{"id":1466,"date":"2026-01-29T22:10:37","date_gmt":"2026-01-29T14:10:37","guid":{"rendered":"http:\/\/www.preluna.xyz\/?p=1466"},"modified":"2026-02-02T09:39:49","modified_gmt":"2026-02-02T01:39:49","slug":"nmap","status":"publish","type":"post","link":"http:\/\/www.preluna.xyz\/index.php\/2026\/01\/29\/nmap\/preluna\/text\/","title":{"rendered":"\u7b2c1\u90e8\u5206\uff1a\u8ba4\u8bc6Nmap \u2014\u2014 \u7f51\u7edc\u4e2d\u7684\u201c\u5730\u56fe\u7ed8\u5236\u4eea\u201d"},"content":{"rendered":"\n<p>Nmap\uff08Network Mapper\uff09\u662f\u4e00\u6b3e\u5f00\u6e90\u7684\u7f51\u7edc\u63a2\u6d4b\u548c\u5b89\u5168\u5ba1\u8ba1\u5de5\u5177\u3002\u4f60\u53ef\u4ee5\u628a\u5b83\u60f3\u8c61\u6210\u7f51\u7edc\u4e16\u754c\u91cc\u7684\u201c\u5730\u56fe\u7ed8\u5236\u4eea\u201d\u6216\u201c\u96f7\u8fbe\u201d\uff0c\u5b83\u7684\u6838\u5fc3\u4f5c\u7528\u662f\u5e2e\u4f60\u53d1\u73b0\u3001\u63a2\u7d22\u548c\u7406\u89e3\u7f51\u7edc\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5b83\u80fd\u505a\u4ec0\u4e48\uff1f<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u53d1\u73b0\u4e3b\u673a<\/strong>\uff1a\u627e\u51fa\u7f51\u7edc\u91cc\u6709\u54ea\u4e9b\u8bbe\u5907\u5728\u7ebf\u3002<\/li>\n\n\n\n<li><strong>\u626b\u63cf\u7aef\u53e3<\/strong>\uff1a\u68c0\u67e5\u76ee\u6807\u8bbe\u5907\u4e0a\u54ea\u4e9b\u201c\u95e8\u201d\uff08\u7aef\u53e3\uff09\u662f\u6253\u5f00\u7684\u3002<\/li>\n\n\n\n<li><strong>\u8bc6\u522b\u670d\u52a1<\/strong>\uff1a\u5224\u65ad\u8fd9\u4e9b\u5f00\u653e\u7684\u201c\u95e8\u201d\u540e\u8fd0\u884c\u7684\u662f\u4ec0\u4e48\u7a0b\u5e8f\uff08\u5982Web\u670d\u52a1\u5668\u3001\u6570\u636e\u5e93\uff09\uff0c\u751a\u81f3\u662f\u4ec0\u4e48\u7248\u672c\u3002<\/li>\n\n\n\n<li><strong>\u63a8\u6d4b\u7cfb\u7edf<\/strong>\uff1a\u5206\u6790\u76ee\u6807\u8bbe\u5907\u8fd0\u884c\u7684\u64cd\u4f5c\u7cfb\u7edf\u7c7b\u578b\u3002<\/li>\n\n\n\n<li><strong>\u9ad8\u7ea7\u811a\u672c<\/strong>\uff1a\u901a\u8fc7\u5185\u7f6e\u811a\u672c\u5f15\u64ce\u8fdb\u884c\u6f0f\u6d1e\u68c0\u6d4b\u7b49\u66f4\u6df1\u5165\u7684\u5de5\u4f5c\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u91cd\u8981\u524d\u63d0\uff1a\u6cd5\u5f8b\u4e0e\u9053\u5fb7<\/strong><br><strong>\u672a\u7ecf\u6388\u6743\u626b\u63cf\u4ed6\u4eba\u7684\u7f51\u7edc\u6216\u7cfb\u7edf\uff0c\u5728\u5f88\u591a\u5730\u533a\u662f\u8fdd\u6cd5\u884c\u4e3a<\/strong>\u3002\u8bf7<strong>\u4ec5\u5728\u4f60\u62e5\u6709\u5408\u6cd5\u6743\u9650\u7684\u7f51\u7edc<\/strong>\uff08\u5982\u4f60\u81ea\u5df1\u7684\u5bb6\u5ead\u7f51\u7edc\u3001\u516c\u53f8\u6388\u6743\u6d4b\u8bd5\u7684\u7f51\u7edc\u3001\u6216\u4e13\u95e8\u7684\u5b9e\u9a8c\u73af\u5883\u5982Metasploitable2\uff09\u4e2d\u8fdb\u884c\u7ec3\u4e60\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u7b2c2\u90e8\u5206\uff1a\u5b89\u88c5Nmap<\/strong><\/h2>\n\n\n\n<p>Nmap\u652f\u6301\u6240\u6709\u4e3b\u6d41\u64cd\u4f5c\u7cfb\u7edf\u3002\u5b98\u65b9\u4e0b\u8f7d\u5730\u5740\u662f <code>https:\/\/nmap.org\/download.html<\/code>\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Windows\u7cfb\u7edf<\/strong>\uff1a\n<ol class=\"wp-block-list\">\n<li>\u4ece\u5b98\u7f51\u4e0b\u8f7d\u5b89\u88c5\u5305\uff08\u5982 <code>nmap-7.98-setup.exe<\/code>\uff09\u3002<\/li>\n\n\n\n<li>\u8fd0\u884c\u5b89\u88c5\u7a0b\u5e8f\uff0c\u52a1\u5fc5\u52fe\u9009\u5b89\u88c5 <strong>Npcap<\/strong>\uff08\u8fd9\u662f\u5b9e\u73b0\u626b\u63cf\u529f\u80fd\u7684\u6838\u5fc3\u9a71\u52a8\uff09\u3002<\/li>\n\n\n\n<li>\u53ef\u9009\u52fe\u9009 <strong>Zenmap<\/strong>\uff08\u56fe\u5f62\u754c\u9762\uff0c\u9002\u5408\u65b0\u624b\u5165\u95e8\uff09\u3002<\/li>\n\n\n\n<li>\u5b89\u88c5\u5b8c\u6210\u540e\uff0c\u6253\u5f00\u201c\u547d\u4ee4\u63d0\u793a\u7b26\u201d\uff0c\u8f93\u5165 <code>nmap --version<\/code>\uff0c\u5982\u663e\u793a\u7248\u672c\u53f7\u5219\u5b89\u88c5\u6210\u529f\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li><strong>Linux (Ubuntu\/Debian)<\/strong>\uff1a<br>\u5728\u7ec8\u7aef\u4e2d\u6267\u884c\uff1a <code>sudo apt-get update sudo apt-get install nmap<\/code><\/li>\n\n\n\n<li><strong>macOS<\/strong>\uff1a<br>\u5982\u679c\u4f60\u5b89\u88c5\u4e86Homebrew\uff0c\u5728\u7ec8\u7aef\u6267\u884c\uff1a <code>brew install nmap<\/code><\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap1-1024x92.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"92\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap1-1024x92.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1467\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u7b2c3\u90e8\u5206\uff1a\u6838\u5fc3\u64cd\u4f5c\u5b9e\u6218 \u2014\u2014 \u4ece\u7b80\u5355\u5230\u7cbe\u901a<\/strong><\/h2>\n\n\n\n<p>Nmap\u7684\u57fa\u672c\u547d\u4ee4\u683c\u5f0f\u4e3a\uff1a<code>nmap [\u626b\u63cf\u7c7b\u578b] [\u9009\u9879] {\u76ee\u6807}<\/code>\u3002\u4e0b\u9762\u6211\u4eec\u4ece\u6700\u7b80\u5355\u7684\u547d\u4ee4\u5f00\u59cb\u3002<\/p>\n\n\n\n<p><strong>\u7b2c\u4e00\u6b65\uff1a\u9a8c\u8bc1\u5b89\u88c5\u4e0e\u9996\u6b21\u626b\u63cf<\/strong><br>\u6253\u5f00\u547d\u4ee4\u884c\uff08\u7ec8\u7aef\/CMD\uff09\uff0c\u8f93\u5165\u4ee5\u4e0b\u547d\u4ee4\uff0c\u8fd9\u5c06\u5bf9Nmap\u5b98\u65b9\u63d0\u4f9b\u7684\u6d4b\u8bd5\u4e3b\u673a\u8fdb\u884c\u4e00\u6b21\u6700\u57fa\u7840\u7684\u626b\u63cf\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap scanme.nmap.org<\/code><\/pre>\n\n\n\n<p>\u4f60\u4f1a\u770b\u5230\u4e00\u4e2a\u7b80\u5355\u7684\u62a5\u544a\uff0c\u5217\u51fa\u8be5\u4e3b\u673a\u5f00\u653e\u7684\u7aef\u53e3\u53ca\u5bf9\u5e94\u7684\u670d\u52a1\u540d\u79f0\uff08\u5982 <code>80\/tcp open http<\/code>\uff09\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap2-1024x320.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"320\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap2-1024x320.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1468\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p><strong>\u7b2c\u4e8c\u6b65\uff1a\u638c\u63e1\u56db\u5927\u6838\u5fc3\u626b\u63cf\u6280\u672f<\/strong><br>\u9488\u5bf9\u4e0d\u540c\u573a\u666f\u548c\u76ee\u6807\uff0c\u4f60\u9700\u8981\u9009\u62e9\u4e0d\u540c\u7684\u626b\u63cf\u65b9\u5f0f\u3002\u4e0b\u8868\u5bf9\u6bd4\u4e86\u6700\u5e38\u7528\u7684\u51e0\u79cd\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u626b\u63cf\u7c7b\u578b<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u547d\u4ee4\u9009\u9879<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u5de5\u4f5c\u539f\u7406<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u7279\u70b9\u4e0e\u9002\u7528\u573a\u666f<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u6240\u9700\u6743\u9650<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>TCP SYN\u626b\u63cf (\u534a\u5f00\u653e\u626b\u63cf)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>-sS<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u53d1\u9001SYN\u5305\uff0c\u6536\u5230SYN\/ACK\u56de\u590d\u5373\u8ba4\u4e3a\u7aef\u53e3\u5f00\u653e\uff0c\u968f\u540e\u4e2d\u65ad\u8fde\u63a5\uff0c\u4e0d\u5b8c\u6210\u4e09\u6b21\u63e1\u624b\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u901f\u5ea6\u5feb\u3001\u9690\u853d\u6027\u597d<\/strong>\uff0c\u662f\u6700\u5e38\u7528\u3001\u9ed8\u8ba4\u7684\u626b\u63cf\u65b9\u5f0f\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u9700\u8981\u7ba1\u7406\u5458\/root\u6743\u9650<\/strong>\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>TCP Connect\u626b\u63cf (\u5168\u8fde\u63a5\u626b\u63cf)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>-sT<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5b8c\u6210\u5b8c\u6574\u7684TCP\u4e09\u6b21\u63e1\u624b\u5efa\u7acb\u8fde\u63a5\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u65e0\u9700\u7279\u6b8a\u6743\u9650\uff0c\u5728\u65e0\u6cd5\u4f7f\u7528SYN\u626b\u63cf\u65f6\u4f7f\u7528\u3002\u4f46<strong>\u901f\u5ea6\u8f83\u6162\uff0c\u4e14\u4f1a\u5728\u76ee\u6807\u65e5\u5fd7\u4e2d\u7559\u4e0b\u5b8c\u6574\u8fde\u63a5\u8bb0\u5f55<\/strong>\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u666e\u901a\u7528\u6237\u6743\u9650\u5373\u53ef\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>UDP\u626b\u63cf<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>-sU<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5411\u76ee\u6807\u7aef\u53e3\u53d1\u9001UDP\u5305\uff0c\u6839\u636e\u54cd\u5e94\u5224\u65ad\u72b6\u6001\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u7528\u4e8e\u63a2\u6d4bDNS\u3001DHCP\u3001SNMP\u7b49UDP\u670d\u52a1\u3002<strong>\u901f\u5ea6\u5f88\u6162<\/strong>\uff0c\u56e0\u4e3aUDP\u534f\u8bae\u65e0\u8fde\u63a5\uff0c\u9700\u8981\u7b49\u5f85\u8d85\u65f6\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u9700\u8981\u7ba1\u7406\u5458\/root\u6743\u9650\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Ping\u626b\u63cf (\u4e3b\u673a\u53d1\u73b0)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>-sn<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u626b\u63cf\u7aef\u53e3\uff0c\u53ea\u68c0\u67e5\u7f51\u6bb5\u4e2d\u6709\u54ea\u4e9b\u4e3b\u673a\u5728\u7ebf\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5feb\u901f\u76d8\u70b9\u7f51\u7edc\u8d44\u4ea7<\/strong>\uff0c\u4f8b\u5982 <code>nmap -sn 192.168.1.0\/24<\/code>\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u901a\u5e38\u9700\u8981\u7ba1\u7406\u5458\u6743\u9650\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u6838\u5fc3\u626b\u63cf\u6280\u672f\u8be6\u89e3\u4e0e\u5b9e\u6218\u793a\u4f8b<\/strong><\/h3>\n\n\n\n<p>\u7406\u89e3\u4e0d\u540c\u626b\u63cf\u7c7b\u578b\u7684\u5173\u952e\u5728\u4e8e\u660e\u767d\u5b83\u4eec\u5982\u4f55\u4e0e\u76ee\u6807\u4e3b\u673a\u7684\u7aef\u53e3\u8fdb\u884c\u201c\u5bf9\u8bdd\u201d\u3002\u4e0b\u9762\u6211\u4eec\u901a\u8fc7\u4e00\u4e2a\u5047\u8bbe\u7684\u76ee\u6807IP <code>192.168.1.105<\/code> \u6765\u6f14\u793a\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>1. TCP SYN\u626b\u63cf (<code>-sS<\/code>)\uff1a \u9ed8\u8ba4\u7684\u3001\u6700\u53d7\u6b22\u8fce\u7684\u626b\u63cf<\/strong><\/h4>\n\n\n\n<p><strong>\u5de5\u4f5c\u539f\u7406<\/strong>\uff1a\u5b83\u53d1\u9001\u4e00\u4e2aSYN\u5305\uff08\u8bf7\u6c42\u8fde\u63a5\uff09\uff0c\u5982\u679c\u7aef\u53e3\u5f00\u653e\uff0c\u76ee\u6807\u4f1a\u56de\u590dSYN\/ACK\u5305\uff1bNmap\u6536\u5230\u540e\uff0c\u4e0d\u4f1a\u5b8c\u6210\u63e1\u624b\uff08\u4e0d\u53d1\u9001ACK\uff09\uff0c\u800c\u662f\u53d1\u9001\u4e00\u4e2aRST\u5305\u4e2d\u65ad\u8fde\u63a5\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u6ca1\u6709\u5efa\u7acb\u5b8c\u6574\u8fde\u63a5\uff0c\u56e0\u6b64\u76f8\u5bf9\u9690\u853d\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u4f8b\u5b50<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap -sS 192.168.1.105\n<\/code><\/pre>\n\n\n\n<p>\u6ce8\u610f\uff1a\u5728Linux\/Unix\u7cfb\u7edf\u4e0a\uff0c<code>-sS<\/code> \u626b\u63cf\u901a\u5e38\u9700\u8981 <code>sudo<\/code> \u83b7\u53d6root\u6743\u9650\uff0c\u56e0\u4e3a\u9700\u8981\u6784\u9020\u539f\u59cb\u6570\u636e\u5305\u3002<\/p>\n\n\n\n<p>\u5728\u521d\u5b66\u7684\u65f6\u4faf\uff0c\u6211\u4eec\u4e0d\u90fd\u662f\u76f4\u63a5\u91c7\u7528sudo\u547d\u4ee4\u5417\uff1f\u8fd9\u91cc\u4e3a\u4ec0\u4e48\u8981\u63d0\u5230\u83b7\u53d6root\u6743\u9650\uff1f\u4e00\u822c\u4e0d\u90fd\u662f\u5b89\u5353\u624d\u4f1a\u63d0\u5230root\u5417\uff1fsudo \u672c\u8eab\u5c31\u662f\u201c\u4e34\u65f6\u83b7\u53d6root\u6743\u9650\u201d\u7684\u5de5\u5177\uff0c\u4e0d\u662f\u72ec\u7acb\u7684\u6743\u9650\uff0c\u5b89\u5353\u7684root\u548cLinux\u7684root\u662f\u540c\u4e00\u4e2a\u6982\u5ff5\uff0c\u53ea\u662f\u573a\u666f\u53eb\u6cd5\u4e0d\u540c\u3002<\/p>\n\n\n\n<p>\u901a\u4fd7\u62c6\u89e3<\/p>\n\n\n\n<p>1.&nbsp;root\u662fLinux\/Unix\u7684\u201c\u6700\u9ad8\u7ba1\u7406\u5458\u6743\u9650\u201d<br>\u7cfb\u7edf\u91cc\u6240\u6709\u6838\u5fc3\u64cd\u4f5c\uff08\u5982\u6784\u9020\u539f\u59cb\u6570\u636e\u5305\u3001\u4fee\u6539\u7cfb\u7edf\u6587\u4ef6\u3001\u67e5\u770b\u6240\u6709\u8fdb\u7a0b\uff09\u90fd\u9700\u8981root\u6743\u9650\uff0c\u666e\u901a\u7528\u6237\u9ed8\u8ba4\u6ca1\u6709\uff0c-sS\u534a\u5f00\u653e\u626b\u63cf\u9700\u8981\u6784\u9020\u81ea\u5b9a\u4e49IP\/TCP\u6570\u636e\u5305\uff0c\u5c5e\u4e8e\u6838\u5fc3\u64cd\u4f5c\uff0c\u5fc5\u987broot\u3002<\/p>\n\n\n\n<p>2.&nbsp;sudo\u662f\u201c\u4e34\u65f6\u501froot\u6743\u9650\u201d\u7684\u547d\u4ee4<br>\u4f60\u8f93\u5165&nbsp;sudo \u67d0\u547d\u4ee4&nbsp;\uff0c\u672c\u8d28\u662f\u544a\u8bc9\u7cfb\u7edf\uff1a\u201c\u8bf7\u4ee5root\u8eab\u4efd\u6267\u884c\u8fd9\u4e2a\u547d\u4ee4\u201d\uff0c\u6267\u884c\u5b8c\u540e\u6743\u9650\u4f1a\u81ea\u52a8\u56de\u5230\u666e\u901a\u7528\u6237\uff0c\u907f\u514d\u4e00\u76f4\u7528root\u64cd\u4f5c\u5e26\u6765\u7684\u98ce\u9669\uff08\u6bd4\u5982\u8bef\u5220\u7cfb\u7edf\u6587\u4ef6\uff09\u3002<\/p>\n\n\n\n<p>3.&nbsp;\u5b89\u5353\u7684root\u548cLinux\u7684root\u662f\u4e00\u56de\u4e8b<br>\u5b89\u5353\u672c\u8eab\u662f\u57fa\u4e8eLinux\u5185\u6838\u7684\u7cfb\u7edf\uff0c\u5b89\u5353\u91cc\u8bf4\u7684\u201c\u83b7\u53d6root\u201d\uff0c\u5c31\u662f\u62ff\u5230\u5b89\u5353\u7cfb\u7edf\u7684\u6700\u9ad8\u7ba1\u7406\u5458\u6743\u9650\uff0c\u548cLinux\/Unix\u91cc\u7684root\u6743\u9650\u5b8c\u5168\u540c\u6e90\uff0c\u53ea\u662f\u624b\u673a\u7aef\u4e3a\u4e86\u5b89\u5168\uff0c\u9ed8\u8ba4\u628aroot\u6743\u9650\u9501\u6b7b\u4e86\uff0c\u9700\u8981\u989d\u5916\u64cd\u4f5c\u89e3\u9501\uff1b\u800c\u7535\u8111\u7aef\u7684Linux\/Unix\uff08\u5982Ubuntu\u3001CentOS\uff09\u9ed8\u8ba4\u4e0d\u9501root\uff0c\u4f46\u666e\u901a\u7528\u6237\u6267\u884c\u9ad8\u6743\u9650\u64cd\u4f5c\u9700\u8981\u7528sudo\u4e34\u65f6\u8c03\u7528\u3002<\/p>\n\n\n\n<p>\u7b80\u5355\u8bf4\uff1a\u4e0d\u662f\u201csudo\u4e4b\u5916\u8fd8\u8981\u83b7\u53d6root\u201d\uff0c\u800c\u662f\u201c\u901a\u8fc7sudo\u6765\u83b7\u53d6\u6267\u884c\u8be5\u547d\u4ee4\u6240\u9700\u7684root\u6743\u9650\u201d\u3002<\/p>\n\n\n\n<p><strong>\u8f93\u51fa\u4e0e\u89e3\u8bfb<\/strong>\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap3-1024x238.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"238\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap3-1024x238.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1469\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>Starting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-29 19:35 +0800\nNmap scan report for 192.168.1.105\nHost is up (0.0000070s latency).\n\nPORT      STATE SERVICE\n1\/tcp     open  tcpmux\n3\/tcp     open  compressnet\n4\/tcp     open  unknown\n6\/tcp     open  unknown\n7\/tcp     open  echo\n9\/tcp     open  discard\n13\/tcp    open  daytime\n63331\/tcp open  unknown\n64623\/tcp open  unknown\n64680\/tcp open  unknown\n65000\/tcp open  unknown\n65129\/tcp open  unknown\n65389\/tcp open  unknown\n\nNmap done: 1 IP address (1 host up) scanned in 0.80 seconds<\/code><\/pre>\n\n\n\n<p><strong>\u8fd9\u4e2a\u626b\u63cf\u7ed3\u679c\u6781\u6709\u53ef\u80fd\u662f\u201c\u4e0d\u771f\u5b9e\u201d\u6216\u201c\u88ab\u8bef\u5bfc\u201d\u7684\u3002<\/strong>&nbsp;\u5b83\u663e\u793a\u76ee\u6807\u4e3b\u673a\uff08192.168.1.105\uff09\u6709<strong>\u8d85\u8fc7900\u4e2aTCP\u7aef\u53e3\u5168\u90e8\u5f00\u653e<\/strong>\uff0c\u8fd9\u5728\u771f\u5b9e\u4e16\u754c\u4e2d\u51e0\u4e4e\u4e0d\u53ef\u80fd\u53d1\u751f\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>2. TCP Connect\u626b\u63cf (<code>-sT<\/code>)\uff1a \u65e0\u9700\u7279\u6743\u7684\u540e\u5907\u65b9\u6848<\/strong><\/h4>\n\n\n\n<p><strong>\u5de5\u4f5c\u539f\u7406<\/strong>\uff1a\u4f7f\u7528\u7cfb\u7edf\u81ea\u5e26\u7684 <code>connect()<\/code> \u51fd\u6570\u5b8c\u6210\u5b8c\u6574\u7684\u4e09\u6b21\u63e1\u624b\u3002\u56e0\u4e3a\u884c\u4e3a\u4e0e\u666e\u901a\u5e94\u7528\u7a0b\u5e8f\u8fde\u63a5\u5b8c\u5168\u76f8\u540c\uff0c\u6240\u4ee5<strong>\u4e0d\u9700\u8981\u7279\u6b8a\u6743\u9650<\/strong>\uff0c\u4f46\u4e5f\u56e0\u6b64<strong>\u4f1a\u5728\u76ee\u6807\u7cfb\u7edf\u65e5\u5fd7\u4e2d\u7559\u4e0b\u5b8c\u6574\u7684\u8fde\u63a5\u8bb0\u5f55<\/strong>\uff0c\u4e0d\u591f\u9690\u853d\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u4f8b\u5b50<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -sT 192.168.1.105<\/code><\/pre>\n\n\n\n<p><strong>\u8f93\u51fa\u4e0eSYN\u626b\u63cf\u5bf9\u6bd4<\/strong>\uff1a<br>\u8f93\u51fa\u7ed3\u679c\u4e0e <code>-sS<\/code> \u626b\u63cf\u76f8\u4f3c\uff0c\u90fd\u80fd\u53d1\u73b0\u5f00\u653e\u7684\u7aef\u53e3\u3002\u4f46\u5173\u952e\u533a\u522b\u5728\u4e8e<strong>\u884c\u4e3a\u5c42\u9762<\/strong>\uff1a\u76ee\u6807\u7cfb\u7edf\u7684\u7f51\u7edc\u8fde\u63a5\u65e5\u5fd7\uff08\u5982<code>\/var\/log\/secure<\/code>\u6216Windows\u4e8b\u4ef6\u65e5\u5fd7\uff09\u91cc\uff0c<code>-sT<\/code>\u626b\u63cf\u4f1a\u4ea7\u751f\u7c7b\u4f3c\u4e8e <code>\u201cClient 192.168.1.100 connected to 192.168.1.105:22\u201d<\/code> \u7684\u8bb0\u5f55\uff0c\u800c <code>-sS<\/code>\u626b\u63cf\u53ef\u80fd\u53ea\u7559\u4e0b\u4e00\u4e2a\u4e0d\u5b8c\u6574\u7684\u8fde\u63a5\u5c1d\u8bd5\u8bb0\u5f55\uff0c\u751a\u81f3\u88ab\u67d0\u4e9b\u9632\u706b\u5899\u5ffd\u7565\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Nmap 7.98 scan initiated Thu Jan 29 20:15:19 2026 as: nmap -sT -T4 -v --reason -p 1-100 -oN tcp_detailed.txt 192.168.0.104\nNmap scan report for 192.168.0.104\nHost is up, received localhost-response (0.000017s latency).\nAll 100 scanned ports on 192.168.0.104 are in ignored states.\nNot shown: 100 closed tcp ports (conn-refused)\n\nRead data files from: D:\\Program\\Professional\\01_Offensive_Security\\01_Reconnaissance\\Nmap\n# Nmap done at Thu Jan 29 20:15:20 2026 -- 1 IP address (1 host up) scanned in 0.76 seconds<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>3. UDP\u626b\u63cf (<code>-sU<\/code>)\uff1a \u63a2\u7d22\u53e6\u4e00\u7247\u5929\u5730<\/strong><\/h4>\n\n\n\n<p><strong>\u5de5\u4f5c\u539f\u7406<\/strong>\uff1a\u5411\u76ee\u6807UDP\u7aef\u53e3\u53d1\u9001\u4e00\u4e2a\u7a7a\u7684UDP\u5305\u3002\u5982\u679c\u6536\u5230\u201c\u7aef\u53e3\u4e0d\u53ef\u8fbe\u201d\u7684ICMP\u54cd\u5e94\uff0c\u5219\u7aef\u53e3\u4e3a<code>closed<\/code>\uff1b\u5982\u679c\u6536\u5230\u4efb\u4f55\u5176\u4ed6UDP\u54cd\u5e94\uff0c\u5219\u7aef\u53e3\u4e3a<code>open<\/code>\uff1b\u5982\u679c\u5b8c\u5168\u6ca1\u6709\u54cd\u5e94\uff0c\u5219\u72b6\u6001\u4e3a<code>open|filtered<\/code>\uff08\u5f00\u653e\u6216\u88ab\u8fc7\u6ee4\uff09\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u4f8b\u5b50<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap -sU -p 53,67,123,161 192.168.1.105<\/code><\/pre>\n\n\n\n<p>\uff08<code>-p<\/code>\u6307\u5b9a\u4e86\u5e38\u89c1\u7684UDP\u7aef\u53e3\uff1aDNS, DHCP, NTP, SNMP\u3002UDP\u626b\u63cf<strong>\u975e\u5e38\u6162<\/strong>\uff0c\u6240\u4ee5\u52a1\u5fc5\u6307\u5b9a\u7aef\u53e3\u3002\uff09<\/p>\n\n\n\n<p><strong>\u8f93\u51fa\u4e0e\u89e3\u8bfb<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>D:\\Program\\Professional\\01_Offensive_Security\\01_Reconnaissance\\Nmap&gt;nmap -sU -p 53,67,123,161 192.168.0.104\nStarting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-29 20:18 +0800\nNmap scan report for 192.168.0.104\nHost is up (0.000095s latency).