nmap没有那么神
扫描某博客网站,nmap告诉我:
OS details: Tomato 1.28 (Linux 2.4.20), Tomato firmware (Linux 2.6.22), Sony Ericsson U8i Vivaz mobile phone
移动时代也不至于拿手机当Web服务器啊。
网站不都像scanme.nmap.org一样配合啊。再说就算猜对了OS,如Linux 3.1.2,我又不知道3.1.2有哪些漏洞和如何黑进去。
SQL injection好像可玩度不错,因为好像有人会把JavaScript代码存在数据库里。听见“关系”、“笛卡尔积”我就发抖,SQL里是CREATE TABLE,不是CREATE RELATION啊。escape? 一律\nnn行不?不差这一点点效率了吧?
Nmap features include:
- Host discovery – Identifying hosts on a network. For example, listing the hosts that respond to TCP and/or ICMP requests or have a particular port open.
- Port scanning – Enumerating the open ports on target hosts.
- Version detection – Interrogating network services on remote devices to determine application name and version number.
- TCP/IP stack fingerprinting – Determining the operating system and hardware characteristics of network devices based on observations of network activity of said devices.
- Scriptable interaction with the target – using Nmap Scripting Engine (NSE) and Lua programming language.
Certain parameters within the TCP protocol definition are left up to the implementation. Different operating systems, and different versions of the same operating system, set different defaults for these values. By collecting and examining these values, one may differentiate among various operating systems, and implementations of TCP/IP. The TCP/IP fields that may vary include the following:
- Initial packet size (16 bits)
- Initial TTL (8 bits)
- Window size (16 bits)
- Max segment size (16 bits)
- Window scaling value (8 bits)
- "don't fragment" flag (1 bit)
- "sackOK" flag (1 bit)
- "nop" flag (1 bit)
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· TypeScript + Deepseek 打造卜卦网站:技术与玄学的结合
· Manus的开源复刻OpenManus初探
· 三行代码完成国际化适配,妙~啊~
· .NET Core 中如何实现缓存的预热?
· 阿里巴巴 QwQ-32B真的超越了 DeepSeek R-1吗?
2022-01-15 apple
2022-01-15 Babbage difference and Quake's Fast Inverse Square Root
2022-01-15 appetite
2022-01-15 A Child's History of England.143
2022-01-15 A Child's History of England.142