º»¹®/³»¿ë
- NmapÀº raw IP ÆÐŶÀ» »ç¿ë ³×Æ®¿öÅ©ÀÇ Æ¯Â¡ Á¡°Ë
1. È£½ºÆ®ÀÇ »óÅÂ
2. ¼ºñ½º(Æ÷Æ®)
3. ¿î¿µÃ¼Á¦(OS ¹öÀü)
4. filter/firewallÀÇ ÆÐŶ ŸÀÔ
2. nmap Ư¡
ºÐ·ù ±â´É / Ư¡
Flexible(À¯¿¬¼º) IP ÇÊÅÍ, ¹æÈº®, ¶ó¿ìÅÍ..ÀÇ ³×Æ®¿öÅ© »óÅÂ(Æ÷Æ® ½ºÄ³´× ¸ÞÄ«´ÏÁò(TCP & UDP), OS °Ë»ö, pings sweeps µî) Á¡°Ë
Powerful(°·ÂÇÔ) ¼öõ ¼ö¹é °³ÀÇ È£½ºÆ®¸¦ °¡Áø °Å´ëÇÑ ³×Æ®¿öÅ©¸¦ °í¼ÓÀ¸·Î ½ºÄµ
Portable(À̽ļº) Linux, Open/Free/Net BSD, Solaris, IRIX, Mac OS X, HP-UX,Sun OSµî ´ëºÎºÐÀÇ ¿î¿µÃ¼Á¦ Áö¿ø
Easy(¿ëÀ̼º) °·ÂÇϸ鼵µ ´Ù¾çÇÑ setÀ» Á¦°øÇÔ¿¡µµ ºÒ±¸ Çϰí`nmap -O -sS targethost`¿Í °°ÀÌ ¾ÆÁÖ °£´ÜÇÑ ¸í·É¾î¸¦ ÀÌ¿ë¶ÇÇÑ command line ¹× graphical (GUI) ¹öÀü ¸ðµÎ¸¦ Áö¿ø
Free(ÀÚÀ²¼º) http://www.insecure.org/nmap¿¡¼ ¹«·á·Î ´Ù¿î¹ÞÀ» ¼ö ÀÖÀ¸¸ç, GNU General Public License(GPL)ÇÏ¿¡ ¸ðµç »ç¶÷ÀÌ ÀÚÀ¯·Ó°Ô »ç¿ëÇÒ ¼ö ÀÖ´Ù.
Popular(ÀÎÁöµµ) ÇöÀç ³×Æ®¿öÅ© ½ºÄµ Åø Áß¿¡¼ °¡Àå ¸¹ÀÌ ÀÌ¿ëµÇ°í ÀÖ´Â ÅøÀÌ´Ù.
3. nmap Áö¿ø ±â´É
1. Vanilla TCP connect() scanning,
2. TCP SYN (half open) scanning,
3. TCP FIN (stealth) scanning,
4¡¦(»ý·«)
IP ÁÖ¼Ò¸¦ DNS È£½ºÆ®¸íÀ¸·Î ¹Ù²ÙÁö ¾Ê´Â´Ù. ¼Óµµ°¡ ºü¸£´Ù.
-R IP ÁÖ¼Ò¸¦ DNS È£½ºÆ®¸íÀ¸·Î ¹Ù²ã¼ ½ºÄµ. ¼Óµµ°¡ ´À¸®´Ù.
-o ½ºÄµ °á°ú¸¦ ÅØ½ºÆ® ÆÄÀÏ·Î ÀúÀå.
-i ½ºÄµ ´ë»ó È£½ºÆ®ÀÇ Á¤º¸¸¦ ÁöÁ¤ÇÑ ÆÄÀÏ¿¡¼ ÀÐ¾î¼ ½ºÄµ.
-oN ½ºÄµÇÑ °á°ú¸¦ ·Î±× ÆÄÀÏ¿¡ ³²±ä´Ù(»ç¶÷ÀÌ ÀÐ±â ÆíÇÑ Æ÷¸Ë).
-oM ½ºÄµÇÑ °á°ú¸¦ ·Î±× ÆÄÀÏ¿¡ ³²±ä´Ù(ÄÄÇ»ÅͰ¡ ÀÐ±â ÆíÇÑ Æ÷¸Ë).
-h µµ¿ò¸» º¸±â
* È£½ºÆ® Àû¿ë Option
±¸ºÐ ¼³¸í
¿¬¼ÓµÇÁö ¾ÊÀº ¿©·¯ °³ÀÇ È£½ºÆ®¸¦ ½ºÄµ È£½ºÆ® »çÀÌ¿¡ `,` ÀÔ·Â
¿¬¼ÓµÇ´Â ¿©·¯ °³ÀÇ È£½ºÆ®¸¦ ½ºÄµ ù ¹øÂ° È£½ºÆ®¿Í ¸¶Áö¸· È£½ºÆ® »çÀÌ¿¡ `-` ÀÔ·Â
Ŭ·¡½º ´ÜÀ§ ½ºÄµ `/mask` ÀÌ¿ë(B class : /16, C class : /24), `*` ÀÌ¿ë, `-` ÀÌ¿ë
* Ç¥½Ã »óÅÂ
±¸ºÐ ¼³¸í
Open È£½ºÆ®ÀÇ Æ÷Æ®·Î accept() Á¢¼ÓÀÌ °¡´ÉÇÔÀ» ÀǹÌÇÑ´Ù.
Filtered ¹æÈº®À̳ª ÇÊÅÍ, ¶Ç´Â ´Ù¸¥ ³×Æ®¿÷ Àåºñ°¡ Æ÷Æ®¸¦ º¸È£Çϰí Àְųª, Æ÷Æ®°¡ open µÇ¾î ÀÖ´ÂÁö¿¡ °üÇØ nmapÀÌ °áÁ¤ÇÒ ¼ö ¾øÀ½À» ÀǹÌÇÑ´Ù.
Unfiltered closed »óÅÂÀ̰í firewall/filter°¡ ¾øÀ½À» ÀǹÌÇÑ´Ù.´ëºÎºÐÀÇ Æ÷Æ®°¡ Unfiltered Æ÷Æ®À̹ǷΠ`unfiltered`´Â state¿¡´Â ÇÁ¸°Æ®µÇÁö ¾Ê´Â´Ù.
6. nmap½Ç½À
* ½Ç½À °èÁ¤ : www.designfor.net (211.239.168.47 : ºÐ´ç IDC)
Âü°í¹®Çå
http://apollon.busanedu.net/eduzine/200307/etc.htm
http://blog.naver.com/aram96.do?Redirect=Log&logNo=20005958486
http://www.linuxsecurity.com/feature_stories/feature_story-4.html
http://blog.naver.com/aram96.do?Redirect=Log&logNo=20005959860
http://www.insecure.org/nmap/
http://www.pcline.co.kr/old_magazine/2002/2002_07/step_by_step/linux/linux_4.htm
http://www.gyn.pe.kr/linux/security/nmap.html
http://enleaf.made.com/bbs/zboard.php?id=news&no=16
http://815server.net/servertip/tip_liunx_view.htm?page=1&no=119&check_ck=&search_sel=&search_name=
http://ict.kaist.ac.kr/www/nmap3.htm
http://www.foundstone.com