\n\nPORT    STATE  SERVICE\n53\/udp  closed domain\n67\/udp  closed dhcps\n123\/udp closed ntp\n161\/udp closed snmp\n\nNmap done: 1 IP address (1 host up) scanned in 0.83 seconds<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u8f93\u51fa\u89e3\u6790<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><code>Host is up<\/code>\uff1a\u76ee\u6807\u4e3b\u673a\u5728\u7ebf<\/li>\n\n\n\n<li>\u5ef6\u8fdf\u6781\u4f4e\uff080.000095\u79d2\uff09\uff0c\u8bf4\u660e\u5728\u540c\u4e00\u5c40\u57df\u7f51\u5185\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7aef\u53e3<\/th><th>\u670d\u52a1<\/th><th>\u72b6\u6001<\/th><th>\u542b\u4e49<\/th><\/tr><\/thead><tbody><tr><td><strong>53\/udp<\/strong><\/td><td>domain (DNS)<\/td><td><strong>closed<\/strong><\/td><td>DNS\u670d\u52a1\u672a\u8fd0\u884c<\/td><\/tr><tr><td><strong>67\/udp<\/strong><\/td><td>dhcps (DHCP\u670d\u52a1\u5668)<\/td><td><strong>closed<\/strong><\/td><td>DHCP\u670d\u52a1\u5668\u672a\u8fd0\u884c<\/td><\/tr><tr><td><strong>123\/udp<\/strong><\/td><td>ntp (\u65f6\u95f4\u540c\u6b65)<\/td><td><strong>closed<\/strong><\/td><td>NTP\u65f6\u95f4\u670d\u52a1\u672a\u8fd0\u884c<\/td><\/tr><tr><td><strong>161\/udp<\/strong><\/td><td>snmp (\u7f51\u7edc\u7ba1\u7406)<\/td><td><strong>closed<\/strong><\/td><td>SNMP\u670d\u52a1\u672a\u8fd0\u884c<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>4. Ping\u626b\u63cf (<code>-sn<\/code>)\uff1a \u5feb\u901f\u7f51\u7edc\u666e\u67e5<\/strong><\/h4>\n\n\n\n<p><strong>\u5de5\u4f5c\u539f\u7406<\/strong>\uff1a\u4e0d\u626b\u63cf\u4efb\u4f55\u7aef\u53e3\uff0c\u53ea\u53d1\u9001ICMP\u56de\u58f0\u8bf7\u6c42\u3001TCP SYN\u5305\u5230443\u7aef\u53e3\u3001TCP ACK\u5305\u523080\u7aef\u53e3\u7b49\u7ec4\u5408\u63a2\u9488\uff0c\u6765\u63a2\u6d4b\u4e3b\u673a\u662f\u5426\u5728\u7ebf\u3002\u8fd9\u662f<strong>\u5feb\u901f\u7ed8\u5236\u7f51\u7edc\u5730\u56fe<\/strong>\u7684\u6700\u4f73\u5de5\u5177\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u4f8b\u5b50<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap -sn 192.168.1.0\/24<\/code><\/pre>\n\n\n\n<p><strong>\u8f93\u51fa\u4e0e\u89e3\u8bfb<\/strong>\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap4-1024x470.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"470\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap4-1024x470.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1470\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>D:\\Program\\Professional\\01_Offensive_Security\\01_Reconnaissance\\Nmap&gt;nmap -sn 192.168.0.104\/24\nStarting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-29 20:31 +0800\nNmap scan report for 192.168.0.1\nHost is up (0.060s latency).\nMAC Address: 74:39:89:D7:9F:1C (TP-Link Technologies)\nNmap scan report for 192.168.0.100\nHost is up (0.076s latency).\nMAC Address: DE:07:9A:12:91:AD (Unknown)\nNmap scan report for 192.168.0.101\nHost is up (0.19s latency).\nMAC Address: 52:2C:14:9E:05:E8 (Unknown)\nNmap scan report for 192.168.0.102\nHost is up (0.14s latency).\nMAC Address: EA:89:88:56:76:7D (Unknown)\nNmap scan report for 192.168.0.103\nHost is up (1.4s latency).\nMAC Address: 52:B8:77:87:4B:BB (Unknown)\nNmap scan report for 192.168.0.104\nHost is up.\nNmap done: 256 IP addresses (6 hosts up) scanned in 6.51 seconds<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u8f93\u51fa\u89e3\u6790<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5b83\u5feb\u901f\u626b\u63cf\u4e86\u6574\u4e2a <code>192.168.1.0<\/code> \u5230 <code>192.168.1.255<\/code> \u7684\u7f51\u6bb5\uff0c\u53d1\u73b0\u4e863\u53f0\u5728\u7ebf\u8bbe\u5907\u3002<\/li>\n\n\n\n<li>\u5217\u51fa\u4e86\u6bcf\u53f0\u8bbe\u5907\u7684IP\u548cMAC\u5730\u5740\uff0c\u751a\u81f3<strong>\u6839\u636eMAC\u5730\u5740\u63a8\u6d4b\u4e86\u5382\u5546<\/strong>\uff0c\u8fd9\u5bf9\u7f51\u7edc\u62d3\u6251\u5206\u6790\u975e\u5e38\u6709\u5e2e\u52a9\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u603b\u7ed3\u4e0e\u7efc\u5408\u5e94\u7528\u793a\u4f8b<\/strong><\/h3>\n\n\n\n<p>\u53ef\u4ee5\u53c2\u8003\u4e0b\u8868\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u626b\u63cf\u7c7b\u578b<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u5178\u578b\u547d\u4ee4<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u6838\u5fc3\u76ee\u7684<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u8f93\u51fa\u5173\u952e\u4fe1\u606f<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u6ce8\u610f\u4e8b\u9879<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>TCP SYN\u626b\u63cf<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>sudo nmap -sS \u76ee\u6807<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5168\u9762\u3001\u9690\u853d\u7684\u7aef\u53e3\u666e\u67e5<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6240\u6709<strong>\u5f00\u653e<\/strong>\u7684TCP\u7aef\u53e3\u53ca\u670d\u52a1\u540d\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u9700\u8981Root\u6743\u9650<\/strong>\uff0c\u662f\u4e13\u4e1a\u6e17\u900f\u6d4b\u8bd5\u9996\u9009\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>TCP Connect\u626b\u63cf<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>nmap -sT \u76ee\u6807<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5728\u65e0\u6cd5\u83b7\u5f97Root\u6743\u9650\u65f6\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u540c\u4e0a\uff0c\u4f46\u51c6\u786e\u6027\u53ef\u80fd\u53d7\u9632\u706b\u5899\u5f71\u54cd\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4f1a\u5728\u76ee\u6807\u7559\u4e0b\u65e5\u5fd7<\/strong>\uff0c\u901f\u5ea6\u8f83\u6162\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>UDP\u626b\u63cf<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>sudo nmap -sU -p \u5e38\u7528\u7aef\u53e3 \u76ee\u6807<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u53d1\u73b0DNS\u3001DHCP\u3001SNMP\u7b49<strong>UDP\u670d\u52a1<\/strong>\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>open<\/code>\uff0c <code>open|filtered<\/code>\uff0c <code>closed<\/code>\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u6781\u5176\u7f13\u6162<\/strong>\uff0c\u5fc5\u987b\u6307\u5b9a\u7aef\u53e3\u8303\u56f4\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Ping\u626b\u63cf<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>sudo nmap -sn \u7f51\u6bb5<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5feb\u901f\u53d1\u73b0\u7f51\u7edc\u4e2d\u6709\u54ea\u4e9b\u6d3b\u8dc3\u4e3b\u673a<\/strong>\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5728\u7ebf\u4e3b\u673a\u7684IP\u548cMAC\u5730\u5740\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u626b\u63cf\u7aef\u53e3\uff0c\u7eaf\u7cb9\u7528\u4e8e\u4e3b\u673a\u53d1\u73b0\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>\u7b2c\u4e09\u6b65\uff1a\u5e38\u7528\u529f\u80fd\u7ec4\u5408\u4e0e\u76ee\u6807\u6307\u5b9a<\/strong><br>\u5b9e\u9645\u5e94\u7528\u4e2d\uff0c\u6211\u4eec\u5e38\u7ec4\u5408\u591a\u4e2a\u9009\u9879\uff0c\u5e76\u5bf9\u4e0d\u540c\u7c7b\u578b\u7684\u76ee\u6807\u8fdb\u884c\u626b\u63cf\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u6307\u5b9a\u626b\u63cf\u7aef\u53e3<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><code>-p 80<\/code>\uff1a\u53ea\u626b\u63cf80\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><code>-p 1-1000<\/code>\uff1a\u626b\u63cf1\u52301000\u53f7\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><code>-p 22,80,443<\/code>\uff1a\u626b\u63cf\u6307\u5b9a\u768422\u300180\u3001443\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><code>-p-<\/code>\uff1a\u626b\u63cf\u6240\u670965535\u4e2a\u7aef\u53e3\uff08<strong>\u901f\u5ea6\u6162\uff0c\u8c28\u614e\u4f7f\u7528<\/strong>\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u670d\u52a1\u4e0e\u7248\u672c\u63a2\u6d4b<\/strong>\uff1a<br>\u52a0\u4e0a <code>-sV<\/code> \u9009\u9879\uff0cNmap\u4f1a\u5c1d\u8bd5\u8fde\u63a5\u5f00\u653e\u7aef\u53e3\uff0c\u5e76<strong>\u63a2\u6d4b\u8fd0\u884c\u670d\u52a1\u7684\u5177\u4f53\u8f6f\u4ef6\u540d\u79f0\u548c\u7248\u672c\u53f7<\/strong>\uff0c\u8fd9\u5bf9\u5b89\u5168\u8bc4\u4f30\u81f3\u5173\u91cd\u8981\u3002 <code>nmap -sV \u76ee\u6807IP<\/code><\/li>\n\n\n\n<li><strong>\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b<\/strong>\uff1a<br>\u52a0\u4e0a <code>-O<\/code> \u9009\u9879\uff0cNmap\u4f1a\u5c1d\u8bd5<strong>\u731c\u6d4b\u76ee\u6807\u4e3b\u673a\u7684\u64cd\u4f5c\u7cfb\u7edf<\/strong>\u3002 <code>nmap -O \u76ee\u6807IP<\/code><\/li>\n\n\n\n<li><strong>\u7efc\u5408\u626b\u63cf\uff08\u201c\u706b\u529b\u5168\u5f00\u201d\uff09<\/strong>\uff1a<br>\u4f7f\u7528 <code>-A<\/code> \u9009\u9879\uff0c\u53ef\u4ee5<strong>\u540c\u65f6\u542f\u7528\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u3001\u7248\u672c\u68c0\u6d4b\u3001\u811a\u672c\u626b\u63cf\u548c\u8def\u7531\u8ddf\u8e2a<\/strong>\uff0c\u4e00\u6b21\u6027\u83b7\u53d6\u6700\u5168\u9762\u7684\u4fe1\u606f\u3002 <code>nmap -A \u76ee\u6807IP<\/code><\/li>\n\n\n\n<li><strong>\u6307\u5b9a\u76ee\u6807\u7684\u65b9\u5f0f<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5355\u4e2aIP\uff1a<code>192.168.1.1<\/code><\/li>\n\n\n\n<li>\u4e3b\u673a\u540d\uff1a<code>example.com<\/code><\/li>\n\n\n\n<li>\u7f51\u6bb5\uff08CIDR\u683c\u5f0f\uff09\uff1a<code>192.168.1.0\/24<\/code><\/li>\n\n\n\n<li>\u8303\u56f4\uff1a<code>192.168.1.1-100<\/code><\/li>\n\n\n\n<li>\u4ece\u6587\u4ef6\u8bfb\u53d6\u76ee\u6807\u5217\u8868\uff1a<code>-iL targets.txt<\/code><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap5-1024x365.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"365\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap5-1024x365.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1471\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap6-1024x646.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"646\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap6-1024x646.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1472\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p>\u597d\u7684\uff0c\u6211\u4eec\u6df1\u5165\u63a2\u8ba8Nmap\u7684\u8fdb\u9636\u6280\u5de7\uff0c\u8fd9\u90e8\u5206\u5185\u5bb9\u80fd\u8ba9\u4f60\u7684\u626b\u63cf\u4ece\u201c\u57fa\u7840\u63a2\u6d4b\u201d\u5347\u7ea7\u4e3a\u201c\u4e13\u4e1a\u8bc4\u4f30\u201d\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u7b2c4\u90e8\u5206\uff1a\u8fdb\u9636\u6280\u5de7\u4e0e\u7b56\u7565\u8be6\u89e3<\/strong><\/h2>\n\n\n\n<p>\u638c\u63e1\u8fd9\u4e9b\u6280\u5de7\uff0c\u4f60\u5c06\u80fd\u66f4\u9ad8\u6548\u3001\u66f4\u9690\u853d\u3001\u66f4\u6df1\u5165\u5730\u5b8c\u6210\u626b\u63cf\u4efb\u52a1\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. \u811a\u672c\u5f15\u64ce\uff08NSE\uff09\u5b9e\u6218\uff1a\u8ba9Nmap\u201c\u62e5\u6709\u667a\u6167\u201d<\/strong><\/h3>\n\n\n\n<p>Nmap\u811a\u672c\u5f15\u64ce\u662f\u5b83\u7684\u201c\u8d85\u7ea7\u5927\u8111\u201d\uff0c\u901a\u8fc7\u4e0a\u5343\u4e2a\u811a\u672c\u5b9e\u73b0\u4e86\u5404\u79cd\u81ea\u52a8\u5316\u4efb\u52a1\u3002\u811a\u672c\u5e93\u4e3b\u8981\u5206\u4e3a\u51e0\u7c7b\uff1a<code>safe<\/code>\uff08\u5b89\u5168\uff09\u3001<code>intrusive<\/code>\uff08\u4fb5\u5165\u6027\uff09\u3001<code>vuln<\/code>\uff08\u6f0f\u6d1e\uff09\u3001<code>exploit<\/code>\uff08\u5229\u7528\uff09\u3001<code>auth<\/code>\uff08\u8ba4\u8bc1\u7834\u89e3\uff09\u3001<code>discovery<\/code>\uff08\u53d1\u73b0\uff09\u7b49\u3002<\/p>\n\n\n\n<p><strong>\uff081\uff09\u4fe1\u606f\u641c\u96c6\u7c7b\u811a\u672c<\/strong><br>\u5728\u6e17\u900f\u6d4b\u8bd5\u7684\u4fe1\u606f\u641c\u96c6\u9636\u6bb5\u975e\u5e38\u6709\u7528\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u83b7\u53d6HTTP\u670d\u52a1\u4fe1\u606f<\/strong>\uff1a<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>  nmap --script http-headers,http-title,http-robots.txt -p 80,443 114.66.59.86<\/code><\/pre>\n\n\n\n<p><strong>\u8f93\u51fa\u89e3\u8bfb<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>D:\\Program\\Professional\\01_Offensive_Security\\01_Reconnaissance\\Nmap&gt;nmap --script http-headers,http-title,http-robots.txt -p 80,443 114.66.59.86\nStarting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-29 22:23 +0800\nNmap scan report for 114.66.59.86\nHost is up (0.023s latency).\n\nPORT    STATE  SERVICE\n80\/tcp  open   http\n|_http-title: Did not follow redirect to http:\/\/183.136.132.24   #\u8bbf\u95ee http:\/\/114.66.59.86 \u4f1a\u91cd\u5b9a\u5411\u5230 http:\/\/183.136.132.24,Nmap\u9ed8\u8ba4\u4e0d\u8ddf\u968f\u91cd\u5b9a\u5411\uff0c\u6240\u4ee5\u65e0\u6cd5\u83b7\u53d6\u6807\u9898,\u88ab\u8098\u51fb\u4e86\n| http-headers:\n|   Server: Apache       # Web\u670d\u52a1\u5668\uff1aApache\n|   Content-Type: text\/html;charset=UTF-8       # \u5185\u5bb9\u7c7b\u578b\u548c\u7f16\u7801\n|   Content-Length: 0      # \u54cd\u5e94\u4f53\u4e3a\u7a7a\uff08\u53ea\u6709\u91cd\u5b9a\u5411\uff09\n|   Cache-control: no-store     # \u7981\u6b62\u7f13\u5b58\n|   Location: http:\/\/183.136.132.24   # \u91cd\u5b9a\u5411\u76ee\u6807\n|   Connection: close       # \u5173\u95ed\u8fde\u63a5\n|\n|_  (Request type: GET)\n443\/tcp closed https\n\nNmap done: 1 IP address (1 host up) scanned in 9.30 seconds<\/code><\/pre>\n\n\n\n<p>\u8fd9\u4e2a\u547d\u4ee4\u4e00\u6b21\u6027\u83b7\u53d6\u4e86\u670d\u52a1\u5668\u7c7b\u578b\u3001\u7f16\u7a0b\u8bed\u8a00\u3001\u7f51\u7ad9\u6807\u9898\u548c\u6f5c\u5728\u7684\u654f\u611f\u76ee\u5f55\uff0c\u662fWeb\u6e17\u900f\u7684\u8d77\u70b9\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u53d1\u73b0\u66f4\u591a\u670d\u52a1\u4fe1\u606f<\/strong>\uff1a<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>  nmap --script dns-brute --script-args dns-brute.domain=example.com 8.8.8.8<\/code><\/pre>\n\n\n\n<p>\u8fd9\u4e2a\u811a\u672c\u4f1a\u5c1d\u8bd5\u5bf9<code>example.com<\/code>\u8fdb\u884cDNS\u5b50\u57df\u540d\u66b4\u529b\u731c\u89e3\uff0c\u53ef\u80fd\u53d1\u73b0<code>mail.example.com<\/code>\u3001<code>admin.example.com<\/code>\u7b49\u9690\u85cf\u8d44\u4ea7\u3002<\/p>\n\n\n\n<p><strong>\uff082\uff09\u6f0f\u6d1e\u68c0\u6d4b\u7c7b\u811a\u672c<\/strong><br>\u8fd9\u662fNSE\u6700\u5f3a\u5927\u7684\u7528\u9014\u4e4b\u4e00\uff0c\u80fd\u81ea\u52a8\u68c0\u6d4b\u5df2\u77e5\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u68c0\u6d4b\u5e38\u89c1\u6f0f\u6d1e<\/strong>\uff1a<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>  nmap --script vuln -p 80,443,21,25 192.168.1.105<\/code><\/pre>\n\n\n\n<p><strong>\u8f93\u51fa\u89e3\u8bfb\uff08\u5982\u679c\u53d1\u73b0\u6f0f\u6d1e\uff09<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>  21\/tcp open  ftp\n  | ftp-anon: Anonymous FTP login allowed (FTP code 230) # \u53d1\u73b0FTP\u533f\u540d\u767b\u5f55\uff01\n  | ftp-syst:\n  |   STAT:\n  |_   \u6b64FTP\u670d\u52a1\u5668\u5f88\u53ef\u80fd\u88ab\u914d\u7f6e\u9519\u8bef\n  80\/tcp open  http\n  | http-slowloris-check:\n  |   VULNERABLE:\n  |   Slowloris DOS attack\n  |     State: VULNERABLE\n  |     Description:\n  |       This web server is vulnerable to the Slowloris Denial of Service attack.\n  |_    (\u98ce\u9669\u8be6\u60c5\u548c\u53c2\u8003\u94fe\u63a5)<\/code><\/pre>\n\n\n\n<p>\u8fd9\u4e2a\u626b\u63cf\u76f4\u63a5\u8bc6\u522b\u51fa\u4e86<strong>\u5141\u8bb8\u533f\u540d\u767b\u5f55\u7684FTP\u670d\u52a1\u5668<\/strong>\uff08\u4e00\u4e2a\u4e25\u91cd\u7684\u5b89\u5168\u914d\u7f6e\u9519\u8bef\uff09\u548c\u6f5c\u5728\u7684<strong>Slowloris\u62d2\u7edd\u670d\u52a1\u6f0f\u6d1e<\/strong>\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9488\u5bf9\u7279\u5b9a\u670d\u52a1\u7684\u6f0f\u6d1e\u68c0\u6d4b<\/strong>\uff1a<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>  nmap --script smb-vuln-ms17-010 -p 445 192.168.1.120<\/code><\/pre>\n\n\n\n<p>\u8fd9\u4e2a\u8457\u540d\u7684\u201c\u6c38\u6052\u4e4b\u84dd\u201d\u6f0f\u6d1e\u68c0\u6d4b\u811a\u672c\uff0c\u4f1a\u4e13\u95e8\u68c0\u67e5\u76ee\u6807Windows\u4e3b\u673a\u7684445\u7aef\u53e3\u662f\u5426\u53d7MS17-010\u6f0f\u6d1e\u5f71\u54cd\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap7-1024x226.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"226\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap7-1024x226.