Active information collection-layer 2 discovery (shell script)
Second-level discovery
Principle: use the ARP protocol to broadcast in the network segment to see if there is a return packet, and if so, prove that the host is alive
Advantages: fast and reliable scanning
Disadvantages: non-routable, only hosts within the same network segment can be found
Environment
Kali 2.0
Using arping command combined with script to realize host discovery
Script 1 (network interface) #! / bin/bash#Author:Taoif [$#-ne 1]; then echo "Usage. / arp.sh [interface]" exitfiintface=$1ipd=$ (ifconfig eth0 | grep 'netmask' | cut-d'-f 10 | cut-d'.'- f 1-3) for num in $(seq 1 255) Do ip=$ipd.$num arping-c 1$ ip | grep bytes | cut-d''- f 5 | cut-d'('- f 2 | cut-d')'- f 1done
One effect of the script:
Script 2 (network interface, no parameters) #! / bin/bash#Author:Taointerface=$ (ifconfig | head-1 | awk-F ":"'{print $1}') ip=$ (ifconfig $interface | grep "netmask" | awk'{print $2}'| cut-d'.'- f 1-3) for i in `seq 1 254`; do arping-c 1$ ip.$i | grep from | cut-d ""-f 5 | cut-d "("-f 2 | cut-d ")"-f 1done > alive.txt "
Note: the above script results will be input to the alive.txt file
Script two-effect picture:
Script 3 (IP) #! / bin/bash#Author:Taofile=$1for I in $(cat $1); do arping-c 1$ I | grep from | cut-d ""-f 5 | cut-d "("-f 2 | cut-d ")"-f 1done > $1-alive.txt
Note: the above script results will be entered into the file name + alive.txt file you passed.
Summary: the script is more or less the same. Record it.