日韩性视频-久久久蜜桃-www中文字幕-在线中文字幕av-亚洲欧美一区二区三区四区-撸久久-香蕉视频一区-久久无码精品丰满人妻-国产高潮av-激情福利社-日韩av网址大全-国产精品久久999-日本五十路在线-性欧美在线-久久99精品波多结衣一区-男女午夜免费视频-黑人极品ⅴideos精品欧美棵-人人妻人人澡人人爽精品欧美一区-日韩一区在线看-欧美a级在线免费观看

歡迎訪問(wèn) 生活随笔!

生活随笔

當(dāng)前位置: 首頁(yè) > 运维知识 > windows >内容正文

windows

​【安全牛学习笔记】操作系统识别

發(fā)布時(shí)間:2025/3/21 windows 20 豆豆
生活随笔 收集整理的這篇文章主要介紹了 ​【安全牛学习笔记】操作系统识别 小編覺(jué)得挺不錯(cuò)的,現(xiàn)在分享給大家,幫大家做個(gè)參考.

該筆記為安全牛課堂學(xué)員筆記,想看此課程或者信息安全類(lèi)干貨可以移步到安全牛課堂


Security+認(rèn)證為什么是互聯(lián)網(wǎng)+時(shí)代最火爆的認(rèn)證?


? ? ??牛妹先給大家介紹一下Security+

? ? ? ? Security+ 認(rèn)證是一種中立第三方認(rèn)證,其發(fā)證機(jī)構(gòu)為美國(guó)計(jì)算機(jī)行業(yè)協(xié)會(huì)CompTIA ;是和CISSP、ITIL 等共同包含在內(nèi)的國(guó)際 IT 業(yè) 10 大熱門(mén)認(rèn)證之一,和CISSP偏重信息安全管理相比,Security+ 認(rèn)證更偏重信息安全技術(shù)和操作。

? ? ? ?通過(guò)該認(rèn)證證明了您具備網(wǎng)絡(luò)安全,合規(guī)性和操作安全,威脅和漏洞,應(yīng)用程序、數(shù)據(jù)和主機(jī)安全,訪問(wèn)控制和身份管理以及加密技術(shù)等方面的能力。因其考試難度不易,含金量較高,目前已被全球企業(yè)和安全專(zhuān)業(yè)人士所普遍采納。

Security+認(rèn)證如此火爆的原因?

? ? ? ??

? ? ? ?原因一:在所有信息安全認(rèn)證當(dāng)中,偏重信息安全技術(shù)的認(rèn)證是空白的,?Security+認(rèn)證正好可以彌補(bǔ)信息安全技術(shù)領(lǐng)域的空白 。

? ??? 目前行業(yè)內(nèi)受認(rèn)可的信息安全認(rèn)證主要有CISP和CISSP,但是無(wú)論CISP還是CISSP都是偏重信息安全管理的,技術(shù)知識(shí)講的寬泛且淺顯,考試都是一帶而過(guò)。而且CISSP要求持證人員的信息安全工作經(jīng)驗(yàn)都要5年以上,CISP也要求大專(zhuān)學(xué)歷4年以上工作經(jīng)驗(yàn),這些要求無(wú)疑把有能力且上進(jìn)的年輕人的持證之路堵住。在現(xiàn)實(shí)社會(huì)中,無(wú)論是找工作還是升職加薪,或是投標(biāo)時(shí)候報(bào)人員,認(rèn)證都是必不可少的,這給年輕人帶來(lái)了很多不公平。而Security+的出現(xiàn)可以掃清這些年輕人職業(yè)發(fā)展中的障礙,由于Security+偏重信息安全技術(shù),所以對(duì)工作經(jīng)驗(yàn)沒(méi)有特別的要求。只要你有IT相關(guān)背景,追求進(jìn)步就可以學(xué)習(xí)和考試。


? ? ???原因二:?IT運(yùn)維人員工作與翻身的利器。

? ? ???在銀行、證券、保險(xiǎn)、信息通訊等行業(yè),IT運(yùn)維人員非常多,IT運(yùn)維涉及的工作面也非常廣。是一個(gè)集網(wǎng)絡(luò)、系統(tǒng)、安全、應(yīng)用架構(gòu)、存儲(chǔ)為一體的綜合性技術(shù)崗。雖然沒(méi)有程序猿們“生當(dāng)做光棍,死亦寫(xiě)代碼”的悲壯,但也有著“鋤禾日當(dāng)午,不如運(yùn)維苦“的感慨。天天對(duì)著電腦和機(jī)器,時(shí)間長(zhǎng)了難免有對(duì)于職業(yè)發(fā)展的迷茫和困惑。Security+國(guó)際認(rèn)證的出現(xiàn)可以讓有追求的IT運(yùn)維人員學(xué)習(xí)網(wǎng)絡(luò)安全知識(shí),掌握網(wǎng)絡(luò)安全實(shí)踐。職業(yè)發(fā)展朝著網(wǎng)絡(luò)安全的方向發(fā)展,解決國(guó)內(nèi)信息安全人才的匱乏問(wèn)題。另外,即使不轉(zhuǎn)型,要做好運(yùn)維工作,學(xué)習(xí)安全知識(shí)取得安全認(rèn)證也是必不可少的。


? ? ? ? 原因三:接地氣、國(guó)際范兒、考試方便、費(fèi)用適中!

