19. Information Gathering and Scanning
19.7 Service Versions, OS Detection and NSE Scripts
Port ughda aahe he kalala, pan tyavar konta software, konta version chalu aahe? He mahit zala tarach aapan pudhchya chapter madhe vulnerability shodhu shakto. Old version mhanje bahutek veles known vulnerability.
sudo nmap -sV 192.168.56.20 # service and version detection
sudo nmap -sV --version-intensity 9 -p 21 192.168.56.20 # try harder on one port
sudo nmap -O 192.168.56.20 # operating system detection
sudo nmap -A 192.168.56.20 # aggressive: -sV + -O + default scripts + traceroute
A typical -sV line looks like 21/tcp open ftp vsftpd 2.3.4. That one line tells you the port, the protocol, the service and the exact version – which you will search in Chapter 20.
NSE – the Nmap Scripting Engine. Nmap ships with hundreds of scripts (written in Lua) stored in /usr/share/nmap/scripts/. They are grouped into categories:
| Category | What it does | Safe on the lab? |
|---|---|---|
default |
Useful, fast, low-risk scripts (-sC) |
Yes |
safe |
Will not crash services | Yes |
discovery |
Extra information (SMB shares, HTTP titles...) | Yes |
vuln |
Checks for known vulnerabilities | Lab only |
auth / brute |
Tests credentials | Lab only – can lock accounts |
intrusive / dos |
May crash or slow the target | Avoid unless the scope allows |
sudo nmap -sC -sV 192.168.56.20 # default scripts + versions (most used combo)
nmap --script http-title,http-headers -p 80 192.168.56.20
nmap --script ftp-anon -p 21 192.168.56.20 # is anonymous FTP allowed?
sudo nmap --script vuln 192.168.56.20 # known-vulnerability checks (lab only)
ls /usr/share/nmap/scripts/ | grep smb # find scripts by name
nmap --script-help ftp-anon # read what a script does before running it
Ravindra Bagale's Tip
-A aani --script vuln khup "cool" vatatat, mhanun students sagalikade vapartat. Pan he khup aawaj karnare (noisy) scans aahet – kharya engagement madhe IDS lagech alert deto, aani kahi scripts service crash karu shaktat. Aadhi --script-help vachun samja script kay karto, mag fakt scope madhe allowed asel tarach chalava.
Lab
Run sudo nmap -sC -sV -oN msf2_services.txt 192.168.56.20. From the output, list every service with its version in a table in your notes (port, service, version). Then run nmap --script ftp-anon -p 21 192.168.56.20 and write down whether anonymous FTP login is allowed.