Hacking tools used in penetration testing. Part-7 NMap (Zenmap)

nmap

How can I forget about NMap. I am so damn ignorant. This is one of the powerful tool used for various scanning process.

Nmap is a free open-source utility for network exploration and security auditing. It is used to discover computers and services on a computer network, thus creating a “map” of the network. Just like many simple port scanners, Nmap is capable of discovering passive services. In addition, Nmap may be able to determine various details about the remote computers. These include operating system, device type, uptime, software product used to run a service, exact version number of that product, presence of some firewall techniques and, on a local area network, even vendor of the remote network card. Nmap runs on Linux, Microsoft Windows etc.

The idle scan is a TCP port scan method that through utility software tools such as Nmap and Hping allows sending spoofed packets to a computer. Idle scans take advantage of predictable Identification field value from IP header. An attacker would first scan for a host with a sequential and predictable sequence number (IPID). The latest versions of Linux, Solaris, and OpenBSD are not suitable targets, since the IPID has been implemented with patches. Computers chosen to be used in this stage are sometimes known as “zombies”. Once a suitable zombie is found the next step would be to send a SYN packet to the target computer, spoofing the IP address from the zombie. If the port of the target computer is open it will respond with a SYN/ACK packet back to the zombie. The zombie computer will then send a RST packet to the target computer because it did not actually send the SYN packet in the first place. Since the zombie had to send the RST packet it will increment its IPID. This is how an attacker would find out if the targets port is open. If the IPID is not incremented then the attacker would know that the particular port is closed.

To perform idle scanning by nmap, the user should find a suitable zombie on the LAN:

nmap -sP 192.168.1.0/24

This tells nmap to do a ping sweep and shows all the hosts that are in a given IP range. Once you have found a zombie, next you should send the spoofed packets:

nmap -P0 -p -sI

Share
This entry was posted in Security and tagged , , , , . Bookmark the permalink.

49 Responses to Hacking tools used in penetration testing. Part-7 NMap (Zenmap)

  1. Kum Waldrip says:

    Thanks for the great desings.It will help me to redesign my jobs site

  2. No, I do not think so, but the style of your article i’ll like it

  3. I am looking for this information, Thanks for that article, very helpful to me.

  4. wow.. i’m very

    enjoy reading your post. great.

  5. I enjoy reading the report, too. It′s easy to understand that a journey like this is the biggest event in ones

    life.

  6. mbt shoes says:

    i am happy to find it thanks for sharing it here. Nice work.

  7. howdy there, i just discovered your blog on google, and i would like to comment that you compose awesomely well on your web portal. i am really impressed by the way that you write, and the subject is good. in any case, i would also love to know whether you would like to exchange links with my web portal? i will be more than happy to reciprocate and drop your link off in the blogroll. anticipating for your respond, thanks and cheers!

  8. Howdy, i read your blog occasionally and i own a similar one and i was just wondering if you get a lot of spam comments? If so how do you prevent it, any plugin or anything you can advise? I get so much lately it’s driving me mad so any assistance is very much appreciated.

  9. Odoclopavap says:

    thanks! :)

    lets write them until the admit it, or stop doing it! i am writing them now!

    :)

  10. cisspfix says:

    Hello.. Yes I am also experiencing the same problem. I am using Akismet plugin to solve this problem. I hope it will help you too.
    Thanks for reading my blog. Hope see your comment around.
    Enjoy reading.

  11. I can see that your case is rather incisive with a good deal of interesting info. Well, was curious whether you would willing to exchange contacts with my site, as I am looking forward to compile more contacts to further inflate and increase web exposure for my web site. I don’t really mind you putting my web links at the sitewide page, just having this links on this respective page is more than adequate. Furthermore, would you please be kind enough to contact me at my web space if you are interested in the link exchange, I would really value that. Thank you very much and I hope to get a reply from you soon!

  12. Now, there are a few websites that I do input on. This one caught my attention. I like how you elaborate on the tips, regarding this topic. Fine points and fantastic work. Thanks!

  13. There exist only a few blogs that I do comment on. This one especially caught my attention. I love the way you are thorough on the tips, especially this topic. Solid points and terrific work. Thanks!

  14. Test says:

    Hi all!

    G’night

  15. Howdy there,Superb blog dude! i am Tired of using RSS feeds and do you use twitter?so i can follow you there:D.
    PS:Have you thought putting video to the blog posts to keep the readers more interested?I think it works.Best wishes, Elizabeth Blackstock

  16. Shawn Shorty says:

    Resources like the one you mentioned here will be very useful to me! I will post a link to this page on my blog. I am sure my visitors will find that very useful.

