Linux nmap Command

Linux Command Reference


nmap (Network Mapper) is one of the most powerful network probing and security auditing tools in Linux systems. It helps system administrators and network security experts:

  • Discover active hosts on the network
  • Scan open ports and services
  • Identify operating system types and versions
  • Detect vulnerabilities in network services

Due to its flexibility, powerful functionality, and cross-platform nature, nmap is widely used in network security assessment, system administration, network monitoring, and other fields.


Basic Syntax

The basic command format of nmap is as follows:

nmap [扫描类型] [选项] {目标规范}

Where:

  • Scan Type: Specifies the scanning technique used by nmap
  • Options: Configures various parameters for scan behavior
  • Target Specification: Can be an IP address, hostname, or IP range

Common Scan Types

TCP SYN Scan (-sS)

The most commonly used and default scanning method, also known as "half-open scanning":

nmap -sS 192.168.1.1

Features:

  • Fast and stealthy
  • Does not complete the TCP three-way handshake
  • Requires root privileges

TCP Connect Scan (-sT)

Standard TCP connect scan:

nmap -sT 192.168.1.1

Features:

  • Does not require root privileges
  • Establishes a full TCP connection
  • Slower and easily detected

UDP Scan (-sU)

Scans UDP ports:

nmap -sU 192.168.1.1

Features:

  • UDP scanning is relatively slow
  • Many UDP services do not respond
  • Requires root privileges

Operating System Detection (-O)

Identifies the target host's operating system:

nmap -O 192.168.1.1

Common Options and Parameters

Port Specification (-p)

Scan specific ports or port ranges:

Examples

nmap -p 80,443 192.168.1.1       # Scan ports 80 and 443
nmap -p 1-100 192.168.1.1        # Scan ports 1-100
nmap -p- 192.168.1.1             # Scan all 65535 ports

Service Version Detection (-sV)

Probe detailed version information of services:

nmap -sV 192.168.1.1

Scan Speed (-T)

Controls scan speed (0-5, the higher the number, the faster):

nmap -T4 192.168.1.1             # 较快的扫描速度

Output Formats

Multiple output format options:

Examples

nmap -oN result.txt 192.168.1.1  # Normal text format
nmap -oX result.xml 192.168.1.1  # XML format
nmap -oG result.gnmap 192.168.1.1 # Grepable format

Practical Examples

Basic Network Scan

nmap 192.168.1.1

Example output:

Starting Nmap 7.80 ( https://nmap.org ) at 2023-05-01 10:00 UTC
Nmap scan report for 192.168.1.1
Host is up (0.045s latency).
Not shown: 998 closed ports
PORT    STATE SERVICE
22/tcp  open  ssh
80/tcp  open  http
443/tcp open  https

Comprehensive Scan (OS + Service Version)

nmap -A 192.168.1.1

Scan an Entire Subnet

nmap 192.168.1.0/24

Read Target List from File

nmap -iL targets.txt

Interpreting Scan Results

Meaning of port states in nmap output:

State Description
open Port is open and an application is listening
closed Port is closed (host is reachable, but no application is listening)
filtered Port is filtered by firewall/network, state cannot be determined
unfiltered Port is accessible, but cannot determine if open or closed (used for ACK scans)
open|filtered Cannot determine if port is open or filtered (common in UDP scans)
closed|filtered Cannot determine if port is closed or filtered

Security and Legal Considerations

  1. Legal use: Only scan networks and systems you have permission to scan
  2. Obtain authorization: Ensure written authorization is obtained before using on enterprise networks
  3. Avoid abuse: Large-scale fast scanning may be regarded as an attack
  4. Respect privacy: Do not scan network resources that do not belong to you

Advanced Techniques

Bypassing Firewalls

Examples

nmap -f --mtu 24 192.168.1.1      # Use fragmentation
nmap --data-length 100 192.168.1.1 # Add random data
nmap -D RND:5 192.168.1.1         # Decoy scan

Scheduled Scan Script

Examples

#!/bin/bash
DATE=$(date +%Y%m%d)
nmap -sS -p- -T4 -oN scan_$DATE.log 192.168.1.0/24

Result Comparison

ndiff scan1.xml scan2.xml

FAQ

Q: Why does nmap scanning require root privileges?A: Certain scan types (such as SYN scans) require direct manipulation of network packets, which requires root privileges.

Q: How can I speed up scanning?A: Use-T4or-T5options, reduce timeout, or limit the port range being scanned.

Q: Can nmap scans be detected by firewalls?A: It depends on the scan type and firewall configuration. SYN scans are more stealthy than full-connect scans.

Q: How do I scan IPv6 addresses?A: Simply use the IPv6 address directly:nmap 2001:db8::1


Recommended Learning Resources

  1. Official documentation:man nmap
  2. Official Nmap book: "Nmap Network Scanning"
  3. Online tutorials:https://nmap.org/book/toc.html
  4. Interactive learning:https://tryhackme.com/room/furthernmap

By mastering nmap, you will gain powerful network probing capabilities, laying a solid foundation for system administration and network security work. It is recommended to start with simple scans and gradually try more complex options and techniques.


Linux Command Reference

Other Extensions