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1476\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p><strong>\u6ca1\u6709\u6f0f\u6d1e\u68c0\u6d4b\u7ed3\u679c<\/strong>\uff0c\u7531\u4e8e\u7aef\u53e3\u72b6\u6001\u662f<code>filtered<\/code>\uff1aNmap\u65e0\u6cd5\u5efa\u7acbSMB\u8fde\u63a5\uff0c\u811a\u672c\u65e0\u6cd5\u53d1\u9001\u68c0\u6d4b\u5305\uff0c\u56e0\u6b64\u65e0\u6cd5\u5224\u65ad\u662f\u5426\u5b58\u5728\u6f0f\u6d1e<\/p>\n\n\n\n<p><strong>\uff083\uff09\u5b89\u5168\u5ba1\u8ba1\u7c7b\u811a\u672c<\/strong><br>\u7528\u4e8e\u68c0\u67e5\u914d\u7f6e\u5f31\u70b9\uff0c\u800c\u975e\u76f4\u63a5\u5229\u7528\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u68c0\u67e5\u6570\u636e\u5e93\u5f31\u53e3\u4ee4<\/strong>\uff1a<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>  nmap --script mysql-brute --script-args userdb=\/path\/users.txt,passdb=\/path\/pass.txt 192.168.1.105<\/code><\/pre>\n\n\n\n<p>\u8be5\u811a\u672c\u4f1a\u4f7f\u7528\u63d0\u4f9b\u7684\u7528\u6237\u540d\u548c\u5bc6\u7801\u5b57\u5178\uff0c\u5c1d\u8bd5\u5bf9MySQL\u670d\u52a1\u8fdb\u884c\u66b4\u529b\u7834\u89e3\uff0c\u9a8c\u8bc1\u662f\u5426\u5b58\u5728\u5f31\u5bc6\u7801\u3002<\/p>\n\n\n\n<p><strong>\uff084\uff09\u7efc\u5408\u5e94\u7528\u793a\u4f8b<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u5bf9Web\u670d\u52a1\u5668\u8fdb\u884c\u4e00\u6b21\u6df1\u5165\u4e14\u76f8\u5bf9\u5b89\u9759\u7684\u201c\u4fa6\u5bdf\u201d\nnmap -sS -p 80,443 --script http-enum,http-sql-injection,http-xssed --script-args httpspider.maxpagecount=50 -T2 192.168.1.105<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>http-enum<\/code>\uff1a\u679a\u4e3e\u7f51\u7ad9\u76ee\u5f55\uff0c\u5bfb\u627e<code>\/admin<\/code>\u3001<code>\/login<\/code>\u7b49\u3002<\/li>\n\n\n\n<li><code>http-sql-injection<\/code>\uff1a\u5bf9\u53d1\u73b0\u7684\u7f51\u9875\u53c2\u6570\u8fdb\u884c\u7b80\u5355\u7684SQL\u6ce8\u5165\u6d4b\u8bd5\u3002<\/li>\n\n\n\n<li><code>http-xssed<\/code>\uff1a\u68c0\u67e5\u5df2\u77e5\u7684XSS\uff08\u8de8\u7ad9\u811a\u672c\uff09\u6f0f\u6d1e\u3002<\/li>\n\n\n\n<li><code>-T2<\/code>\uff1a\u964d\u4f4e\u901f\u5ea6\uff0c\u51cf\u5c11\u5bf9\u76ee\u6807\u7684\u5f71\u54cd\u548c\u81ea\u8eab\u66b4\u9732\u7684\u98ce\u9669\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. \u8c03\u6574\u626b\u63cf\u901f\u5ea6\uff08-T\u6a21\u677f\uff09\u7684\u5b9e\u9645\u5f71\u54cd<\/strong><\/h3>\n\n\n\n<p><code>-T<\/code>\u53c2\u6570\uff080-5\uff09\u4e0d\u53ea\u662f\u8c03\u8282\u901f\u5ea6\uff0c\u5b83\u6539\u53d8\u4e86\u626b\u63cf\u7684\u5e76\u884c\u5ea6\u3001\u91cd\u8bd5\u6b21\u6570\u3001\u8d85\u65f6\u65f6\u95f4\u7b49\u4e00\u6574\u5957\u884c\u4e3a\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u5bf9\u6bd4\u4e0e\u573a\u666f\u5206\u6790\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u573a\u666f1\uff1a\u626b\u63cf\u5bb6\u7528\u8def\u7531\u5668\uff0c\u8ffd\u6c42\u6781\u901f\uff08\u727a\u7272\u9690\u853d\u6027\uff09\nnmap -T5 -F 192.168.1.1\n# -T5 (Insane)\uff1a\u6781\u5feb\uff0c\u9002\u5408\u4f60\u5b8c\u5168\u63a7\u5236\u7684\u3001\u7a33\u5b9a\u7684\u5185\u90e8\u7f51\u7edc\u3002\u53ef\u80fd\u56e0\u901f\u5ea6\u8fc7\u5feb\u6f0f\u62a5\u7aef\u53e3\u3002\n\n# \u573a\u666f2\uff1a\u5bf9\u751f\u4ea7\u670d\u52a1\u5668\u8fdb\u884c\u521d\u6b65\u626b\u63cf\uff0c\u5e73\u8861\u901f\u5ea6\u4e0e\u51c6\u786e\u6027\nnmap -T4 -sS --top-ports 1000 \u76ee\u6807\u670d\u52a1\u5668IP\n# -T4 (Aggressive)\uff1a\u9ed8\u8ba4\u63a8\u8350\uff0c\u5728\u901f\u5ea6\u548c\u53ef\u9760\u6027\u95f4\u53d6\u5f97\u826f\u597d\u5e73\u8861\u3002\n\n# \u573a\u666f3\uff1a\u8fdb\u884c\u9690\u853d\u626b\u63cf\uff0c\u907f\u514d\u89e6\u53d1\u5b89\u5168\u8b66\u62a5\nnmap -T2 -sS -p 1-10000 \u76ee\u6807IP\n# -T2 (Polite)\uff1a\u663e\u8457\u964d\u4f4e\u53d1\u5305\u901f\u5ea6\uff0c\u589e\u52a0\u5ef6\u8fdf\uff0c\u4f7f\u626b\u63cf\u6d41\u91cf\u6df7\u5165\u6b63\u5e38\u80cc\u666f\u6d41\u91cf\u4e2d\uff0c\u96be\u4ee5\u88abIDS\uff08\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf\uff09\u7684\u9608\u503c\u8b66\u62a5\u53d1\u73b0\u3002\n\n# \u573a\u666f4\uff1a\u626b\u63cf\u7f51\u7edc\u94fe\u8def\u5dee\u6216\u4e25\u683c\u8fc7\u6ee4\u7684\u8bbe\u5907\nnmap -T1 -sS --max-retries 3 \u76ee\u6807IP\n# -T1 (Sneaky)\uff1a\u975e\u5e38\u6162\uff0c\u7528\u4e8e\u626b\u63cf\u8001\u65e7\u7684\u3001\u53cd\u5e94\u6162\u7684\u6216\u7f51\u7edc\u72b6\u51b5\u4e0d\u4f73\u7684\u8bbe\u5907\uff0c\u4e5f\u6781\u5176\u9690\u853d\u3002<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. \u8f93\u51fa\u626b\u63cf\u7ed3\u679c\uff1a\u4e3a\u62a5\u544a\u548c\u5206\u6790\u505a\u51c6\u5907<\/strong><\/h3>\n\n\n\n<p>\u4e13\u4e1a\u7684\u626b\u63cf\u5fc5\u987b\u4fdd\u5b58\u7ed3\u679c\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u6700\u4f73\u5b9e\u8df5\uff1a\u4f7f\u7528 -oA \u4e00\u6b21\u6027\u4fdd\u5b58\u6240\u6709\u683c\u5f0f\nsudo nmap -sS -sV -O -A -oA full_scan_report 192.168.1.105<\/code><\/pre>\n\n\n\n<p>\u8fd9\u6761\u547d\u4ee4\u6267\u884c\u7efc\u5408\u626b\u63cf\uff0c\u5e76\u751f\u6210\u4e09\u4e2a\u6587\u4ef6\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>full_scan_report.nmap<\/code>\uff1a<strong>\u6807\u51c6\u6587\u672c\u683c\u5f0f<\/strong>\uff0c\u4fbf\u4e8e\u4eba\u7c7b\u9605\u8bfb\u3002<\/li>\n\n\n\n<li><code>full_scan_report.xml<\/code>\uff1a<strong>\u7ed3\u6784\u5316XML\u683c\u5f0f<\/strong>\uff0c\u53ef\u5bfc\u5165Metasploit\u3001NeXpose\u3001OpenVAS\u7b49\u6f0f\u6d1e\u7ba1\u7406\u5e73\u53f0\u8fdb\u884c\u540e\u7eed\u5206\u6790\u3002<\/li>\n\n\n\n<li><code>full_scan_report.gnmap<\/code>\uff1a<strong>Grep\u53cb\u597d\u683c\u5f0f<\/strong>\uff0c\u4fbf\u4e8e\u7528<code>grep<\/code>\u3001<code>awk<\/code>\u7b49\u547d\u4ee4\u884c\u5de5\u5177\u5feb\u901f\u63d0\u53d6\u7279\u5b9a\u4fe1\u606f\uff0c\u5982 <code>cat full_scan_report.gnmap | grep \"open\"<\/code>\u3002<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap8.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"803\" height=\"90\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap8.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1479\"  sizes=\"auto, (max-width: 803px) 100vw, 803px\" \/><\/div><\/figure>\n\n\n\n<p><strong>XML\u683c\u5f0f\u7684\u4f18\u52bf<\/strong>\uff1a\u53ef\u4ee5\u7528\u6d4f\u89c8\u5668\u6253\u5f00\uff0c\u6216\u4f7f\u7528Nmap\u81ea\u5e26\u7684<code>xsltproc<\/code>\u5de5\u5177\u8f6c\u6362\u4e3a\u7f8e\u89c2\u7684HTML\u62a5\u544a\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>xsltproc full_scan_report.xml -o full_scan_report.html<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. \u7ed5\u8fc7\u9632\u706b\u5899\/IDS\u7684\u7b80\u5355\u6280\u5de7<\/strong><\/h3>\n\n\n\n<p>\u8fd9\u4e9b\u6280\u5de7\u4e3b\u8981\u9488\u5bf9\u7b80\u5355\u7684\u72b6\u6001\u68c0\u6d4b\u9632\u706b\u5899\u6216\u57fa\u4e8e\u89c4\u5219\u7684\u521d\u7ea7IDS\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5206\u7247\u626b\u63cf (<code>-f<\/code>) \u4e0e\u8bf1\u9975\u626b\u63cf (<code>-D<\/code>)<\/strong><\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>  # \u5c06TCP\u5934\u5206\u6210\u591a\u4e2a\u5c0f\u6570\u636e\u5305\u53d1\u9001\uff0c\u53ef\u80fd\u7ed5\u8fc7\u7b80\u5355\u7684\u5305\u8fc7\u6ee4\u548cIDS\u68c0\u6d4b\n  sudo nmap -f -sS \u76ee\u6807IP\n\n  # \u4f7f\u7528\u8bf1\u9975\u626b\u63cf\uff0c\u9690\u85cf\u771f\u5b9e\u626b\u63cf\u6e90IP\n  sudo nmap -D RND:5,me -sS \u76ee\u6807IP\n  # \u8fd9\u6761\u547d\u4ee4\u4f1a\u751f\u62105\u4e2a\u968f\u673a\u7684\u8bf1\u9975IP\uff0c\u5e76\u5c06\u81ea\u5df1\u7684\u771f\u5b9eIP\uff08me\uff09\u6df7\u5728\u5176\u4e2d\uff0c\u76ee\u6807\u9632\u706b\u5899\u4f1a\u770b\u5230\u6765\u81ea6\u4e2a\u4e0d\u540cIP\u7684\u626b\u63cf\u6d41\u91cf\uff0c\u96be\u4ee5\u5b9a\u4f4d\u771f\u5b9e\u7684\u4f60\u3002<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u6307\u5b9a\u6e90\u7aef\u53e3 (<code>--source-port<\/code>)<\/strong><\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>  # \u5047\u8bbe\u76ee\u6807\u9632\u706b\u5899\u4fe1\u4efb\u6765\u81ea53\u7aef\u53e3\uff08DNS\uff09\u7684\u6d41\u91cf\n  sudo nmap --source-port 53 -sS \u76ee\u6807IP<\/code><\/pre>\n\n\n\n<p><strong>\u539f\u7406<\/strong>\uff1a\u4e00\u4e9b\u914d\u7f6e\u4e0d\u5f53\u7684\u9632\u706b\u5899\u89c4\u5219\u53ef\u80fd\u5199\u7740\u201c\u5141\u8bb8\u6765\u81ea53\u7aef\u53e3\uff08UDP\/TCP\uff09\u7684\u6d41\u91cf\u8fdb\u5165\u201d\uff0c\u5229\u7528\u8fd9\u4e00\u70b9\u53ef\u4ee5\u7a7f\u8fc7\u89c4\u5219\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u968f\u673a\u987a\u5e8f\u626b\u63cf (<code>--randomize-hosts<\/code>) \u548c\u6162\u901f\u626b\u63cf (<code>--scan-delay<\/code>)<\/strong><\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>  # \u968f\u673a\u5316\u626b\u63cf\u4e3b\u673a\u7684\u987a\u5e8f\uff0c\u5e76\u8bbe\u7f6e\u6bcf\u4e2a\u63a2\u9488\u4e4b\u95f4\u7684\u5ef6\u8fdf\n  sudo nmap -sS --randomize-hosts --scan-delay 1s 192.168.1.0\/24<\/code><\/pre>\n\n\n\n<p>\u8fd9\u4f1a\u8ba9\u626b\u63cf\u884c\u4e3a\u770b\u8d77\u6765\u4e0d\u50cf\u4e00\u4e2a\u81ea\u52a8\u5316\u5de5\u5177\u5728\u6309\u987a\u5e8f\u201c\u722c\u201dIP\u5730\u5740\uff0c\u4ece\u800c\u89c4\u907f\u4e00\u4e9b\u57fa\u4e8e\u884c\u4e3a\u6a21\u5f0f\u7684IDS\u68c0\u6d4b\u3002<\/p>\n\n\n\n<p><strong>\u91cd\u8981\u63d0\u9192<\/strong>\uff1a\u73b0\u4ee3\u4f01\u4e1a\u7ea7\u9632\u706b\u5899\u548c\u4e0b\u4e00\u4ee3IDS\uff08\u5982Suricata\uff09\u5177\u5907\u6df1\u5ea6\u5305\u68c0\u6d4b\u548c\u5f02\u5e38\u6d41\u91cf\u5206\u6790\u80fd\u529b\uff0c\u4e0a\u8ff0\u7b80\u5355\u6280\u5de7\u5f88\u53ef\u80fd\u65e0\u6548\u3002\u5b83\u4eec\u4e3b\u8981\u7528\u4e8e\u5e94\u5bf9\u8001\u65e7\u6216\u914d\u7f6e\u7b80\u5355\u7684\u9632\u5fa1\u8bbe\u5907\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u7efc\u5408\u5b9e\u6218\u6848\u4f8b\uff1a\u4e00\u6b21\u5b8c\u6574\u7684\u5185\u90e8\u7f51\u7edc\u5b89\u5168\u8bc4\u4f30<\/strong><\/h3>\n\n\n\n<p>\u5047\u8bbe\u4f60\u88ab\u6388\u6743\u8bc4\u4f30 <code>192.168.10.0\/24<\/code> \u7f51\u6bb5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u7b2c1\u6b65\uff1a\u5b89\u9759\u7684\u8d44\u4ea7\u53d1\u73b0\uff0c\u627e\u51fa\u6240\u6709\u5728\u7ebf\u4e3b\u673a\nsudo nmap -sn -T2 -oA network_hosts 192.168.10.0\/24\n\n# \u7b2c2\u6b65\uff1a\u5206\u6790\u4e0a\u4e00\u6b65\u7684\u7ed3\u679c\u6587\u4ef6\uff0c\u63d0\u53d6\u51fa\u5728\u7ebf\u4e3b\u673aIP\uff08\u4f8b\u5982\u662f .50, .101, .150\uff09\ncat network_hosts.gnmap | grep \"Status: Up\" | cut -d\" \" -f2 &gt; live_hosts.txt<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code># \u7b2c3\u6b65\uff1a\u5bf9\u5173\u952e\u670d\u52a1\u5668(\u5047\u8bbe\u662f.101)\u8fdb\u884c\u6df1\u5ea6\u3001\u9690\u853d\u7684\u7aef\u53e3\u548c\u670d\u52a1\u53d1\u73b0\nsudo nmap -sS -sV -O -p- --script safe,discovery -T3 -oA deep_scan_101 192.168.10.101<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code># \u7b2c4\u6b65\uff1a\u6839\u636e\u7b2c3\u6b65\u7684\u7ed3\u679c\uff0c\u9488\u5bf9\u53d1\u73b0\u7684\u7279\u5b9a\u670d\u52a1\uff08\u5982Web\u3001SMB\uff09\u8fdb\u884c\u6f0f\u6d1e\u626b\u63cf\nsudo nmap -p 80,443,445 --script vuln,http-vuln*,smb-vuln* -T2 -oA vuln_scan_101 192.168.10.101<\/code><\/pre>\n\n\n\n<p>\u901a\u8fc7\u8fd9\u79cd\u5206\u5c42\u3001\u9010\u6b65\u6df1\u5165\u7684\u626b\u63cf\u7b56\u7565\uff0c\u4f60\u53ef\u4ee5\u5728\u4e0d\u60ca\u6270\u76ee\u6807\u7cfb\u7edf\u7684\u60c5\u51b5\u4e0b\uff0c\u7cfb\u7edf\u6027\u5730\u5b8c\u6210\u4ece\u53d1\u73b0\u5230\u6df1\u5ea6\u8bc4\u4f30\u7684\u5168\u8fc7\u7a0b\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Nmap\u76ee\u6807\u8bf4\u660e &#8211; \u8be6\u7ec6\u6559\u5b66\u6307\u5357<\/strong><\/h2>\n\n\n\n<p>\u76ee\u6807\u8bf4\u660e\u662fNmap\u626b\u63cf\u7684\u8d77\u70b9\uff0c\u5b83\u5b9a\u4e49\u4e86\u201c\u4f60\u8981\u626b\u63cf\u8c01\u201d\u3002\u7075\u6d3b\u4e14\u51c6\u786e\u5730\u6307\u5b9a\u76ee\u6807\u662f\u9ad8\u6548\u626b\u63cf\u7684\u7b2c\u4e00\u6b65\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u7b2c\u4e00\u90e8\u5206\uff1a\u57fa\u7840\u76ee\u6807\u683c\u5f0f\u8be6\u89e3\u4e0e\u793a\u4f8b<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5355\u4e2aIP\u5730\u5740<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u8bf4\u660e<\/strong>\uff1a\u6700\u76f4\u63a5\u7684\u5f62\u5f0f\uff0c\u6307\u5411\u7f51\u7edc\u4e2d\u7684\u4e00\u53f0\u7279\u5b9a\u8bbe\u5907\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br><code>bash nmap 192.168.1.1<\/code><br><em>\uff08\u626b\u63cf\u672c\u5730\u7f51\u5173\uff09<\/em><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4e3b\u673a\u540d\uff08\u57df\u540d\uff09<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u8bf4\u660e<\/strong>\uff1aNmap\u4f1a\u81ea\u52a8\u901a\u8fc7DNS\u7cfb\u7edf\u5c06\u4e3b\u673a\u540d\u89e3\u6790\u4e3aIP\u5730\u5740\u3002\u8fd9\u975e\u5e38\u65b9\u4fbf\uff0c\u4f46\u9700\u8981\u6ce8\u610f\uff0c\u5982\u679cDNS\u8bb0\u5f55\u4e0d\u51c6\u786e\u6216\u5b58\u5728CDN\uff0c\u626b\u63cf\u7684\u53ef\u80fd\u662f\u9519\u8bef\u7684\u670d\u52a1\u5668\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br><code>bash nmap scanme.nmap.org nmap www.example.com<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CIDR\u65e0\u7c7b\u522b\u57df\u95f4\u8def\u7531\u8868\u793a\u6cd5<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u6838\u5fc3\u6982\u5ff5<\/strong>\uff1a<code>\/&lt;\u4f4d\u6570&gt;<\/code> \u8868\u793a\u7f51\u7edc\u524d\u7f00\u56fa\u5b9a\u7684\u957f\u5ea6\u3002\u4f4d\u6570\u8d8a\u5927\uff0c\u8303\u56f4\u8d8a\u5c0f\u8d8a\u7cbe\u786e\u3002<\/li>\n\n\n\n<li><strong>\u8bb0\u5fc6\u6280\u5de7<\/strong>\uff1a\u628a\u5b83\u60f3\u8c61\u6210\u201c\u90ae\u653f\u7f16\u7801\u201d\u3002<code>\/24<\/code> \u8868\u793a\u4e00\u4e2a\u201c\u5c0f\u533a\u201d\uff08256\u4e2a\u5730\u5740\uff09\uff0c<code>\/16<\/code> \u8868\u793a\u4e00\u4e2a\u201c\u57ce\u533a\u201d\uff0865536\u4e2a\u5730\u5740\uff09\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b\u4e0e\u89e3\u6790<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><code>192.168.1.0\/24<\/code>\n<ul class=\"wp-block-list\">\n<li><strong>\u542b\u4e49<\/strong>\uff1a\u626b\u63cf\u4ece <code>192.168.1.0<\/code> \u5230 <code>192.168.1.255<\/code> \u7684\u6240\u6709IP\uff08\u5171256\u4e2a\uff09\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u573a\u666f<\/strong>\uff1a\u626b\u63cf\u6574\u4e2a\u5bb6\u5ead\u6216\u5c0f\u578b\u529e\u516c\u7f51\u7edc\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><code>10.0.0.0\/8<\/code>\n<ul class=\"wp-block-list\">\n<li><strong>\u542b\u4e49<\/strong>\uff1a\u626b\u63cf\u4ece <code>10.0.0.0<\/code> \u5230 <code>10.10.255.255.255<\/code> \u7684\u6240\u6709IP\uff08\u7ea61677\u4e07\u4e2a\uff09\u3002\u8fd9\u662f\u6574\u4e2aA\u7c7b\u79c1\u6709\u5730\u5740\u6bb5\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u573a\u666f<\/strong>\uff1a\u5927\u578b\u4f01\u4e1a\u5185\u90e8\u7f51\u7edc\u53d1\u73b0\uff08\u9700\u8c28\u614e\uff0c\u8303\u56f4\u6781\u5927\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><code>203.0.113.100\/30<\/code>\n<ul class=\"wp-block-list\">\n<li><strong>\u542b\u4e49<\/strong>\uff1a\u53ea\u626b\u63cf <code>203.0.113.100<\/code>, <code>203.0.113.101<\/code>, <code>203.0.113.102<\/code>, <code>203.0.113.103<\/code> \u8fd94\u4e2aIP\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u573a\u666f<\/strong>\uff1a\u626b\u63cf\u4e00\u4e2a\u5c0f\u7684\u5b50\u7f51\u6216\u4e00\u5bf9\u70b9\u5bf9\u70b9\u94fe\u8def\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u516b\u4f4d\u5b57\u8282\u8303\u56f4\u5217\u8868\uff08\u6700\u7075\u6d3b\uff09<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u8bf4\u660e<\/strong>\uff1a\u8fd9\u662fNmap\u6700\u5f3a\u5927\u7684\u76ee\u6807\u6307\u5b9a\u529f\u80fd\u4e4b\u4e00\u3002\u4f60\u53ef\u4ee5\u4e3aIP\u5730\u5740\u7684\u56db\u4e2a\u90e8\u5206\uff08\u5982 <code>A.B.C.D<\/code>\uff09\u5206\u522b\u6307\u5b9a\u5217\u8868\u6216\u8303\u56f4\u3002<\/li>\n\n\n\n<li><strong>\u683c\u5f0f<\/strong>\uff1a<code>[\u8303\u56f41].[\u8303\u56f42].[\u8303\u56f43].[\u8303\u56f44]<\/code><\/li>\n\n\n\n<li><strong>\u793a\u4f8b\u4e0e\u89e3\u6790<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><code>192.168.1,2,3.1-254<\/code>\n<ul class=\"wp-block-list\">\n<li><strong>\u542b\u4e49<\/strong>\uff1a\u626b\u63cf <code>192.168.1.1-254<\/code>\u3001<code>192.168.2.1-254<\/code>\u3001<code>192.168.3.1-254<\/code> \u4e09\u4e2a\u7f51\u6bb5\u7684\u6240\u6709\u4e3b\u673a\uff0c\u4f46\u6392\u9664 <code>.0<\/code>\uff08\u7f51\u7edc\u5730\u5740\uff09\u548c <code>.255<\/code>\uff08\u5e7f\u64ad\u5730\u5740\uff09\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u573a\u666f<\/strong>\uff1a\u626b\u63cf\u591a\u4e2a\u4e0d\u8fde\u7eed\u7684\u5b50\u7f51\uff0c\u5e76\u81ea\u52a8\u907f\u5f00\u8fb9\u754c\u5730\u5740\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><code>10.0-255.0-255.1<\/code>\n<ul class=\"wp-block-list\">\n<li><strong>\u542b\u4e49<\/strong>\uff1a\u626b\u63cf\u6240\u6709\u5f62\u5982 <code>10.x.y.1<\/code> \u7684IP\uff08x\u548cy\u4ece0\u5230255\uff09\u3002\u5373\u6240\u6709\u5b50\u7f51\u7684\u7b2c\u4e00\u4e2a\u53ef\u7528\u4e3b\u673a\uff08\u901a\u5e38\u662f\u7f51\u5173\uff09\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u573a\u666f<\/strong>\uff1a\u5728\u5927\u578b\u7f51\u7edc\u4e2d\u5feb\u901f\u5b9a\u4f4d\u6240\u6709\u5b50\u7f51\u7684\u7f51\u5173\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><code>172.16-31.0-255.100-200<\/code>\n<ul class=\"wp-block-list\">\n<li><strong>\u542b\u4e49<\/strong>\uff1a\u626b\u63cf\u6574\u4e2aB\u7c7b\u79c1\u6709\u5730\u5740\u6bb5 <code>172.16.0.0\/12<\/code> \u4e2d\uff0c\u6240\u6709IP\u6700\u540e\u4e00\u4e2a\u5b57\u8282\u5728100\u5230200\u4e4b\u95f4\u7684\u4e3b\u673a\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u573a\u666f<\/strong>\uff1a\u9488\u5bf9\u7279\u5b9a\u7c7b\u578b\u7684\u670d\u52a1\u5668\uff08\u5982IP\u8303\u56f4\u56fa\u5b9a\u7684\u7ec8\u7aef\u670d\u52a1\u5668\uff09\u8fdb\u884c\u626b\u63cf\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap9-1024x244.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"244\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap9-1024x244.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1483\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap10-1024x199.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"199\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap10-1024x199.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1484\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u7b2c\u4e8c\u90e8\u5206\uff1a\u9ad8\u7ea7\u76ee\u6807\u9009\u62e9\u9009\u9879\u8be6\u89e3\u4e0e\u793a\u4f8b<\/strong><\/h3>\n\n\n\n<p>\u8fd9\u4e9b\u9009\u9879\u7528\u4e8e\u7ba1\u7406\u590d\u6742\u7684\u626b\u63cf\u76ee\u6807\u5217\u8868\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong><code>-iL &lt;\u6587\u4ef6\u540d&gt;<\/code>\uff1a\u4ece\u5217\u8868\u6587\u4ef6\u8f93\u5165<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u4e3a\u4ec0\u4e48\u9700\u8981\u5b83<\/strong>\uff1a\u5f53\u4f60\u6709\u6210\u767e\u4e0a\u5343\u4e2a\u76ee\u6807\u65f6\uff0c\u65e0\u6cd5\u5728\u547d\u4ee4\u884c\u624b\u52a8\u8f93\u5165\u3002\u4f60\u53ef\u4ee5\u4ece\u8d44\u4ea7\u7ba1\u7406\u7cfb\u7edf\u3001\u65e5\u5fd7\u6587\u4ef6\u6216\u5176\u4ed6\u626b\u63cf\u5de5\u5177\u4e2d\u5bfc\u51fa\u76ee\u6807\u5217\u8868\u3002<\/li>\n\n\n\n<li><strong>\u6587\u4ef6\u683c\u5f0f<\/strong>\uff1a\u6bcf\u884c\u4e00\u4e2a\u76ee\u6807\uff0c\u652f\u6301\u6240\u6709Nmap\u683c\u5f0f\uff08IP\u3001\u4e3b\u673a\u540d\u3001CIDR\u3001\u8303\u56f4\uff09\u3002\u652f\u6301\u7a7a\u683c\u3001\u5236\u8868\u7b26\u5206\u9694\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a\n<ol class=\"wp-block-list\">\n<li>\u521b\u5efa\u4e00\u4e2a\u6587\u4ef6 <code>targets.txt<\/code>\uff0c\u5185\u5bb9\u5982\u4e0b\uff1a<br>scanme.nmap.org 192.168.1.1 192.168.1.10-50 10.1.1.0\/24<\/li>\n\n\n\n<li>\u8fd0\u884c\u547d\u4ee4\uff1a<br>bash                                                                                                                                                            nmap -iL targets.txt<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li><strong>\u7279\u6b8a\u7528\u6cd5<\/strong>\uff1a\u4f7f\u7528 <code>-<\/code> \u4ece\u6807\u51c6\u8f93\u5165\u8bfb\u53d6\u3002\u53ef\u4ee5\u4e0e\u5176\u4ed6\u547d\u4ee4\u7ed3\u5408\u3002<br><code>bash echo \u201c192.168.1.1\u201d | nmap -iL - cat massive_list.txt | grep \u201cweb-server\u201d | nmap -iL -<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-iR &lt;\u6570\u91cf&gt;<\/code>\uff1a\u968f\u673a\u76ee\u6807\u751f\u6210<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u8b66\u544a<\/strong>\uff1a<strong>\u4ec5\u5728\u60a8\u62e5\u6709\u5b8c\u5168\u6388\u6743\u3001\u7528\u4e8e\u5b66\u672f\u7814\u7a76\u6216\u5b89\u5168\u666e\u67e5\u65f6\u4f7f\u7528\uff01<\/strong> \u968f\u673a\u626b\u63cf\u4e92\u8054\u7f51\u4e3b\u673a\u5728\u8bb8\u591a\u5730\u533a\u662f\u975e\u6cd5\u7684\uff0c\u4e14\u6781\u6613\u89e6\u53d1\u5b89\u5168\u8b66\u62a5\u3002<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\u7f51\u7edc\u6d4b\u91cf\u5b66\u7814\u7a76\u3001\u8bc4\u4f30\u4e92\u8054\u7f51\u670d\u52a1\u7684\u66b4\u9732\u9762\u3001\u6d4b\u8bd5IDS\/IPS\u89c4\u5219\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br>bash # \u968f\u673a\u9009\u62e9100\u4e2aIP\u5730\u5740\uff0c\u626b\u63cf\u517680\u548c443\u7aef\u53e3 nmap -iR 100 -p 80,443 &#8211;open<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>--exclude &lt;\u76ee\u68071,\u76ee\u68072,...