CompTIA作為全球ICT領(lǐng)域最具影響力的全球領(lǐng)先機(jī)構(gòu),在信息安全人才認(rèn)證方面是專(zhuān)業(yè)、公平、公正的。Security+認(rèn)證偏重操作且和一線工程師的日常工作息息相關(guān)。適合銀行、證券、保險(xiǎn)、互聯(lián)網(wǎng)公司等IT相關(guān)人員學(xué)習(xí)。作為國(guó)際認(rèn)證在全球147個(gè)國(guó)家受到廣泛的認(rèn)可。

? ? ? ? 在目前的信息安全大潮之下,人才是信息安全發(fā)展的關(guān)鍵。而目前國(guó)內(nèi)的信息安全人才是非常匱乏的,相信Security+認(rèn)證一定會(huì)成為最火爆的信息安全認(rèn)證。

?近期,安全牛課堂在做此類(lèi)線上培訓(xùn),感興趣可以了解

操作系統(tǒng)識(shí)別

╋━━━━━━━━━━━━━━━╋

┃操作系統(tǒng)識(shí)別? ? ? ? ? ? ? ? ? ┃

┃操作系統(tǒng)識(shí)別技術(shù)? ? ? ? ? ? ? ┃

┃? 總類(lèi)繁多? ? ? ? ? ? ? ? ? ? ┃

┃? 好產(chǎn)品采用多種技術(shù)組合? ? ? ┃

┃TTL起始值? ? ? ? ? ? ? ? ? ? ?┃

┃? Windows: 128 (65-----128)? ?┃

┃? Linux/Unix: 60 (1-64)? ? ? ?┃

┃? 某些Unix: 255? ? ? ? ? ? ? ?┃

╋━━━━━━━━━━━━━━━╋

╋━━━━━━━━━━━━━━━╋

┃操作系統(tǒng)識(shí)別? ? ? ? ? ? ? ? ? ┃

┃python? ? ? ? ? ? ? ? ? ? ? ? ┃

┃? from scapy.all import? ? ? ?┃

┃? win="1.1.1.1"? ? ? ? ? ? ? ?┃

┃? linu="1.1.1.2"? ? ? ? ? ? ? ┃

┃? aw=sr1(IP(dst=win)/ICMP())? ┃

┃? al=sr1(IP(dst=linu)/ICMP()) ┃

┃? if a[IP].ttl<=64? ? ? ? ? ? ┃

┃? ? ? print "host is Linux"? ?┃

┃? else? ? ? ? ? ? ? ? ? ? ? ? ┃

┃? ? ? print "host is windows" ┃

┃? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ┃

┃./ttl_os.py? ? ? ? ? ? ? ? ? ?┃

╋━━━━━━━━━━━━━━━╋

╭────────────────────────────────────────────╮

[ttl_os.py]

#!/usr/bin/python

from scapy.all import *

import loggging

logging.getLogger("scapy.runtime").setLevel(logging.ERROR)

import sys

if len(sys.argv)!=2:

? print "Usage - ./ttl_os.py [IP Address]"

? print "Example - ./ttl_os.py 10.0.0.5"

? print "Example will perform ttl analysis to attempt to determine whether the system is windows or Linux"

? sys.exit()

ip=sys.argv[1]

ans=sr1(IP(dst=str(ip))/ICMP(),timeout=1,verbose=0)

if ans == None:

? print "No response was returned"

elif int(ans[IP].ttl)<=64:

? print "Host is Linux/Unix"

else:

? print "Host is Windows"

╰────────────────────────────────────────────╯

root@kali:~# chmod u+x ttl_os.py

root@kali:~# ./ttl_os.py 192.168.1.133

WARNING: No route found for IPv6 destination :: (no default route?)

Host is Windows

root@kali:~# ./ttl_os.py 192.168.1.134

WARNING: No route found for IPv6 destination :: (no default route?)

Host is Linux/Unix

root@kali:~# ./ttl_os.py 192.168.1.1

WARNING: No route found for IPv6 destination :: (no default route?)

Host is Linux/Unix

╋━━━━━━━━━━━━━━━╋

┃操作系統(tǒng)識(shí)別? ? ? ? ? ? ? ? ? ┃

┃nmap使用多種技術(shù)識(shí)別操作系統(tǒng)? ┃

┃? nmap 1.1.1.1 -O? ? ? ? ? ? ?┃

┃? 系統(tǒng)服務(wù)特征? ? ? ? ? ? ? ? ┃

╋━━━━━━━━━━━━━━━╋

root@kali:~# nmap -O 192.138.1.133

Starting Nmap 6.49BETA5 ( https://nmap.org ) at 2015-10-05 01:24 CST

Nmap scan report for 192.138.1.133

Host is up (0.00073s latency).