  17. Took me period to review all the comments, but I definitely enjoyed the article. It proved to be Very neighbourly to me and I am unwavering to all the commenters here! It’s always nice when you can not however be in touch, but also entertained! I’m sure you had fun scribble literary works this article.

  18. Pingback: Tools used for OS Fingerprinting. | CISSP Fix

  19. Hi,just found your Blog when i google something and wonder what hosting do you use for your wordpress,the speed is more faster than my website, i really need it.will back to check it out,many thanks!

  20. You in fact a really smart individual! Nice post! GA is also my biggest earning. Nonetheless, it’s not a much.

  21. e-cigarette says:

    I very much agree with the comment above me, the web is without a doubtgrowing to be the most important medium of communication across the world and its due to sites like this that information is spreading so quickly.

  22. Jeff Olive says:

    I was just having a conversation over this I am glad I came across this it cleared some of the questions I had.

  23. Is it me or did this article make you want to buy an iPad?

  24. Thank you for another great article. Where else could anyone get that kind of information in such a perfect way of writing? I have a presentation next week, and I am on the look for such information.

  25. Generally I do not post on sites, however , I would like to state that this post really obligated me to take action! really nice post

  26. There are certainly a lot of details like that to take into consideration. That is a great point to bring up. I offer the thoughts above as general inspiration but clearly there are questions like the one you bring up where the most important thing will be working in honest good faith. I don?t know if best practices have emerged around things like that, but I am sure that your job is clearly identified as a fair game.

  27. Appreciation pro this article. Present are categorically tips participating in at this juncture to I choice benefit.

  28. Couldn?t be written any better. Reading this post reminds me of my old room mate! He always kept talking about this. I will forward this article to him. Pretty sure he will have a good read. Thanks for sharing!

  29. You may have not intended to do so, but I think you have managed to express the state of mind that a lot of people are in. The sense of wanting to help, but not knowing how or where, is something a lot of us are going through.

  30. Hello

    This point is very interesting.
    I positively like that I discovered this topic that Ihave been looking for.
    I will pursue checking insensible this keynote on … to lay one’s hands on any late-model ideas more this post

  31. There exist only a few blogs that I do comment on. This one especially captured my attention. I like how you elaborate on the points, regarding this subject matter. Nice points and fantastic work. Microsoft XP Registry Cleaner Thanks!

  32. Shena Kirson says:

    Hi there could I reference some of the information from this post if I reference you with a link back to your site?

  33. i know i¡¯m a little off topic, but i just wanted to say i love the layout of your blog. i¡¯m new to the blogegine platform, so any suggestions on getting my blog looking nice would be appreciated.

  34. Grover Kubas says:

    Thank you for another fantastic blog. Where else could I get this kind of info written in such an incite full way? I have been looking for such information.

  35. Hi I have been reading your blog for the past two weeks and it is interesting, do you have a RSS feed?

  36. Hmm your website is showing errors on my browser Internet Explorer. Can you please correct it.

  37. The comment above me is well thought… and no I’m not being sarcastic. No pun intended.

  38. Saw your Blog bookmarked on Reddit.I really enjoy your blog and marketing tactic. Investigate out my Farmville Guidebook in the event you get a moment.

  39. Your website is simply recording drawbacks on my Firefox browser.

  40. Hey I stumbled upon your blog by luck on ask while searching for something totally irrelevant but I am really pleased that I did, You have just captured yourself another subscriber. :)

  41. Howdy! Our staff members are on the lookout for forthcoming copy writers, may well you be attracted? This situation wouldn’t make you prosperous unfortunately there is an ideal compensation and if you really adore authoring then that opportunity is for you.

  42. Whats up! Our staff members are checking for long term freelance writers, would you be intrigued? This one would not allow you rich nonetheless there is an alluring salary and if you greatly take delight in publishing then this situation opportunity is for you.

  43. this internet site is my aspiration , real excellent layout and perfect articles .

  44. cityville says:

    occasionally and I’m grateful to report this newest contribution is in actual fact fairly good quality and a whole good deal improved than 1 / 2 the various poor quality junk I read today

  45. Thora Yongue says:

    I am really thankful to this topic because it really gives great information .-.

  46. *~: I am very thankful to this topic because it really gives up to date information `;~

  47. sudoku says:

    After study a couple of of the blog posts in your website now, and I truly like your method of blogging. I bookmarked it to my bookmark website list and might be checking back soon. Pls check out my site as nicely and let me know what you think.

  48. Lilia Oeder says:

    Hello! I know this is somewhat off topic but I was wondering if you knew where I could locate a captcha plugin for my comment form? I’m using the same blog platform as yours and I’m having difficulty finding one? Thanks a lot!

  49. Great write-up, I’m regular visitor of one’s site, maintain up the excellent operate, and It is going to be a regular visitor for a lengthy time.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>