&gt;<\/code> \u4e0e <code>--excludefile &lt;\u6587\u4ef6\u540d&gt;<\/code>\uff1a\u6392\u9664\u76ee\u6807<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u6838\u5fc3\u4ef7\u503c<\/strong>\uff1a\u5728\u626b\u63cf\u4e00\u4e2a\u5927\u7684\u8303\u56f4\u65f6\uff0c\u907f\u514d\u626b\u63cf\u5173\u952e\u751f\u4ea7\u670d\u52a1\u5668\u3001\u5df2\u77e5\u7684\u871c\u7f50\u3001\u6216\u53cb\u90bb\u7f51\u7edc\uff0c\u4ece\u800c\u51cf\u5c11\u5e72\u6270\u548c\u98ce\u9669\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br><code>bash # \u626b\u63cf\u6574\u4e2a192.168.1.0\/24\u7f51\u6bb5\uff0c\u4f46\u4e0d\u626b\u63cf\u7f51\u5173\u548c\u4e00\u53f0\u7279\u5b9a\u670d\u52a1\u5668 nmap 192.168.1.0\/24 --exclude 192.168.1.1,192.168.1.50 # \u626b\u63cf\u591a\u4e2a\u7f51\u6bb5\uff0c\u4f46\u6392\u9664\u4e00\u4e2a\u654f\u611f\u7684\u5b50\u7f51nmap 192.168.1.0\/24,10.0.0.0\/16 --exclude 10.0.1.0\/24<\/code><\/li>\n\n\n\n<li><code>--excludefile<\/code> \u7528\u6cd5\u4e0e <code>-iL<\/code> \u7c7b\u4f3c\uff0c\u7528\u4e8e\u7ba1\u7406\u590d\u6742\u7684\u6392\u9664\u5217\u8868\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap11.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"891\" height=\"266\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap11.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1485\"  sizes=\"auto, (max-width: 891px) 100vw, 891px\" \/><\/div><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u7b2c\u4e09\u90e8\u5206\uff1a\u4f7f\u7528\u6307\u5357\u4e0e\u5b9e\u8df5<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5982\u4f55\u9009\u62e9\u76ee\u6807\u683c\u5f0f\uff1f\u2014\u2014 \u51b3\u7b56\u6d41\u7a0b\u56fe<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5355\u53f0\u4e3b\u673a\u6216\u57df\u540d -&gt; <strong>\u76f4\u63a5\u4f7f\u7528IP\u6216\u4e3b\u673a\u540d<\/strong>\u3002<\/li>\n\n\n\n<li>\u4e00\u4e2a\u8fde\u7eed\u7684IP\u6bb5\uff08\u5b50\u7f51\uff09-&gt; <strong>\u4f18\u5148\u4f7f\u7528CIDR<\/strong>\uff08\u5982 <code>\/24<\/code>\uff09\uff0c\u5b83\u6700\u7b80\u6d01\u3002<\/li>\n\n\n\n<li>\u591a\u4e2a\u4e0d\u8fde\u7eedIP\u3001\u590d\u6742\u8303\u56f4\u3001\u9700\u8981\u8df3\u8fc7\u7279\u5b9a\u5730\u5740 -&gt; <strong>\u5fc5\u987b\u4f7f\u7528\u516b\u4f4d\u5b57\u8282\u8303\u56f4\u5217\u8868<\/strong>\u3002<\/li>\n\n\n\n<li>\u76ee\u6807\u5217\u8868\u5df2\u5b58\u5728\u4e8e\u6587\u4ef6\u4e2d -&gt; <strong>\u4f7f\u7528 <code>-iL<\/code><\/strong>\u3002<\/li>\n\n\n\n<li>\u5927\u8303\u56f4\u626b\u63cf\u4e2d\u9700\u8981\u907f\u514d\u67d0\u4e9b\u4e3b\u673a -&gt; <strong>\u7ed3\u5408\u4f7f\u7528 <code>--exclude<\/code> \u6216 <code>--excludefile<\/code><\/strong>\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7efc\u5408\u793a\u4f8b<\/strong><br><code>bash # \u573a\u666f\uff1a\u626b\u63cf\u5185\u90e8\u529e\u516c\u7f51\u7edc\uff08192.168.10.0\/24\uff09\uff0c\u4f46\u6392\u9664IT\u90e8\u95e8\u7684\u670d\u52a1\u5668\u6bb5\uff08.100-.120\uff09\u548c\u6253\u5370\u673a\uff08.50\uff09\uff0c\u540c\u65f6\u626b\u63cfDMZ\u533a\u7684\u4e00\u53f0Web\u670d\u52a1\u5668\u3002 nmap 192.168.10.0\/24,203.0.113.5 --exclude 192.168.10.100-120,192.168.10.50 -oN internal_scan.txt<\/code><\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Nmap\u4e3b\u673a\u53d1\u73b0 &#8211; \u8be6\u7ec6\u6559\u5b66\u6307\u5357<\/strong><\/h2>\n\n\n\n<p>\u4e3b\u673a\u53d1\u73b0\u7684\u76ee\u6807\u662f\u5c06\u5e9e\u5927\u7684IP\u5730\u5740\u5217\u8868\u7f29\u51cf\u4e3a\u4e00\u4efd\u201c\u6d3b\u52a8\u4e3b\u673a\u201d\u6e05\u5355\u3002\u76f2\u76ee\u626b\u63cf\u6240\u6709IP\u7684\u6240\u6709\u7aef\u53e3\uff0c\u5728\u65f6\u95f4\u548c\u8d44\u6e90\u4e0a\u90fd\u662f\u707e\u96be\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u7b2c\u4e00\u90e8\u5206\uff1a\u6838\u5fc3\u6982\u5ff5\u4e0e\u9ed8\u8ba4\u884c\u4e3a\u89e3\u6790<\/strong><\/h3>\n\n\n\n<p><strong>1. \u6838\u5fc3\u6bd4\u55bb\uff1a\u5982\u4f55\u201c\u6572\u95e8\u201d<\/strong><br>\u60f3\u8c61\u4f60\u8981\u786e\u5b9a\u4e00\u680b\u516c\u5bd3\u697c\u91cc\u54ea\u4e9b\u623f\u95f4\u6709\u4eba\u3002\u4f60\u53ef\u4ee5\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u8f7b\u8f7b\u6572\u95e8\uff08ICMP Echo\uff09<\/strong>\uff1a\u8bf4\u201c\u4f60\u597d\uff0c\u6709\u4eba\u5417\uff1f\u201d<\/li>\n\n\n\n<li><strong>\u8bd5\u56fe\u62e7\u52a8\u95e8\u628a\u624b\uff08TCP SYN\uff09<\/strong>\uff1a\u770b\u95e8\u662f\u5426\u9501\u7740\u3002<\/li>\n\n\n\n<li><strong>\u68c0\u67e5\u95e8\u7f1d\u4e0b\u662f\u5426\u6709\u5149\uff08ARP\u8bf7\u6c42\uff09<\/strong>\uff1a\u5728\u540c\u4e00\u4e2a\u697c\u9053\u91cc\uff0c\u76f4\u63a5\u558a\u623f\u95f4\u4e3b\u4eba\u7684\u540d\u5b57\u3002<br>Nmap\u7684\u4e3b\u673a\u53d1\u73b0\u5c31\u662f\u8fd0\u7528\u4e86\u7f51\u7edc\u4e16\u754c\u4e2d\u5404\u79cd\u201c\u6572\u95e8\u201d\u65b9\u5f0f\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>2. \u9ed8\u8ba4\u884c\u4e3a\u662f\u4ec0\u4e48\uff1f\uff08\u5fc5\u987b\u77e5\u9053\uff09<\/strong><br>\u5f53\u4f60\u5728\u547d\u4ee4\u884c\u53ea\u8f93\u5165 <code>nmap &lt;\u76ee\u6807&gt;<\/code> \u800c\u4e0d\u6307\u5b9a\u4efb\u4f55\u53d1\u73b0\u9009\u9879\u65f6\uff0cNmap\u4f1a\u6267\u884c\u4e00\u5957<strong>\u7ec4\u5408\u62f3<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5bf9\u5c40\u57df\u7f51\u5185\u7684\u76ee\u6807<\/strong>\uff1a\u9ed8\u8ba4\u4f7f\u7528 <strong>ARP\u53d1\u73b0 (<code>-PR<\/code>)<\/strong>\u3002\u8fd9\u662f\u6700\u5feb\u7684\uff0c\u56e0\u4e3aARP\u662f\u5c40\u57df\u7f51\u901a\u4fe1\u7684\u57fa\u7840\u534f\u8bae\uff0c\u65e0\u6cd5\u88ab\u4e3b\u673a\u9632\u706b\u5899\u963b\u6b62\u3002<\/li>\n\n\n\n<li><strong>\u5bf9\u975e\u5c40\u57df\u7f51\uff08\u4e92\u8054\u7f51\uff09\u7684\u76ee\u6807<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u53d1\u9001\u4e00\u4e2a <strong>TCP ACK\u62a5\u6587<\/strong> \u5230\u76ee\u6807\u768480\u7aef\u53e3\u3002<\/li>\n\n\n\n<li>\u53d1\u9001\u4e00\u4e2a <strong>ICMP\u56de\u58f0\u8bf7\u6c42\uff08ping\uff09<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\uff08\u975e\u7279\u6743\u7528\u6237\uff09<\/strong> \u53d1\u9001\u4e00\u4e2a <strong>TCP SYN\u62a5\u6587<\/strong> \u5230\u76ee\u6807\u768480\u7aef\u53e3\uff08\u901a\u8fc7<code>connect()<\/code>\u7cfb\u7edf\u8c03\u7528\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u8865\u5145<\/h4>\n\n\n\n<p>Nmap\u6838\u5fc3\u901a\u8fc7\u76ee\u6807IP\u7684\u7f51\u6bb5\u5c5e\u6027+\u672c\u5730\u7f51\u5361\u7684\u8def\u7531\/\u5b50\u7f51\u914d\u7f6e\u5224\u65ad\u76ee\u6807\u662f\u5c40\u57df\u7f51\uff08\u5185\u7f51\uff09\u8fd8\u662f\u5916\u7f51\uff0c\u6838\u5fc3\u52063\u6b65\u6267\u884c\uff0c\u5224\u65ad\u903b\u8f91\uff1a<\/p>\n\n\n\n<p>1.&nbsp;\u5339\u914d\u672c\u5730\u5b50\u7f51\uff1aNmap\u5148\u8bfb\u53d6\u672c\u5730\u6240\u6709\u7f51\u5361\u7684IP\u3001\u5b50\u7f51\u63a9\u7801\uff08\u5982&nbsp;192.168.1.0\/24&nbsp;\u3001&nbsp;10.0.0.0\/8&nbsp;\uff09\uff0c\u5224\u65ad\u76ee\u6807IP\u662f\u5426\u843d\u5728\u672c\u5730\u76f4\u8fde\u7684\u5b50\u7f51\u7f51\u6bb5\u5185\uff0c\u82e5\u662f\u5219\u5224\u5b9a\u4e3a\u5c40\u57df\u7f51\u3002<br>2.&nbsp;\u68c0\u67e5\u8def\u7531\u8868\uff1a\u82e5\u76ee\u6807IP\u4e0d\u5728\u672c\u5730\u5b50\u7f51\uff0cNmap\u67e5\u8be2\u7cfb\u7edf\u8def\u7531\u8868\uff0c\u770b\u76ee\u6807\u662f\u5426\u6307\u5411\u76f4\u8fde\u7684\u7f51\u5173\u63a5\u53e3\uff08\u800c\u975e\u516c\u7f51\u7f51\u5173\uff09\uff0c\u76f4\u8fde\u5219\u4e3a\u5185\u7f51\uff0c\u5426\u5219\u4e3a\u5916\u7f51\u3002<br>3.&nbsp;\u7279\u6b8a\u60c5\u51b5\u515c\u5e95\uff1a\u5bf9&nbsp;127.0.0.0\/8&nbsp;\uff08\u672c\u5730\u56de\u73af\uff09\u3001&nbsp;169.254.0.0\/16&nbsp;\uff08\u94fe\u8def\u672c\u5730\uff09\u7b49\u79c1\u6709\/\u4fdd\u7559\u7f51\u6bb5\uff0c\u76f4\u63a5\u5224\u5b9a\u4e3a\u5185\u7f51\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u53ea\u8981\u5224\u5b9a\u4e3a\u5c40\u57df\u7f51\u76ee\u6807\uff0c\u9ed8\u8ba4\u626b\u63cf\u5c31\u4f18\u5148\u7528&nbsp;-PR&nbsp;\uff08ARP\u626b\u63cf\uff09\uff0c\u56e0\u4e3aARP\u662f\u4e8c\u5c42\u534f\u8bae\uff0c\u4e0d\u7ecf\u8fc7IP\u8def\u7531\uff0c\u9632\u706b\u5899\u65e0\u6cd5\u62e6\u622a\uff0c\u901f\u5ea6\u6700\u5feb\uff1b<\/li>\n\n\n\n<li>\u5224\u5b9a\u4e3a\u5916\u7f51\u76ee\u6807\uff0c\u5219\u653e\u5f03ARP\uff08\u4e8c\u5c42\u534f\u8bae\u8de8\u7f51\u6bb5\u65e0\u6548\uff09\uff0c\u6539\u7528\u4f60\u8bf4\u7684TCP ACK+ICMP Ping+\uff08\u975e\u7279\u6743\uff09TCP SYN\u7684\u4e09\u5c42\/\u56db\u5c42\u63a2\u6d4b\u7ec4\u5408\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u7b80\u5355\u9a8c\u8bc1\u65b9\u6cd5<\/p>\n\n\n\n<p>\u5728\u547d\u4ee4\u884c\u8f93\u5165&nbsp;nmap -v &lt;\u76ee\u6807IP&gt;&nbsp;\uff0c\u901a\u8fc7verbose\u65e5\u5fd7\u80fd\u76f4\u63a5\u770b\u5230Nmap\u7684\u5224\u5b9a\u7ed3\u679c\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5185\u7f51\u76ee\u6807\u4f1a\u663e\u793a&nbsp;Initiating ARP Ping Scan&nbsp;\uff1b<\/li>\n\n\n\n<li>\u5916\u7f51\u76ee\u6807\u4f1a\u663e\u793a&nbsp;Initiating Ping Scan&nbsp;\uff08\u5bf9\u5e94TCP\/ICMP\u63a2\u6d4b\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap12-1024x497.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"497\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap12-1024x497.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1490\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap13-1024x520.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"520\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap13-1024x520.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1491\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p>\u5224\u65ad\u65b9\u6cd5\uff1a\u770bNmap\u521d\u59cb\u5316\u7684\u9996\u4e2a\u63a2\u6d4b\u7c7b\u578b\uff08\u6700\u76f4\u63a5\uff0c\u548cIP\u6bb5\u65e0\u5173\uff09<\/p>\n\n\n\n<p>Nmap\u4f1a\u6839\u636e\u5185\u5916\u7f51\uff0c\u81ea\u52a8\u89e6\u53d1\u4e0d\u540c\u7684\u5b58\u6d3b\u63a2\u6d4b\u65b9\u5f0f\uff0c\u626b\u63cf\u65e5\u5fd7\u7b2c\u4e00\u884c\u7684\u63a2\u6d4b\u5173\u952e\u8bcd\u662f\u6838\u5fc3\u6807\u8bc6\uff0c\u8fd9\u662f\u6bd4IP\u6bb5\u66f4\u8d34\u5408\u626b\u63cf\u7ed3\u679c\u7684\u5224\u65ad\u4f9d\u636e\uff1a<\/p>\n\n\n\n<p>\u5916\u7f51\u76ee\u6807\uff1a\u65e5\u5fd7\u9996\u884c\u663e\u793a\u300c&nbsp;Initiating Ping Scan&nbsp;\u300d<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5bf9\u5e94\u4f60\u7b2c\u4e8c\u4e2a\u626b\u63cf\uff08114.66.59.86\uff09\uff1a\u7b2c\u4e00\u884c\u5c31\u662f&nbsp;Initiating Ping Scan&nbsp;\uff0c\u8fd9\u662fNmap\u5bf9\u5916\u7f51\u7684\u9ed8\u8ba4\u5b58\u6d3b\u63a2\u6d4b\uff0c\u53ea\u4f1a\u5bf9\u8de8\u7f51\u6bb5\u7684\u516c\u7f51\u76ee\u6807\u89e6\u53d1\uff1b<\/li>\n\n\n\n<li>\u8865\u5145\uff1a\u5916\u7f51Ping Scan\u5b9e\u9645\u662f\u300cTCP ACK+ICMP\u56de\u58f0+\uff08\u975e\u7279\u6743\uff09TCP SYN\u300d\u7684\u7ec4\u5408\u63a2\u6d4b\uff0c\u65e5\u5fd7\u91cc\u7b80\u5316\u663e\u793a\u4e3aPing Scan\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u5185\u7f51\u76ee\u6807\uff1a\u65e5\u5fd7\u4f1a\u663e\u793a\u300c&nbsp;Initiating ARP Ping Scan&nbsp;\u300d\uff08\u6838\u5fc3\u7279\u5f81\uff09<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u82e5\u4f60\u7b2c\u4e00\u4e2a\u5185\u7f51\u626b\u63cf\uff08192.168.48.1\uff09\u672a\u8df3\u8fc7ARP\u63a2\u6d4b\uff0c\u65e5\u5fd7\u9996\u884c\u4f1a\u4f18\u5148\u51fa\u73b0\u8fd9\u4e2a\u5173\u952e\u8bcd\uff0c\u8fd9\u662fNmap\u5bf9\u5185\u7f51\u76f4\u8fde\u76ee\u6807\u7684\u4e13\u5c5e\u63a2\u6d4b\uff08\u4e8c\u5c42ARP\u534f\u8bae\uff0c\u5916\u7f51\u65e0\u6cd5\u4f7f\u7528\uff09\uff1b<\/li>\n\n\n\n<li>\u4f60\u7b2c\u4e00\u4e2a\u626b\u63cf\u672a\u663e\u793a\u8be5\u65e5\u5fd7\uff0c\u662f\u56e0\u4e3aNmap\u5feb\u901f\u5b8c\u6210SYN\u626b\u63cf\u5e76\u786e\u8ba4\u4e3b\u673a\u5b58\u6d3b\uff0c\u8df3\u8fc7\u4e86\u663e\u5f0f\u7684ARP Ping Scan\u65e5\u5fd7\uff0c\u4f46\u8fd9\u662f\u5185\u7f51\u626b\u63cf\u7684\u300c\u7279\u6b8a\u60c5\u51b5\u300d\uff0c\u800c\u975e\u5e38\u6001\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u8f85\u52a9\u5224\u65ad\uff1a\u770b\u626b\u63cf\u5ef6\u8fdf+\u63a2\u6d4b\u987a\u5e8f\uff08\u5185\u5916\u7f51\u5dee\u5f02\u660e\u663e\uff09<\/p>\n\n\n\n<p>1.&nbsp;\u5185\u7f51\uff1a\u4e3b\u673a\u5b58\u6d3b\u5ef6\u8fdf\u6781\u4f4e\uff08\u5982\u4f60\u7b2c\u4e00\u4e2a\u626b\u63cf&nbsp;0.00098s&nbsp;\uff09\uff0c\u901a\u5e38\u6beb\u79d2\u7ea7\u751a\u81f3\u5fae\u79d2\u7ea7\uff1b\u5916\u7f51\u5ef6\u8fdf\u81f3\u5c11\u51e0\u5341ms\u8d77\u6b65\uff08\u516c\u7f51\u8def\u7531\u8f6c\u53d1\u6709\u8017\u65f6\uff09\uff1b<br>2.&nbsp;\u5185\u7f51\uff1a\u82e5\u672a\u8df3\u8fc7ARP\u63a2\u6d4b\uff0cARP Ping Scan\u4f1a\u5728DNS\u89e3\u6790\/\u7aef\u53e3\u626b\u63cf\u524d\u6267\u884c\uff1b\u5916\u7f51\u5219\u662fPing Scan\u5148\u6267\u884c\uff0c\u518d\u8d70DNS\u89e3\u6790+\u7aef\u53e3\u626b\u63cf\uff08\u548c\u4f60\u7b2c\u4e8c\u4e2a\u626b\u63cf\u7684\u987a\u5e8f\u5b8c\u5168\u4e00\u81f4\uff09\u3002<\/p>\n\n\n\n<p>\u603b\u7ed3\uff1a\u8131\u79bbIP\u6bb5\uff0c\u7eaf\u770b\u626b\u63cf\u7ed3\u679c\u76843\u6b65\u5feb\u901f\u5224\u65ad\u6cd5<\/p>\n\n\n\n<p>1.&nbsp;\u627e\u65e5\u5fd7\u6700\u5f00\u5934\u7684\u63a2\u6d4b\u884c\uff1a\u6709&nbsp;ARP Ping Scan&nbsp;=\u5185\u7f51\uff0c\u6709&nbsp;Ping Scan&nbsp;=\u5916\u7f51\uff08\u6838\u5fc3\uff09\uff1b<br>2.&nbsp;\u770b\u4e3b\u673a\u5b58\u6d3b\u5ef6\u8fdf\uff1a\u22640.01s\uff08\u5343\u5206\u4e4b\u4e00\u79d2\uff09=\u5185\u7f51\uff0c\u22650.01s\u4e14\u66f4\u9ad8=\u5916\u7f51\uff08\u8f85\u52a9\uff09\uff1b<br>3.&nbsp;\u770b\u63a2\u6d4b\u4e0eDNS\u7684\u987a\u5e8f\uff1aARP\u63a2\u6d4b\u5728DNS\u524d=\u5185\u7f51\uff0cPing\u63a2\u6d4b\u5728DNS\u524d=\u5916\u7f51\uff08\u9a8c\u8bc1\uff09\u3002<\/p>\n\n\n\n<p>\u9488\u5bf9\u4e24\u4e2a\u626b\u63cf\u7684\u7eaf\u7ed3\u679c\u5224\u5b9a\uff08\u629b\u5f00IP\uff09<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>192.168.48.1\uff08\u5185\u7f51\uff09\uff1a\u5ef6\u8fdf&nbsp;0.00098s&nbsp;\uff08\u5185\u7f51\u5178\u578b\u4f4e\u5ef6\u8fdf\uff09\uff0cNmap\u76f4\u63a5\u89e6\u53d1SYN\u626b\u63cf\u4e14\u65e0\u5916\u7f51\u7684&nbsp;Ping Scan&nbsp;\u524d\u7f6e\u63a2\u6d4b\uff0c\u7b26\u5408\u5185\u7f51\u626b\u63cf\u7279\u5f81\uff1b<\/li>\n\n\n\n<li>114.66.59.86\uff08\u5916\u7f51\uff09\uff1a\u65e5\u5fd7\u9996\u884c\u660e\u786e&nbsp;Initiating Ping Scan&nbsp;\uff08\u5916\u7f51\u4e13\u5c5e\u63a2\u6d4b\uff09\uff0c\u63a2\u6d4b\u540e\u624d\u6267\u884cDNS\u89e3\u6790+SYN\u626b\u63cf\uff0c\u5b8c\u5168\u5339\u914d\u5916\u7f51\u626b\u63cf\u903b\u8f91\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u7406\u89e3\u8fd9\u4e00\u70b9\u81f3\u5173\u91cd\u8981<\/strong>\uff1a\u8fd9\u89e3\u91ca\u4e86\u4e3a\u4ec0\u4e48\u626b\u63cf\u672c\u5730\u7f51\u7edc\u98de\u5feb\uff0c\u800c\u626b\u63cf\u5916\u90e8IP\u6709\u65f6\u4f1a\u6162\u4e00\u4e9b\uff0c\u5e76\u4e14\u6709\u4e9b\u4e3b\u673a\u660e\u660e\u5728\u7ebf\u5374\u6ca1\u88ab\u53d1\u73b0\uff08\u56e0\u4e3a\u9632\u706b\u5899\u62e6\u4f4f\u4e86\u9ed8\u8ba4\u7684\u63a2\u6d4b\u5305\uff09\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u7b2c\u4e8c\u90e8\u5206\uff1a\u4e3b\u673a\u53d1\u73b0\u9009\u9879\u8be6\u89e3\u4e0e\u573a\u666f\u5e94\u7528<\/strong><\/h3>\n\n\n\n<p>\u6211\u4eec\u6309\u201c\u7b56\u7565\u7c7b\u578b\u201d\u6765\u91cd\u65b0\u7ec4\u7ec7\u8fd9\u4e9b\u9009\u9879\uff0c\u65b9\u4fbf\u4f60\u7406\u89e3\u3002<\/p>\n\n\n\n<p><strong>A. \u7b56\u7565\u6027\u9009\u9879\uff08\u51b3\u5b9a\u201c\u6572\u4e0d\u6572\u95e8\u201d\u6216\u201c\u600e\u4e48\u6572\u95e8\u201d\uff09<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong><code>-sL<\/code> (\u5217\u8868\u626b\u63cf) \u2014\u2014 \u201c\u53ea\u67e5\u770b\u95e8\u724c\u53f7\u201d<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u672c\u8d28<\/strong>\uff1a<strong>\u96f6\u626b\u63cf<\/strong>\u3002\u4e0d\u5411\u76ee\u6807\u53d1\u9001\u4efb\u4f55\u63a2\u6d4b\u5305\uff0c\u4ec5\u8fdb\u884cDNS\u53cd\u5411\u89e3\u6790\uff0c\u5217\u51fa\u6240\u6709\u76ee\u6807\u3002<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u76ee\u6807\u6e05\u5355\u6838\u5b9e<\/strong>\uff1a\u786e\u4fdd\u4f60\u8981\u626b\u63cf\u7684IP\u8303\u56f4\u6b63\u786e\uff0c\u907f\u514d\u8bef\u626b\u3002<\/li>\n\n\n\n<li><strong>\u4fe1\u606f\u641c\u96c6<\/strong>\uff1a\u901a\u8fc7DNS\u89e3\u6790 (<code>nmap -sL --dns-servers &lt;DNS_IP&gt; \u76ee\u6807<\/code>)\uff0c\u53ef\u80fd\u53d1\u73b0\u5982 <code>printer1.corp.com<\/code>\uff0c <code>fw.dmz.com<\/code> \u7b49\u6709\u4ef7\u503c\u7684\u4e3b\u673a\u540d\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br><code>bash # \u67e5\u770b192.168.1.0\/24\u7f51\u6bb5\u6240\u6709\u4e3b\u673a\u540d nmap -sL 192.168.1.0\/24 # \u4ec5\u8f93\u51faIP\uff0c\u4e0d\u8fdb\u884cDNS\u89e3\u6790\uff08\u66f4\u5feb\uff09 nmap -sL -n 192.168.1.0\/24<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-sn<\/code> (\u539f <code>-sP<\/code>) (Ping\u626b\u63cf) \u2014\u2014 \u201c\u53ea\u6572\u95e8\uff0c\u4e0d\u8fdb\u53bb\u201d<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u672c\u8d28<\/strong>\uff1a<strong>\u4ec5\u4e3b\u673a\u53d1\u73b0<\/strong>\u3002\u6267\u884c\u53d1\u73b0\u6b65\u9aa4\uff0c\u4e00\u65e6\u786e\u8ba4\u4e3b\u673a\u5b58\u6d3b\u5c31\u505c\u6b62\uff0c<strong>\u4e0d\u8fdb\u884c\u7aef\u53e3\u626b\u63cf<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u91cd\u8981\u7ec6\u8282<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5b83\u4f7f\u7528\u7684\u662fNmap\u9ed8\u8ba4\u7684\u6216\u4f60\u6307\u5b9a\u7684\u4e3b\u673a\u53d1\u73b0\u63a2\u9488\uff08\u5982<code>-PS<\/code>\uff0c <code>-PA<\/code>\u7b49\uff09\uff0c\u4e0d\u4ec5\u4ec5\u662fICMP ping\u3002<\/li>\n\n\n\n<li>\u5728\u5c40\u57df\u7f51\u4e0a\uff0c\u7279\u6743\u7528\u6237\u9ed8\u8ba4\u4f1a\u4f7f\u7528ARP (<code>-PR<\/code>)\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u6e05\u70b9<\/strong>\uff1a\u5feb\u901f\u7edf\u8ba1\u7f51\u7edc\u4e2d\u6709\u591a\u5c11\u5728\u7ebf\u8bbe\u5907\u3002<\/li>\n\n\n\n<li><strong>\u5b58\u6d3b\u76d1\u63a7<\/strong>\uff1a\u5b9a\u671f\u8fd0\u884c\u4ee5\u76d1\u63a7\u5173\u952e\u670d\u52a1\u5668\u662f\u5426\u5728\u7ebf\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br><code>bash # \u5feb\u901f\u627e\u51fa192.168.1.0\/24\u7f51\u6bb5\u6240\u6709\u5728\u7ebf\u4e3b\u673a nmap -sn 192.168.1.0\/24 # \u4f7f\u7528\u66f4\u6fc0\u8fdb\u7684\u63a2\u9488\u6765\u7a7f\u900f\u9632\u706b\u5899\u8fdb\u884c\u5b58\u6d3b\u5224\u65ad nmap -sn -PS22,80,443 -PA21,25,3389 -PU53 203.0.113.0\/24<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-Pn<\/code> (\u539f <code>-P0<\/code>) (\u65e0Ping) \u2014\u2014 \u201c\u5047\u8bbe\u6240\u6709\u95e8\u540e\u90fd\u6709\u4eba\uff0c\u76f4\u63a5\u5c1d\u8bd5\u5f00\u9501\u201d<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u672c\u8d28<\/strong>\uff1a<strong>\u8df3\u8fc7\u4e3b\u673a\u53d1\u73b0<\/strong>\uff0c\u5c06\u6240\u6709\u76ee\u6807\u89c6\u4e3a\u5728\u7ebf\uff0c\u76f4\u63a5\u8fdb\u884c\u540e\u7eed\u7684\u7aef\u53e3\u626b\u63cf\u3001\u7248\u672c\u63a2\u6d4b\u7b49\u3002<strong>\u8fd9\u662f\u7a7f\u900f\u4e25\u683c\u9632\u706b\u5899\u7684\u5e38\u7528\u624b\u6bb5\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u8b66\u544a<\/strong>\uff1a\u8fd9\u4f1a<strong>\u663e\u8457\u589e\u52a0\u626b\u63cf\u65f6\u95f4<\/strong>\uff0c\u56e0\u4e3a\u4f1a\u5bf9\u6bcf\u4e00\u4e2a\u6307\u5b9a\u7684IP\uff08\u5373\u4f7f\u662f\u6b7b\u7684\uff09\u8fdb\u884c\u5168\u5957\u626b\u63cf\u3002<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u76ee\u6807\u4e3b\u673a\u914d\u7f6e\u4e3a<strong>\u4e0d\u54cd\u5e94\u4efb\u4f55Ping\u63a2\u6d4b<\/strong>\u3002<\/li>\n\n\n\n<li>\u4f60<strong>\u660e\u786e\u77e5\u9053<\/strong>\u76ee\u6807\u7f51\u7edc\u5728\u7ebf\uff0c\u4f46\u9632\u706b\u5899\u8fc7\u6ee4\u4e86\u53d1\u73b0\u63a2\u9488\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br><code>bash # \u5047\u8bbe\u76ee\u6807\u9632\u706b\u5899\u4e22\u5f03ICMP\u548c\u975e\u5e38\u7528\u7aef\u53e3\u7684SYN\/ACK\uff0c\u76f4\u63a5\u626b\u63cf\u5176Web\u7aef\u53e3 nmap -Pn -p 80,443,8080,8443 10.0.0.0\/24<\/code><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap14.