PORT? ? ? STATE SERVICE

135/tcp? ?open? msrpc

139/tcp? ?open? netbios- ssn

445/tcp? ?open? microsoft-ds

3389/tcp? open? ms-wbt-server

MAC Address: 80:00:27:B0:3A:76(Cadmus Computer Systems)

Device type: general purpose

Running: Microsoft Windows XP

OS CPE: cpe:/o:microsoft:windows_xp::sp2 cpe:/o:microsoft:windows_xp::sp3

OS details: microsoft Windos XP SP2 or SP3

OS detection performed. Please report any incorrect results at https://nmap.org/submit/ .

Nmap done: 1 IP address (1 host up) scanned in 7.47 seconds

root@kali:~# nmap -O 192.138.1.134

tarting Nmap 6.49BETA5 ( https://nmap.org ) at 2015-10-05 01:24 CST

Nmap scan report for 192.138.1.133

Host is up (0.00073s latency).

PORT? ? ?STATE SERVICE

21/tcp? ?open? ftp

22/tcp? ?open? ssh

23/tcp? ?open? telnet

25/tcp? ?open? smtb

53/tcp? ?open? domain

80/tcp? ?open? http

111/tcp? open? rpcbind

139/tcp? open? netbios-ssn

445/tcp? open? microsoft-ds

512/tcp? open? exec

513/tcp? open? login

514/tcp? open? shell

1099/tcp open? rmiregistry

1524/tcp open? ingreslock

2049/tcp open? nfs

2121/tcp open? ccproxy-ftp

3306/tcp open? mysql

5432/tcp open? postgresql

5900/tcp open? vnc

6000/tcp open? X11

6667/tcp open? irc

8009/tcp open? ajp13

8180/tcp open? unknown

MAC Address: 80:00:27:B0:3A:76(Cadmus Computer Systems)

Device type: general purpose

Running: Linux 2.6.X

OS CPE: cpe:/o: linux: linux_kernel:2.6

OS details: Linux 2.6.9 - 2.6.33

Network Distance: 1 hop

OS detection performed. Please report any incorrect results at https://nmap.org/submit/ .

Nmap done: 1 IP address (1 host up) scanned in 7.47 seconds

root@kali:~# nmap -O 192.138.1.1

Starting Nmap 6.49BETA5 ( https://nmap.org ) at 2015-10-03 16:31 CST

Nmap scan report for 192.168.1.1

Host is up (0.00082s latency).

PORT? ? ?STATE SERVICE

80/tcp? ?open? http

1900/tcp open? upup

MAC Address: Do:C7:C0:99:ED:3A (Tp-link Technologies Co.)

Warning: OSScan results may be unrelibale because we coule not find at least 1 open and 1 closed port

Aggressive OS guesses: Canon p_w_picpathRUNNER C5185 printer (98%), VxWorks(94%), Can on p_w_picpathRUNNER C2380i pinter(93%), Fujitsu Externus DX80 or IBM DCS9900 NAS divie(93%), Avaya 4526GTX switch (92%), HP ProCurve 3500yl,5406zl, or 6200yl switch or UTStarcom F100 VoIP phone(89%), Nortel CS1000M VoIP PBX or Xerox Phaser 8560DT printer(88%)

No exact OS matches for host (test conditions non-ideal).

Network distance: 1 hop

OS detection performed. Please report any incorrect results at https://nmap.org/submit/ .

Nmap done: 1 IP address (1 host up) scanned in 7.47 seconds

root@kali:~# xpro

xprobe2? xpro

root@kali:~# xprobe2 192.168.1.133? ? ? ? ? ? ? //專(zhuān)門(mén)識(shí)別操作系統(tǒng)的一個(gè)工具

? ? ? ? ? ? ? ? ? ? ? ? ? ? ?Xprobe2:主動(dòng)操作系統(tǒng)指紋工具

? ? XProbe是一款遠(yuǎn)程主機(jī)操作系統(tǒng)探查工具。開(kāi)發(fā)者基于和Nmap相同的一些技術(shù)(same techniques),并加入了自己的創(chuàng)新。Xprobe通過(guò)ICMP協(xié)議來(lái)獲得指紋。最新版本是Xprobe2.0.3版本,Xprobe2通過(guò)模糊矩陣統(tǒng)計(jì)分析主動(dòng)探測(cè)數(shù)據(jù)報(bào)對(duì)應(yīng)的ICMP數(shù)據(jù)報(bào)特征,進(jìn)而探測(cè)得到遠(yuǎn)端操作系統(tǒng)的類(lèi)型。注:經(jīng)過(guò)本人測(cè)試,對(duì)比較老的操作系統(tǒng),識(shí)別效果非常高,對(duì)新內(nèi)核系統(tǒng)則識(shí)別效果不太準(zhǔn)確。

? ? 下載鏈接:html">http://www.2cto.com/Soft/201012/25526.html

? ? 安裝步驟:

? ? #tar -zxvf? xprobe2-0.3.tar.gz

? ? #./configure --prefix=/usr/loca/

? ? # make

? ? #make install

? ? ?用法:

? ? #/usr/local/xprobe/bin/xprobe2 -h

? ?Options:

? ? ? ? ? ? ? -v? ? ? ? ? ? ? ? ? ? ? ?Be verbose

? ? ? ? ? ? ? -r? ? ? ? ? ? ? ? ? ? ? ?Show route to target(traceroute)

? ? ? ? ? ? ? -p Specify portnumber, protocol and state.

? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?Example: tcp:23:open, UDP:53:CLOSED

? ? ? ? ? ? ? -c? ? ? ? ? ?Specify config file to use.

? ? ? ? ? ? ? -h? ? ? ? ? ? ? ? ? ? ? ?Print this help.

? ? ? ? ? ? ? -o? ? ? ? ? ? ? ? Use logfile to log everything.

? ? ? ? ? ? ? -t? ? ? ? ? ? ?Set initial receive timeout or roundtrip time.

? ? ? ? ? ? ? -s? ? ? ? ? ?Set packsending delay (milseconds).

? ? ? ? ? ? ? -d? ? ? ? ? ? ? Specify debugging level.

? ? ? ? ? ? ? -D? ? ? ? ? ? ? ?Disable module number .

? ? ? ? ? ? ? -M? ? ? ? ? ? ? ?Enable module number .

? ? ? ? ? ? ? -L? ? ? ? ? ? ? ? ? ? ? ?Display modules.

? ? ? ? ? ? ? -m? ? ? ? ?Specify number of matches to print.

? ? ? ? ? ? ? -T? ? ? ? ? ? ?Enable TCP portscan for specified port(s).

? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?Example: -T21-23,53,110

? ? ? ? ? ? ? -U? ? ? ? ? ? ?Enable UDP portscan for specified port(s).

? ? ? ? ? ? ? -f? ? ? ? ? ? ? force fixed round-trip time (-t opt).

? ? ? ? ? ? ? -F? ? ? ? ? Generate signature (use -o to save to a file).

? ? ? ? ? ? ? -X? ? Generate XML output and save it to logfile specified with -o.

? ? ? ? ? ? ? -B? ?Options forces TCP handshake module to try to guess open TCP port

? ? ? ? ? ? ? -A? ?Perform analysis of sample packets gathered during portscan in

? ? ? ? ? ? ? ? ? ? order to detect suspicious traffic (i.e. transparent proxies,

? ? ? ? ? firewalls/NIDSs resetting connections). Use with -T.

? ? 以上個(gè)選項(xiàng),讀者可自己去測(cè)試。本人給出一個(gè)簡(jiǎn)單的測(cè)試,假設(shè)當(dāng)前目錄在/usr/local/xprobe/bin/下

? ? #./xprobe2 www.163.com

? ? Xprobe2 v.0.3 Copyright (c) 2002-2005 fyodor@o0o.nu, ofir@sys-security.com,

? ? ?meder@o0o.nu

? ? [+] Target is www.163.com

? ? [+] Loading modules.

? ? [+] Following modules are loaded:

? ? [x] [1] ping:icmp_ping? -? ICMP echo discovery module

? ? [x] [2] ping:tcp_ping? -? TCP-based ping discovery module

? ? [x] [3] ping:udp_ping? -? UDP-based ping discovery module

? ? [x] [4] infogather:ttl_calc? -? TCP and UDP based TTL distance calculation

? ? [x] [5] infogather:portscan? -? TCP and UDP PortScanner

? ? [x] [6] fingerprint:icmp_echo? -? ICMP Echo request fingerprinting module

? ? [x] [7] fingerprint:icmp_tstamp? -? ICMP Timestamp request fingerprinting module

? ? [x] [8] fingerprint:icmp_amask? -? ICMP Address mask request fingerprinting module

? ? [x] [9] fingerprint:icmp_port_unreach? -? ICMP port unreachable fingerprinting module

? ? [x] [10] fingerprint:tcp_hshake? -? TCP Handshake fingerprinting module

? ? [x] [11] fingerprint:tcp_rst? -? TCP RST fingerprinting module

? ? [x] [12] fingerprint:smb? -? SMB fingerprinting module

? ? [x] [13] fingerprint:snmp? -? SNMPv2c fingerprinting module

? ? [+] 13 modules registered

? ? [+] Initializing scan engine

? ? [+] Running scan engine

? ? [-] ping:tcp_ping module: no closed/open TCP ports known on 220.181.28.51.?

? ? Module test failed

? ? [-] ping:udp_ping module: no closed/open UDP ports known on 220.181.28.51.?

? ? Module test failed

? ? [-] No distance calculation. 220.181.28.51 appears to be dead or no ports known

? ? [+] Host: 220.181.28.51 is up (Guess probability: 50%)

? ? [+] Target: 220.181.28.51 is alive. Round-Trip Time: 0.02320 sec

? ? [+] Selected safe Round-Trip Time value is: 0.04640 sec

? ? [-] fingerprint:tcp_hshake Module execution aborted (no open TCP ports known)

? ? [-] fingerprint:smb need either TCP port 139 or 445 to run

? ? [-] fingerprint:snmp: need UDP port 161 open

? ? [+] Primary guess:

? ? [+] Host 220.181.28.51 Running OS: "Linux Kernel 2.6.6" (Guess probability: 100%)

? ? [+] Other guesses:

? ? [+] Host 220.181.28.51 Running OS: "Linux Kernel 2.6.7" (Guess probability: 100%)

? ? [+] Host 220.181.28.51 Running OS: "Linux Kernel 2.6.8" (Guess probability: 100%)

? ? [+] Host 220.181.28.51 Running OS: "Linux Kernel 2.6.9" (Guess probability: 100%)

