Nmap in the Enterprise: Your Guide to Network Scanning

Orebaugh, Angela; Pinkard, Becky

In stock
Regular price 23.500 KD inc. VAT
License
Table of contents
  • Cover
  • Authorsv
  • Technical Editorvii
  • Contentsix
  • Chapter 1: Introducing Network Scanning1
  • Introduction2
  • What is Network Scanning?2
  • Networking and Protocol Fundamentals3
  • Explaining Ethernet4
  • Understanding the Open Systems Interconnection Model5
  • Layer 1: Physical7
  • Layer 2: Data Link7
  • Layer 3: Network8
  • Layer 4: Transport9
  • Layer 5: Session12
  • Layer 6: Presentation13
  • Layer 7: Application13
  • Carrier Sense Multiple Access/Collision Detection (CSMA/CD)14
  • The Major Protocols: IP, TCP, UDP, and ICMP15
  • IP15
  • Internet Control Message Protocol17
  • TCP17
  • The TCP Handshake17
  • TCP Sequence18
  • UDP18
  • Network Scanning Techniques18
  • Host Discovery18
  • Port and Service Scanning20
  • OS Detection21
  • Optimization21
  • Evasion and Spoofing22
  • Common Network Scanning Tools23
  • Who Uses Network Scanning?23
  • Detecting and Protecting26
  • Network Scanning and Policy26
  • Summary28
  • Solutions Fast Track28
  • Frequently Asked Questions31
  • Chapter 2: Introducing Nmap33
  • Introduction34
  • What is Nmap?34
  • History of Nmap34
  • Nmap Features37
  • Nmap's User Interface38
  • Additional Nmap Resources40
  • Using Nmap in the Enterprise42
  • Using Nmap for Compliance Testing43
  • Using Nmap for Inventory and Asset Management46
  • Using Nmap for Security Auditing52
  • Using Nmap for System Administration53
  • Securing Nmap53
  • Executable and End-User Requirements53
  • System Environment54
  • Security of scan results55
  • Optimizing Nmap56
  • Advanced Nmap Scanning Techniques57
  • Summary60
  • Solutions Fast Track60
  • Frequently Asked Questions62
  • Chapter 3: Getting and Installing Nmap63
  • Introduction64
  • Getting Nmap65
  • Platforms and System Requirements67
  • Installing Nmap on Windows68
  • Installing Nmap from Windows Self-Installer69
  • Installing Nmap from the Command-line Zip files71
  • Installing Nmap on Linux72
  • Installing Nmap from the RPMs72
  • Installing Nmap RPMs Using YUM74
  • Installing Nmap on Mac OS X75
  • Installing Nmap on Mac OS X from Source75
  • Installing Nmap on Mac OS X Using MacPorts77
  • Installing Nmap on Mac OS X Using Fink78
  • Installing Nmap from Source79
  • Using the configure Script81
  • Summary83
  • Solutions Fast Track83
  • Frequently Asked Questions85
  • Chapter 4: Using Nmap87
  • Introduction88
  • Starting Nmap Scanning88
  • Target Specification93
  • Discovering Hosts95
  • Port Scanning99
  • Basic Port Scanning100
  • Advanced Port Scanning103
  • Specifying Ports105
  • Detecting Operating Systems110
  • Detecting Service and Application Versions111
  • Other Scanning Options115
  • Nmap Scripting Engine116
  • Performance and Optimization118
  • Evasion and Spoofing121
  • Output Logging125
  • Miscellaneous131
  • Summary133
  • Solutions Fast Track133
  • Frequently Asked Questions136
  • Chapter 5: Using Zenmap137
  • Introduction138
  • Running Zenmap138
  • Managing Zenmap Scans148
  • Building Commands with the Zenmap Command Wizard149
  • Managing Zenmap Profiles151
  • Managing Zenmap Results153
  • Summary157
  • Solutions Fast Track157
  • Frequently Asked Questions159
  • Chapter 6: Nmap OS Fingerprinting161
  • Introduction162
  • What is OS fingerprinting?162
  • The Mechanics of Nmap OS Fingerprinting163
  • Nmap OS Fingerprint Scan as an Administrative Tool167
  • Nmap to the Rescue! Tool for Crisis?174
  • Saving Hard Money with the Nmap OSFS175
  • Security Audits and Inventory175
  • H4x0rz, Tigers and Bears...Oh MY!176
  • Detecting and Evading the OS Fingerprint Scan177
  • Morph and IP Personality177
  • Honey Pots178
  • Summary179
  • Solutions Fast Track180
  • Frequently Asked Questions182
  • Chapter 7: Tooling Around with Nmap185
  • Introduction186
  • NDiff-Nmap Diff186
  • Source and Install187
  • Example Usage188
  • RNmap-Remote Nmap190
  • Source and Install190
  • Example Usage193
  • Bilbo194
  • Source and Install194
  • Example Usage196
  • Nmap-Parser200
  • Source and Install200
  • Example Usage203
  • Summary207
  • Solutions Fast Track207
  • Frequently Asked Questions209
  • Chapter 8: Nmap Scanning in the Real World211
  • Introduction212
  • Detecting Nmap on your Network212
  • TCP Connect Scan212
  • SYN Scan217
  • XMAS Scan219
  • Null Scan220
  • Discovering Stealthy Scanning Techniques221
  • Nmap Fragment Scan223
  • Nmap Decoys224
  • Detecting Nmap Fragment Scans225
  • Discovering Unauthorized Applications and Services227
  • Testing Incident Response and Managed Services Alerting230
  • Scanning to Test Alert Procedures230
  • Targeted Reconnaissance with Nmap231
  • Summary237
  • Solutions Fast Track238
  • Frequently Asked Questions240
  • Index241
Book details
  • Vendor Elsevier S & T
  • SKU 9781597492416
  • ISBN-13 9780080558745
  • Author Orebaugh, Angela; Pinkard, Becky
  • Category Computers
  • Subject General

