Ravindra BagaleCourses & study guides

19. Information Gathering and Scanning

19.7 Service Versions, OS Detection and NSE Scripts

Port ughda aahe he kalala, pan tyavar konta software, konta version chalu aahe? He mahit zala tarach aapan pudhchya chapter madhe vulnerability shodhu shakto. Old version mhanje bahutek veles known vulnerability.

sudo nmap -sV 192.168.56.20                    # service and version detection
sudo nmap -sV --version-intensity 9 -p 21 192.168.56.20   # try harder on one port
sudo nmap -O 192.168.56.20                     # operating system detection
sudo nmap -A 192.168.56.20                     # aggressive: -sV + -O + default scripts + traceroute

A typical -sV line looks like 21/tcp open ftp vsftpd 2.3.4. That one line tells you the port, the protocol, the service and the exact version – which you will search in Chapter 20.

NSE – the Nmap Scripting Engine. Nmap ships with hundreds of scripts (written in Lua) stored in /usr/share/nmap/scripts/. They are grouped into categories:

Category What it does Safe on the lab?
default Useful, fast, low-risk scripts (-sC) Yes
safe Will not crash services Yes
discovery Extra information (SMB shares, HTTP titles...) Yes
vuln Checks for known vulnerabilities Lab only
auth / brute Tests credentials Lab only – can lock accounts
intrusive / dos May crash or slow the target Avoid unless the scope allows
sudo nmap -sC -sV 192.168.56.20                          # default scripts + versions (most used combo)
nmap --script http-title,http-headers -p 80 192.168.56.20
nmap --script ftp-anon -p 21 192.168.56.20               # is anonymous FTP allowed?
sudo nmap --script vuln 192.168.56.20                    # known-vulnerability checks (lab only)
ls /usr/share/nmap/scripts/ | grep smb                   # find scripts by name
nmap --script-help ftp-anon                              # read what a script does before running it

Ravindra Bagale's Tip

-A and --script vuln feel very "cool", so students use them everywhere. But these are very noisy scans – in a real engagement the IDS alerts immediately, and some scripts can crash services. First read --script-help to understand what a script does, then run it only if it's allowed in the scope.

Lab

Run sudo nmap -sC -sV -oN msf2_services.txt 192.168.56.20. From the output, list every service with its version in a table in your notes (port, service, version). Then run nmap --script ftp-anon -p 21 192.168.56.20 and write down whether anonymous FTP login is allowed.