? ? [+] Host 220.181.28.51 Running OS: "Linux Kernel 2.6.10" (Guess probability: 100%)

? ? [+] Host 220.181.28.51 Running OS: "Linux Kernel 2.6.11" (Guess probability: 100%)

? ? [+] Host 220.181.28.51 Running OS: "Linux Kernel 2.6.5" (Guess probability: 100%)

? ? [+] Host 220.181.28.51 Running OS: "Linux Kernel 2.6.4" (Guess probability: 100%)

? ? [+] Host 220.181.28.51 Running OS: "Linux Kernel 2.6.0" (Guess probability: 100%)

? ? [+] Host 220.181.28.51 Running OS: "Linux Kernel 2.6.1" (Guess probability: 100%)

? ? [+] Cleaning up scan engine

? ? [+] Modules deinitialized

? ? [+] Execution completed

╋━━━━━━━━━━━━━━━╋

┃操作系統(tǒng)識(shí)別? ? ? ? ? ? ? ? ? ┃

┃被動(dòng)操作系統(tǒng)識(shí)別? ? ? ? ? ? ? ┃

┃? IDS? ? ? ? ? ? ? ? ? ? ? ? ?┃

┃? 抓包分析? ? ? ? ? ? ? ? ? ? ┃

┃被動(dòng)掃描? ? ? ? ? ? ? ? ? ? ? ┃

┃p0f? ? ? ? ? ? ? ? ? ? ? ? ? ?┃

┃? 結(jié)合ARP地址欺騙識(shí)別全網(wǎng)OS? ?┃

╋━━━━━━━━━━━━━━━╋

root@kali:~# p0f

--- p0f 3.07b by Michal Zalewski <lcamtuf@coredump.cx> ---

[+] Closed 1 file descriptor.

[+] Loaded 320 signatures from 'p0f.fp'.

[+] Intercepting traffic on default interface 'eth0'.

[+] Default packet filtering configured [+VLAN].

[+] Entered main event loop.

.-[ 192.168.1.107/50093 -> 64.233.187.136/443 (syn) ]-

|

| client? ?= 192.168.1.107/50093

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/50093 -> 64.233.187.136/443 (mtu) ]-

|

| client? ?= 192.168.1.107/50093

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/50094 -> 64.233.187.136/443 (syn) ]-

|

| client? ?= 192.168.1.107/50094

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/50094 -> 64.233.187.136/443 (mtu) ]-

|

| client? ?= 192.168.1.107/50094

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/50094 -> 64.233.187.136/443 (uptime) ]-

|

| client? ?= 192.168.1.107/50094

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 250.00 Hz

|

`----

^C[!] WARNING: User-initiated shutdown.

All done. Processed 10 packets.

root@kali:~# p0f

--- p0f 3.07b by Michal Zalewski <lcamtuf@coredump.cx> ---

[+] Closed 1 file descriptor.

[+] Loaded 320 signatures from 'p0f.fp'.

[+] Intercepting traffic on default interface 'eth0'.

[+] Default packet filtering configured [+VLAN].

[+] Entered main event loop.

.-[ 192.168.1.107/54895 -> 180.97.33.107/80 (syn) ]-

|

| client? ?= 192.168.1.107/54895

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/54895 -> 180.97.33.107/80 (mtu) ]-

|

| client? ?= 192.168.1.107/54895

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/54895 -> 180.97.33.107/80 (syn+ack) ]-

|

| server? ?= 180.97.33.107/80

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/54895 -> 180.97.33.107/80 (mtu) ]-

|

| server? ?= 180.97.33.107/80

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/54895 -> 180.97.33.107/80 (http request) ]-

|

| client? ?= 192.168.1.107/54895

| app? ? ? = Firefox 10.x or newer

| lang? ? ?= English

| params? ?= none

| raw_sig? = 1:Host,User-Agent,Accept=[text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8],Accept-Language=[en-US,en;q=0.5],Accept-Encoding=[gzip, deflate],?Cookie,Connection=[keep-alive]:Accept-Charset,Keep-Alive:Mozilla/5.0 (X11; Linux i686; rv:38.0) Gecko/20100101 Firefox/38.0 Iceweasel/38.3.0

|

`----

-[ 192.168.1.107/54895 -> 180.97.33.107/80 (http response) ]-

|

| server? ?= 180.97.33.107/80

| app? ? ? = ???

| lang? ? ?= none

| params? ?= none

| raw_sig? = 1:Date,Content-Type,?Content-Length,Connection=[Keep-Alive],?Location,Server,X-UA-Compatible=[IE=Edge,chrome=1],?Set-Cookie:Keep-Alive,Accept-Ranges:BWS/1.1

|

`----

.-[ 192.168.1.107/57542 -> 180.97.33.107/443 (syn) ]-

|

| client? ?= 192.168.1.107/57542

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/57542 -> 180.97.33.107/443 (mtu) ]-

|

| client? ?= 192.168.1.107/57542

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/57542 -> 180.97.33.107/443 (uptime) ]-

|

| client? ?= 192.168.1.107/57542

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 258.62 Hz

|

`----

.-[ 192.168.1.107/57542 -> 180.97.33.107/443 (syn+ack) ]-

|

| server? ?= 180.97.33.107/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/57542 -> 180.97.33.107/443 (mtu) ]-

