Kevin De Baerdemaeker

Nmap

Modified 2024-04-22

Port scanning allows an attacker to understand which services are running on the host. The more knowledge you gain by port scanning, the more options available for a possible attack.

If an attacker doesn't know which ports are open, then there's no chance in successfully attacking the target.

nmap -p- IP

Scan Types

TCP Connect Scans -sT

The RFC 9293 states that if a connection doesn't exist (CLOSED), send a RST to a SYN request. Obviously, if SYN/ACK means the port is open and Nmap sends back ACK. If the port does not return any response the port is filtered.

Keep in mind it's possible to configure the firewall to send a RST TCP packet to make it difficult to get an accurate reading.

iptables -I INPUT -p tcp --dport <port> -j REJECT --reject-with tcp-reset

SYN Scans -sS

Also known as stealth or half-open scans. The SYN scans send back a RST packet upon receiving the SYN/ACK, which cuts the connection.

UDP Scans -sU

Packets sent via UDP should not have a response, so Nmap marks them as open|filtered and checks them a second time. If it does get an answer, it marks it as open. If a packet reaches a closed port, the target should respond with an ICMP (ping) packet saying the port is unreachable.

These types of scans are slow.

NULL -sN, FIN -sF and Xmas -sX TCP scans

These scans are commonly used for firewall evasion, because Nmap is not sending a SYN packet. The NULL scan sends a packet with no flags set. The FIN scans have the FIN flag set (graceful closing of connection). The Xmas scans send malformed TCP packets.

The expected response for these types of scans is similar to UDP scan. It's recommended to send RST for closed ports, but not for open. However, in Windows and a lot of Cisco devices they respond with RST to any malformed packet, regardless of it being open or not.

ICMP Networking Scanning (ping sweep) -sn

Nmap sends an ICMP packet to each possible IP address for the specified network, and when it receives a response marks it as alive. Inaccurate, but can provide a baseline.

Nmap Scripting Engine (NSE)

Lua extends the capabilities of Nmap to make it do powerful things. The scripts belong to certain categories.

grep "safe" /usr/share/nmap/scripts/script.db

Firewall Evasion

The Windows host blocks all ICMP packets, Nmap pings the host by default. So that's a problem. The -Pn option tells Nmap to not bother pinging first, which means the scan can take ages.

The --badsum is an interesting one, because a firewall might default to automatically respond without bothering to check the checksum, which determines the presence of a Firewall/IDS.

References


Backlinks