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"968\" height=\"419\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap14.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1493\"  sizes=\"auto, (max-width: 968px) 100vw, 968px\" \/><\/div><figcaption class=\"wp-element-caption\"><code>nmap -sL -n 192.168.48.0\/24<\/code><\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap15-1024x221.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"221\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap15-1024x221.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1495\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><figcaption class=\"wp-element-caption\"><code>nmap -sn -PS22,80,443 -PA21,25,3389 -PU53 192.168.48.0\/24<\/code><\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap16-1024x517.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"517\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap16-1024x517.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1500\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><figcaption class=\"wp-element-caption\">nmap -Pn -p 80,443,8080,8443 192.168.48.0\/24<\/figcaption><\/figure>\n\n\n\n<p><strong>B. \u4e3b\u52a8\u63a2\u6d4b\u9009\u9879\uff08\u51b3\u5b9a\u201c\u7528\u4ec0\u4e48\u65b9\u5f0f\u6572\u95e8\u201d\uff09<\/strong><\/p>\n\n\n\n<p>\u8fd9\u4e9b\u9009\u9879\u53ef\u4ee5\u7ec4\u5408\u4f7f\u7528\uff0c\u4ee5\u589e\u52a0\u7a7f\u900f\u80fd\u529b\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong><code>-PS &lt;\u7aef\u53e3\u5217\u8868&gt;<\/code> (TCP SYN Ping) \u2014\u2014 \u201c\u8f7b\u8f7b\u62e7\u4e00\u4e0b\u95e8\u628a\u624b\u201d<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5411\u6307\u5b9a\u7aef\u53e3\u53d1\u9001\u4e00\u4e2a<strong>SYN\u5305<\/strong>\uff08\u8bd5\u56fe\u5efa\u7acb\u8fde\u63a5\uff09\u3002<\/li>\n\n\n\n<li>\u5982\u679c\u7aef\u53e3\u5173\u95ed\uff0c\u76ee\u6807\u56de\u590d <strong>RST<\/strong> (\u8868\u793a\u201c\u95e8\u9501\u7740\uff0c\u522b\u62e7\u4e86\u201d) -&gt; <strong>\u4e3b\u673a\u5b58\u6d3b<\/strong>\u3002<\/li>\n\n\n\n<li>\u5982\u679c\u7aef\u53e3\u5f00\u653e\uff0c\u76ee\u6807\u56de\u590d <strong>SYN\/ACK<\/strong> (\u8868\u793a\u201c\u95e8\u5f00\u4e86\uff0c\u8bf7\u8fdb\u201d) -&gt; <strong>\u4e3b\u673a\u5b58\u6d3b<\/strong>\u3002<\/li>\n\n\n\n<li>Nmap\u4f1a\u53d1\u9001RST\u7ec8\u6b62\u8fde\u63a5\uff0c\u907f\u514d\u5efa\u7acb\u5b8c\u6574\u8fde\u63a5\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<code>nmap -sn -PS80,443 192.168.1.100<\/code> (\u63a2\u6d4b\u76ee\u6807\u768480\u548c443\u7aef\u53e3)<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-PA &lt;\u7aef\u53e3\u5217\u8868&gt;<\/code> (TCP ACK Ping) \u2014\u2014 \u201c\u63a8\u4e00\u4e0b\u770b\u4f3c\u865a\u63a9\u7684\u95e8\u201d<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5411\u6307\u5b9a\u7aef\u53e3\u53d1\u9001\u4e00\u4e2a<strong>ACK\u5305<\/strong>\uff08\u5047\u88c5\u662f\u5df2\u5efa\u7acb\u8fde\u63a5\u7684\u4e00\u90e8\u5206\u6570\u636e\uff09\u3002<\/li>\n\n\n\n<li>\u65e0\u8bba\u7aef\u53e3\u72b6\u6001\u5982\u4f55\uff0c\u4e00\u4e2a\u672a\u53d1\u8d77\u8fde\u63a5\u7684\u4e3b\u673a\u90fd\u5fc5\u987b\u56de\u590d <strong>RST<\/strong> -&gt; <strong>\u4e3b\u673a\u5b58\u6d3b<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u4ef7\u503c<\/strong>\uff1a\u7528\u4e8e\u7a7f\u900f<strong>\u53ea\u8fc7\u6ee4\u5165\u7ad9SYN\u5305\uff08\u65b0\u8fde\u63a5\uff09<\/strong> \u7684\u7b80\u5355\u65e0\u72b6\u6001\u9632\u706b\u5899\u3002ACK\u5305\u770b\u8d77\u6765\u50cf\u662f\u5bf9\u5185\u90e8\u4e3b\u673a\u5411\u5916\u53d1\u8d77\u8fde\u63a5\u7684\u56de\u5e94\uff0c\u53ef\u80fd\u88ab\u653e\u884c\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7ec4\u5408\u62f3\uff1a<code>-PS -PA<\/code><\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u6700\u4f73\u5b9e\u8df5<\/strong>\uff1a\u540c\u65f6\u4f7f\u7528SYN\u548cACK Ping\uff0c\u4ee5\u5e94\u5bf9\u4e0d\u540c\u7c7b\u578b\u7684\u9632\u706b\u5899\u89c4\u5219\uff08\u65e0\u72b6\u6001 vs \u6709\u72b6\u6001\uff09\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<code>nmap -sn -PS80 -PA80 \u76ee\u6807<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-PU &lt;\u7aef\u53e3\u5217\u8868&gt;<\/code> (UDP Ping) \u2014\u2014 \u201c\u5f80\u95e8\u91cc\u6254\u4e2a\u5c0f\u7eb8\u6761\u201d<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5411\u6307\u5b9a\u7aef\u53e3\u53d1\u9001\u4e00\u4e2a<strong>\u7a7a\u7684UDP\u5305<\/strong>\u3002<\/li>\n\n\n\n<li>\u5982\u679c\u7aef\u53e3\u5173\u95ed\uff0c\u76ee\u6807\u56de\u590d <strong>ICMP\u7aef\u53e3\u4e0d\u53ef\u8fbe<\/strong> -&gt; <strong>\u4e3b\u673a\u5b58\u6d3b<\/strong>\u3002<\/li>\n\n\n\n<li>\u5982\u679c\u7aef\u53e3\u5f00\u653e\uff0c\u5927\u90e8\u5206\u670d\u52a1\u4f1a\u5ffd\u7565\u7a7a\u5305\uff0c<strong>\u65e0\u56de\u5e94<\/strong> -&gt; Nmap\u53ef\u80fd\u8bef\u5224\u4e3a\u5173\u673a\u3002\u56e0\u6b64\uff0c\u5e94\u9009\u62e9<strong>\u5927\u6982\u7387\u5173\u95ed<\/strong>\u7684\u9ad8\u7aef\u53e3\uff08\u5982\u9ed8\u8ba4\u768431338\uff09\u3002<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\u7a7f\u900f<strong>\u53ea\u8fc7\u6ee4TCP<\/strong>\u7684\u9632\u706b\u5899\/\u89c4\u5219\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<code>nmap -sn -PU53,161 \u76ee\u6807<\/code> (\u63a2\u6d4bDNS\u548cSNMP\u670d\u52a1\u5e38\u7528\u7684UDP\u7aef\u53e3)<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>ICMP Ping\u7cfb\u5217 (<code>-PE<\/code>, <code>-PP<\/code>, <code>-PM<\/code>)<\/strong>\n<ul class=\"wp-block-list\">\n<li><code>-PE<\/code>\uff1a \u6807\u51c6ICMP Echo\u8bf7\u6c42\uff08\u4f20\u7edfping\uff09\u3002<\/li>\n\n\n\n<li><code>-PP<\/code>\uff1a ICMP\u65f6\u95f4\u6233\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><code>-PM<\/code>\uff1a ICMP\u5730\u5740\u63a9\u7801\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\u5728<strong>\u5185\u90e8\u7f51\u7edc<\/strong>\u4e2d\uff0c\u7ba1\u7406\u5458\u53ef\u80fd\u53ea\u5141\u8bb8\u7279\u5b9a\u7684ICMP\u7c7b\u578b\u3002<code>-PP<\/code>\u548c<code>-PM<\/code>\u53ef\u4f5c\u4e3a<code>-PE<\/code>\u7684\u66ff\u4ee3\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<code>nmap -sn -PE -PP \u76ee\u6807<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-PR<\/code> (ARP Ping) \u2014\u2014 \u201c\u5728\u697c\u9053\u91cc\u558a\u540d\u5b57\u201d<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5c40\u57df\u7f51\u4e13\u5c5e<\/strong>\uff0c\u6700\u5feb\u6700\u53ef\u9760\u3002<\/li>\n\n\n\n<li>Nmap\u5bf9\u540c\u4e00\u7f51\u6bb5\u7684\u76ee\u6807<strong>\u9ed8\u8ba4\u542f\u7528<\/strong>\uff0c\u9664\u975e\u4f60\u4f7f\u7528 <code>--send-ip<\/code> \u5f3a\u5236\u4f7f\u7528IP\u5c42\u63a2\u6d4b\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p><strong>C. \u8f85\u52a9\u9009\u9879<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>-n<\/code> (\u4e0d\u89e3\u6790\u57df\u540d)<\/strong>\uff1a \u626b\u63cf\u8fc7\u7a0b\u4e2d<strong>\u4e0d\u8fdb\u884c<\/strong>DNS\u53cd\u5411\u89e3\u6790\uff0c\u63d0\u5347\u901f\u5ea6\u3002<\/li>\n\n\n\n<li><strong><code>-R<\/code> (\u603b\u662f\u89e3\u6790\u57df\u540d)<\/strong>\uff1a \u5bf9\u6240\u6709\u6d3b\u52a8IP\u8fdb\u884c\u53cd\u5411DNS\u89e3\u6790\uff08\u5373\u4f7f\u672a\u626b\u63cf\uff09\uff0c\u83b7\u53d6\u66f4\u591a\u4fe1\u606f\u3002<\/li>\n\n\n\n<li><strong><code>--dns-servers &lt;serv1[,serv2]&gt;<\/code><\/strong>\uff1a \u6307\u5b9a\u81ea\u5b9a\u4e49DNS\u670d\u52a1\u5668\u8fdb\u884c\u89e3\u6790\uff0c\u5728\u5185\u7f51\u6e17\u900f\u4e2d\u975e\u5e38\u6709\u7528\u3002<\/li>\n\n\n\n<li><strong><code>--traceroute<\/code><\/strong>\uff1a \u5728\u626b\u63cf\u540e\u8fdb\u884c\u8def\u7531\u8ffd\u8e2a\uff08\u4e0d\u662f\u53d1\u73b0\u9009\u9879\uff0c\u4f46\u5e38\u4e0e\u53d1\u73b0\u7ed3\u5408\u4f7f\u7528\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u8865\u51451:-sL&nbsp;\u53ea\u5217\u51fa\u7f51\u6bb5\uff0c\u65e2\u4e0d\u63a2\u6d4b\uff0c\u4e5f\u4e0d\u5224\u65ad\uff0c\u5230\u5e95\u6709\u4ec0\u4e48\u7528\u5462\uff1f<\/h4>\n\n\n\n<p>-sL&nbsp;\uff08\u5217\u8868\u626b\u63cf\uff09\u770b\u4f3c\u53ea\u5217IP\u6ca1\u5b9e\u9645\u63a2\u6d4b\uff0c\u4f46\u5374\u662f\u6e17\u900f\u6d4b\u8bd5\u3001\u7f51\u7edc\u7ba1\u7406\u4e2d\u524d\u671f\u7f51\u6bb5\u89c4\u5212\/\u4fe1\u606f\u68b3\u7406\u7684\u9ad8\u6548\u5de5\u5177\uff0c\u6838\u5fc3\u4f5c\u7528\u662f\u65e0\u63a2\u6d4b\u3001\u65e0\u75d5\u8ff9\u5730\u5b8c\u6210\u7f51\u6bb5IP\u679a\u4e3e\uff0c\u89e3\u51b3&#8221;\u63d0\u524d\u77e5\u9053\u76ee\u6807\u7f51\u6bb5\u6709\u54ea\u4e9bIP\u53ef\u6d4b&#8221;,&#8221;\u907f\u514d\u626b\u63cf\u8bef\u89e6&#8221;\u7b49\u95ee\u9898\uff0c\u4e14\u5168\u7a0b\u4e0d\u53d1\u4efb\u4f55\u6570\u636e\u5305\uff0c\u4e0d\u4f1a\u88ab\u9632\u706b\u5899\/IDS\u68c0\u6d4b\u5230\uff0c\u8fd9\u662f\u5b83\u548c\u5e38\u89c4\u626b\u63cf\u7684\u5dee\u5f02\u3002<\/p>\n\n\n\n<p><strong>\u90a3\u95ee\u9898\u5c31\u662f\u76ee\u6807\u7f51\u6bb5\u7684IP\uff0c\u5b83\u65e2\u7136\u662f\u5168\u90e8\u5217\u51fa\uff0c\u4e0d\u8fdb\u884c\u4efb\u4f55\u5224\u65ad\u7684\u8bdd\uff0c\u90a3\u4e48\u4e00\u4e2a\u5b66\u4e60\u8fc7\u8fd9\u4e2aIP\u5730\u5740\u5212\u5206\u7684\uff0c\u4ed6\u90fd\u5e94\u8be5\u77e5\u9053\u8fd9\u4e2a\u7f51\u7ad9\u8fd8\u6709\u591a\u5c11IP\u554a\uff1f\u90a3\u8fd9\u6837\u5b50\u6709\u4ec0\u4e48\u7528\u5462\uff1f<\/strong><\/p>\n\n\n\n<p>\u624b\u52a8\u61c2IP\u5212\u5206\u2260\u5b9e\u64cd\u4e2d\u9ad8\u6548\/\u7cbe\u51c6\/\u53ef\u590d\u7528\uff0c&nbsp;-sL&nbsp;\u7684\u4ef7\u503c\u4ece\u6765\u4e0d\u662f\u201c\u6559\u4f60\u7f51\u6bb5\u6709\u591a\u5c11IP\u201d,\uff0c\u800c\u662f\u628a\u201c\u624b\u52a8\u61c2\u7684\u7406\u8bba\u201d\u76f4\u63a5\u8f6c\u5316\u4e3a\u201c\u53ef\u76f4\u63a5\u7528\u7684\u5b9e\u64cd\u7ed3\u679c\u201d\u54ea\u6015\u5b8c\u5168\u61c2\u5b50\u7f51\u5212\u5206\uff0c\u624b\u52a8\u64cd\u4f5c\u5728\u5b9e\u64cd\u573a\u666f\u4e2d\u4f9d\u7136\u6709\u786c\u4f24\uff0c&nbsp;-sL&nbsp;\u662f\u7eaf\u5de5\u5177\u5316\u7684\u89e3\u51b3\u65b9\u6848\uff0c\u4e3e\u51e0\u4e2a\u6700\u5e38\u89c1\u7684\u4f8b\u5b50\uff1a<\/p>\n\n\n\n<p>1.\u5c0f\u7f51\u6bb5\u624b\u52a8\u7b97\u8fd8\u884c\uff0c\u5927\u7f51\u6bb5\/\u975e\u6807\u51c6\u63a9\u7801\uff0c\u624b\u52a8\u7b97\u76f4\u63a5\u6b47\u83dc<\/p>\n\n\n\n<p>\u61c2\/24\u3001\/27\u8fd9\u4e9b\u5e38\u7528\u63a9\u7801\uff0c\u4f46\u9047\u5230<strong>\/22\u3001\/19\u3001\/29\u8fd9\u7c7b\u975e\u6807\u51c6\u63a9\u7801\uff0c\u6216\u8005\u5927\u7f51\u6bb5\uff08\u598210.0.0.0\/16\uff0c65536\u4e2aIP\uff09<\/strong>\uff0c\u624b\u52a8\u7b97\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u8981\u7b97\u7f51\u7edc\u5730\u5740\u3001\u5e7f\u64ad\u5730\u5740\u3001\u53ef\u7528IP\u8303\u56f4\uff0c\u6b65\u9aa4\u591a\u4e14\u6613\u7b97\u9519\uff1b<\/li>\n\n\n\n<li>\u5c31\u7b97\u7b97\u5bf9\u4e86\uff0c\u4e5f\u4e0d\u53ef\u80fd\u628a\u51e0\u5343\/\u51e0\u4e07\u4e2aIP\u4e00\u4e2a\u4e2a\u5217\u51fa\u6765\uff1b<br>\u800c&nbsp;-sL&nbsp;\u4e0d\u7ba1\u662f\/29\u8fd8\u662f\/16\uff0c\u76f4\u63a5\u5217\u51fa\u5168\u91cfIP\uff0c\u65e0\u4efb\u4f55\u8ba1\u7b97\u8bef\u5dee\uff0c\u8fd9\u662f\u624b\u52a8\u505a\u4e0d\u5230\u7684\u3002<\/li>\n<\/ul>\n\n\n\n<p>2.\u5b9e\u64cd\u4e2d\u9700\u8981<strong>\u201c\u73b0\u6210\u7684IP\u5217\u8868\u201d<\/strong>\uff0c\u800c\u975e\u201c\u77e5\u9053\u6709\u591a\u5c11IP\u201d<\/p>\n\n\n\n<p>\u5b66\u4e60\u65f6\u53ea\u9700\u8981\u201c\u77e5\u9053192.168.48.0\/24\u6709254\u4e2a\u53ef\u7528IP\u201d\uff0c\u4f46\u5de5\u4f5c\/\u6e17\u900f\u4e2d\uff0c\u9700\u8981\u7684\u662f\u201c192.168.48.1\u300148.2\u2026\u202648.254\u201d\u8fd9\u4e2a\u73b0\u6210\u7684\u5217\u8868\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7f51\u7ba1\u8981\u6279\u91cfping\u7f51\u6bb5\u5185IP\uff0c\u9700\u8981\u628aIP\u590d\u5236\u5230\u811a\u672c\u91cc\uff1b<\/li>\n\n\n\n<li>\u6e17\u900f\u6d4b\u8bd5\u8981\u628aIP\u5bfc\u5165masscan\/Metasploit\uff0c\u9700\u8981\u7eafIP\u683c\u5f0f\u7684\u6587\u672c\uff1b<br>\u624b\u52a8\u6572\u8fd9\u4e9bIP\uff0c\u4e0d\u4ec5\u6162\uff0c\u8fd8\u5bb9\u6613\u6f0f\/\u9519\uff0c\u800c&nbsp;-sL&nbsp;\u53ef\u4ee5\u76f4\u63a5\u5bfc\u51fa\u7ed3\u6784\u5316\u7684IP\u5217\u8868\uff0c\u65e0\u7f1d\u5bf9\u63a5\u5176\u4ed6\u5de5\u5177\uff0c\u8fd9\u662f\u201c\u77e5\u9053\u6570\u91cf\u201d\u5b8c\u5168\u66ff\u4ee3\u4e0d\u4e86\u7684\u3002<\/li>\n<\/ul>\n\n\n\n<p> 3.\u907f\u514d<strong>\u201c\u7406\u8bba\u6b63\u786e\uff0c\u5b9e\u64cd\u8e29\u5751\u201d<\/strong>\u7684\u4f4e\u7ea7\u9519\u8bef<\/p>\n\n\n\n<p>\u6bd4\u5982\u7406\u8bba\u4e0a\u77e5\u9053\/24\u7f51\u6bb5\u7684\u7f51\u7edc\u5730\u5740\u662fx.x.x.0\uff0c\u5e7f\u64ad\u5730\u5740\u662fx.x.x.255\uff0c\u8fd9\u4e24\u4e2aIP\u4e0d\u53ef\u7528\uff0c\u4f46\u624b\u52a8\u6574\u7406\u5217\u8868\u65f6\uff0c\u5f88\u5bb9\u6613\u4e0d\u5c0f\u5fc3\u628a\u8fd9\u4e24\u4e2aIP\u52a0\u8fdb\u53bb\uff0c\u5bfc\u81f4\u540e\u7eed\u626b\u63cf\/\u6279\u91cf\u64cd\u4f5c\u51fa\u73b0\u65e0\u6548\u8bf7\u6c42\uff1b<br>\u800c&nbsp;-sL&nbsp;\u4f1a\u4e25\u683c\u6309\u5b50\u7f51\u63a9\u7801\u679a\u4e3e\uff0c\u5217\u51fa\u7684IP\u8303\u56f4\u7cbe\u51c6\u65e0\u8bef\uff0c\u76f4\u63a5\u89c4\u907f\u8fd9\u79cd\u201c\u77e5\u9053\u4f46\u505a\u4e0d\u5bf9\u201d\u7684\u5b9e\u64cd\u5751\u3002<\/p>\n\n\n\n<p>4.\u591a\u4eba\u534f\u4f5c\/\u6279\u91cf\u64cd\u4f5c\u4e2d\uff0c\u7edf\u4e00\u626b\u63cf\u8303\u56f4\uff0c\u907f\u514d\u6c9f\u901a\u6210\u672c<\/p>\n\n\n\n<p>\u56e2\u961f\u4e2d\u6709\u4eba\u61c2IP\u5212\u5206\uff0c\u6709\u4eba\u4e0d\u61c2\uff0c\u82e5\u624b\u52a8\u8bf4\u201c\u626b192.168.48.0\/24\u201d\uff0c\u4e0d\u61c2\u7684\u4eba\u53ef\u80fd\u4f1a\u626b\u9519\u8303\u56f4\uff1b<br>\u800c\u7528&nbsp;-sL&nbsp;\u751f\u6210\u7edf\u4e00\u7684IP\u5217\u8868\uff0c\u56e2\u961f\u6240\u6709\u4eba\u76f4\u63a5\u7528\u8fd9\u4e2a\u5217\u8868\u64cd\u4f5c\uff0c\u65e0\u9700\u518d\u6c9f\u901a\u201c\u54ea\u4e9bIP\u8981\u626b\u3001\u54ea\u4e9b\u4e0d\u8981\u201d\uff0c\u5f7b\u5e95\u6d88\u9664\u8ba4\u77e5\u5dee\u5f02\u5e26\u6765\u7684\u64cd\u4f5c\u8bef\u5dee\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u7b2c\u4e09\u90e8\u5206\uff1a\u6838\u5fc3\u4f7f\u7528\u6307\u5357\u4e0e\u6700\u4f73\u5b9e\u8df5<\/strong><\/h3>\n\n\n\n<p><strong>1. \u5982\u4f55\u9009\u62e9\u4e3b\u673a\u53d1\u73b0\u7b56\u7565\uff1f\u2014\u2014 \u51b3\u7b56\u6d41\u7a0b\u56fe<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u76ee\u6807\u5728\u7f51\u7edc\u4e2d\uff1f \n  \u251c\u2500 \u662f\uff08\u5c40\u57df\u7f51\uff09\u2192 \u9ed8\u8ba4\u4f7f\u7528 `-PR` (ARP) \u6700\u5feb\u3002\u53ef\u52a0 `-sn` \u4ec5\u53d1\u73b0\u3002\n  \u2514\u2500 \u5426\uff08\u4e92\u8054\u7f51\/\u8de8\u7f51\u6bb5\uff09\u2192 \n        \u251c\u2500 \u5e38\u89c4\u63a2\u6d4b \u2192 \u4f7f\u7528 `-sn -PS80,443 -PA80` \uff08\u9ed8\u8ba4\u884c\u4e3a\u7684\u5f3a\u5316\u7248\uff09\n        \u251c\u2500 \u76ee\u6807\u7981Ping \u2192 \u4f7f\u7528 `-Pn` \uff08\u8df3\u8fc7\u53d1\u73b0\uff0c\u76f4\u63a5\u7aef\u53e3\u626b\u63cf\uff09\n        \u2514\u2500 \u9632\u706b\u5899\u4e25\u82db \u2192 \u4f7f\u7528\u7ec4\u5408\u63a2\u9488\uff1a`-sn -PS&lt;\u5e38\u7528\u7aef\u53e3&gt; -PA&lt;\u5e38\u7528\u7aef\u53e3&gt; -PU&lt;UDP\u7aef\u53e3&gt;`<\/code><\/pre>\n\n\n\n<p><strong>2. \u7efc\u5408\u5b9e\u6218\u793a\u4f8b<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u573a\u666f1\uff1a\u5185\u90e8\u7f51\u7edc\u8d44\u4ea7\u6e05\u70b9\uff08\u5feb\u901f\u3001\u5b89\u9759\uff09\nnmap -sn -PR 10.10.0.0\/24 -oN inventory_scan.txt\n\n# \u573a\u666f2\uff1a\u5916\u90e8Web\u670d\u52a1\u5668\u5b58\u6d3b\u63a2\u6d4b\uff08\u7a7f\u900f\u529b\u5f3a\uff09\n# \u5047\u8bbe\u76ee\u6807\u9632\u706b\u5899\u53ef\u80fd\u5141\u8bb8\u53bb\u5f80Web\u7aef\u53e3\u7684ACK\u5305\u548c\u6765\u81ea\u5916\u90e8\u7684DNS\u67e5\u8be2\nnmap -sn -PS80,443 -PA80,443 -PU53 --dns-servers 8.8.8.8 203.0.113.50-100\n\n# \u573a\u666f3\uff1a\u5bf9\u5df2\u77e5\u7981Ping\u7684\u670d\u52a1\u5668\u8fdb\u884c\u5168\u7aef\u53e3\u626b\u63cf\nnmap -Pn -p- --min-rate=1000 -T4 10.0.0.100 -oA full_scan_no_ping\n\n# \u573a\u666f4\uff1a\u5b89\u5168\u8bc4\u4f30\u4e2d\u7684\u5168\u9762\u53d1\u73b0\uff08\u7ec4\u5408\u62f3\uff09\nnmap -sn -PE -PS21,22,23,25,80,110,139,443,445,3389 -PA80,443 -PU53,161,162 \u76ee\u6807\/24<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Nmap\u4e3b\u673a\u53d1\u73b0<\/h2>\n\n\n\n<p>\u4e3b\u673a\u53d1\u73b0\u662f\u7f51\u7edc\u4fa6\u5bdf\u7684\u9996\u8981\u9636\u6bb5\uff0c\u5176\u76ee\u6807\u662f\u5c06\u4e00\u4e2aIP\u5730\u5740\u8303\u56f4\uff08\u5982\u4e00\u4e2a\u5b50\u7f51\uff09\u7f29\u51cf\u4e3a\u5b9e\u9645\u5728\u7ebf\u7684\u3001\u53ef\u54cd\u5e94\u7684\u4e3b\u673a\u5217\u8868\u3002\u8df3\u8fc7\u6b64\u6b65\u9aa4\u76f4\u63a5\u8fdb\u884c\u5168\u7aef\u53e3\u626b\u63cf\uff0c\u5728\u6548\u7387\u4e0a\u662f\u4e0d\u53ef\u884c\u7684\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e00\u3001 \u6838\u5fc3\u6982\u5ff5\u4e0e\u6280\u672f\u57fa\u7840<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1.1 \u4e3b\u673a\u53d1\u73b0\u7684\u57fa\u672c\u539f\u7406<\/h4>\n\n\n\n<p>\u4e3b\u673a\u53d1\u73b0\u901a\u8fc7\u5411\u76ee\u6807\u53d1\u9001\u7279\u5b9a\u7684\u7f51\u7edc\u63a2\u6d4b\u62a5\u6587\uff0c\u5e76\u6839\u636e\u54cd\u5e94\uff08\u6216\u7f3a\u4e4f\u54cd\u5e94\uff09\u6765\u5224\u65ad\u5176\u5b58\u6d3b\u72b6\u6001\u3002\u5176\u672c\u8d28\u662f\u7f51\u7edc\u534f\u8bae\u6808\u7684\u4ea4\u4e92\u6d4b\u8bd5\uff0c\u800c\u975e\u76f4\u63a5\u68c0\u6d4b\u4e3b\u673a\u7269\u7406\u7535\u6e90\u72b6\u6001\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.2 