Nmap
Prof. Tushar Gohil,
Assistant professor,
Information technology Department,
Sarvajanik college of engineering and technology, Surat.
Prof. Tushar Gohil | SCET, Surat.
Session Outline
• Introduction
• Getting Started with Nmap
• Scanning Techniques in Nmap
• Host Discovery Techniques
• Port Scanning and Service Detection
• Network Mapping and Visual Output
• Advanced Nmap Features
• Nmap in Cybersecurity
• Q&A Session
Prof. Tushar Gohil | SCET, Surat.
Introduction to Nmap
Prof. Tushar Gohil | SCET, Surat.
Introduction to Nmap
• Overview and Purpose
• Brief History and Evolution
• Real-World Use Cases
Prof. Tushar Gohil | SCET, Surat.
Introduction to Nmap
Overview and Purpose
• Network Mapper (Nmap) is an open-source tool designed for network discovery
and security auditing.
• Primary Purpose
• Scanning networks to detect live hosts, open ports, services, and running applications.
• Used for security auditing and identifying network vulnerabilities.
• Key Features
• Supports a variety of scan types (e.g., TCP, SYN, UDP).
• Includes the Nmap Scripting Engine (NSE) for advanced functionality.
• Flexible output formats, including XML, plaintext, and visual mapping.
Prof. Tushar Gohil | SCET, Surat.
Introduction to Nmap
Brief History and Evolution
• Initial Release (1997)
• Created by Gordon Lyon (known as Fyodor) and introduced in Phrack Magazine as a network security tool.
• Development and Adoption
• Rapidly evolved due to community involvement and contributions.
• Became essential in the cybersecurity community for penetration testing and network scanning.
• Significant Milestones
• 2009: Nmap Scripting Engine (NSE) introduced, enhancing functionality for automated vulnerability detection.
• 2012: Featured in The Matrix Reloaded and other media, spotlighting its prominence in cybersecurity.
• Continues to be maintained and updated with new features and scan capabilities to keep up with evolving security
challenges.
Prof. Tushar Gohil | SCET, Surat.
Introduction to Nmap
Real World Use Cases
• Network Security Audits
• Regularly used by IT professionals to detect potential security risks by identifying open ports and services.
• Vulnerability Assessment
• Used by penetration testers to map out target networks and look for potential entry points.
• Inventory and Asset Management
• Helps IT teams identify and monitor devices on a network to maintain an accurate inventory.
• Incident Response
• Assists in quickly assessing affected systems and open services during security incidents.
• Educational Tool
• Widely used in cybersecurity education for teaching network scanning, reconnaissance, and threat detection.
Prof. Tushar Gohil | SCET, Surat.
Getting Started with Nmap
Prof. Tushar Gohil | SCET, Surat.
Getting Started with Nmap
• Installing Nmap on Different OS (Linux, Windows, macOS)
• Basic Syntax
Prof. Tushar Gohil | SCET, Surat.
Getting Started with Nmap
Installing Nmap
• Linux
For Debian/Ubuntu
For CentOS/RHEL
• sudo apt update
• sudo yum install nmap
• sudo apt install nmap
For Fedora
• sudo dnf install nmap
Prof. Tushar Gohil | SCET, Surat.
Getting Started with Nmap
Installing Nmap
• Windows
• Go to the Nmap download page and download the Windows installer.
• Run the .exe file and follow the installation instructions.
Verify the Installation
• Open Command Prompt or PowerShell and type:.
• nmap --version
Prof. Tushar Gohil | SCET, Surat.
Getting Started with Nmap
Installing Nmap
• Windows
Prof. Tushar Gohil | SCET, Surat.
Getting Started with Nmap
Basic Syntax
• The general syntax of an Nmap command is:
➢ nmap [Scan Type(s)] [Options] {target specification}
• This structure allows customization of scan types, target IPs or ranges, and additional options
for scan depth, output format, and other parameters.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
• TCP Connect Scan (-sT)
• SYN Scan (-sS)
• UDP Scan (-sU)
• FIN, Xmas, and Null Scans
• Ping Scanning (-sP)
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
TCP Connect Scan
• The TCP Connect Scan (-sT) is a scan type that completes a full TCP handshake (3-way
handshake) with each target port.
• It’s also known as a full-open scan because it fully establishes and closes a connection with each
open port.
• This scan is typically used when users don’t have sufficient privileges to send raw packets (like in
SYN Scans) or when scanning firewalls that block other types of scans.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
TCP Connect Scan
• How TCP Connect Scan Works
• Step 1: Nmap sends a SYN packet to the target port to initiate a connection.