|

| server? ?= 180.97.33.107/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/33274 -> 58.215.118.32/443 (syn) ]-

|

| client? ?= 192.168.1.107/33274

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/33274 -> 58.215.118.32/443 (mtu) ]-

|

| client? ?= 192.168.1.107/33274

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/33274 -> 58.215.118.32/443 (uptime) ]-

|

| client? ?= 192.168.1.107/33274

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 249.49 Hz

|

`----

.-[ 192.168.1.107/33274 -> 58.215.118.32/443 (syn+ack) ]-

|

| server? ?= 58.215.118.32/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,2:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/33274 -> 58.215.118.32/443 (mtu) ]-

|

| server? ?= 58.215.118.32/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/57544 -> 180.97.33.107/443 (syn) ]-

|

| client? ?= 192.168.1.107/57544

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/57544 -> 180.97.33.107/443 (mtu) ]-

|

| client? ?= 192.168.1.107/57544

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/57544 -> 180.97.33.107/443 (uptime) ]-

|

| client? ?= 192.168.1.107/57544

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 252.34 Hz

|

`----

.-[ 192.168.1.107/57544 -> 180.97.33.107/443 (syn+ack) ]-

|

| server? ?= 180.97.33.107/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/57544 -> 180.97.33.107/443 (mtu) ]-

|

| server? ?= 180.97.33.107/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/42700 -> 58.215.118.33/443 (syn) ]-

|

| client? ?= 192.168.1.107/42700

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/42700 -> 58.215.118.33/443 (mtu) ]-

|

| client? ?= 192.168.1.107/42700

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/42700 -> 58.215.118.33/443 (uptime) ]-

|

| client? ?= 192.168.1.107/42700

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 233.33 Hz

|

`----

.-[ 192.168.1.107/42701 -> 58.215.118.33/443 (syn) ]-

|

| client? ?= 192.168.1.107/42701

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/42701 -> 58.215.118.33/443 (mtu) ]-

|

| client? ?= 192.168.1.107/42701

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/42702 -> 58.215.118.33/443 (syn) ]-

|

| client? ?= 192.168.1.107/42702

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/42702 -> 58.215.118.33/443 (mtu) ]-

|

| client? ?= 192.168.1.107/42702

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/42700 -> 58.215.118.33/443 (syn+ack) ]-

|

| server? ?= 58.215.118.33/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,2:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/42700 -> 58.215.118.33/443 (mtu) ]-

|

| server? ?= 58.215.118.33/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/42702 -> 58.215.118.33/443 (syn+ack) ]-

|

| server? ?= 58.215.118.33/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,2:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/42702 -> 58.215.118.33/443 (mtu) ]-

|

| server? ?= 58.215.118.33/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/42701 -> 58.215.118.33/443 (syn+ack) ]-

|

| server? ?= 58.215.118.33/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,2:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/42701 -> 58.215.118.33/443 (mtu) ]-

|

| server? ?= 58.215.118.33/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/42703 -> 58.215.118.33/443 (syn) ]-

|

| client? ?= 192.168.1.107/42703

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/42703 -> 58.215.118.33/443 (mtu) ]-

|

| client? ?= 192.168.1.107/42703

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/42703 -> 58.215.118.33/443 (syn+ack) ]-

|

| server? ?= 58.215.118.33/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,2:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/42703 -> 58.215.118.33/443 (mtu) ]-

|

| server? ?= 58.215.118.33/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/42703 -> 58.215.118.33/443 (uptime) ]-

|

| client? ?= 192.168.1.107/42703

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 261.90 Hz

|

`----

.-[ 192.168.1.107/33280 -> 58.215.118.32/443 (syn) ]-

|

| client? ?= 192.168.1.107/33280

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/33280 -> 58.215.118.32/443 (mtu) ]-

|

| client? ?= 192.168.1.107/33280

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/33280 -> 58.215.118.32/443 (uptime) ]-

|

| client? ?= 192.168.1.107/33280

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 250.87 Hz

|

`----

.-[ 192.168.1.107/33281 -> 58.215.118.32/443 (syn) ]-

|

| client? ?= 192.168.1.107/33281

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/33281 -> 58.215.118.32/443 (mtu) ]-

|

| client? ?= 192.168.1.107/33281

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/33280 -> 58.215.118.32/443 (syn+ack) ]-

|

| server? ?= 58.215.118.32/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,2:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/33280 -> 58.215.118.32/443 (mtu) ]-

|

| server? ?= 58.215.118.32/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/33281 -> 58.215.118.32/443 (syn+ack) ]-

|

| server? ?= 58.215.118.32/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,2:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/33281 -> 58.215.118.32/443 (mtu) ]-

|

| server? ?= 58.215.118.32/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/57551 -> 180.97.33.107/443 (syn) ]-

|

| client? ?= 192.168.1.107/57551

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/57551 -> 180.97.33.107/443 (mtu) ]-

|

| client? ?= 192.168.1.107/57551

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/57551 -> 180.97.33.107/443 (uptime) ]-