Nmap\u9ed8\u8ba4\u53d1\u73b0\u884c\u4e3a\u89e3\u6790<\/h4>\n\n\n\n<p>\u5f53\u6267\u884c <code>nmap &lt;target&gt;<\/code> \u800c\u672a\u6307\u5b9a\u4efb\u4f55\u4e3b\u673a\u53d1\u73b0\u9009\u9879\uff08\u5982 <code>-sn<\/code>, <code>-Pn<\/code>\uff09\u65f6\uff0cNmap\u7684\u884c\u4e3a\u903b\u8f91\u5982\u4e0b\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u76ee\u6807\u7f51\u7edc\u4f4d\u7f6e\u5224\u5b9a<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>Nmap\u9996\u5148\u57fa\u4e8e\u672c\u5730\u8def\u7531\u8868\u4e0e\u7f51\u7edc\u63a5\u53e3\u914d\u7f6e\uff0c\u5224\u65ad\u76ee\u6807IP\u5730\u5740\u76f8\u5bf9\u4e8e\u626b\u63cf\u4e3b\u673a\u7684\u7f51\u7edc\u4f4d\u7f6e\u3002<\/li>\n\n\n\n<li><strong>\u5c40\u57df\u7f51\u5224\u5b9a<\/strong>\uff1a\u82e5\u76ee\u6807IP\u4f4d\u4e8e\u626b\u63cf\u4e3b\u673a\u4efb\u4e00\u7f51\u7edc\u63a5\u53e3\u7684\u76f4\u8fde\u5b50\u7f51\u5185\uff0c\u6216\u7ecf\u7531\u76f4\u8fde\u7f51\u5173\u53ef\u8fbe\u7684\u79c1\u6709\/\u4fdd\u7559\u7f51\u6bb5\uff08\u5982 <code>127.0.0.0\/8<\/code>, <code>169.254.0.0\/16<\/code>\uff09\uff0c\u5219\u89c6\u4e3a\u5c40\u57df\u7f51\u76ee\u6807\u3002<\/li>\n\n\n\n<li><strong>\u4e92\u8054\u7f51\u5224\u5b9a<\/strong>\uff1a\u5426\u5219\uff0c\u89c6\u4e3a\u4e92\u8054\u7f51\uff08\u5916\u7f51\uff09\u76ee\u6807\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u9ed8\u8ba4\u63a2\u6d4b\u7b56\u7565\u6267\u884c<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5bf9\u5c40\u57df\u7f51\u76ee\u6807<\/strong>\uff1a\u9ed8\u8ba4\u91c7\u7528 <strong>ARP\u53d1\u73b0 (<code>-PR<\/code>)<\/strong>\u3002\u56e0\u4e3aARP\u662f\u4e8c\u5c42\u534f\u8bae\uff0c\u4e0d\u6d89\u53caIP\u8def\u7531\uff0c\u6548\u7387\u6700\u9ad8\u4e14\u901a\u5e38\u65e0\u6cd5\u88ab\u4e3b\u673a\u9632\u706b\u5899\u8fc7\u6ee4\u3002\u6b64\u884c\u4e3a\u5728\u65e5\u5fd7\u4e2d\u4f53\u73b0\u4e3a <code>Initiating ARP Ping Scan<\/code>\u3002\u82e5ARP\u63a2\u6d4b\u5feb\u901f\u6210\u529f\uff0c\u540e\u7eed\u7684IP\u5c42\u63a2\u6d4b\u53ef\u80fd\u88ab\u8df3\u8fc7\u3002<\/li>\n\n\n\n<li><strong>\u5bf9\u4e92\u8054\u7f51\u76ee\u6807<\/strong>\uff1a\u653e\u5f03ARP\uff08\u65e0\u6548\uff09\uff0c\u8f6c\u800c\u6267\u884c\u4e00\u5957IP\u5c42\u63a2\u6d4b\u7ec4\u5408\uff0c\u65e5\u5fd7\u4e2d\u663e\u793a\u4e3a <code>Initiating Ping Scan<\/code>\u3002\u8be5\u7ec4\u5408\u5305\u62ec\uff1a<br>a. \u4e00\u4e2a <strong>TCP ACK\u62a5\u6587<\/strong> \u53d1\u5f80\u76ee\u6807\u768480\u7aef\u53e3 (<code>-PA80<\/code>)\u3002<br>b. \u4e00\u4e2a <strong>ICMP Echo Request (Type 8)<\/strong> \u62a5\u6587 (<code>-PE<\/code>)\u3002<br>c. \u82e5\u626b\u63cf\u8fdb\u7a0b <strong>\u65e0\u7279\u6743<\/strong>\uff08\u5982\u975eroot\u7528\u6237\uff09\uff0c\u5219\u8ffd\u52a0\u4e00\u4e2a\u901a\u8fc7 <code>connect()<\/code> \u7cfb\u7edf\u8c03\u7528\u53d1\u8d77\u7684 <strong>TCP SYN\u62a5\u6587<\/strong> \u5230\u76ee\u6807\u768480\u7aef\u53e3\uff08\u7b49\u6548\u4e8e <code>-PS80<\/code>\uff0c\u4f46\u4ee5\u975e\u7279\u6743\u65b9\u5f0f\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p><strong>\u9a8c\u8bc1\u65b9\u6cd5<\/strong>\uff1a\u4f7f\u7528 <code>nmap -v &lt;target&gt;<\/code> \u547d\u4ee4\uff0c\u89c2\u5bdf\u521d\u59cb\u65e5\u5fd7\u884c\u5373\u53ef\u660e\u786eNmap\u6267\u884c\u7684\u53d1\u73b0\u7c7b\u578b\u3002\u4e3b\u673a\u5b58\u6d3b\u5ef6\u8fdf\uff08\u901a\u5e38\u663e\u793a\u4e3a <code>latency<\/code>\uff09\u4ea6\u53ef\u4f5c\u4e3a\u8f85\u52a9\u5224\u65ad\u4f9d\u636e\uff1a\u5c40\u57df\u7f51\u5ef6\u8fdf\u901a\u5e38\u5728\u4e9a\u6beb\u79d2\u81f3\u6beb\u79d2\u7ea7\uff0c\u800c\u4e92\u8054\u7f51\u5ef6\u8fdf\u81f3\u5c11\u4e3a\u6570\u5341\u6beb\u79d2\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e8c\u3001 \u4e3b\u673a\u53d1\u73b0\u9009\u9879\u8be6\u89e3<\/h3>\n\n\n\n<p>\u4e3b\u673a\u53d1\u73b0\u9009\u9879\u53ef\u5206\u4e3a\u7b56\u7565\u6027\u3001\u4e3b\u52a8\u63a2\u6d4b\u6027\u548c\u8f85\u52a9\u6027\u4e09\u7c7b\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.1 \u7b56\u7565\u6027\u9009\u9879<\/h4>\n\n\n\n<p>\u8fd9\u4e9b\u9009\u9879\u63a7\u5236\u4e3b\u673a\u53d1\u73b0\u7684\u6574\u4f53\u6267\u884c\u65b9\u5f0f\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>-sL<\/code> (\u5217\u8868\u626b\u63cf)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u529f\u80fd<\/strong>\uff1a\u751f\u6210\u76ee\u6807\u5217\u8868\u4f46\u4e0d\u8fdb\u884c\u4efb\u4f55\u7f51\u7edc\u63a2\u6d4b\u3002\u4ec5\u5bf9\u76ee\u6807\u6267\u884cDNS\u53cd\u5411\u89e3\u6790\uff08\u9664\u975e\u4f7f\u7528 <code>-n<\/code> \u7981\u7528\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6280\u672f\u7ec6\u8282<\/strong>\uff1a\u8be5\u9009\u9879\u4e25\u683c\u4f9d\u636e\u8f93\u5165\u7684\u76ee\u6807\u89c4\u8303\uff08\u5982 <code>192.168.1.0\/24<\/code>\uff09\u679a\u4e3e\u6240\u6709\u53ef\u80fd\u7684IP\u5730\u5740\uff0c\u5e76\uff08\u53ef\u9009\u5730\uff09\u8fdb\u884c\u53cd\u5411DNS\u67e5\u8be2\u3002\u5b83\u4e0d\u533a\u5206\u7f51\u7edc\u5730\u5740\u3001\u5e7f\u64ad\u5730\u5740\u6216\u53ef\u7528\u4e3b\u673a\u5730\u5740\uff0c\u7eaf\u7cb9\u8fdb\u884c\u5217\u8868\u751f\u6210\u4e0e\u89e3\u6790\u3002<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\n<ol class=\"wp-block-list\">\n<li>\u9a8c\u8bc1\u76ee\u6807\u8303\u56f4\u5b9a\u4e49\u7684\u51c6\u786e\u6027\uff0c\u907f\u514d\u56e0\u8f93\u5165\u9519\u8bef\u5bfc\u81f4\u626b\u63cf\u975e\u9884\u671f\u7f51\u7edc\u3002<\/li>\n\n\n\n<li>\u901a\u8fc7\u53cd\u5411DNS\u8bb0\u5f55\u63d0\u524d\u83b7\u53d6\u4e3b\u673a\u540d\u4fe1\u606f\uff0c\u8f85\u52a9\u60c5\u62a5\u6536\u96c6\uff08\u5982\u8bc6\u522b <code>mail.corp.com<\/code>, <code>dc1.internal<\/code>\uff09\u3002<\/li>\n\n\n\n<li>\u751f\u6210\u7eaf\u51c0\u7684IP\u5730\u5740\u5217\u8868\uff0c\u4f9b\u5176\u4ed6\u811a\u672c\u6216\u5b89\u5168\u5de5\u5177\uff08\u5982 <code>masscan<\/code>, <code>hydra<\/code>\uff09\u4f5c\u4e3a\u8f93\u5165\u6e90\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br><code>bash # \u679a\u4e3e\u7f51\u6bb5\u5e76\u5c1d\u8bd5\u89e3\u6790\u4e3b\u673a\u540d nmap -sL 192.168.48.0\/24 # \u4ec5\u679a\u4e3e\u7f51\u6bb5IP\uff0c\u4e0d\u8fdb\u884cDNS\u89e3\u6790\uff08\u66f4\u5feb\uff0c\u65e0\u7f51\u7edc\u8bf7\u6c42\uff09 nmap -sL -n 192.168.48.0\/24<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-sn<\/code> (Ping\u626b\u63cf\uff0c\u66fe\u7528 <code>-sP<\/code>)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u529f\u80fd<\/strong>\uff1a\u4ec5\u6267\u884c\u4e3b\u673a\u53d1\u73b0\uff0c\u53d1\u73b0\u4e3b\u673a\u5b58\u6d3b\u540e\u5373\u505c\u6b62\uff0c\u4e0d\u8fdb\u884c\u540e\u7eed\u7684\u7aef\u53e3\u626b\u63cf\u3001\u7248\u672c\u63a2\u6d4b\u6216\u64cd\u4f5c\u7cfb\u7edf\u8bc6\u522b\u3002<\/li>\n\n\n\n<li><strong>\u6280\u672f\u7ec6\u8282<\/strong>\uff1a<code>-sn<\/code> \u5e76\u975e\u4ec5\u6307ICMP Ping\u3002\u5b83\u4f1a\u6267\u884c\u5176\u5173\u8054\u7684\u3001\u6216\u7528\u6237\u901a\u8fc7 <code>-PS<\/code>, <code>-PA<\/code>, <code>-PU<\/code>, <code>-PE<\/code> \u7b49\u9009\u9879\u6307\u5b9a\u7684\u6240\u6709\u4e3b\u673a\u53d1\u73b0\u63a2\u9488\u3002\u5728\u5c40\u57df\u7f51\u4e0a\uff0c\u9ed8\u8ba4\u5305\u542bARP\u63a2\u6d4b(<code>-PR<\/code>)\u3002<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\n<ol class=\"wp-block-list\">\n<li>\u5feb\u901f\u7f51\u7edc\u8d44\u4ea7\u6e05\u70b9\u4e0e\u5b58\u6d3b\u4e3b\u673a\u7edf\u8ba1\u3002<\/li>\n\n\n\n<li>\u76d1\u63a7\u5173\u952e\u4e3b\u673a\u6216\u7f51\u7edc\u6bb5\u7684\u5728\u7ebf\u72b6\u6001\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br><code>bash # \u5feb\u901f\u53d1\u73b0192.168.48.0\/24\u7f51\u6bb5\u5185\u5b58\u6d3b\u4e3b\u673a\uff08\u7279\u6743\u7528\u6237\u5728\u5c40\u57df\u7f51\u9ed8\u8ba4\u7528ARP\uff09 nmap -sn 192.168.48.0\/24 # \u5bf9\u4e92\u8054\u7f51\u76ee\u6807\u4f7f\u7528\u81ea\u5b9a\u4e49\u63a2\u9488\u7ec4\u5408\u8fdb\u884c\u5b58\u6d3b\u5224\u65ad nmap -sn -PS22,80,443 -PA80,443 -PU53 203.0.113.0\/28<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-Pn<\/code> (\u65e0Ping\u626b\u63cf\uff0c\u66fe\u7528 <code>-P0<\/code>, <code>-PO<\/code>)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u529f\u80fd<\/strong>\uff1a\u8df3\u8fc7\u4e3b\u673a\u53d1\u73b0\u9636\u6bb5\uff0c<strong>\u5047\u5b9a\u6240\u6709\u6307\u5b9a\u76ee\u6807\u5747\u4e3a\u5728\u7ebf\u72b6\u6001<\/strong>\uff0c\u5e76\u76f4\u63a5\u5bf9\u5b83\u4eec\u8fdb\u884c\u540e\u7eed\u7684\u7aef\u53e3\u626b\u63cf\u7b49\u64cd\u4f5c\u3002<\/li>\n\n\n\n<li><strong>\u8b66\u544a<\/strong>\uff1a\u6b64\u9009\u9879\u4f1a\u663e\u8457\u589e\u52a0\u626b\u63cf\u65f6\u95f4\u4e0e\u7f51\u7edc\u6d41\u91cf\uff0c\u56e0\u4e3a\u5c06\u5bf9\u6e05\u5355\u4e2d\u7684\u6bcf\u4e00\u4e2aIP\uff08\u5305\u62ec\u5b9e\u9645\u79bb\u7ebf\u7684\uff09\u6267\u884c\u5b8c\u6574\u7684\u540e\u7eed\u626b\u63cf\u6b65\u9aa4\u3002<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\n<ol class=\"wp-block-list\">\n<li>\u626b\u63cf\u5df2\u77e5\u7981\u7528\u6216\u8fc7\u6ee4\u6240\u6709\u4e3b\u673a\u53d1\u73b0\u63a2\u9488\uff08ICMP, TCP SYN\/ACK to specific ports\uff09\u7684\u76ee\u6807\u3002<\/li>\n\n\n\n<li>\u7a7f\u900f\u914d\u7f6e\u4e25\u683c\u7684\u9632\u706b\u5899\uff0c\u8fd9\u4e9b\u9632\u706b\u5899\u901a\u5e38\u5141\u8bb8\u5bf9\u7279\u5b9a\u670d\u52a1\u7aef\u53e3\uff08\u598280, 443\uff09\u7684\u8bbf\u95ee\uff0c\u4f46\u5c4f\u853d\u53d1\u73b0\u6027\u6d41\u91cf\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br><code>bash # \u5047\u8bbe\u76ee\u6807\u7f51\u7edc\u8fc7\u6ee4\u4e86ICMP\u548c\u975e\u5e38\u7528\u7aef\u53e3\u7684\u63a2\u6d4b\uff0c\u76f4\u63a5\u626b\u63cf\u5176Web\u670d\u52a1\u7aef\u53e3 nmap -Pn -p 80,443,8080,8443 10.0.0.0\/24<\/code><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2.2 \u4e3b\u52a8\u63a2\u6d4b\u9009\u9879<\/h4>\n\n\n\n<p>\u8fd9\u4e9b\u9009\u9879\u5b9a\u4e49\u7528\u4e8e\u63a2\u6d4b\u4e3b\u673a\u5b58\u6d3b\u7684\u5177\u4f53\u7f51\u7edc\u62a5\u6587\u7c7b\u578b\uff0c\u53ef\u7ec4\u5408\u4f7f\u7528\u4ee5\u63d0\u9ad8\u7a7f\u900f\u6027\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>-PS &lt;port list&gt;<\/code> (TCP SYN Ping)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406<\/strong>\uff1a\u5411\u76ee\u6807\u6307\u5b9a\u7aef\u53e3\u53d1\u9001\u4e00\u4e2a\u8bbe\u7f6e\u4e86SYN\u6807\u5fd7\u4f4d\u7684TCP\u62a5\u6587\u3002\n<ul class=\"wp-block-list\">\n<li>\u82e5\u7aef\u53e3<strong>\u5173\u95ed<\/strong>\uff0c\u76ee\u6807\u5e94\u8fd4\u56de\u4e00\u4e2aRST\u62a5\u6587\u3002\u2192 <strong>\u4e3b\u673a\u5b58\u6d3b<\/strong><\/li>\n\n\n\n<li>\u82e5\u7aef\u53e3<strong>\u5f00\u653e<\/strong>\uff0c\u76ee\u6807\u5e94\u8fd4\u56de\u4e00\u4e2aSYN\/ACK\u62a5\u6587\u3002\u2192 <strong>\u4e3b\u673a\u5b58\u6d3b<\/strong><\/li>\n\n\n\n<li>\u82e5\u65e0\u54cd\u5e94\uff0c\u53ef\u80fd\u4e3a\u8fc7\u6ee4\u6216\u4e3b\u673a\u79bb\u7ebf\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5907\u6ce8<\/strong>\uff1aNmap\u5728\u6536\u5230SYN\/ACK\u540e\uff0c\u4f1a\u53d1\u9001RST\u4ee5\u7ec8\u6b62\u8fde\u63a5\u5c1d\u8bd5\uff0c\u907f\u514d\u5efa\u7acb\u5b8c\u6574\u8fde\u63a5\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b<\/strong>\uff1a<br><code>bash nmap -sn -PS80,443 192.168.1.100<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-PA &lt;port list&gt;<\/code> (TCP ACK Ping)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406<\/strong>\uff1a\u5411\u76ee\u6807\u6307\u5b9a\u7aef\u53e3\u53d1\u9001\u4e00\u4e2a\u8bbe\u7f6e\u4e86ACK\u6807\u5fd7\u4f4d\u7684TCP\u62a5\u6587\u3002\n<ul class=\"wp-block-list\">\n<li>\u5bf9\u4e8e\u672a\u5efa\u7acb\u8fde\u63a5\u7684\u4e3b\u673a\uff0c\u65e0\u8bba\u76ee\u6807\u7aef\u53e3\u72b6\u6001\u5982\u4f55\uff08\u5f00\u653e\u6216\u5173\u95ed\uff09\uff0c\u5408\u89c4\u7684TCP\/IP\u534f\u8bae\u6808\u90fd\u5fc5\u987b\u56de\u590d\u4e00\u4e2aRST\u62a5\u6587\u3002\u2192 <strong>\u4e3b\u673a\u5b58\u6d3b<\/strong><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4ef7\u503c<\/strong>\uff1a\u7528\u4e8e\u5c1d\u8bd5\u7a7f\u900f\u4ec5\u8fc7\u6ee4<strong>\u5165\u7ad9SYN\u62a5\u6587<\/strong>\uff08\u65b0\u8fde\u63a5\u8bf7\u6c42\uff09\u7684<strong>\u7b80\u5355\u65e0\u72b6\u6001\u9632\u706b\u5899\/ACL<\/strong>\u3002ACK\u62a5\u6587\u53ef\u80fd\u88ab\u8bef\u8ba4\u4e3a\u662f\u5df2\u5efa\u7acb\u8fde\u63a5\u7684\u6570\u636e\u5305\u800c\u88ab\u653e\u884c\u3002<\/li>\n\n\n\n<li><strong>\u6700\u4f73\u5b9e\u8df5<\/strong>\uff1a\u5e38\u4e0e <code>-PS<\/code> \u7ec4\u5408\u4f7f\u7528 (<code>-PS80 -PA80<\/code>)\uff0c\u4ee5\u5e94\u5bf9\u6709\u72b6\u6001\u6216\u65e0\u72b6\u6001\u7684\u8fc7\u6ee4\u89c4\u5219\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-PU &lt;port list&gt;<\/code> (UDP Ping)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406<\/strong>\uff1a\u5411\u76ee\u6807\u6307\u5b9a\u7aef\u53e3\u53d1\u9001\u4e00\u4e2a\u7a7a\u7684UDP\u6570\u636e\u62a5\u3002\n<ul class=\"wp-block-list\">\n<li>\u82e5\u7aef\u53e3<strong>\u5173\u95ed<\/strong>\uff0c\u76ee\u6807\u53ef\u80fd\uff08\u4f46\u4e0d\u4fdd\u8bc1\uff09\u8fd4\u56de\u4e00\u4e2aICMP\u7aef\u53e3\u4e0d\u53ef\u8fbe(Type 3, Code 3)\u9519\u8bef\u3002\u2192 <strong>\u4e3b\u673a\u5b58\u6d3b<\/strong><\/li>\n\n\n\n<li>\u82e5\u7aef\u53e3<strong>\u5f00\u653e<\/strong>\uff0c\u670d\u52a1\u901a\u5e38\u5ffd\u7565\u7a7a\u62a5\u6587\uff0c\u65e0\u54cd\u5e94\u3002\u2192 <strong>Nmap\u53ef\u80fd\u5c06\u5176\u6807\u8bb0\u4e3a <code>open|filtered<\/code> \u5e76\u89c6\u60c5\u51b5\u5224\u65ad\u4e3b\u673a\u72b6\u6001\u3002<\/strong><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5173\u952e\u70b9<\/strong>\uff1a\u5e94\u9009\u62e9<strong>\u5927\u6982\u7387\u5173\u95ed<\/strong>\u7684\u9ad8\u7aef\u53e3\u4f5c\u4e3a\u63a2\u6d4b\u7aef\u53e3\uff08\u9ed8\u8ba4\u662f40125\uff09\uff0c\u6216\u9009\u62e9\u76ee\u6807\u7f51\u7edc\u53ef\u80fd\u5f00\u653e\u7684UDP\u670d\u52a1\u7aef\u53e3\uff08\u598253-DNS, 161-SNMP\uff09\u3002<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\u63a2\u6d4b\u4ec5\u8fc7\u6ee4TCP\u6d41\u91cf\u6216\u7279\u5b9aUDP\u670d\u52a1\u6709\u54cd\u5e94\u7684\u4e3b\u673a\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-PE<\/code>\/<code>-PP<\/code>\/<code>-PM<\/code> (ICMP Ping Types)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong><code>-PE<\/code><\/strong>\uff1a\u53d1\u9001 <strong>ICMP Echo Request (Type 8)<\/strong>\uff0c\u5373\u4f20\u7edf&#8221;ping&#8221;\u8bf7\u6c42\u3002\u671f\u671b\u6536\u5230ICMP Echo Reply (Type 0)\u3002<\/li>\n\n\n\n<li><strong><code>-PP<\/code><\/strong>\uff1a\u53d1\u9001 <strong>ICMP Timestamp Request (Type 13)<\/strong>\u3002\u671f\u671b\u6536\u5230ICMP Timestamp Reply (Type 14)\u3002\u90e8\u5206\u4e3b\u673a\u53ef\u80fd\u54cd\u5e94\u6b64\u8bf7\u6c42\u800c\u5ffd\u7565Echo Request\u3002<\/li>\n\n\n\n<li><strong><code>-PM<\/code><\/strong>\uff1a\u53d1\u9001 <strong>ICMP Address Mask Request (Type 17)<\/strong>\u3002\u671f\u671b\u6536\u5230ICMP Address Mask Reply (Type 18)\u3002\u73b0\u5df2\u8f83\u5c11\u4f7f\u7528\u3002<\/li>\n\n\n\n<li><strong>\u7528\u9014<\/strong>\uff1a\u5728\u5185\u90e8\u7f51\u7edc\u4e2d\uff0c\u7ba1\u7406\u5458\u53ef\u80fd\u9009\u62e9\u6027\u5141\u8bb8\u90e8\u5206ICMP\u7c7b\u578b\uff0c\u53ef\u7ec4\u5408\u4f7f\u7528\u4ee5\u589e\u52a0\u53d1\u73b0\u6982\u7387\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>-PR<\/code> (ARP Ping)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406<\/strong>\uff1a\u5728\u4ee5\u592a\u7f51\u7b49\u652f\u6301ARP\u7684\u5c40\u57df\u7f51\u4e2d\uff0c\u76f4\u63a5\u53d1\u9001ARP\u8bf7\u6c42\u67e5\u8be2\u76ee\u6807IP\u5bf9\u5e94\u7684MAC\u5730\u5740\u3002\u82e5\u6536\u5230ARP\u56de\u590d\uff0c\u5219\u4e3b\u673a\u5b58\u6d3b\u3002<\/li>\n\n\n\n<li><strong>\u7279\u6027<\/strong>\uff1a<strong>\u4ec5\u9002\u7528\u4e8e\u672c\u5730\u7f51\u7edc<\/strong>\u3002\u901f\u5ea6\u6781\u5feb\uff0c\u4e14\u7531\u4e8e\u662f\u4e8c\u5c42\u534f\u8bae\uff0c\u4e3b\u673a\u9632\u706b\u5899\u901a\u5e38\u65e0\u6cd5\u963b\u6b62\uff08\u56e0\u5904\u7406\u5728\u9a71\u52a8\u5c42\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6ce8\u610f<\/strong>\uff1aNmap\u5bf9\u5c40\u57df\u7f51\u76ee\u6807\u9ed8\u8ba4\u542f\u7528\u6b64\u9009\u9879\u3002\u4f7f\u7528 <code>--send-ip<\/code> \u53ef\u5f3a\u5236\u7981\u7528ARP\uff0c\u6539\u7528IP\u5c42\u63a2\u6d4b\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2.3 \u8f85\u52a9\u9009\u9879<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>-n<\/code><\/strong>\uff1a\u7981\u6b62\u5728\u626b\u63cf\u8fc7\u7a0b\u4e2d\u8fdb\u884cDNS\u53cd\u5411\u89e3\u6790\u3002\u53ef\u63d0\u5347\u626b\u63cf\u901f\u5ea6\u3002<\/li>\n\n\n\n<li><strong><code>-R<\/code><\/strong>\uff1a\u59cb\u7ec8\u5bf9\u76ee\u6807\u8fdb\u884cDNS\u53cd\u5411\u89e3\u6790\uff08\u5373\u4f7f\u76ee\u6807\u4e0d\u5b58\u6d3b\uff09\u3002\u7528\u4e8e\u4fe1\u606f\u6536\u96c6\uff0c\u4f46\u4f1a\u51cf\u6162\u901f\u5ea6\u3002<\/li>\n\n\n\n<li><strong><code>--dns-servers &lt;server1[,server2...]&gt;<\/code><\/strong>\uff1a\u6307\u5b9a\u7528\u4e8e\u89e3\u6790\u7684\u81ea\u5b9a\u4e49DNS\u670d\u52a1\u5668\u3002\u5728\u5185\u7f51\u6e17\u900f\u4e2d\u53ef\u7528\u4e8e\u6307\u5b9a\u5185\u90e8DNS\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e09\u3001 \u7b56\u7565\u9009\u62e9\u4e0e\u7efc\u5408\u5e94\u7528<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">3.1 \u51b3\u7b56\u903b\u8f91<\/h4>\n\n\n\n<p>\u9009\u62e9\u4e3b\u673a\u53d1\u73b0\u7b56\u7565\u5e94\u57fa\u4e8e\u76ee\u6807\u7f51\u7edc\u73af\u5883\u548c\u626b\u63cf\u76ee\u6807\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap17-1024x820.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"820\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap17-1024x820.