Nmap
Modified 2024-04-22
Port scanning allows an attacker to understand which services are running on the host. The more knowledge you gain by port scanning, the more options available for a possible attack.
If an attacker doesn't know which ports are open, then there's no chance in successfully attacking the target.
nmap -p- IPScan Types
TCP Connect Scans -sT
The RFC 9293 states that if a connection doesn't exist (CLOSED), send a RST to
a SYN request. Obviously, if SYN/ACK means the port is open and Nmap sends
back ACK. If the port does not return any response the port is filtered.
Keep in mind it's possible to configure the firewall to send a RST TCP packet
to make it difficult to get an accurate reading.
iptables -I INPUT -p tcp --dport <port> -j REJECT --reject-with tcp-resetSYN Scans -sS
Also known as stealth or half-open scans. The SYN scans send back a RST
packet upon receiving the SYN/ACK, which cuts the connection.
- bypasses much older intrusion detection
- not logged by applications listening on open ports
- faster
- require sudo (due to sending raw packets)
- unstable services can go down due to SYN scans
UDP Scans -sU
Packets sent via UDP should not have a response, so Nmap marks them as
open|filtered and checks them a second time. If it does get an answer, it
marks it as open. If a packet reaches a closed port, the target should respond
with an ICMP (ping) packet saying the port is unreachable.
These types of scans are slow.
NULL -sN, FIN -sF and Xmas -sX TCP scans
These scans are commonly used for firewall evasion, because Nmap is not sending
a SYN packet. The NULL scan sends a packet with no flags set. The FIN scans
have the FIN flag set (graceful closing of connection). The Xmas scans send
malformed TCP packets.
The expected response for these types of scans is similar to UDP scan. It's recommended to send RST for closed ports, but not for open. However, in Windows and a lot of Cisco devices they respond with RST to any malformed packet, regardless of it being open or not.
ICMP Networking Scanning (ping sweep) -sn
Nmap sends an ICMP packet to each possible IP address for the specified network, and when it receives a response marks it as alive. Inaccurate, but can provide a baseline.
Nmap Scripting Engine (NSE)
Lua extends the capabilities of Nmap to make it do powerful things. The scripts belong to certain categories.
grep "safe" /usr/share/nmap/scripts/script.dbFirewall Evasion
The Windows host blocks all ICMP packets, Nmap pings the host by default. So
that's a problem. The -Pn option tells Nmap to not bother pinging first, which
means the scan can take ages.
The --badsum is an interesting one, because a firewall might default to
automatically respond without bothering to check the checksum, which determines
the presence of a Firewall/IDS.