Secrets of Network Cartography:
A Comprehensive Guide to nmap
Written by James Messer
A NetworkUptime.com Publication
Like the online e-book?
You'll love the downloadable version!
Buy it here!
Table of Contents
INTRODUCTION
- What is nmap?
- Windows Operating Systems and nmap
- Is nmap Good or Evil?
- About This Book
- How This Book is Organized
- Conventions Used in This Book
CHAPTER 1: THE BASICS
- Internet Protocol
- Transmission Control Protocol (TCP)
- User Datagram Protocol (UDP)
- Internet Control Message Protocol (ICMP)
- The Basics of nmap
- Nmap Scan Summary
- TCP SYN Scan (-sS)
- TCP connect() Scan (-sT)
- Stealth Scanning – The FIN Scan (-sF), Xmas Tree Scan (-sX), and Null Scan (-sN)
- Ping Scan (-sP)
- Version Detection (-sV)
- UDP Scan (-sU)
- IP Protocol Scan (-sO)
- ACK Scan (-sA)
- Window Scan (-sW)
- RPC Scan (-sR)
- List Scan (-sL)
- Idlescan (-sI <zombie host:[probeport]>)
- FTP Bounce Attack (-b)
CHAPTER 4: OPERATING SYSTEM FINGERPRINTING
- Operating System Fingerprinting (-O) Operation
- The nmap-os-fingerprints Support File
- The Operating System Fingerprinting Process
- Advantages of Operating System Fingerprinting
- Disadvantages of Operating System Fingerprinting
- When to use Operating System Fingerprinting
- The nmap-os-fingerprints Support File
- Limit Operating System Scanning (--osscan_limit)
- More Guessing Flexibility (--osscan_guess, --fuzzy)
- Additional, Advanced, and Aggressive (-A)
- Exclude Targets (--exclude <host1 [,host2] [,host3]...>)
- Exclude Targets in File (--excludefile <exclude_file>)
- Read Targets from File (-iL <inputfilename>)
- Pick Random Numbers for Targets (-iR <numhosts> )
- Randomize Hosts (--randomize_hosts, -rH)
- No Random Ports (-r)
- Source Port (--source_port or -g)
- Specify Protocol or Port Numbers (-p <port range>)
- Fast Scan Mode (-F)
- Create Decoys (-D <decoy1 [,decoy2][,ME],...>)
- Source Address (-S<IP_address>)
- Interface (-e <interface>)
- Help for Windows (--win_help)
- List All Network Interfaces (--win_list_interfaces)
- Disable Raw Socket Support (--win_norawsock)
- Try Raw Sockets Even on non-W2K Systems (--win_forcerawsock)
- Disable WinPcap Support (--win_nopcap)
- Test NT 4.0 Route Code (--win_nt4route)
- Test Response to Lack of iphlpapi.dll (--win_noiphlpapi)
- Trace Through Raw IP Initialization (--win_trace)
- Skip Windows IP Initialization (--win_skip_winip_init)
- Quick Reference Screen (--help, -h)
- Nmap Version (--version, -V)
- Data Directory (--datadir)
- Quash Argument Vector (-q)
- Define Custom Scan Flags (--scanflags[flagval])
- (Uriel) Maimon Scan (-sM)
- IPv6 Support (-6)
- Identifying the Remnants of a Virus Outbreak or Spyware Infestation
- Vulnerability Assessments
- Security Policy Compliance Testing
- Asset Management
- Firewall Auditing
- Perpetual Network Auditing
To view a copy of this license, visit http://creativecommons.org/licenses/by-nc-nd/2.0/
or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.


