Linux nmap Command
nmap (Network Mapper) is one of the most powerful network probing and security auditing tools in Linux systems. It helps system administrators and network security experts:
- Discover active hosts on the network
- Scan open ports and services
- Identify operating system types and versions
- Detect vulnerabilities in network services
Due to its flexibility, powerful functionality, and cross-platform nature, nmap is widely used in network security assessment, system administration, network monitoring, and other fields.
Basic Syntax
The basic command format of nmap is as follows:
nmap [扫描类型] [选项] {目标规范}
Where:
Scan Type: Specifies the scanning technique used by nmapOptions: Configures various parameters for scan behaviorTarget Specification: Can be an IP address, hostname, or IP range
Common Scan Types
TCP SYN Scan (-sS)
The most commonly used and default scanning method, also known as "half-open scanning":
nmap -sS 192.168.1.1
Features:
- Fast and stealthy
- Does not complete the TCP three-way handshake
- Requires root privileges
TCP Connect Scan (-sT)
Standard TCP connect scan:
nmap -sT 192.168.1.1
Features:
- Does not require root privileges
- Establishes a full TCP connection
- Slower and easily detected
UDP Scan (-sU)
Scans UDP ports:
nmap -sU 192.168.1.1
Features:
- UDP scanning is relatively slow
- Many UDP services do not respond
- Requires root privileges
Operating System Detection (-O)
Identifies the target host's operating system:
nmap -O 192.168.1.1
Common Options and Parameters
Port Specification (-p)
Scan specific ports or port ranges:
Examples
nmap -p 1-100 192.168.1.1 # Scan ports 1-100
nmap -p- 192.168.1.1 # Scan all 65535 ports
Service Version Detection (-sV)
Probe detailed version information of services:
nmap -sV 192.168.1.1
Scan Speed (-T)
Controls scan speed (0-5, the higher the number, the faster):
nmap -T4 192.168.1.1 # 较快的扫描速度
Output Formats
Multiple output format options:
Examples
nmap -oX result.xml 192.168.1.1 # XML format
nmap -oG result.gnmap 192.168.1.1 # Grepable format
Practical Examples
Basic Network Scan
nmap 192.168.1.1
Example output:
Starting Nmap 7.80 ( https://nmap.org ) at 2023-05-01 10:00 UTC Nmap scan report for 192.168.1.1 Host is up (0.045s latency). Not shown: 998 closed ports PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 443/tcp open https
Comprehensive Scan (OS + Service Version)
nmap -A 192.168.1.1
Scan an Entire Subnet
nmap 192.168.1.0/24
Read Target List from File
nmap -iL targets.txt
Interpreting Scan Results
Meaning of port states in nmap output:
| State | Description |
|---|---|
| open | Port is open and an application is listening |
| closed | Port is closed (host is reachable, but no application is listening) |
| filtered | Port is filtered by firewall/network, state cannot be determined |
| unfiltered | Port is accessible, but cannot determine if open or closed (used for ACK scans) |
| open|filtered | Cannot determine if port is open or filtered (common in UDP scans) |
| closed|filtered | Cannot determine if port is closed or filtered |
Security and Legal Considerations
- Legal use: Only scan networks and systems you have permission to scan
- Obtain authorization: Ensure written authorization is obtained before using on enterprise networks
- Avoid abuse: Large-scale fast scanning may be regarded as an attack
- Respect privacy: Do not scan network resources that do not belong to you
Advanced Techniques
Bypassing Firewalls
Examples
nmap --data-length 100 192.168.1.1 # Add random data
nmap -D RND:5 192.168.1.1 # Decoy scan
Scheduled Scan Script
Examples
DATE=$(date +%Y%m%d)
nmap -sS -p- -T4 -oN scan_$DATE.log 192.168.1.0/24
Result Comparison
ndiff scan1.xml scan2.xml
FAQ
Q: Why does nmap scanning require root privileges?A: Certain scan types (such as SYN scans) require direct manipulation of network packets, which requires root privileges.
Q: How can I speed up scanning?A: Use-T4or-T5options, reduce timeout, or limit the port range being scanned.
Q: Can nmap scans be detected by firewalls?A: It depends on the scan type and firewall configuration. SYN scans are more stealthy than full-connect scans.
Q: How do I scan IPv6 addresses?A: Simply use the IPv6 address directly:nmap 2001:db8::1
Recommended Learning Resources
- Official documentation:
man nmap - Official Nmap book: "Nmap Network Scanning"
- Online tutorials:https://nmap.org/book/toc.html
- Interactive learning:https://tryhackme.com/room/furthernmap
By mastering nmap, you will gain powerful network probing capabilities, laying a solid foundation for system administration and network security work. It is recommended to start with simple scans and gradually try more complex options and techniques.
Other Extensions