Ravindra BagaleCourses & study guides

19. Information Gathering and Scanning

19.7 Service Versions, OS Detection and NSE Scripts

Port ughda aahe he kalala, pan tyavar konta software, konta version chalu aahe? He mahit zala tarach aapan pudhchya chapter madhe vulnerability shodhu shakto. Old version mhanje bahutek veles known vulnerability.

sudo nmap -sV 192.168.56.20                    # service and version detection
sudo nmap -sV --version-intensity 9 -p 21 192.168.56.20   # try harder on one port
sudo nmap -O 192.168.56.20                     # operating system detection
sudo nmap -A 192.168.56.20                     # aggressive: -sV + -O + default scripts + traceroute

A typical -sV line looks like 21/tcp open ftp vsftpd 2.3.4. That one line tells you the port, the protocol, the service and the exact version – which you will search in Chapter 20.

NSE – the Nmap Scripting Engine. Nmap ships with hundreds of scripts (written in Lua) stored in /usr/share/nmap/scripts/. They are grouped into categories:

Category What it does Safe on the lab?
default Useful, fast, low-risk scripts (-sC) Yes
safe Will not crash services Yes
discovery Extra information (SMB shares, HTTP titles...) Yes
vuln Checks for known vulnerabilities Lab only
auth / brute Tests credentials Lab only – can lock accounts
intrusive / dos May crash or slow the target Avoid unless the scope allows
sudo nmap -sC -sV 192.168.56.20                          # default scripts + versions (most used combo)
nmap --script http-title,http-headers -p 80 192.168.56.20
nmap --script ftp-anon -p 21 192.168.56.20               # is anonymous FTP allowed?
sudo nmap --script vuln 192.168.56.20                    # known-vulnerability checks (lab only)
ls /usr/share/nmap/scripts/ | grep smb                   # find scripts by name
nmap --script-help ftp-anon                              # read what a script does before running it

Ravindra Bagale's Tip

-A aani --script vuln khup "cool" vatatat, mhanun students sagalikade vapartat. Pan he khup aawaj karnare (noisy) scans aahet – kharya engagement madhe IDS lagech alert deto, aani kahi scripts service crash karu shaktat. Aadhi --script-help vachun samja script kay karto, mag fakt scope madhe allowed asel tarach chalava.

Lab

Run sudo nmap -sC -sV -oN msf2_services.txt 192.168.56.20. From the output, list every service with its version in a table in your notes (port, service, version). Then run nmap --script ftp-anon -p 21 192.168.56.20 and write down whether anonymous FTP login is allowed.