• Step 2: If the target port is open, it responds with a SYN-ACK packet.
• Step 3: Nmap completes the handshake by sending an ACK packet back to the target.
• Step 4: Immediately after the handshake, Nmap sends an RST (reset) packet to tear down the connection, allowing
it to continue scanning without keeping connections open.
➢ nmap -sT <target>
➢ nmap -sT [Link]
Prof. Tushar Gohil | SCET, Surat.
Advantages Disadvantages
Slower than SYN Scans: TCP Connect Scans
Reliability: Since it completes the TCP handshake, it is are generally slower since they complete the
highly accurate in determining whether a port is open. entire TCP handshake, making them less efficient
for scanning many ports.
No Special Permissions Needed: Unlike SYN scans,
Easier to Detect: Because it completes a full
TCP Connect scans can be run by non-root users because
it relies on the operating system’s TCP/IP stack to connection, it’s easier for firewalls and Intrusion
complete the handshake. Detection Systems (IDS) to detect.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
TCP Syn Scan
• The TCP SYN Scan (also called a "half-open scan") is one of the most popular and efficient
types of scans in Nmap, especially useful for identifying open ports stealthily and quickly.
• The TCP SYN Scan initiates a TCP connection with the target without completing the full 3-way
handshake.
• It is often used by security professionals because it’s faster and less detectable than a TCP
Connect Scan.
• Only root or administrator privileges can perform this scan, as it requires sending raw packets.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
TCP SYN Scan
• How TCP SYN Scan Works
• Step 1: Nmap sends a SYN packet to the target port to initiate a connection.
• Step 2: The target responds based on the port's status:
• Open: Target replies with a SYN-ACK packet.
• Closed: Target replies with an RST (reset) packet.
• Filtered: No response, or the response may be an ICMP error.
• Step 3: If the target port responds with a SYN-ACK (indicating the port is open), Nmap immediately sends an RST
packet to end the connection, without completing the handshake.
➢ nmap -sS <target> ➢ nmap -sS [Link]
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
TCP SYN Scan
Prof. Tushar Gohil | SCET, Surat.
Advantages Disadvantages
Speed: Quicker than TCP Connect Scans as it doesn’t Requires Elevated Privileges: Needs root or
complete the handshake. administrative access to send raw packets.
Stealth: Less detectable by firewalls and IDS, as it Still Detectable by Advanced IDS: While
doesn’t establish a full connection. stealthier than a TCP Connect Scan, SYN Scans
can still be detected by intrusion detection
systems (IDS) configured to detect raw SYN
packets.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
TCP UDP Scan
• The UDP Scan in Nmap (-sU) is used to discover services running on UDP ports of a target.
• Unlike TCP, UDP is a connectionless protocol, meaning that communication does not require a
handshake.
• This scan type is crucial for identifying services on UDP ports, such as DNS, DHCP, and SNMP.
• The UDP Scan sends UDP packets to each specified port on a target and analyzes responses to
determine if ports are open, closed, or filtered.
• Since UDP is connectionless, this scan relies on different types of responses or lack thereof to
determine port states.
• A lack of response generally means a port is open or filtered, while an ICMP "port unreachable"
response indicates a closed port.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
TCP UDP Scan
• How TCP UDP Scan Works
• Open or Filtered Ports: If the target port is open or filtered, it may not respond, or it may respond with protocol-
specific data (e.g., DNS responses for port 53).
• Closed Ports: If the target port is closed, the system often responds with an ICMP message indicating "port
unreachable."
• Filtered Ports: Firewalls and filtering devices may block UDP packets altogether, resulting in no response and an
“open|filtered” status for some ports.
➢ nmap -sU <target> ➢ nmap -sU [Link]
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
TCP UDP Scan
Prof. Tushar Gohil | SCET, Surat.
Advantages Disadvantages
Slow: Due to the nature of UDP, scanning can be
Detection of UDP Services: Finds services unique to
UDP, such as DNS (53), SNMP (161), NTP (123), and significantly slower than TCP since Nmap often
DHCP (67/68). needs to wait for responses (or lack thereof) to
determine the port state.
Avoids TCP-Focused Firewalls: UDP scans are often Prone to False Positives: Because open UDP
not monitored as strictly as TCP traffic, allowing for ports often don’t respond, Nmap may report
potential bypassing of simple firewalls. some open ports as “open|filtered,” requiring
further verification.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
FIN, Xmas, Null Scans
• The FIN, Xmas, and Null scans are types of TCP scans that attempt to determine the state of a
port without using the usual SYN packet, making them more stealthy but also dependent on how
a target system responds to non-standard TCP packets.