Do you have questions about this book?

Ask an expert!

Nmap, or Network Mapper, is a free, open source tool that is available under the GNU General Public License as published by the Free Software Foundation. It is most often used by network administrators and IT security professionals to scan corporate networks, looking for live hosts, specific services, or specific operating systems. Part of the beauty of Nmap is its ability to create IP packets from scratch and send them out utilizing unique methodologies to perform the above-mentioned types of scans and more. This book provides comprehensive coverage of all Nmap features, including detailed, real-world case studies.

• Understand Network Scanning
Master networking and protocol fundamentals, network scanning techniques, common network scanning tools, along with network scanning and policies.
• Get Inside Nmap
Use Nmap in the enterprise, secure Nmap, optimize Nmap, and master advanced Nmap scanning techniques.
• Install, Configure, and Optimize Nmap
Deploy Nmap on Windows, Linux, Mac OS X, and install from source.
• Take Control of Nmap with the Zenmap GUI
Run Zenmap, manage Zenmap scans, build commands with the Zenmap command wizard, manage Zenmap profiles, and manage Zenmap results.
• Run Nmap in the Enterprise
Start Nmap scanning, discover hosts, port scan, detecting operating systems, and detect service and application versions
• Raise those Fingerprints
Understand the mechanics of Nmap OS fingerprinting, Nmap OS fingerprint scan as an administrative tool, and detect and evade the OS fingerprint scan.
• “Tool” around with Nmap
Learn about Nmap add-on and helper tools: NDiff--Nmap diff, RNmap--Remote Nmap, Bilbo, Nmap-parser.
• Analyze Real-World Nmap Scans
Follow along with the authors to analyze real-world Nmap scans.
• Master Advanced Nmap Scanning Techniques
Torque Nmap for TCP scan flags customization, packet fragmentation, IP and MAC address spoofing, adding decoy scan source IP addresses, add random data to sent packets, manipulate time-to-live fields, and send packets with bogus TCP or UDP checksums.