Task 3 - Nmap Switches
What is the first switch listed in the help menu for a 'Syn Scan' (more on this later!)?
Which switch would you use for a "UDP scan"?
If you wanted to detect which operating system the target is running on, which switch would you use?
Nmap provides a switch to detect the version of the services running on the target. What is this switch?
The default output provided by nmap often does not provide enough information for a pentester. How would you increase the verbosity?
Verbosity level one is good, but verbosity level two is better! How would you set the verbosity level to two? (Note: it's highly advisable to always use at least this option)
Verbosity and debugging options
What switch would you use to save the nmap results in three major formats?
What switch would you use to save the nmap results in a "normal" format?
A very useful output format: how would you save results in a "grepable" format?
How would you activate this setting?
How would you set the timing template to level 5?
How would you tell nmap to only scan port 80?
How would you tell nmap to scan ports 1000-1500?
How would you tell nmap to scan all ports?
How would you activate a script from the nmap scripting library (lots more on this later!)?
How would you activate all of the scripts in the "vuln" category?
Last updated