• These scans are often used for probing firewall and Intrusion Detection System (IDS) evasion,
though they may not work on all systems, as they rely on specific behaviors defined in the
TCP/IP RFCs.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
FIN Scan
• The FIN Scan sends only a TCP FIN packet to the target port.
• An open port typically ignores the packet and doesn’t respond.
• A closed port generally replies with a TCP RST (reset) packet, indicating that the port is closed.
➢ nmap -sF <target>
➢ nmap -sF [Link]
Prof. Tushar Gohil | SCET, Surat.
Advantages Disadvantages
Not Effective on Windows Systems:
Stealthy: Since it doesn’t initiate a handshake, it’s less Windows systems often respond the same way to
likely to be detected by basic firewalls and IDS. both open and closed ports, making it unreliable
against them.
Useful for Firewalls: Can help identify open ports
Requires Elevated Privileges: Needs root or
without triggering some types of firewall responses.
administrator access.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
Xmas Scan
• The Xmas Scan sets the FIN, URG, and PSH flags in the TCP header, creating a packet that is
"lit up" like a Christmas tree.
• Open ports typically ignore the packet, while closed ports usually respond with a TCP RST
packet.
➢ nmap -sX <target>
➢ nmap -sX [Link]
Prof. Tushar Gohil | SCET, Surat.
Advantages Disadvantages
Not Effective on Windows Systems:
Stealthy: Like the FIN Scan, Xmas scans don’t initiate a Windows systems often respond the same way to
TCP handshake and are harder to detect. both open and closed ports, making it unreliable
against them.
Evasion Tactic: Often bypasses basic firewall filtering
Requires Elevated Privileges: Needs root or
rules that are focused on SYN packets.
administrator access.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
Null Scan
• The Null Scan sends a TCP packet with no flags set.
• Open ports generally do not respond, while closed ports respond with a TCP RST packet.
➢ nmap -sN <target>
➢ nmap -sN [Link]
Prof. Tushar Gohil | SCET, Surat.
Advantages Disadvantages
Not Effective on Windows Systems:
Stealthy: Like the FIN Scan, Xmas scans don’t initiate a Windows systems often respond the same way to
TCP handshake and are harder to detect. both open and closed ports, making it unreliable
against them.
Evasion Tactic: Often bypasses basic firewall filtering
Requires Elevated Privileges: Needs root or
rules that are focused on SYN packets.
administrator access.
Prof. Tushar Gohil | SCET, Surat.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
Ping Scan
• Ping Scanning (-sP), also known as Ping Sweep, is a technique used in Nmap to identify active
hosts on a network without performing a full port scan.
• It’s particularly useful for quickly finding which devices are up and reachable on a network.
• The Ping Scan (-sP) sends ICMP Echo Requests (ping requests) and/or TCP/UDP packets to
probe the target hosts.
• It doesn’t scan ports, only reports whether a host is online or not.
• This is a fast, low-bandwidth scan primarily for host discovery.
Prof. Tushar Gohil | SCET, Surat.
Scanning Techniques in Nmap
Ping Scan
• How Ping Scan Works
• Nmap typically uses multiple techniques to detect if a host is alive:
• ICMP Echo Request (ping): Sends an ICMP Echo Request and waits for a reply.
• TCP ACK packet: Sends a TCP packet with the ACK flag to port 80 (or other ports if specified); if it receives a
RST response, the host is considered up.
• TCP SYN packet: Sends a TCP SYN packet to a common port (such as 443 or 80); if it receives a SYN-ACK,
the host is up.
• UDP packet: Sends a UDP packet to ports like 53 (DNS); if a response is received, the host is up.
• If any of these packets elicit a response, Nmap considers the host to be online.
➢ nmap -sP <target>
➢ nmap –sP [Link]
Prof. Tushar Gohil | SCET, Surat.
Advantages Disadvantages
Fast and Efficient: Quickly identifies live hosts without May Be Blocked: Some firewalls and IDS systems
performing a full scan on each host. block ICMP or other discovery packets, so ping scans
may not detect all devices.
Low Resource Usage: Consumes less bandwidth and
Only Shows Online/Offline Status: Does not
processing power, ideal for large networks.
provide information on open ports or services.
Useful for Discovery: Effective for initial Limited by Permissions: Some options (like
reconnaissance and to map out active devices before
TCP-based host discovery) may require
deeper scanning.
administrative privileges.
Prof. Tushar Gohil | SCET, Surat.
Host Discovery Techniques
Prof. Tushar Gohil | SCET, Surat.
