C:\Users\Yongz\nmap# nmap -sn 192.168.146.0/24 Starting Nmap 7.92 ( https://nmap.org ) at 2022-05-05 11:38 中国标准时间 Nmap scan report for 192.168.146.1 Host is up. Nmap scan report for 192.168.146.150 Host is up (0.0010s latency). MAC Address: 00:0C:29:B7:DB:7E (VMware) Nmap scan report for 192.168.146.254 Host is up (0.0010s latency). MAC Address: 00:50:56:E0:85:FD (VMware) Nmap done: 256 IP addresses (3 hosts up) scanned in 31.39 seconds
判断出 192.168.146.147 为靶机 IP 地址。
arp-scan
1 2 3 4 5
C:\Users\Yongz# arp-scan.exe -t 192.168.146.0/24 Reply that 00:50:56:C0:00:08 is 192.168.146.1 in 0.199400 Reply that 00:0C:29:B7:DB:7E is 192.168.146.150 in 14.624700 Reply that 00:50:56:E0:85:FD is 192.168.146.254 in 15.266600 Reply that 00:50:56:C0:00:08 is 192.168.146.255 in 0.027500
判断出 192.168.146.147 为靶机 IP 地址。
服务探测
1 2 3 4 5 6 7 8 9 10
C:\Users\Yongz\nmap# nmap -sS -p- -sV 192.168.146.150 Starting Nmap 7.92 ( https://nmap.org ) at 2022-05-05 11:42 中国标准时间 Nmap scan report for 192.168.146.150 Host is up (0.00056s latency). Not shown: 65531 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0) 80/tcp open http nginx 1.18.0 (Ubuntu) 7755/tcp open http Apache httpd 2.4.41 ((Ubuntu)) 33060/tcp open mysqlx?