|

| client? ?= 192.168.1.107/57551

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 248.83 Hz

|

`----

.-[ 192.168.1.107/57551 -> 180.97.33.107/443 (syn+ack) ]-

|

| server? ?= 180.97.33.107/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/57551 -> 180.97.33.107/443 (mtu) ]-

|

| server? ?= 180.97.33.107/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/38572 -> 180.97.33.108/443 (syn) ]-

|

| client? ?= 192.168.1.107/38572

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/38572 -> 180.97.33.108/443 (mtu) ]-

|

| client? ?= 192.168.1.107/38572

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/38572 -> 180.97.33.108/443 (uptime) ]-

|

| client? ?= 192.168.1.107/38572

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 247.93 Hz

|

`----

.-[ 192.168.1.107/38572 -> 180.97.33.108/443 (syn+ack) ]-

|

| server? ?= 180.97.33.108/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/38572 -> 180.97.33.108/443 (mtu) ]-

|

| server? ?= 180.97.33.108/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/50093 -> 64.233.187.136/443 (syn) ]-

|

| client? ?= 192.168.1.107/50093

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

----

.-[ 192.168.1.107/50093 -> 64.233.187.136/443 (mtu) ]-

|

| client? ?= 192.168.1.107/50093

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/50093 -> 64.233.187.136/443 (uptime) ]-

|

| client? ?= 192.168.1.107/50093

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 253.38 Hz

|

`----

.-[ 192.168.1.107/38573 -> 180.97.33.108/443 (syn) ]-

|

| client? ?= 192.168.1.107/38573

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/38573 -> 180.97.33.108/443 (mtu) ]-

|

| client? ?= 192.168.1.107/38573

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/38573 -> 180.97.33.108/443 (uptime) ]-

|

| client? ?= 192.168.1.107/38573

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 248.91 Hz

|

`----

.-[ 192.168.1.107/38573 -> 180.97.33.108/443 (syn+ack) ]-

|

| server? ?= 180.97.33.108/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/38573 -> 180.97.33.108/443 (mtu) ]-

|

| server? ?= 180.97.33.108/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

.-[ 192.168.1.107/50094 -> 64.233.187.136/443 (syn) ]-

|

| client? ?= 192.168.1.107/50094

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/50094 -> 64.233.187.136/443 (mtu) ]-

|

| client? ?= 192.168.1.107/50094

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/50094 -> 64.233.187.136/443 (uptime) ]-

|

| client? ?= 192.168.1.107/50094

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 259.26 Hz

|

`----

.-[ 192.168.1.107/57554 -> 180.97.33.107/443 (syn) ]-

|

| client? ?= 192.168.1.107/57554

| os? ? ? ?= Linux 3.11 and newer

| dist? ? ?= 0

| params? ?= none

| raw_sig? = 4:64+0:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/57554 -> 180.97.33.107/443 (mtu) ]-

|

| client? ?= 192.168.1.107/57554

| link? ? ?= Ethernet or modem

| raw_mtu? = 1500

|

`----

.-[ 192.168.1.107/57554 -> 180.97.33.107/443 (uptime) ]-

|

| client? ?= 192.168.1.107/57554

| uptime? ?= 0 days 0 hrs 8 min (modulo 198 days)

| raw_freq = 245.76 Hz

|

`----

.-[ 192.168.1.107/57554 -> 180.97.33.107/443 (syn+ack) ]-

|

| server? ?= 180.97.33.107/443

| os? ? ? ?= ???

| dist? ? ?= 9

| params? ?= none

| raw_sig? = 4:55+9:0:1440:mss*20,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:0

|

`----

.-[ 192.168.1.107/57554 -> 180.97.33.107/443 (mtu) ]-

|

| server? ?= 180.97.33.107/443

| link? ? ?= IPIP or SIT

| raw_mtu? = 1480

|

`----

╋━━━━━━━━━━━━━━━━━━━━━━━━╋

┃SNMP? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ┃

┃snmp? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ┃

┃? 信息的金礦? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ┃

┃? 經(jīng)常被錯(cuò)誤配置? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ┃

┃? public / prtvate / manager? ? ? ? ? ? ? ? ? ? ┃

┃MIB Tree? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ┃

┃? SNMP Management Informattion Base (MID)? ? ? ?┃

┃? 樹(shù)形的網(wǎng)絡(luò)設(shè)備管理功能數(shù)據(jù)庫(kù)? ? ? ? ? ? ? ? ? ┃

┃? 1.3.6.1.4.1.77.1.2.25? ? ? ? ? ? ? ? ? ? ? ? ?┃

┃onesixtyone 1.1.1.1 public? ? ? ? ? ? ? ? ? ? ? ┃

┃onesixtyone -c dict.txt -i hosts -o my.log -w 100┃

╋━━━━━━━━━━━━━━━━━━━━━━━━╋

? ? ?簡(jiǎn)單網(wǎng)絡(luò)管理協(xié)議(SNMP),由一組網(wǎng)絡(luò)管理的標(biāo)準(zhǔn)組成,包含一個(gè)應(yīng)用層協(xié)議(application layer protocol)、數(shù)據(jù)庫(kù)模型(database schema)和一組資源對(duì)象。該協(xié)議能夠支持網(wǎng)絡(luò)管理系統(tǒng),用以監(jiān)測(cè)連接到網(wǎng)絡(luò)上的設(shè)備是否有任何引起管理上關(guān)注的情況。該協(xié)議是互聯(lián)網(wǎng)工程工作小組(IETF,Internet Engineering Task Force)定義的internet協(xié)議簇的一部分。SNMP的目標(biāo)是管理互聯(lián)網(wǎng)Internet上眾多廠家生產(chǎn)的軟硬件平臺(tái),因此SNMP受Internet標(biāo)準(zhǔn)網(wǎng)絡(luò)管理框架的影響也很大。SNMP已經(jīng)出到第三個(gè)版本的協(xié)議,其功能較以前已經(jīng)大大地加強(qiáng)和改進(jìn)了。

