Other Scanning Methods¶
Scanning and enumeration techniques beyond Nmap: banner grabbing, UDP, and local network discovery.
When I Use It¶
- Confirming a service version by reading its banner directly
- Scanning UDP services that a default TCP scan misses
- Discovering live hosts on the local subnet, including confirming I am on the right VLAN on site
Common Tasks¶
Banner Grabbing¶
Connect to a service and read the banner it returns for version and fingerprint information.
nc -v TARGET-IP 25
telnet TARGET-IP 25
For HTTP, send a minimal request after connecting:
nc TARGET-IP 80
GET / HTTP/1.1
Host: TARGET-IP
UDP Scanning¶
UDP services are easy to miss. udp-proto-scanner probes known UDP protocols.
./udp-proto-scanner.pl -f ips.txt # all probes against a list of IPs
udp-proto-scanner.pl -p ntp -f ips.txt # a specific service
Local Network Discovery¶
netdiscover finds hosts, MAC addresses, and vendors from ARP, which is handy for confirming you are on the expected VLAN on site.
netdiscover -r 192.168.1.0/24
Reading the Output¶
- A banner gives the service and often the exact version, which maps to known vulnerabilities
- UDP results are less reliable than TCP; corroborate anything interesting
- netdiscover's vendor column helps tell infrastructure (switches, printers) from endpoints