Host Discovery Technique
• ICMP Echo Requests
• TCP SYN Ping
• TCP ACK Ping
• ARP Ping (Local Network Scanning)
Prof. Tushar Gohil | SCET, Surat.
Host Discovery Techniques
ICMP Echo Request (Ping)
Description: Sends an ICMP Echo Request packet, often called a "ping," to determine if a host is online.
Expected Response: An ICMP Echo Reply if the host is up.
Command : nmap -PE <target>
Advantages: Simple and effective; suitable for basic discovery on networks without ICMP filtering.
Limitations: Many firewalls and security devices block ICMP Echo Requests, potentially causing false negatives.
Prof. Tushar Gohil | SCET, Surat.
Host Discovery Techniques
TCP SYN Ping
Description: Sends a TCP SYN packet to a specified port, typically 80 or 443.
Expected Response: An open port will respond with a TCP SYN-ACK, and a closed port with a TCP RST, indicating the host is
online.
Command : nmap –PS <target>
Advantages: Effective for bypassing ICMP restrictions; works on TCP ports frequently allowed through firewalls.
Limitations: Some IDS/IPS systems may log or block SYN packets.
Prof. Tushar Gohil | SCET, Surat.
Host Discovery Techniques
TCP ACK Ping
Description: Sends a TCP ACK packet to the target, typically to port 80 or another common port.
Expected Response: An RST response indicates the host is online; no response suggests a filtered or offline host.
Command : nmap –PA <target>
Advantages: Useful for networks where SYN packets are more likely to be blocked or monitored.
Limitations: Some systems may drop ACK packets to uninitiated connections, leading to incomplete results.
Prof. Tushar Gohil | SCET, Surat.
Host Discovery Techniques
ARP Ping (Local Area Network Only)
Description: Uses ARP requests for discovery on local Ethernet networks, where IP addresses are mapped to MAC addresses.
Expected Response: An ARP reply indicates the host is online.
Command : nmap –PR <target>
Advantages: Very reliable on local networks since ARP requests are not blockable. Also, very fast.
Limitations: Only works on local networks, as ARP cannot cross network boundaries.
Prof. Tushar Gohil | SCET, Surat.
Prof. Tushar Gohil | SCET, Surat.
Prof. Tushar Gohil | SCET, Surat.
Port Scanning and Service
Detection
Prof. Tushar Gohil | SCET, Surat.
Port Scanning and Service Detection
• Identifying Open Ports and Services
• Service Version Detection (-sV)
• Operating System Detection (-O)
• Aggressive Scanning (-A)
Prof. Tushar Gohil | SCET, Surat.
Port Scanning and Service Detection
Identifying Open Ports and Services
Command : nmap –sT –p22 <target>
Command : nmap –sT –p22-30 <target>
Command : nmap –sT –p22,80,443 <target>
Prof. Tushar Gohil | SCET, Surat.
Port Scanning and Service Detection
Service Version Detection
Command : nmap –sV –p22 <target>
Command : nmap –sV –p22-30 <target>
Command : nmap –sT –p22,80,443 <target>
Prof. Tushar Gohil | SCET, Surat.
Port Scanning and Service Detection
Operating System Detection
Command : nmap –O <target>
Prof. Tushar Gohil | SCET, Surat.
Port Scanning and Service Detection
Aggressive Scanning
Command : nmap –A <target>
Prof. Tushar Gohil | SCET, Surat.
Network Mapping and Visual
Output
Prof. Tushar Gohil | SCET, Surat.
Network Mapping and Visual Output
• Network Mapping Techniques
• Visualization Tools like Zenmap
• Using Nmap XML Output for External Analysis
Prof. Tushar Gohil | SCET, Surat.
Network Mapping and Visual Output
Network Mapping Techniques
• Network Mapping is a technique to visualize the structure of a network, including how different
hosts and devices are connected, their roles, and their relationships.
• With Nmap, you can create network maps and, when combined with tools like Zenmap or other
visualization software, generate graphical representations of the network topology.
Prof. Tushar Gohil | SCET, Surat.
Network Mapping and Visual Output
Visualization Tools like Zenmap
• Zenmap is Nmap’s official GUI, which makes network mapping and visualization easier.
• Zenmap allows users to visualize the network and provides features for organizing and analyzing
scan results.
• It has a built-in network topology viewer, which helps in mapping out the discovered hosts and
connections visually.
Prof. Tushar Gohil | SCET, Surat.
Network Mapping and Visual Output
Visualization Tools like Zenmap
Run a Scan in Zenmap:
• Open Zenmap and enter your desired Nmap command
• nmap –sn <target-network>
View the Topology:
• After the scan completes, switch to the Topology tab.