root@kali:~# onesixtyone

onesixtyone 0.3.2 [options] <host> <community>

? -c <communityfile> file with community names to try

? -i <inputfile>? ? ?file with target hosts

? -o <outputfile>? ? output log

? -d? ? ? ? ? ? ? ? ?debug mode, use twice for more information


? -w n? ? ? ? ? ? ? ?wait n milliseconds (1/1000 of a second) between sending packets (default 10)

? -q? ? ? ? ? ? ? ? ?quiet mode, do not print log to stdout, use with -l

examples: ./s -c dict.txt 192.168.4.1 public

? ? ? ? ? ./s -c dict.txt -i hosts -o my.log -w 100

root@kali:~# onesixtyone 192.168.1.133 pulic

Scanning 1 hosts, 1 communities

192.168.1.133 [public] Hardware: x86 Family 6 Model 42 Steping 7 AT/AT COMPATIBLE - Software: Windows 2000 Version 5.1(Bulid 2600 Uniprocessor Free)

root@kali:~# dpkg -L onesixtyone

/.

/usr

/usr/bin

/usr/bin/onesixtyone

/usr/share

/usr/share/man

/usr/share/man/man1

/usr/share/man/man1/onesixtyone.1.gz

/usr/share/doc

/usr/share/doc/onesixtyone

/usr/share/doc/onesixtyone/copyright

/usr/share/doc/onesixtyone/changelog.gz

/usr/share/doc/onesixtyone/dict.txt

/usr/share/doc/onesixtyone/README

/usr/share/doc/onesixtyone/changelog.Debian.gz

root@kali:~# onesixtyone -c /usr/share/doc/onesixtyone/dict.txt 192.168.1.133 -o my.log -w 100

Logging to file my.log

Scanning 1 hosts, 49 communities

root@kali:~# nmap -sU -p161 192.168.1.134

Starting Nmap 6.49BETA5 ( https://nmap.org ) at 2015-10-06 00:32 CST

Note is up(0.00105 latency).

PORT? ? STATE? SERVICE

161/udp closed snmp

MAC Address: 08:00:27:Bo:3A:76 (Cadmus Computer Systems)

Nmap done: 1 IP address (0 hosts up) scanned in 0.55 seconds

╋━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╋

┃SNMP掃描? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ┃

┃snmpwalk 192.168.20.199 -c public -v 2c? ? ? ? ? ? ? ? ? ?┃

┃用戶? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ┃

┃? ? snmpwalk -c public -v 2c 1.1.1.1 1.3.6.1.4.1.77.1.2.25┃

┃snmpcheck -t 192.168.20.199? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?┃

┃snmpcheck? -t 192.168.20.199 -c private -v 2? ? ? ? ? ? ? ┃

┃snmpcheck? -t 192.168.20.199 -w? ? ? ? ? ? ? ? ? ? ? ? ? ?┃

╋━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╋

root@kali:~# snmpwalk 192.168.1.133 -c public -v 2c

root@kali:~# snmpwalk -c public -v 2c 192.168.1.133 1.3.6.1.4.1.77.1.2.25

root@kali:~# snmpwalk -c public -v 2c 192.168.1.133 1.3.6.1.2.1.25.6.3.1.2

root@kali:~# snmpcheck -h

Usage:? snmpcheck [-x] [-n|y] [-h] [-H] [-V NUM] [-L] [-f] [[-a] HOSTS]?

? -h Display this message.

? -a check error log file AND hosts specified on command line.

? -p Don't try and ping-echo the host first

? -f Only check for things I can fix

? HOSTS check these hosts for problems.

X Options:

? -x forces ascii base if $DISPLAY set (instead of tk).

? -H start in hidden mode.? (hides user interface)

? -V NUM sets the initial verbosity level of the command log (def: 1)

? -L Show the log window at startup

? -d Don't start by checking anything.? Just bring up the interface.

Ascii Options:

? -n Don't ever try and fix the problems found.? Just list.

? -y Always fix problems found.

root@kali:~# snmpcheck -t 192.168.1.133

轉(zhuǎn)載于:https://blog.51cto.com/11672938/1965387

總結(jié)

以上是生活随笔為你收集整理的​【安全牛学习笔记】操作系统识别的全部?jī)?nèi)容,希望文章能夠幫你解決所遇到的問(wèn)題。

如果覺(jué)得生活随笔網(wǎng)站內(nèi)容還不錯(cuò),歡迎將生活随笔推薦給好友。