????Nmap?????
????· Open: Open?????Nmap?????????????
????· Close: Close??????????????????????????п??????????????????????????????Close????????????С?????????????????????????????
????· Filtered: Filtered???????????????????????????Nmap????ж??????????????????п???????????????£??????????????????????
????· Unfiltered: ?????ACK???????????????????????????б???????????????????????????????????????????????漰????TCP???????????????????????Google????
????· Open|Filtered: ??????????????????????????????????????????????????????????跽???
????· Closed|Filtered: ???????????????????????????????????IPID Idle???
??????????????
??????????壬???????????????Щ???.
???????:
????· nmap T0 [target] ?????????裬????IDS(????????)???
????· nmap T1 [target] ????????裬????0??2?????????????????ЩIDS
????· nmap T2 [target] ??????????????????
????· nmap T3 [target] ?????????
????· nmap T4 [target] ??????裬???????????????з????????????
????· nmap T5 [target] ??????裬??????????????????.
???????????
???????:
????· nmap -p [port]|(1-9999) [target] ???????(??????Χ)???
????· nmap -F [target] ?????????????????????nmap-services??
????· nmap -r ??????(?????nmap?????????)
????· nmap --top-ports (n) ????????????n?????
????TCP SYN???
?????????跽?????????????????????裬??????????????????????????????????????????TCP???????????????SYN TCP??????????RST???????????????????SYN/ACK?????????????nmap??????????????????????????????????RST?ж??????
???????: nmap -sS [target]
????TCP ACK???
??????TCP SYN????????????ACK TCP????????????ж???????????????????????????????????RST????????????????????????ICMP??????????????Filtered??
???????: nmap -sA [target]
????TCP???????
???????????????跽???????TCP??????????????????????????SYN????????????????????п???????????????????????????
???????: nmap -sT [target]
?????????TCP???
??????????????????TCP?Щ???λ???????????TCP??衣?????????????TCP/IP?????
???????: nmap --scanflags [Symbols] [target]
???????з????????URG??ACK??PSH??RST??SYN??FIN?????????????????
????UDP ???
?????????????UDP????????????ICMP???????????????????????????????????????????????ж??????????????????UDP???????????????????-p????????????
???????: nmap -sU -p [port list] [target]
???????????
???????:
????· nmap -sN [target] Null??裬?????????TCP?????????????????????RST?????????????????
????· nmap -sF [target]??FIN??裬??SYN??????????SYN?滻?FIN
????· nmap -sX [target] ?????????FIN??PSH??URG???λ??????RFC793?漲??????????????RST??????????????????RFC793?????????????????????RST??
???????????
????????????????????????????跽???????????Ч??????IDS???????????????????£??????????ο????????
??????????????:
????· ?ж????TCP???????????????????????????????TCP SYN???????????????????????SYN/ACK???????????????RST????
????· ???????SYN/ACK????????RST?????????RST??????
????· ???????????IP??????????????????????(IP ID)??????????????????????????????????????IP ID ????????????????????????????????
??????й???:
????· ????????????????????????IP ID
????· ????????????????????α?????????IP??SYN??????????????????????????????????????????????????SYN/ACK??????????RST??
????· ?????????????IP ID???????????????2??????????????????????????????????????????????????????????????1???????????????????????????????????????????????????2?????????????????????????
???????????????????????IP???????ι????????????????????????????IP???????????????????????????????????????????
???????: nmap -sI [zombie ip] [target ip]
?????ο?????
????IPЭ?????
??????????????????跽????????????????????????TCP??UDP???????????IPЭ????????????????????????ЩIPЭ????
???????: nmap -sO [target]