Advanced network scanning with Nmap 6
Henri Doreau henri.doreau@gmail.com 13th LSM - Geneva 2012
Advanced network scanning with Nmap 6 Henri Doreau - - PowerPoint PPT Presentation
Advanced network scanning with Nmap 6 Henri Doreau henri.doreau@gmail.com 13 th LSM - Geneva 2012 Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion Outline Project presentation 1 Introduction
Henri Doreau henri.doreau@gmail.com 13th LSM - Geneva 2012
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
1
2
3
4
2/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
1
2
3
4
3/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
4/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
5/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
6/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
1
2
3
4
7/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
8/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
9/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
1
Host enumeration
2
Host discovery
3
Reverse DNS resolution
4
Port scan
5
Version detection / RPC grind
6
OS fingerprinting
7
Traceroute
8
Script scan
9
Output
10/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
h o s t r u l e = f u n c t i o n ( host ) r e t u r n host . d i r e c t l y c o n n e c t e d end p o r t u l e = s h o r t p o r t . http
11/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
Nmap scan r e p o r t f o r scanme . nmap . org ( 7 4. 20 7. 244 .2 21 ) PORT STATE SERVICE VERSION 22/ tcp
ssh OpenSSH 5.3 p1 Debian 3ubuntu7 80/ tcp
http Apache httpd 2 . 2 . 1 4 (( Ubuntu )) | http −t i t l e : Go ahead and ScanMe ! S e r v i c e I n f o : OS: Linux ; CPE: cpe :/ o : l i n u x : k e r n e l Host s c r i p t r e s u l t s : | f i r e w a l k : | HOP HOST PROTOCOL BLOCKED PORTS | 192.168.0.15 tcp 139 | 10 6 4 . 6 2 . 2 5 0 . 6 tcp 135 ,445
12/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
13/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
nmap −−s c r i p t samba−vuln−cve −2012−1182 <target > nmap −−s c r i p t +mongodb−i n f o −p80 <target >
nmap −−s c r i p t ” http −∗ and not brute ” <target >
14/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
15/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
1
2
3
4
16/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
17/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
17/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
18/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
19/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
19/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
20/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
21/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
1 nping in server mode on target 2 client probes the target 3 server returns captured probes to the client(s) as encrypted
22/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
23/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
24/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
25/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
1
2
3
4
26/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
27/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
28/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
29/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
...and code? ;)
30/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
31/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
32/33
Project presentation Nmap Scripting Engine Nmap 6 new features Ongoing developments Conclusion
http://nmap.org nmap-dev@insecure.org (it’s cool, join!)
33/33