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1501\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">3.2 \u7efc\u5408\u5b9e\u6218\u793a\u4f8b<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5185\u90e8\u7f51\u7edc\u8d44\u4ea7\u5feb\u901f\u6e05\u70b9<\/strong> <code># \u5b89\u9759\u3001\u5feb\u901f\u5730\u5217\u51fa\u6240\u6709\u5728\u7ebf\u8bbe\u5907 nmap -sn -PR 10.10.0.0\/24 -oN network_inventory.txt<\/code><\/li>\n\n\n\n<li><strong>\u5916\u90e8Web\u670d\u52a1\u5668\u96c6\u7fa4\u5b58\u6d3b\u63a2\u6d4b<\/strong> <code># \u4f7f\u7528Web\u670d\u52a1\u7aef\u53e3\u4f5c\u4e3a\u63a2\u9488\uff0c\u5e76\u7ed3\u5408DNS\u67e5\u8be2 nmap -sn -PS80,443 -PA80,443 -PU53 --dns-servers 8.8.8.8 203.0.113.50-100<\/code><\/li>\n\n\n\n<li><strong>\u5bf9\u4e25\u683c\u8fc7\u6ee4\u73af\u5883\u7684\u76ee\u6807\u8fdb\u884c\u5168\u7aef\u53e3\u626b\u63cf<\/strong> <code># \u5047\u8bbe\u76ee\u6807\u4e22\u5f03\u6240\u6709Ping\u548c\u975e\u5e38\u89c4\u7aef\u53e3\u63a2\u6d4b\uff0c\u76f4\u63a5\u626b\u63cf\u5168\u90e8TCP\u7aef\u53e3 nmap -Pn -p- --min-rate=1000 -T4 10.0.0.100 -oA full_scan_no_discovery<\/code><\/li>\n\n\n\n<li><strong>\u5b89\u5168\u8bc4\u4f30\u4e2d\u7684\u5168\u9762\u4e3b\u673a\u53d1\u73b0<\/strong><br><code>bash # \u7ec4\u5408\u591a\u79cd\u63a2\u9488\uff0c\u6700\u5927\u5316\u53d1\u73b0\u673a\u4f1a nmap -sn -PE -PS21,22,23,25,80,110,139,443,445,3389 -PA80,443 -PU53,161,162 \u76ee\u6807IP\/24<\/code><\/li>\n<\/ol>\n\n\n\n<p>\u901a\u8fc7\u7406\u89e3\u4e0a\u8ff0\u539f\u7406\u5e76\u6839\u636e\u5b9e\u9645\u573a\u666f\u7075\u6d3b\u7ec4\u5408\u9009\u9879\uff0c\u53ef\u4ee5\u6709\u6548\u63d0\u5347\u4e3b\u673a\u53d1\u73b0\u7684\u51c6\u786e\u6027\u4e0e\u6548\u7387\uff0c\u4e3a\u540e\u7eed\u6df1\u5165\u7684\u7aef\u53e3\u626b\u63cf\u4e0e\u670d\u52a1\u8bc6\u522b\u5960\u5b9a\u53ef\u9760\u57fa\u7840\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u7b2c4\u90e8\u5206\uff1a\u4e13\u4e1a\u626b\u63cf\u6280\u672f \u2014\u2014 \u9690\u533f\u3001\u6b3a\u9a97\u4e0e\u6df1\u5ea6\u63a2\u6d4b<\/strong><\/h3>\n\n\n\n<p>\u5728\u638c\u63e1\u4e86\u56db\u5927\u6838\u5fc3\u626b\u63cf\u6280\u672f\u540e\uff0c\u4f60\u5c06\u4ece\u4e00\u4e2a\u7f51\u7edc\u5730\u56fe\u7684\u201c\u7ed8\u5236\u8005\u201d\u5347\u7ea7\u4e3a\u201c\u6d1e\u5bdf\u8005\u201d\u3002Nmap\u7684\u771f\u6b63\u5a01\u529b\u5728\u4e8e\u5176\u4e30\u5bcc\u7684\u626b\u63cf\u6280\u672f\u77e9\u9635\uff0c\u5b83\u4eec\u80fd\u5e2e\u4f60\u89c4\u907f\u9632\u706b\u5899\u3001\u63a2\u6d4b\u5b89\u5168\u8bbe\u5907\u7b56\u7565\uff0c\u751a\u81f3\u8fdb\u884c\u5b8c\u5168\u533f\u540d\u7684\u626b\u63cf\u3002\u4e0b\u8868\u662f\u8fd9\u4e9b\u9ad8\u7ea7\u6280\u672f\u7684\u6218\u7565\u5730\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u626b\u63cf\u6280\u672f<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u547d\u4ee4\u9009\u9879<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u6838\u5fc3\u6218\u672f\u76ee\u7684<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u5de5\u4f5c\u539f\u7406\u6bd4\u55bb<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u5173\u952e\u9650\u5236\u4e0e\u6218\u573a\u6807\u8bc6<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u9690\u79d8\u626b\u63cf<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>-sN<\/code>; <code>-sF<\/code>; <code>-sX<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u7ed5\u8fc7\u7b80\u964b\u7684\u5305\u8fc7\u6ee4\u8bbe\u5907<\/strong>\uff0c\u8fdb\u884c\u66f4\u5b89\u9759\u7684\u4fa6\u5bdf\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6d3e\u9063\u201c\u884c\u4e3a\u5f02\u5e38\u7684\u4fe1\u4f7f\u201d\uff08\u4e0d\u542bSYN\/RST\/ACK\u7684\u5305\uff09\u53bb\u6572\u95e8\u3002\u5b88\u89c4\u77e9\u7684\u76ee\u6807\uff08\u5982Linux\uff09\u53ea\u5bf9\u5173\u95ed\u7684\u95e8\u56de\u5e94\uff1b\u4e0d\u5b88\u89c4\u77e9\u7684\uff08\u5982Windows\uff09\u5219\u4f1a\u56de\u5e94\u6240\u6709\u95e8\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u9ad8\u5ea6\u4f9d\u8d56\u76ee\u6807\u64cd\u4f5c\u7cfb\u7edf<\/strong>\u3002\u5bf9Windows\u3001Cisco\u8bbe\u5907\u901a\u5e38\u65e0\u6548\uff0c\u7ed3\u679c\u4f1a\u663e\u793a\u6240\u6709\u7aef\u53e3 <code>closed<\/code>\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u9632\u706b\u5899\u63a2\u6d4b\u626b\u63cf<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>-sA<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u7ed8\u5236\u9632\u706b\u5899\u89c4\u5219\u56fe<\/strong>\uff0c\u63a2\u6d4b\u5176\u662f\u6709\u72b6\u6001\u8fd8\u662f\u65e0\u72b6\u6001\uff0c\u54ea\u4e9b\u7aef\u53e3\u88ab\u201c\u770b\u5b88\u201d\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6d3e\u4e00\u4e2a\u201c\u70b9\u5934\u786e\u8ba4\u7684\u4fe1\u4f7f\u201d\uff08ACK\u5305\uff09\u95ef\u5173\u3002\u5982\u679c\u5173\u5361\uff08\u9632\u706b\u5899\uff09\u4e0d\u5b58\u5728\u6216\u4e0d\u7ba1\uff0c\u76ee\u6807\u4e3b\u673a\u4f1a\u76f4\u63a5\u62d2\u7edd\uff08RST\uff09\uff1b\u5982\u679c\u5173\u5361\u62e6\u622a\uff0c\u5219\u4fe1\u4f7f\u77f3\u6c89\u5927\u6d77\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u65e0\u6cd5\u5224\u65ad\u7aef\u53e3\u5f00\u653e\u4e0e\u5426<\/strong>\uff0c\u53ea\u80fd\u6807\u8bb0 <code>unfiltered<\/code>\uff08\u5305\u53ef\u8fbe\uff09\u6216 <code>filtered<\/code>\uff08\u5305\u88ab\u62e6\uff09\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u7a7a\u95f2\u626b\u63cf<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>-sI &lt;\u50f5\u5c38\u4e3b\u673a&gt;<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5b9e\u73b0\u5b8c\u5168\u533f\u540d\u7684\u7aef\u53e3\u626b\u63cf<\/strong>\uff0c\u5ac1\u7978\u4e8e\u4e00\u53f0\u65e0\u8f9c\u7684\u201c\u50f5\u5c38\u201d\u4e3b\u673a\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u64cd\u63a7\u4e00\u4e2a\u201c\u673a\u68b0\u8ba1\u6570\u201d\u7684\u7b2c\u4e09\u65b9\uff08\u50f5\u5c38\u673a\uff09\uff0c\u901a\u8fc7\u89c2\u5bdf\u5176\u8ba1\u6570\uff08IP ID\uff09\u7684\u53d8\u5316\uff0c\u95f4\u63a5\u63a8\u6d4b\u76ee\u6807\u7aef\u53e3\u7684\u5f00\u95ed\u72b6\u6001\uff0c\u6574\u4e2a\u8fc7\u7a0b\u4f60\u7684\u771f\u5b9eIP\u4ece\u672a\u51fa\u73b0\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u9700\u8981\u627e\u5230\u4e00\u53f0\u95f2\u7f6e\u3001IP ID\u9012\u589e\u4e14\u53ef\u9884\u6d4b\u7684\u201c\u50f5\u5c38\u201d\u4e3b\u673a\uff0c\u8fc7\u7a0b\u590d\u6742\u4f46\u6781\u5176\u9690\u853d\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>IP\u534f\u8bae\u626b\u63cf<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>-sO<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u63a2\u6d4b\u76ee\u6807\u4e3b\u673a\u652f\u6301\u54ea\u4e9b\u7f51\u7edc\u5c42\u534f\u8bae<\/strong>\uff08\u5982ICMP, IGMP, GRE\uff09\uff0c\u53d1\u73b0\u6f5c\u5728\u7684\u96a7\u9053\u6216\u534f\u8bae\u6f0f\u6d1e\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u68c0\u67e5\u623f\u5b50\u7684\u201c\u95e8\u201d\uff08\u7aef\u53e3\uff09\uff0c\u800c\u662f\u68c0\u67e5\u5b83\u652f\u6301\u54ea\u4e9b\u201c\u5efa\u7b51\u6750\u6599\u201d\uff08IP\u534f\u8bae\uff09\u3002<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u9700\u8981root\u6743\u9650\uff0c\u62a5\u544a\u7684\u662f\u534f\u8bae\u53f7\uff08\u5982 <code>protocol 47<\/code> \u662fGRE\uff09\u800c\u975e\u7aef\u53e3\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>1. \u9690\u79d8\u626b\u63cf\u4e09\u5251\u5ba2 (-sN, -sF, -sX)\uff1a\u89c4\u5219\u7684\u6f0f\u6d1e<\/strong><\/h4>\n\n\n\n<p>\u8fd9\u4e09\u8005\u539f\u7406\u4e00\u81f4\uff0c\u4ec5\u53d1\u9001\u7684TCP\u6807\u5fd7\u4f4d\u4e0d\u540c\uff0c\u65e8\u5728\u5229\u7528<strong>RFC 793<\/strong>\u7684\u4e00\u4e2a\u7406\u8bba\u6f0f\u6d1e\uff1a\u5173\u95ed\u7684\u7aef\u53e3\u5fc5\u987b\u7528RST\u54cd\u5e94\u4efb\u4f55\u4e0d\u5305\u542bSYN\u3001RST\u6216ACK\u7684\u62a5\u6587\uff0c\u800c\u5f00\u653e\u7684\u7aef\u53e3\u5e94\u5ffd\u7565\u6b64\u7c7b\u62a5\u6587\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u793a\u4f8b\u4e0e\u8f93\u51fa\u89e3\u8bfb\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap -sF 192.168.48.1<\/code><\/pre>\n\n\n\n<p><strong>\u5178\u578b\u8f93\u51fa\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Starting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-30 17:51 +0800\nNmap scan report for 192.168.48.1\nHost is up (0.00s latency).\nAll 1000 scanned ports on 192.168.48.1 are in ignored states.\nNot shown: 1000 closed tcp ports (reset)\n\nNmap done: 1 IP address (1 host up) scanned in 0.79 seconds<\/code><\/pre>\n\n\n\n<p><strong>\u89e3\u8bfb<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u76ee\u6807\u8bbe\u5907\uff08192.168.48.1\uff09\u5927\u6982\u7387\u662f<strong>\u5c40\u57df\u7f51\u5185\u7684\u7f51\u7edc\u8bbe\u5907<\/strong>\uff08\u5982\u8def\u7531\u5668\u3001\u4ea4\u6362\u673a\uff09\u6216<strong>\u5173\u95ed\u4e86\u6240\u6709\u5e38\u89c1\u7aef\u53e3\u7684\u7535\u8111 \/ \u670d\u52a1\u5668<\/strong>\uff1b \u7aef\u53e3\u5168\u90e8\u5173\u95ed\u7684\u539f\u56e0\u53ef\u80fd\u662f\uff1a\n<ul class=\"wp-block-list\">\n<li>\u8bbe\u5907\u672c\u8eab\u662f\u7f51\u7edc\u57fa\u7840\u8bbe\u65bd\uff08\u5982\u8def\u7531\u5668\uff09\uff0c\u5176\u7ba1\u7406\u7aef\u53e3\uff08\u5982 8080\u300122\uff09\u53ef\u80fd\u672a\u5728 \u201c1000 \u4e2a\u5e38\u7528\u7aef\u53e3\u201d \u4e2d\uff0c\u6216\u88ab\u7ba1\u7406\u5458\u624b\u52a8\u4fee\u6539\u5230\u975e\u9ed8\u8ba4\u7aef\u53e3\uff1b<\/li>\n\n\n\n<li>\u8bbe\u5907\u5f00\u542f\u4e86\u4e25\u683c\u7684\u9632\u706b\u5899\u89c4\u5219\uff0c\u62d2\u7edd\u54cd\u5e94\u5916\u90e8\u7aef\u53e3\u626b\u63cf\uff0c\u6216\u4e3b\u52a8\u5173\u95ed\u4e86\u6240\u6709\u4e0d\u5fc5\u8981\u7684 TCP \u670d\u52a1\uff08\u51fa\u4e8e\u5b89\u5168\u8003\u8651\uff09\uff1b<\/li>\n\n\n\n<li>\u8bbe\u5907\u662f\u7eaf\u7f51\u7edc\u8f6c\u53d1\u8bbe\u5907\uff08\u5982\u4ea4\u6362\u673a\uff09\uff0c\u672c\u8eab\u4e0d\u63d0\u4f9b\u4e0a\u5c42\u7f51\u7edc\u670d\u52a1\uff08\u65e0\u5f00\u653e\u7aef\u53e3\u662f\u6b63\u5e38\u73b0\u8c61\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>\u901a\u4fd7\u62c6\u89e3<\/strong>\uff1a<br>\u60f3\u8c61\u4f60\u7528\u4e00\u79cd\u5916\u661f\u8bed\u8a00\u53bb\u558a\u95e8\u3002\u5730\u7403\u4e0a\u6709\u7684\u623f\u5b50\uff08Linux\/Unix\uff09\u7ea6\u5b9a\uff1a\u542c\u61c2\u5c31\u4fdd\u6301\u6c89\u9ed8\uff08\u7aef\u53e3\u5f00\u653e\uff09\uff0c\u542c\u4e0d\u61c2\u5c31\u9a82\u4e00\u53e5\u201c\u6eda\u5f00\u201d\uff08RST\uff0c\u7aef\u53e3\u5173\u95ed\uff09\u3002<strong>\u4f46\u6709\u7684\u623f\u5b50\uff08Windows\uff09\u4e0d\u7ba1\u542c\u4e0d\u542c\u5f97\u61c2\uff0c\u53ea\u8981\u4f60\u7528\u5916\u661f\u8bed\uff0c\u5b83\u5c31\u9a82\u201c\u6eda\u5f00\u201d\u3002\u4e8e\u662f\uff0c\u5728\u540e\u8005\u773c\u91cc\uff0c\u4f60\u626b\u63cf\u7684\u6240\u6709\u95e8\u90fd\u663e\u793a\u201c\u5173\u95ed\u201d\uff0c\u4fa6\u5bdf\u5931\u8d25\u3002<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>2. ACK\u626b\u63cf (-sA)\uff1a\u7ed8\u5236\u9632\u706b\u5899\u7684\u201c\u5730\u5f62\u56fe\u201d<\/strong><\/h4>\n\n\n\n<p>\u8fd9\u662f<strong>\u63a2\u6d4b\u9632\u706b\u5899\u89c4\u5219<\/strong>\u7684\u795e\u5668\uff0c\u800c\u975e\u7528\u6765\u627e\u5f00\u653e\u670d\u52a1\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u793a\u4f8b\u4e0e\u8f93\u51fa\u89e3\u8bfb\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap -sA 192.168.48.1<\/code><\/pre>\n\n\n\n<p><strong>\u8f93\u51fa\uff1a<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap19-1024x202.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"202\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap19-1024x202.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1505\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p><strong>\u89e3\u8bfb<\/strong>\uff1a<code>1000 unfiltered tcp ports (reset)<\/code>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>unfiltered<\/code>\uff08\u672a\u88ab\u8fc7\u6ee4\uff09\uff1a\u76ee\u6807\u8bbe\u5907\u7684\u9632\u706b\u5899<strong>\u6ca1\u6709\u62e6\u622a<\/strong>Nmap \u53d1\u9001\u7684 ACK \u63a2\u6d4b\u5305\uff08\u5373\u9632\u706b\u5899\u5bf9\u8fd9\u4e9b\u7aef\u53e3\u7684 ACK \u5305 \u201c\u653e\u884c\u201d\uff0c\u4e0d\u505a\u62e6\u622a\uff09\uff1b<\/li>\n\n\n\n<li><code>(reset)<\/code>\uff1a\u76ee\u6807\u8bbe\u5907\u6536\u5230 ACK \u63a2\u6d4b\u5305\u540e\uff0c\u8fd4\u56de\u4e86\u300cTCP \u91cd\u7f6e\u5305\u300d\u2014\u2014 \u8fd9\u8868\u660e\u7aef\u53e3\u672c\u8eab\u662f<strong>\u5173\u95ed<\/strong>\u7684\uff08\u56e0\u4e3a\u6ca1\u6709\u5bf9\u5e94\u7684\u6d3b\u8dc3\u8fde\u63a5\u9700\u8981 \u201c\u786e\u8ba4\u201d\uff0c\u6240\u4ee5\u7528 reset \u5305\u62d2\u7edd\uff09\uff1b<\/li>\n\n\n\n<li>\u7b80\u5355\u8bf4\uff1a\u8fd9\u4e9b\u7aef\u53e3 \u201c\u6ca1\u88ab\u9632\u706b\u5899\u62e6\u7740\uff0c\u4f46\u672c\u8eab\u786e\u5b9e\u6ca1\u5f00\u670d\u52a1\u201d\u3002<\/li>\n\n\n\n<li><code>in ignored states<\/code>\uff1aNmap \u5df2\u786e\u8ba4\u6240\u6709\u7aef\u53e3\u7684\u72b6\u6001\uff08\u672a\u8fc7\u6ee4 + \u5173\u95ed\uff09\uff0c\u65e0\u9700\u8fdb\u4e00\u6b65\u63a2\u6d4b\uff0c\u6240\u4ee5\u6807\u8bb0\u4e3a \u201c\u5ffd\u7565\u72b6\u6001\u201d\uff08\u65e0\u9700\u989d\u5916\u5904\u7406\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u901a\u4fd7\u62c6\u89e3<\/strong>\uff1a<br>\u4f60\u6d3e\u4e00\u4e2a\u4fe1\u4f7f\u8dd1\u5230\u6bcf\u4e2a\u57ce\u95e8\u524d\uff0c\u53ea\u505a\u4e00\u4ef6\u4e8b\uff1a\u5bf9\u7740\u57ce\u95e8\u70b9\u4e00\u4e0b\u5934\uff08\u53d1\u9001ACK\uff09\u3002\u5982\u679c\u57ce\u91cc\u536b\u5175\u76f4\u63a5\u628a\u4f60\u8d76\u51fa\u6765\uff08RST\uff09\uff0c\u8bf4\u660e\u57ce\u95e8\u901a\u9053\u662f\u901a\u7684\uff0c\u536b\u5175\u5728\u5c97\u3002\u5982\u679c\u70b9\u5934\u540e\u6beb\u65e0\u53cd\u5e94\uff0c\u8bf4\u660e\u5728\u62a4\u57ce\u6cb3\u5916\u5c31\u88ab\u54e8\u5854\uff08\u9632\u706b\u5899\uff09\u5c04\u6740\u4e86\uff0c\u4f60\u8fde\u57ce\u95e8\u901a\u4e0d\u901a\u90fd\u4e0d\u77e5\u9053\u3002\u8fd9\u4e2a\u52a8\u4f5c\u5e2e\u4f60\u6478\u6e05\u4e86\u54e8\u5854\u7684\u9632\u5fa1\u8303\u56f4\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>3. \u7a7a\u95f2\u626b\u63cf (-sI)\uff1a\u5b8c\u7f8e\u7684\u201c\u5e7d\u7075\u201d\u884c\u52a8<\/strong><\/h4>\n\n\n\n<p>\u8fd9\u662fNmap\u4e2d\u6700\u9690\u853d\u3001\u6784\u601d\u6700\u5de7\u5999\u7684\u626b\u63cf\u65b9\u5f0f\uff0c\u5b9e\u73b0\u4e86<strong>\u771f\u6b63\u7684\u533f\u540d<\/strong>\u3002<\/p>\n\n\n\n<p><strong>\u5de5\u4f5c\u539f\u7406\u7b80\u8ff0<\/strong>\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5bfb\u627e\u201c\u50f5\u5c38\u201d<\/strong>\uff1a\u4f60\u9700\u8981\u4e00\u53f0\u95f2\u7f6e\u4e14IP ID\u5e8f\u5217\u4e3a<strong>\u5168\u5c40\u9012\u589e<\/strong>\uff08\u6bcf\u53d1\u4e00\u4e2a\u5305\u5c31+1\uff09\u7684\u4e3b\u673a\u3002<\/li>\n\n\n\n<li><strong>\u95f4\u63a5\u63a2\u9488<\/strong>\uff1a\u4f60\u5148\u95ee\u201c\u50f5\u5c38\u201d\uff1a\u201c\u4f60\u73b0\u5728\u7684IP ID\u662f\u591a\u5c11\uff1f\u201d\uff08\u8bb0\u4e0bID\uff09\u3002\u7136\u540e\uff0c\u4f2a\u9020\u4e00\u4e2a\u6e90\u5730\u5740\u4e3a\u201c\u50f5\u5c38\u201d\u7684\u6570\u636e\u5305\u53d1\u7ed9\u76ee\u6807\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><strong>\u89c2\u5bdf\u53d8\u5316<\/strong>\uff1a\u518d\u6b21\u8be2\u95ee\u201c\u50f5\u5c38\u201d\u7684IP ID\u3002\u5982\u679c\u76ee\u6807\u7aef\u53e3<strong>\u5f00\u653e<\/strong>\uff0c\u76ee\u6807\u4e3b\u673a\u4f1a\u5411\u201c\u50f5\u5c38\u201d\u56de\u9001\u54cd\u5e94\u5305\uff0c\u201c\u50f5\u5c38\u201d\u7684IP ID\u4f1a\u56e0\u6b64<strong>\u589e\u52a02<\/strong>\uff08\u4e00\u6b21\u4f60\u7684\u8be2\u95ee\uff0c\u4e00\u6b21\u76ee\u6807\u7684\u56de\u5e94\uff09\uff1b\u5982\u679c\u76ee\u6807\u7aef\u53e3<strong>\u5173\u95ed<\/strong>\uff0c\u5219\u53ea\u589e\u52a01\u3002<\/li>\n<\/ol>\n\n\n\n<p><strong>\u547d\u4ee4\u793a\u4f8b\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap -sI 192.168.48.1:80 144.66.59.86<\/code><\/pre>\n\n\n\n<p><strong>\u89e3\u8bfb<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>192.168.48.1:80 \u662f\u4f60\u63a7\u5236\u7684\u50f5\u5c38\u4e3b\u673a\u53ca\u5176\u6e90\u7aef\u53e3\u3002<\/li>\n\n\n\n<li>144.66.59.86\u662f\u4f60\u8981\u626b\u63cf\u7684\u771f\u5b9e\u76ee\u6807\u3002<\/li>\n\n\n\n<li>\u6700\u7ec8\uff0c\u76ee\u6807 144.66.59.86\u7684\u9632\u706b\u5899\u65e5\u5fd7\u53ea\u4f1a\u663e\u793a\u626b\u63cf\u6765\u81ea 192.168.48.1<\/li>\n<\/ul>\n\n\n\n<p><strong>\u901a\u4fd7\u62c6\u89e3<\/strong>\uff1a<br>\u8fd9\u5c31\u50cf\u4f60\u63a7\u5236\u4e86\u4e00\u4e2a\u6bcf\u9694\u4e00\u79d2\u5c31\u558a\u4e00\u6b21\u6570\u5b57\u7684\u673a\u68b0\u6728\u5076\uff08\u50f5\u5c38\u673a\uff09\u3002\u4f60\u60f3\u77e5\u9053\u9694\u58c1\u623f\u95f4\u7684\u95e8\u9501\u7740\u6ca1\uff0c\u5c31\u6234\u7740\u6728\u5076\u7684\u9762\u5177\uff08\u4f2a\u9020IP\uff09\u53bb\u63a8\u4e00\u4e0b\u95e8\u3002\u5982\u679c\u95e8\u5f00\u7740\uff0c\u91cc\u9762\u7684\u4eba\u4f1a\u8ffd\u51fa\u6765\u62cd\u4e00\u4e0b\u6728\u5076\u7684\u80a9\u8180\uff0c\u6728\u5076\u53d7\u60ca\u540e\u558a\u6570\u5b57\u7684\u8282\u594f\u5c31\u4f1a\u4e71\uff08IP ID\u8df3\u53d82\u6b21\uff09\u3002\u4f60\u53ea\u9700\u8eb2\u5728\u8fdc\u5904\u542c\u6728\u5076\u558a\u7684\u6570\u5b57\uff0c\u5c31\u80fd\u77e5\u9053\u95e8\u7684\u72b6\u6001\uff0c\u800c\u623f\u95f4\u91cc\u7684\u4eba\u53ea\u8bb0\u4f4f\u4e86\u6728\u5076\u7684\u8138\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u6280\u672f\u9009\u62e9\u51b3\u7b56\u6d41<\/strong><\/h3>\n\n\n\n<p>\u9762\u5bf9\u590d\u6742\u73af\u5883\u65f6\uff0c\u4f60\u53ef\u4ee5\u9075\u5faa\u4ee5\u4e0b\u51b3\u7b56\u8def\u5f84\u6765\u9009\u62e9\u626b\u63cf\u6280\u672f\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap18-1024x848.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"848\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap18-1024x848.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1504\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>\u9664\u4e86\u4e0a\u8ff0\u5185\u5bb9\uff0c\u5bf9\u7aef\u53e3\u9009\u62e9\u4e0e\u626b\u63cf\u987a\u5e8f\u7684\u8fdb\u4e00\u6b65\u8bf4\u660e\u5982\u4e0b\uff1a<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u7aef\u53e3\u8bf4\u660e\u548c\u626b\u63cf\u987a\u5e8f<\/strong><\/h2>\n\n\n\n<p><strong>1. \u7cbe\u786e\u6307\u5b9a\u7aef\u53e3\u4e0e\u6df7\u5408\u534f\u8bae (<code>-p<\/code>)<\/strong><br>\u6b64\u9009\u9879\u7684\u6838\u5fc3\u5728\u4e8e\u7075\u6d3b\u6027\uff0c\u60a8\u53ef\u4ee5\u6839\u636e\u6d4b\u8bd5\u76ee\u6807\u7cbe\u786e\u63a7\u5236\u626b\u63cf\u8303\u56f4\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u57fa\u672c\u793a\u4f8b<\/strong>\uff1a\u626b\u63cf\u76ee\u6807\u6700\u5e38\u89c1\u7684 Web \u548c\u670d\u52a1\u7aef\u53e3\u3002<br><code>bash nmap -p 80,443,22,21,25,110,143,3306,3389 target.com<\/code><\/li>\n\n\n\n<li><strong>\u8303\u56f4\u793a\u4f8b<\/strong>\uff1a\u626b\u63cf\u4e00\u4e2a\u8fde\u7eed\u7684\u7aef\u53e3\u6bb5\uff0c\u5e38\u7528\u4e8e\u53d1\u73b0\u5f00\u53d1\u6216\u6d4b\u8bd5\u670d\u52a1\u5668\u4e0a\u7684\u975e\u6807\u51c6\u670d\u52a1\u3002<br><code>bash nmap -p 8000-8100 192.168.1.100<\/code><\/li>\n\n\n\n<li><strong>\u6df7\u5408\u534f\u8bae\u793a\u4f8b<\/strong>\uff1a<strong>\u8fd9\u662f\u539f\u6587\u63d0\u5230\u4f46\u672a\u4e3e\u4f8b\u7684\u5173\u952e\u7528\u6cd5<\/strong>\u3002\u540c\u65f6\u626b\u63cf\u7279\u5b9a\u7684 TCP \u548c UDP \u7aef\u53e3\u3002 <code>bash nmap -sS -sU -p U:53,67,161,T:21-25,80,135,139,445 192.168.1.1<\/code>\n<ul class=\"wp-block-list\">\n<li><code>-sS<\/code>: TCP SYN \u626b\u63cf<\/li>\n\n\n\n<li><code>-sU<\/code>: UDP \u626b\u63cf<\/li>\n\n\n\n<li>\u8be5\u547d\u4ee4\u5c06\u626b\u63cf UDP \u7684 DNS\u3001DHCP\u3001SNMP \u7aef\u53e3\u4ee5\u53ca TCP \u7684\u6587\u4ef6\u5171\u4eab\u3001Web \u548c\u7ba1\u7406\u7aef\u53e3\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>2. \u5feb\u901f\u626b\u63cf (<code>-F<\/code>) \u7684\u5b9e\u9645\u610f\u4e49<\/strong><br>\u5feb\u901f\u626b\u63cf\u7684\u901f\u5ea6\u4f18\u52bf\u5728\u5927\u578b\u7f51\u7edc\u626b\u63cf\u4e2d\u6781\u4e3a\u660e\u663e\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5bf9\u6bd4\u793a\u4f8b<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u9ed8\u8ba4\u626b\u63cf\uff08\u7ea61600\u4e2a\u7aef\u53e3\uff09\uff1a <code>bash nmap 10.0.0.0\/24<\/code>\n<ul class=\"wp-block-list\">\n<li>\u8fd9\u5c06\u5bf9 256 \u4e2a IP \u5730\u5740\u7684\u6bcf\u4e2a\u5730\u5740\u626b\u63cf\u7ea61600\u4e2a\u7aef\u53e3\uff0c\u603b\u5c1d\u8bd5\u6b21\u6570\u7ea6\u4e3a <strong>409,600 \u6b21<\/strong>\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u5feb\u901f\u626b\u63cf\uff08\u7ea61200\u4e2a\u7aef\u53e3\uff09\uff1a <code>bash nmap -F 10.0.0.0\/24<\/code>\n<ul class=\"wp-block-list\">\n<li>\u626b\u63cf\u6bcf\u4e2a IP \u7684\u7ea61200\u4e2a\u7aef\u53e3\uff0c\u603b\u5c1d\u8bd5\u6b21\u6570\u7ea6\u4e3a <strong>307,200 \u6b21<\/strong>\u3002\u51cf\u5c11\u4e86\u7ea625%\u7684\u63a2\u6d4b\u5305\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6781\u7aef\u81ea\u5b9a\u4e49\u793a\u4f8b<\/strong>\uff1a\u5047\u8bbe\u60a8\u4ec5\u5173\u5fc3\u5185\u90e8\u7f51\u7edc\u7684 Web\uff0880\uff0c443\uff0c8080\uff09\u3001SSH\uff0822\uff09\u548c\u6570\u636e\u5e93\uff083306\uff0c5432\uff09\u670d\u52a1\u3002<ol><li>\u521b\u5efa\u4e00\u4e2a\u6587\u4ef6 <code>my-services<\/code>\uff0c\u5185\u5bb9\u5982\u4e0b\uff1a<br><code>80\/tcp http 443\/tcp https 8080\/tcp http-proxy 22\/tcp ssh 3306\/tcp mysql 5432\/tcp postgresql<\/code><\/li><li>\u8fd0\u884c\u547d\u4ee4\uff1a<br><code>bash nmap -F --datadir . 