• Zenmap will display a graphical map of the network, with icons representing hosts and lines indicating connections.
Customize the Map:
• Zoom, pan, and adjust the layout to focus on specific sections of the network.
• Hover over nodes to see details such as IP addresses, hostnames, open ports, and services.
Prof. Tushar Gohil | SCET, Surat.
Prof. Tushar Gohil | SCET, Surat.
Network Mapping and Visual Output
Using Nmap XML Output for external analysis
• Zenmap allows exporting of scan results for documentation or further analysis.
Command :
• nmap –oX scan_result.xml <target-network>
Prof. Tushar Gohil | SCET, Surat.
Advanced Nmap Features
Prof. Tushar Gohil | SCET, Surat.
Advanced Nmap Features
• Detailed NSE Scripts for Vulnerability and Exploit Detection
• Firewall Evasion Techniques (e.g., -D for decoys, -S for spoofed IP)
Prof. Tushar Gohil | SCET, Surat.
Advanced Nmap Features
Detailed NSE Scripts for Vulnerability & Exploit Detection
• Nmap’s NSE (Nmap Scripting Engine) allows users to extend its functionality using scripts,
many of which are designed for vulnerability and exploit detection.
• These scripts can scan for specific vulnerabilities, identify misconfigurations, detect outdated
software, and in some cases, exploit known issues.
• NSE scripts are grouped into categories, with vuln being the primary category for vulnerability
detection, and exploit for testing certain known exploits.
Prof. Tushar Gohil | SCET, Surat.
Prof. Tushar Gohil | SCET, Surat.
Prof. Tushar Gohil | SCET, Surat.
Prof. Tushar Gohil | SCET, Surat.
Prof. Tushar Gohil | SCET, Surat.
Advanced Nmap Features
Firewall Evasion Techniques
• Firewall evasion techniques in Nmap are used to bypass or avoid detection by firewalls, IDS
(Intrusion Detection Systems), and IPS (Intrusion Prevention Systems).
Prof. Tushar Gohil | SCET, Surat.
Advanced Nmap Features
Firewall Evasion Techniques – Decoy Scan (-D)
Description: Makes it appear as if multiple hosts are scanning the target, not just your IP, by adding "decoy" IP addresses.
Command: nmap -D RND:10 <target>
Benefits : Increases anonymity by creating false traffic, making it harder to detect the real scanner.
Prof. Tushar Gohil | SCET, Surat.
Advanced Nmap Features
Firewall Evasion Techniques – Spoofed IP Address (-S)
Description: Fakes the source IP address to bypass firewall rules that block specific IPs.
Command: nmap -S <spoofed_IP> <target>
Note: This technique requires network configuration and may not work with TCP-based scans since it lacks the usual TCP
handshake.
Prof. Tushar Gohil | SCET, Surat.
Nmap Role in Cybersecurity
Prof. Tushar Gohil | SCET, Surat.
Nmap Role in Cybersecurity
• Role in Vulnerability Assessments
• Compliance and Security Audits
• Legal and Ethical Considerations
Prof. Tushar Gohil | SCET, Surat.
Nmap Role in Cyber Security
Role in Vulnerability Assessments
• Nmap plays a crucial role in vulnerability assessments, where its capabilities enable
cybersecurity teams to identify, evaluate, and prioritize vulnerabilities within networks and
systems.
• Here’s how Nmap is used effectively in this process:
• Comprehensive Port and Service Scanning
• Detection of Vulnerable Services Using NSE Scripts
• Operating System and Version Detection
• Misconfiguration Identification
• Firewall and IDS/IPS Testing
• Report Generation
Prof. Tushar Gohil | SCET, Surat.
Nmap Role in Cyber Security
Compliance and Security Audit
• In compliance and security audits, Nmap assists in meeting regulatory requirements by
offering tools to verify secure configurations, monitor network assets, test firewall
effectiveness, and detect vulnerabilities.
Prof. Tushar Gohil | SCET, Surat.
Nmap Role in Cyber Security
Legal and Ethical Considerations
• While Nmap is a powerful tool for security assessment, improper use can lead to legal
consequences and ethical breaches.
• Here are key legal and ethical considerations to keep in mind:
• Authorization and Consent
• Adhering to Terms of Service and Policies
• Privacy and Data Protection
• Non-Disclosure and Confidentiality
• Logging and Documentation
• Use for Learning and Training
Prof. Tushar Gohil | SCET, Surat.
Q&A Session
Prof. Tushar Gohil | SCET, Surat.
Thank You.
Prof. Tushar Gohil | SCET, Surat.