Nmap: Network Exploration Tool and Security Scanner
Nmap (“Network Mapper”) is a free and open-source utility for network discovery and security auditing. It is widely used by network administrators and security professionals for tasks such as:
- Host Discovery: Identifying live hosts on a network.
- Port Scanning: Detecting open ports and services running on those ports.
- Service Version Detection: Determining the application name and version.
- Operating System Detection: Fingerprinting the operating system of the target.
- Vulnerability Scanning: Using Nmap Scripting Engine (NSE) scripts to detect common vulnerabilities.
Basic Scan Commands
Comprehensive Scan (Verbose, All Ports, Stealth, Service/OS Detection, Scripting)
This command is a powerful starting point, combining several common Nmap features.
sudo nmap -v -p- -sS -sV -sC -O <target_ip_or_hostname>sudo: Nmap often requires root privileges for raw socket operations (e.g.,-sS).-v: Verbose output (increases verbosity level).-p-: Scans all 65535 TCP ports. Without this, Nmap scans only the most common 1000 ports.-sS: SYN scan (stealth scan). This is often less intrusive than a full TCP connect scan.-sV: Service version detection. Attempts to determine the service and version number running on open ports.-sC: Runs default Nmap scripts. These scripts cover a wide range of common vulnerability checks and information gathering tasks.-O: Enables OS detection.<target_ip_or_hostname>: The IP address or hostname of the target.
Initial Reconnaissance Scan (Output to File)
A good initial scan for reconnaissance, saving the output to a normal text file.
sudo nmap -v -sC -sV -oN nmap/initial <target_ip_or_hostname>-oN <filename>: Output scan results in normal text format to the specified file.
Port Specification
Scan a Single Port
nmap -p 22 <target_ip_or_hostname>Scan Multiple Specific Ports
nmap -p 22,80,443 <target_ip_or_hostname>Scan All Ports (1-65535)
nmap -p- <target_ip_or_hostname>Scan Types
Stealth Scan (SYN Scan)
Attempts to identify open ports without completing the full TCP 3-way handshake, making it less detectable by some firewalls.
nmap -sS <target_ip_or_hostname>UDP Scan
Scans for open UDP ports. UDP scans are typically slower and less reliable than TCP scans due to the connectionless nature of UDP.
sudo nmap -sU <target_ip_or_hostname>Service and OS Detection
Service Version Detection
Attempts to determine the exact service and its version running on open ports.
nmap -sV <target_ip_or_hostname>Testing Against a Local HTTP Echo Server
When testing how Nmap interacts with a web service, run a disposable echo server and watch the request details in the container logs. The mendhak/http-https-echo container is useful for confirming HTTP probes, headers, paths, and TLS behavior during safe lab testing.
docker run -it --rm -p 80:8080 -p 443:8443 mendhak/http-https-echoThen scan the local listener:
nmap -sV -sC -p 80,443 localhostOperating System Detection
Attempts to determine the operating system of the target host.
nmap -O <target_ip_or_hostname>Bypassing Firewalls
Do Not Ping (Host Discovery)
If a host does not respond to ICMP pings, Nmap might assume it’s down. -Pn tells Nmap to skip the host discovery phase and assume the host is online, attempting to scan it directly.
nmap -Pn <target_ip_or_hostname>Nmap Scripting Engine (NSE)
NSE is a powerful feature that allows users to write (and share) simple scripts to automate a wide variety of networking tasks.
SSL Certificate Check
Uses an NSE script to enumerate SSL/TLS ciphers and certificate details on a target.
nmap -sV --script ssl-enum-ciphers -p 443 <target_ip_or_hostname>Disclaimer: Nmap is a powerful network scanning tool. Its use should be restricted to legal and ethical purposes, such as authorized penetration testing, security auditing of your own networks, or academic research with proper consent. Unauthorized scanning of networks is illegal and unethical.