Host Scanning

nmap

Fast simple scan

nmap 10.11.1.111

Nmap ultra fast

nmap 10.11.1.111 –max-retries 1 –min-rate 1000

Get open ports

nmap -p – -Pn -n 10.10.10.10

Get sV from ports

nmap -pXX,XX,XX,XX,XX -Pn -sV -n 10.10.10.10

Full complete slow scan with output

nmap -v -A -p- -Pn –script vuln -oA full 10.11.1.111

Network filtering evasion

nmap –source-port 53 -p 5555 10.11.1.111
# If work, set IPTABLES to bind this port
iptables -t nat -A POSTROUTING -d 10.11.1.111 -p tcp -j SNAT –to :53

Scan for UDP

nmap 10.11.1.111 -sU
nmap -sU -F -Pn -v -d -sC -sV –open –reason -T5 10.11.1.111

FW evasion

nmap -f
nmap –mtu 24
nmap –data-length 30

image (27).png
image (44).png