -v -iR 1 -P0 -p 80

Starting Nmap 4.20 ( http://insecure.org ) at 2007-08-03 21:21 EDT
Initiating Parallel DNS resolution of 1 host. at 21:21
Completed Parallel DNS resolution of 1 host. at 21:21, 1.26s elapsed
Initiating Connect() Scan at 21:21
Scanning 87.255.246.128 [1 port]
Completed Connect() Scan at 21:21, 12.01s elapsed (1 total ports)
Host 87.255.246.128 appears to be up ... good.
Interesting ports on 87.255.246.128:
PORT   STATE    SERVICE
80/tcp filtered http

Nmap finishead: 1 IP address (1 host up) scanned in 13.271 seconds
ishkur@linuxbox:~$
--------------------

A little explanation is in order. The First command there (-v) just makes it a more intense scan, more packets being sent. Secondly, (-iR) tells it to scan random hosts, then the number right after it tells it how many to scan. The next bit (-P0) tell it to just skip host discovery. Last but not least, the (-p 80) part should be self explanatory... but basically that just defines what port to scan.

And for a little bit more advanced string.
"sudo nmap -v -f 205.217.153.53 -e eth1 -P0 -S RND -p 80 "

What that string does:

1.) runs the app as root, a key to the more tricky functions
2.) sends more packets with the -v command.
3.) fragments the packets and makes it harder for the host to figure out what's going on.
4.) targets the host (in this case, insecure.org)
5.) specifies what interface to send out of (eth1 for me)
6.) tells it to skip host discovery
7.) spoofs the source with a Random (RND) source,
8.) and finally tells it what port to look for.

here's the output of that:
---------------------
ishkur@linuxbox:~$ sudo nmap -v -f 205.217.153.53 -e eth1 -P0 -S RND -p 80

Starting Nmap 4.20 ( http://insecure.org ) at 2007-08-03 22:12 EDT
Initiating Parallel DNS resolution of 1 host. at 22:12
Completed Parallel DNS resolution of 1 host. at 22:12, 0.07s elapsed
Initiating SYN Stealth Scan at 22:12
Scanning www.insecure.org (205.217.153.53) [1 port]
Completed SYN Stealth Scan at 22:12, 2.02s elapsed (1 total ports)
Host www.insecure.org (205.217.153.53) appears to be up ... good.
Interesting ports on www.insecure.org (205.217.153.53):
PORT   STATE    SERVICE
80/tcp filtered http

Nmap finished: 1 IP address (1 host up) scanned in 2.182 seconds
               Raw packets sent: 6 (168B) | Rcvd: 0 (0B)
ishkur@linuxbox:~$
--------------------

Well, hope I didn't make too many mistakes, and hope you peoples make good use of Nmap

Return to Category Selection
Comment By: droopysnowmen 2011-03-10 13:58:31
According to the nmap man page, the v switch alters the verbosity level, having nothing to do with theammount of packets being sent.

If you wish to submit a comment, you must be a registered member and logged in.

Login or Register.



Return to Category Selection

 

Who Visited EnigmaGroup Today?

1396 Guests, 222 Users (217 Spiders)
junaid_junaid59, famous0123, Molinaro, JohnJohnJohn, tgm001, ssmaslov, Galagatron, psychomarine, Dregoon, cat1vo, plex, Patrickk, mjneat, Aska, Beat_Slayer, M0rdak, Ausome1, dark_void, Imre, TheCheeseDemon, rockcraft, Vreality2007, mmndglxuwn, m0rt, unholyblood, iterrumzz, VurbTrurb, CJ_Omaha, Mayonoula, MAMWOURBROR, mutabor, gobinda, cossyDrybrich, Razin, zaCruBumas8, hunja, johny34, pantoufle, bagy, arctica, hackarchives, UsedDeteKef, Peculator, Fadhilat606, TheTrueMonarch, Pascall01, hackaday, Tjm, arndevil, flairvelocity, lol, alphbond, kdivanov, elizbethallis6, Rik, bn11, BorgBot, SHASHANK101hello, 4poc4lyptic, ksajxai, nbmorri1, electro-technic, saraf, شمالي عرعر, lamb, AutobotPrime, Underleaf, The End, tomtombomb, killobyte, snowgirlx, so_saucey, zerolife, Althor, Cramps, Hekser, Hyperborn, cyber-guard, jhgrunn, cobra, Partisan, MAZI_, cyborg, GenbreedX, moel77, cliptoX, pwnpwnlolz, letshavepie, Mrwormz, yshiau, mirmo, roozyoppomo, soft_devil, cls777, scoobywan, Reiversed, joshua, st3alth, Afrika, PaiffDryday, venter, Anthony12796, sh3llcod3, 8FIGURE, Rannim, Evil1, maloaboy, BACanON, SlayingDragons, Repuhlsive, IvanDimitriev, lolzsec, 1RiB, mzungudo, Micro_Geek, iMaxx, aciboummamymn, k0unterkulcher, somebody777, m14m16, GoododotAlcob, negasora, Rastii, UninueMem, Swifsolja, ad.conquest, ngolatkar, Infinity8, Jigoku, thesupervisor, p0is0n5ting, kernel_mod, AKL, GothicLogic, themastersinner, dnatrixene135, ChewBigRed, kalak55, sejem, cve916, pollolololo, triecturn, Violatedsmurf, Ops, jmp, xsiemich, generalisimo, strudels, ga3ttpom, KingOfBritains, epoch_qwert, suten, FriskyKat, Ryuske, Adonis Achilles, ubqbcdzzhf, 3vil, Nightraven, US£RNAM£, Weindittewcon, Batesheelocot, GSmyrlis, MaxMeier, Elite.America, rabbidmind, Psiber_Syn, phoenix22, imittyerrotte, peewster, cyberturtle, ctb, dexgeda, sdw, Pizza, White_widdow, devarian, finesse, Nature112091777, Danc7171, Alphadragon, Estadagause, 53QR10U5, Xargos, Alkomage, hardlock, Barry Gonzoles, MineDweller, Gkjt, N4g4c3N, [I]nfectedbug, wimsteege, aqr5zdcw, xin214, Bugshuppy, SnoopSky, Hessesian, voodooKobra, sKcarr, IROverRated, W1F1G3NJU75U, Baddy, ziadmosaan, gamble86, realzs, CruelDemon, Shinju, aVoid, aquiredanonymity, kukumumu, web_request, callmeneon, KissMyDAFFODIL, Feld Grau, Abhinav2107, prabhataditya, mbuyiselo, shumer, phenom216, princennamdi, huskyboiza, ninety-nine, lucca65
 
Enigma Group