Port scan for Information Collection-- Amap
Man amapamap [Mode] [Options] [...] Scan accuracy optimization 1.-u udp scan the port, default tcp scan 2.-6 use IPv6, default use IPv4 scan parameter tuning 1.-R does not recognize RPC service. The RPC service is recognized by default. (when identifying a RPC service, a connection to the target machine port will be created many times to identify the type and version of the RPC service, which is time-consuming and easy to find.-CN sets the number of timeout retries 3.-CN sets the number of concurrency, default 32, maximum 2564. -T n sets the timeout for completing the TCP three-way handshake connection, which defaults to 55. -t n sets the time to wait for a response, which defaults to 56. -H setting does not send harmful service identification packets, you can use appdefs.trig to see how to mark a harmful service identification packet quickly scan all ports of the target (scan can be completed in 4 minutes And does not affect the accuracy in the private network) # print all ports open amap-T 1-t 1-C 0-c 256 1-6553 "print only open ports amap-T 1-t 1-C 0-c 256 1-65535 | grep Protocol# only view open ports and service information amap-T 1-t 1-C 0-c 256 1-65535 | grep Protocol | awk'{print $3 $5}'# scan amap-u-t 1-C 0-c 256 1-65535 for UDP | grep Protocol | awk'{print $3 $5}'# get the open port amap-1-Q-t 1-C 0-c 256 10.129.5.105-u 137 | grep Protocol | awk'{print $3}'| awk-fanglue'{print $2}'| awk-flip end'{print $1}'# obtain the open service amap-1-Q-t 1-C 0-c 256 10.129.5.105-u 137 | grep Protocol | awk'{print $5} 'reference man amap
-- to be continued.