Nmap 速查表
扫描单个 IP nmap 192.168.1.1
扫描主机 nmap www.testhostname.com
扫描 IP 范围 nmap 192.168.1.1-20
扫描子网 nmap 192.168.1.0/24
从文本文件扫描目标 nmap -iL list-of-ips.txt
扫描单个端口 nmap -p 22 192.168.1.1
扫描端口范围 nmap -p 1-100 192.168.1.1
扫描 100 个最常见端口(快速) nmap -F 192.168.1.1
扫描所有 65535 个端口 nmap -p- 192.168.1.1
使用 TCP 连接扫描 nmap -sT 192.168.1.1
使用 TCP SYN 扫描(默认) nmap -sS 192.168.1.1
扫描 UDP 端口 nmap -sU -p 123,161,162 192.168.1.1
扫描选定端口 - 忽略发现 nmap -Pn -F 192.168.1.1
检测操作系统和服务 nmap -A 192.168.1.1
标准服务检测 nmap -sV 192.168.1.1
更激进的服务检测 nmap -sV --version-intensity 5 192.168.1.1
更轻量的横幅抓取检测 nmap -sV --version-intensity 0 192.168.1.1
将默认输出保存到文件 nmap -oN outputfile.txt 192.168.1.1
将结果保存为 XML nmap -oX outputfile.xml 192.168.1.1
以 grep 兼容格式保存结果 nmap -oG outputfile.txt 192.168.1.1
保存所有格式 nmap -oA outputfile 192.168.1.1
使用默认安全脚本扫描 nmap -sV -sC 192.168.1.1
获取脚本帮助 nmap --script-help=ssl-heartbleed
使用特定 NSE 脚本扫描 nmap -sV -p 443 –script=ssl-heartbleed.nse 192.168.1.1
使用一组脚本扫描 nmap -sV --script=smb* 192.168.1.1
扫描 UDP DDOS 反射器 nmap –sU –A –PN –n –pU:19,53,123,161 –script=ntp-monlist,dns-recursion,snmp-sysdescr 192.168.1.0/24
收集 HTTP 服务的页面标题 nmap --script=http-title 192.168.1.0/24
获取 Web 服务的 HTTP 头 nmap --script=http-headers 192.168.1.0/24
从已知路径查找 Web 应用 nmap --script=http-enum 192.168.1.0/24
Heartbleed 测试 nmap -sV -p 443 --script=ssl-heartbleed 192.168.1.0/24
查找 IP 地址信息 nmap --script=asn-query,whois,ip-geolocation-maxmind 192.168.1.0/24
nmap -sV -p 1-65535 192.168.1.1/24
- 所有端口,所有服务版本,简单脚本 = 仅显示开放的端口
nmap -p- -sV -sC $IP --open