zj1244
zj1244
因为之前使用masscan+nmap的扫描方式产生漏报太多了,所以后来琢磨单单使用nmap来扫的话,时间上是否能接受? 首先看看masscan+nmap扫描一个【c段(192.168.1.1-192.168.1.255)+1-65535端口】所用的时间,基本上在22分钟左右: data:image/s3,"s3://crabby-images/0e7ee/0e7eeb1c5a0f07f14e857de53ab79bf6f4311247" alt="image" 再看看使用以下参数扫描一个ip所用的时间大概在89秒左右: `nmap -sV 192.168.xxx.31 -p1-65535` data:image/s3,"s3://crabby-images/cc03f/cc03f23a4e8d3de9d4d5f93ffa13093075fed933" alt="image" data:image/s3,"s3://crabby-images/c7d1b/c7d1bbb48e55af59e5472c01f1636d0b8cb47ce5" alt="image" 接着添加T4参数看看速度是否有变化: data:image/s3,"s3://crabby-images/e32e1/e32e11f164dcfccac53feaa0ea2065179b4ceeea" alt="image" 可以看到也是89秒左右,接着继续添加--version-intensity 4参数: data:image/s3,"s3://crabby-images/0d256/0d256482c51e179aa7244b1c40eef00bbfff5b57" alt="image" 可以看到速度缩短到43秒左右,但是带来的影响是有些指纹识别不出来,如下图: data:image/s3,"s3://crabby-images/8c745/8c74555e67a8c20dbf0a4f1d80af5771607a5a20" alt="image" 这就需要分析哪些协议没识别出来,然后手动修改,首先在/usr/share/nmap/nmap-service-probes里查找rmiregistry,然后把rarity的值改成4就行了 data:image/s3,"s3://crabby-images/65297/65297f8b6b7c46733aaac89090708162bdb3e470" alt="image" 但是有些指纹并没有rarity,如:jdwp data:image/s3,"s3://crabby-images/921b4/921b494011ab3f405a57c3423b8913d5c3dd9840" alt="image" 这时候可以通过`grep -r "Java Debug Wire Protocol" /usr/share/nmap/`查找rarity的判断在哪个文件,后来找到原来在/usr/share/nmap/scripts/jdwp-version.nse文件里,修改成4,这样就可以--version-intensity 4的时候也识别出来了 data:image/s3,"s3://crabby-images/625e1/625e10dc3857580ad3dde394688a3d5a1404371d" alt="image"...
在使用masscan做扫描的时候,经常会因为设置rate过大导致出现漏报,下图是扫同一台机器出现的完全不同的结果: data:image/s3,"s3://crabby-images/4d05c/4d05cb7807570b8cb27b203cad15aedc1396d805" alt="image" 可以看出速率是70000的时候,一个端口都没扫到。而速率是7000的时候,扫到了两个端口。虽然之前就有预料到这个情况,但是还是没想到差距那么大,这也导致了扫描大量主机的时候,会有很多漏报,如下图: data:image/s3,"s3://crabby-images/75ae9/75ae9efd6b7605a8516a9ff918b7811d828919ab" alt="image" 之后应该不会使用masscan+nmap的方式来监控,原因就是漏报太多了
1. 查看当前系统安装了几个内核版本 ```bash rpm -qa|grep -i kernel-3.10 ``` data:image/s3,"s3://crabby-images/7cc31/7cc31c8960668858317e00db6a4dbe372fe3c87d" alt="image" 2. 谷歌搜索并下载类似如下命名的三个文件: kernel-3.10.0-229.el7.x86_64.rpm kernel-tools-3.10.0-229.el7.x86_64.rpm kernel-tools-libs-3.10.0-229.el7.x86_64.rpm 3. 依次安装这三个文件: ```bash yum install kernel-tools-3.10.0-229.el7.x86_64.rpm ``` 如果安装失败就用rpm强制安装 ```bash rpm -ivh --force kernel-tools-3.10.0-229.el7.x86_64.rpm ``` 然后查看安装成功没有: data:image/s3,"s3://crabby-images/073a8/073a8ac83d1ade67b0c8635753a7edf1bb7445ae" alt="image"...
This PR was automatically created by Snyk using the credentials of a real user.Snyk has created this PR to fix one or more vulnerable packages in the `pip` dependencies of...
This PR was automatically created by Snyk using the credentials of a real user.data:image/s3,"s3://crabby-images/6a34c/6a34c0e6bed848716398f37d655badff6030e8d5" alt="snyk-top-banner" ### Snyk has created this PR to fix 1 vulnerabilities in the pip dependencies of this...
This PR was automatically created by Snyk using the credentials of a real user.data:image/s3,"s3://crabby-images/6a34c/6a34c0e6bed848716398f37d655badff6030e8d5" alt="snyk-top-banner" ### Snyk has created this PR to fix 1 vulnerabilities in the pip dependencies of this...