10.0.0.0\/24<\/code><\/li><\/ol>\n<ul class=\"wp-block-list\">\n<li>\u6b64\u65f6\uff0cNmap \u5c06\u53ea\u626b\u63cf\u8fd9 6 \u4e2a\u7aef\u53e3\uff0c\u626b\u63cf\u901f\u5ea6\u6781\u5feb\uff0c\u603b\u5c1d\u8bd5\u6b21\u6570\u4ec5\u4e3a <strong>1,536 \u6b21<\/strong>\uff0c\u975e\u5e38\u9002\u5408\u65e5\u5e38\u7684\u8d44\u4ea7\u5b58\u6d3b\u68c0\u67e5\u548c\u5feb\u901f\u5ba1\u8ba1\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>3. \u987a\u5e8f\u626b\u63cf (<code>-r<\/code>) \u7684\u8c03\u8bd5\u573a\u666f<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9632\u706b\u5899\u89c4\u5219\u6d4b\u8bd5\u793a\u4f8b<\/strong>\uff1a\u5047\u8bbe\u60a8\u6000\u7591\u9632\u706b\u5899\u5bf9 1000-2000 \u7aef\u53e3\u6709\u7279\u6b8a\u7684\u901f\u7387\u9650\u5236\u89c4\u5219\u3002 <code>bash nmap -p 1000-2000 -r --max-parallelism 1 --scan-delay 1s firewall.example.com<\/code>\n<ul class=\"wp-block-list\">\n<li><code>-r<\/code>: \u6309\u987a\u5e8f\uff081\uff0c2\uff0c3\u2026\uff09\u626b\u63cf\uff0c\u4f7f\u89e6\u53d1\u884c\u4e3a\u53ef\u9884\u6d4b\u3002<\/li>\n\n\n\n<li><code>--max-parallelism 1<\/code>: \u4e00\u6b21\u53ea\u626b\u63cf\u4e00\u4e2a\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><code>--scan-delay 1s<\/code>: \u6bcf\u4e2a\u63a2\u6d4b\u5305\u95f4\u96941\u79d2\u3002<\/li>\n\n\n\n<li>\u8fd9\u79cd\u201c\u6162\u901f\u987a\u5e8f\u626b\u63cf\u201d\u53ef\u4ee5\u5e2e\u52a9\u60a8\u7cbe\u786e\u89c2\u5bdf\u5728\u626b\u63cf\u5230\u54ea\u4e2a\u7279\u5b9a\u7aef\u53e3\u65f6\uff0c\u9632\u706b\u5899\u5f00\u59cb\u4e22\u5f03\u6570\u636e\u5305\u6216\u89e6\u53d1\u8b66\u62a5\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u670d\u52a1\u548c\u7248\u672c\u63a2\u6d4b\uff08\u547d\u4ee4\u793a\u4f8b\u8865\u5145\uff09<\/strong><\/h2>\n\n\n\n<p><strong>1. \u57fa\u672c\u7248\u672c\u63a2\u6d4b\u4e0e\u5f3a\u5ea6\u63a7\u5236<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u6807\u51c6\u7248\u672c\u626b\u63cf<\/strong>\uff1a <code>bash nmap -sV 192.168.<\/code>48.1\n<ul class=\"wp-block-list\">\n<li>\u8f93\u51fa\u793a\u4f8b\uff1a\n<ul class=\"wp-block-list\">\n<li>Starting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-30 19:52 +0800<\/li>\n\n\n\n<li>Nmap scan report for 192.168.48.1<\/li>\n\n\n\n<li>Host is up (0.000012s latency).<\/li>\n\n\n\n<li>Not shown: 995 closed tcp ports (reset)<\/li>\n\n\n\n<li>PORT STATE SERVICE VERSION<\/li>\n\n\n\n<li>139\/tcp open netbios-ssn Microsoft Windows netbios-ssn<\/li>\n\n\n\n<li>445\/tcp open microsoft-ds?<\/li>\n\n\n\n<li>902\/tcp open ssl\/vmware-auth VMware Authentication Daemon 1.10 (Uses VNC, SOAP)<\/li>\n\n\n\n<li>912\/tcp open vmware-auth VMware Authentication Daemon 1.0 (Uses VNC, SOAP)<\/li>\n\n\n\n<li>2179\/tcp open vmrdp?<\/li>\n\n\n\n<li>Service Info: OS: Windows; CPE: cpe:\/o:microsoft:windows<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8f7b\u91cf\u7ea7\u6a21\u5f0f (<code>--version-light<\/code>)<\/strong>\uff1a\u9002\u5408\u5feb\u901f\u4e86\u89e3\u4e3b\u8981\u670d\u52a1\u3002 <code>bash nmap -sV --version-light 192.168.<\/code>48.1\n<ul class=\"wp-block-list\">\n<li>\u5b83\u53ef\u80fd\u53ea\u8bc6\u522b\u51fa SSH \u548c HTTP\uff0c\u800c\u4e0d\u4f1a\u5c1d\u8bd5\u53bb\u8bc6\u522b\u4e00\u4e2a\u8fd0\u884c\u5728 8080 \u7aef\u53e3\u7684\u3001\u4e0d\u90a3\u4e48\u5e38\u89c1\u7684 Java \u5e94\u7528\u670d\u52a1\u5668\u3002\n<ul class=\"wp-block-list\">\n<li>D:\\Program\\Professional\\01_Offensive_Security\\01_Reconnaissance\\Nmap&gt;nmap -sV &#8211;version-light 192.168.48.1<\/li>\n\n\n\n<li>Starting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-30 20:04 +0800<\/li>\n\n\n\n<li>Nmap scan report for 192.168.48.1<\/li>\n\n\n\n<li>Host is up (0.00015s latency).<\/li>\n\n\n\n<li>Not shown: 995 closed tcp ports (reset)<\/li>\n\n\n\n<li>PORT STATE SERVICE VERSION<\/li>\n\n\n\n<li>139\/tcp open netbios-ssn Microsoft Windows netbios-ssn<\/li>\n\n\n\n<li>445\/tcp open microsoft-ds?<\/li>\n\n\n\n<li>902\/tcp open ssl\/vmware-auth VMware Authentication Daemon 1.10 (Uses VNC, SOAP)<\/li>\n\n\n\n<li>912\/tcp open vmware-auth VMware Authentication Daemon 1.0 (Uses VNC, SOAP)<\/li>\n\n\n\n<li>2179\/tcp open vmrdp?<\/li>\n\n\n\n<li>Service Info: OS: Windows; CPE: cpe:\/o:microsoft:windows<\/li>\n\n\n\n<li>Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .<\/li>\n\n\n\n<li>Nmap done: 1 IP address (1 host up) scanned in 16.93 seconds<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5168\u9762\u6a21\u5f0f (<code>--version-all<\/code>)<\/strong>\uff1a\u5f53\u60a8\u6000\u7591\u76ee\u6807\u8fd0\u884c\u7740\u8001\u65e7\u6216\u975e\u6807\u51c6\u670d\u52a1\u65f6\u4f7f\u7528\u3002 <code>bash nmap -sV --version-all 192.168.<\/code>48.1\n<ul class=\"wp-block-list\">\n<li>\u8fd9\u4f1a\u5c1d\u8bd5\u6240\u6709\u63a2\u6d4b\uff0c\u53ef\u80fd\u4f1a\u8bc6\u522b\u51fa\u4e00\u4e2a\u65e7\u578b\u53f7\u8def\u7531\u5668\u5728 80 \u7aef\u53e3\u8fd0\u884c\u7684\u3001\u5b9a\u5236\u7248\u672c\u7684 Boa Web \u670d\u52a1\u5668\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>2. \u5904\u7406\u7279\u6b8a\u60c5\u51b5\uff1a\u52a0\u5bc6\u670d\u52a1\u4e0e\u6253\u5370\u673a<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u8bc6\u522b HTTPS \u80cc\u540e\u7684\u670d\u52a1<\/strong>\uff1a <code>bash nmap -sV -p 443 192.168.48.1<\/code>\n<ul class=\"wp-block-list\">\n<li>\u5982\u679c Nmap \u652f\u6301 SSL\uff0c\u8f93\u51fa\u4f1a\u662f <code>ssl\/http Apache httpd 2.4.41<\/code> \u6216 <code>ssl\/https-node.js Express<\/code> \u7b49\uff0c\u660e\u786e\u63ed\u793a\u4e86\u52a0\u5bc6\u5c42\u540e\u7684\u5177\u4f53\u8f6f\u4ef6\u3002\n<ul class=\"wp-block-list\">\n<li>D:\\Program\\Professional\\01_Offensive_Security\\01_Reconnaissance\\Nmap&gt;nmap -sV &#8211;version-all 192.168.48.1<\/li>\n\n\n\n<li>Starting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-30 20:29 +0800<\/li>\n\n\n\n<li>Stats: 0:00:07 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan<\/li>\n\n\n\n<li>Service scan Timing: About 40.00% done; ETC: 20:29 (0:00:09 remaining)<\/li>\n\n\n\n<li>Nmap scan report for 192.168.48.1<\/li>\n\n\n\n<li>Host is up (0.00044s latency).<\/li>\n\n\n\n<li>Not shown: 995 closed tcp ports (reset)<\/li>\n\n\n\n<li>PORT STATE SERVICE VERSION<\/li>\n\n\n\n<li>139\/tcp open netbios-ssn Microsoft Windows netbios-ssn<\/li>\n\n\n\n<li>445\/tcp open microsoft-ds?<\/li>\n\n\n\n<li>902\/tcp open ssl\/vmware-auth VMware Authentication Daemon 1.10 (Uses VNC, SOAP)<\/li>\n\n\n\n<li>912\/tcp open vmware-auth VMware Authentication Daemon 1.0 (Uses VNC, SOAP)<\/li>\n\n\n\n<li>2179\/tcp open vmrdp?<\/li>\n\n\n\n<li>Service Info: OS: Windows; CPE: cpe:\/o:microsoft:windows<\/li>\n\n\n\n<li>Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .<\/li>\n\n\n\n<li>Nmap done: 1 IP address (1 host up) scanned in 67.34 seconds<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5f3a\u5236\u626b\u63cf\u6240\u6709\u7aef\u53e3\uff08\u5305\u62ec\u6253\u5370\u673a\u7aef\u53e3\uff09<\/strong>\uff1a <code>bash # \u8b66\u544a\uff1a\u8fd9\u53ef\u80fd\u4f1a\u8ba9\u7f51\u7edc\u6253\u5370\u673a\u6253\u5370\u51fa\u4e71\u7801\uff01 <\/code>nmap -sV &#8211;allports 192.168.48.1\n<ul class=\"wp-block-list\">\n<li>D:\\Program\\Professional\\01_Offensive_Security\\01_Reconnaissance\\Nmap&gt;nmap -sV &#8211;allports 192.168.48.1<\/li>\n\n\n\n<li>Starting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-30 20:38 +0800<\/li>\n\n\n\n<li>Nmap scan report for 192.168.48.1<\/li>\n\n\n\n<li>Host is up (0.00018s latency).<\/li>\n\n\n\n<li>Not shown: 995 closed tcp ports (reset)<\/li>\n\n\n\n<li>PORT STATE SERVICE VERSION<\/li>\n\n\n\n<li>139\/tcp open netbios-ssn Microsoft Windows netbios-ssn<\/li>\n\n\n\n<li>445\/tcp open microsoft-ds?<\/li>\n\n\n\n<li>902\/tcp open ssl\/vmware-auth VMware Authentication Daemon 1.10 (Uses VNC, SOAP)<\/li>\n\n\n\n<li>912\/tcp open vmware-auth VMware Authentication Daemon 1.0 (Uses VNC, SOAP)<\/li>\n\n\n\n<li>2179\/tcp open vmrdp?<\/li>\n\n\n\n<li>Service Info: OS: Windows; CPE: cpe:\/o:microsoft:windows<\/li>\n\n\n\n<li>Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .<\/li>\n\n\n\n<li>Nmap done: 1 IP address (1 host up) scanned in 22.16 seconds<\/li>\n\n\n\n<li><strong>\u66f4\u5b89\u5168\u7684\u505a\u6cd5<\/strong>\u662f\u7f16\u8f91 <code>nmap-service-probes<\/code> \u6587\u4ef6\uff0c\u5728 <code>Exclude<\/code> \u90e8\u5206\u7cbe\u786e\u6dfb\u52a0\u60a8\u7f51\u7edc\u4e2d\u6253\u5370\u673a\u7684 IP \u6216\u7aef\u53e3\uff0c\u800c\u4e0d\u662f\u4f7f\u7528 <code>--allports<\/code>\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>3. RPC \u626b\u63cf (<code>-sR<\/code>) \u7684\u72ec\u7acb\u4f7f\u7528<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5f53\u60a8\u5df2\u7ecf\u901a\u8fc7\u5176\u4ed6\u65b9\u5f0f\uff08\u5982 <code>-sS<\/code>\uff09\u77e5\u9053\u4e86\u5f00\u653e\u7aef\u53e3\uff0c\u53ea\u60f3\u5feb\u901f\u9a8c\u8bc1\u5176\u4e2d\u662f\u5426\u6709 RPC \u670d\u52a1\u65f6\uff1a <code>bash nmap -sR -p 111,2049,32771 192.168.1.102<\/code>\n<ul class=\"wp-block-list\">\n<li>\u8f93\u51fa\u4f1a\u76f4\u63a5\u663e\u793a\u7c7b\u4f3c <code>111\/tcp open rpcbind 2-4 (RPC #100000)<\/code> \u7684\u4fe1\u606f\uff0c\u800c\u4e0d\u4f1a\u8fdb\u884c HTTP\u3001SSH \u7b49\u65e0\u5173\u7684\u63a2\u6d4b\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap20-1024x79.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"79\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap20-1024x79.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1510\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b&#8211;\u8be6\u89e3\u4e0e\u793a\u4f8b<\/strong><\/h2>\n\n\n\n<p>Nmap\u7684\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b\u662f\u5176\u6700\u5f3a\u5927\u7684\u529f\u80fd\u4e4b\u4e00\uff0c\u5b83\u4f9d\u8d56\u4e8e\u5bf9TCP\/IP\u534f\u8bae\u6808\u5b9e\u73b0\u4e2d\u7ec6\u5fae\u5dee\u522b\u7684\u6df1\u5ea6\u5206\u6790\u3002\u8fd9\u4e9b\u201c\u6307\u7eb9\u201d\u5dee\u5f02\u5982\u540c\u4eba\u7c7b\u7684\u6307\u7eb9\uff0c\u4e0d\u540c\u5382\u5546\u3001\u7248\u672c\u751a\u81f3\u8bbe\u5907\u7c7b\u578b\u7684\u7cfb\u7edf\u90fd\u6709\u5176\u72ec\u7279\u4e4b\u5904\u3002\u4ee5\u4e0b\u5c06\u901a\u8fc7\u793a\u4f8b\uff0c\u6df1\u5165\u9610\u8ff0\u5176\u4f7f\u7528\u65b9\u6cd5\u548c\u9ad8\u7ea7\u573a\u666f\u3002<\/p>\n\n\n\n<p><strong>1. \u57fa\u7840\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b (<code>-O<\/code>) \u53ca\u5176\u524d\u7f6e\u6761\u4ef6<\/strong><br>\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b\u7684\u6709\u6548\u6027\u9ad8\u5ea6\u4f9d\u8d56\u4e8e\u4ece\u76ee\u6807\u83b7\u53d6\u8db3\u591f\u591a\u7684\u54cd\u5e94\u4fe1\u606f\u3002<strong>\u6700\u5173\u952e\u7684\u4e00\u70b9\u662f\uff0cNmap\u9700\u8981\u81f3\u5c11\u4e00\u4e2a<code>\u5f00\u653e<\/code>\u7aef\u53e3\u548c\u4e00\u4e2a<code>\u5173\u95ed<\/code>\u7aef\u53e3\u6765\u5b8c\u6210\u53ef\u9760\u7684\u68c0\u6d4b<\/strong>\u3002\u8fd9\u662f\u56e0\u4e3a\u8bb8\u591a\u6d4b\u8bd5\uff08\u5982TCP\u5e8f\u5217\u53f7\u751f\u6210\u3001\u7a97\u53e3\u5927\u5c0f\u7b49\uff09\u9700\u8981\u5bf9\u6bd4\u76ee\u6807\u4e3b\u673a\u5bf9\u4e0d\u540c\u72b6\u6001\u7aef\u53e3\u7684\u53cd\u5e94\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u57fa\u7840\u793a\u4f8b<\/strong>\uff1a <code>nmap -O 192.168.48.1<\/code>\n<ul class=\"wp-block-list\">\n<li><strong>\u8f93\u51fa\u5206\u6790<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>D:\\Program\\Professional\\01_Offensive_Security\\01_Reconnaissance\\Nmap&gt;nmap -O 192.168.48.1<\/li>\n\n\n\n<li>Starting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-30 20:45 +0800<\/li>\n\n\n\n<li>Nmap scan report for 192.168.48.1<\/li>\n\n\n\n<li>Host is up (0.00s latency).<\/li>\n\n\n\n<li>Not shown: 995 closed tcp ports (reset)<\/li>\n\n\n\n<li>PORT STATE SERVICE<\/li>\n\n\n\n<li>139\/tcp open netbios-ssn<\/li>\n\n\n\n<li>445\/tcp open microsoft-ds<\/li>\n\n\n\n<li>902\/tcp open iss-realsecure<\/li>\n\n\n\n<li>912\/tcp open apex-mesh<\/li>\n\n\n\n<li>2179\/tcp open vmrdp<\/li>\n\n\n\n<li>Device type: general purpose<\/li>\n\n\n\n<li>Running: Microsoft Windows 10<\/li>\n\n\n\n<li>OS CPE: cpe:\/o:microsoft:windows_10<\/li>\n\n\n\n<li>OS details: Microsoft Windows 10 1511 &#8211; 1607<\/li>\n\n\n\n<li>Network Distance: 0 hops<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u89e3\u8bfb<\/strong>\uff1a<code>Device type: general purpose<\/code>\uff1a\u76ee\u6807\u662f<strong>\u901a\u7528\u7528\u9014\u8bbe\u5907<\/strong>\uff08\u666e\u901a PC \/ \u670d\u52a1\u5668\uff09\uff0c\u4e0d\u662f\u6253\u5370\u673a\u3001\u8def\u7531\u5668\u3001\u5de5\u63a7\u673a\u3001\u6444\u50cf\u5934\u7b49\u4e13\u7528\u8bbe\u5907\uff1b <code>Running: Microsoft Windows 10<\/code>\uff1a<strong>\u6838\u5fc3\u7ed3\u8bba<\/strong>\u2014\u2014 \u76ee\u6807\u4e3b\u673a\u8fd0\u884c\u7684\u64cd\u4f5c\u7cfb\u7edf\u662f<strong>Windows 10<\/strong>\uff1b <code>OS CPE: cpe:\/o:microsoft:windows_10<\/code>\uff1a\u6807\u51c6\u5316\u7684<strong>CPE \u6807\u8bc6<\/strong>\uff08\u901a\u7528\u5e73\u53f0\u679a\u4e3e\uff09\uff0c\u7cbe\u51c6\u6307\u5411\u5fae\u8f6f Windows 10 \u7cfb\u7edf\uff0c\u65b9\u4fbf\u81ea\u52a8\u5316\u5de5\u5177 \/ \u811a\u672c\u8bc6\u522b\uff1b <code>OS details: Microsoft Windows 10 1511 - 1607<\/code>\uff1a\u66f4\u7ec6\u81f4\u7684\u7248\u672c\u8303\u56f4 \u2014\u2014Windows 10 \u7684<strong>1511<\/strong>\u5230<strong>1607<\/strong> \u7248\u672c\uff0cNmap \u901a\u8fc7\u6307\u7eb9\u5339\u914d\u63a8\u65ad\u51fa\u7684\u5177\u4f53\u7248\u672c\u533a\u95f4\uff1b <code>Network Distance: 0 hop<\/code>\uff1a<strong>\u7f51\u7edc\u8df3\u6570\u4e3a 0<\/strong>\uff0c\u8bf4\u660e<strong>\u4f60\u7684\u626b\u63cf\u4e3b\u673a\u548c\u76ee\u6807 192.168.48.1 \u5728\u540c\u4e00\u7269\u7406\u5c40\u57df\u7f51 \/ \u540c\u4e00\u7f51\u6bb5<\/strong>\uff0c\u6ca1\u6709\u7ecf\u8fc7\u8def\u7531\u5668\u3001\u4ea4\u6362\u673a\u7b49\u8bbe\u5907\u8f6c\u53d1\uff0c\u8fd9\u4e5f\u662f\u5ef6\u8fdf\u51e0\u4e4e\u4e3a 0 \u7684\u6839\u672c\u539f\u56e0\u3002<br>\u5982\u679c\u76ee\u6807\u4e3b\u673a\u6240\u6709\u7aef\u53e3\u90fd\u88ab\u9632\u706b\u5899\u8fc7\u6ee4\uff08\u5168\u95ed\u6216\u5168\u5f00\uff09\uff0c<code>-O<\/code> \u626b\u63cf\u53ef\u80fd\u5931\u8d25\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>2. \u9ad8\u6548\u626b\u63cf\uff1a\u9650\u5236\u68c0\u6d4b\u76ee\u6807 (<code>--osscan-limit<\/code>)<\/strong><br>\u5728\u5bf9\u5927\u578b\u7f51\u7edc\uff08\u5982 <code>\/24<\/code> \u7f51\u6bb5\uff09\u8fdb\u884c\u626b\u63cf\u65f6\uff0c\u76f2\u76ee\u5bf9\u6240\u6709IP\u8fdb\u884c\u5b8c\u6574\u7684OS\u68c0\u6d4b\u975e\u5e38\u8017\u65f6\u3002<code>--osscan-limit<\/code> \u9009\u9879\u80fd\u667a\u80fd\u5730\u8282\u7701\u65f6\u95f4\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u573a\u666f\u793a\u4f8b<\/strong>\uff1a\u5feb\u901f\u627e\u51fa\u4e00\u4e2a\u7f51\u6bb5\u4e2d\u6240\u6709\u5728\u7ebf\u4e3b\u673a\u53ca\u5176\u64cd\u4f5c\u7cfb\u7edf\u3002 <code>bash nmap -sn 10.0.0.0\/24 -oG hosts-up.txt grep Up hosts-up.txt | awk '{print $2}' &gt; targets.txt nmap -O --osscan-limit -iL targets.txt<\/code>\n<ul class=\"wp-block-list\">\n<li><strong>\u547d\u4ee4\u5206\u89e3<\/strong>\uff1a\n<ol class=\"wp-block-list\">\n<li><code>nmap -sn<\/code>: \u8fdb\u884cPing\u626b\u63cf\uff0c\u4ec5\u53d1\u73b0\u5b58\u6d3b\u4e3b\u673a\uff0c\u7ed3\u679c\u5b58\u4e3a<code>hosts-up.txt<\/code>\u3002<\/li>\n\n\n\n<li><code>grep<\/code> \u548c <code>awk<\/code>: \u63d0\u53d6\u5b58\u6d3b\u4e3b\u673a\u7684IP\u5730\u5740\u5230 <code>targets.txt<\/code>\u3002<\/li>\n\n\n\n<li><code>nmap -O --osscan-limit -iL targets.txt<\/code>: \u4ec5\u5bf9 <code>targets.txt<\/code> \u5217\u8868\u4e2d\u7684\u4e3b\u673a\u8fdb\u884c\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\uff0c\u5e76\u4e14<strong>\u53ea\u5bf9\u90a3\u4e9b\u6ee1\u8db3\u201c\u6709\u5f00\u6709\u5173\u7aef\u53e3\u201d\u6761\u4ef6\u7684\u4e3b\u673a\u6267\u884c\u5b8c\u6574\u7684OS\u6307\u7eb9\u68c0\u6d4b<\/strong>\u3002\u8fd9\u907f\u514d\u4e86\u5728\u65e0\u6cd5\u68c0\u6d4b\u7684\u4e3b\u673a\u4e0a\u6d6a\u8d39\u65f6\u95f4\u3002<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>3. \u63a8\u6d4b\u4e0e\u6a21\u7cca\u5339\u914d (<code>--osscan-guess<\/code>, <code>--fuzzy<\/code>)<\/strong><br>\u5f53 Nmap \u65e0\u6cd5\u627e\u5230\u5b8c\u5168\u5339\u914d\u7684\u6307\u7eb9\u65f6\uff0c\u5b83\u4f1a\u5c1d\u8bd5\u5bfb\u627e\u6700\u63a5\u8fd1\u7684\u5339\u914d\u3002<code>--osscan-guess<\/code> \u6216 <code>--fuzzy<\/code> \u9009\u9879\u4f1a<strong>\u63d0\u9ad8\u5176\u62a5\u544a\u8fd9\u4e9b\u63a8\u6d4b\u7ed3\u679c\u7684\u9608\u503c<\/strong>\uff0c\u8ba9\u4f60\u770b\u5230\u66f4\u591a\u53ef\u80fd\u6027\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u793a\u4f8b<\/strong>\uff1a\u626b\u63cf\u4e00\u4e2a\u4e0d\u5e38\u89c1\u7684\u5d4c\u5165\u5f0f\u8bbe\u5907\u6216\u5b9a\u5236\u7cfb\u7edf\u3002 <code>bash <\/code><\/li>\n\n\n\n<li>\n<ul class=\"wp-block-list\">\n<li><strong>\u53ef\u80fd\u8f93\u51fa<\/strong>\uff1a<br><code>Aggressive OS guesses: ASUS RT-AC52U wireless router (96%), Linux 3.1 (95%), Linux 3.2 (94%), Linux 3.4 (94%), BlueArc Titan 2100 NAS device (93%)<\/code><\/li>\n\n\n\n<li><strong>\u89e3\u8bfb<\/strong>\uff1aNmap \u5217\u51fa\u4e86\u591a\u4e2a\u9ad8\u7f6e\u4fe1\u5ea6\u7684\u53ef\u80fd\u7cfb\u7edf\u3002\u6392\u540d\u7b2c\u4e00\u7684\u662f\u534e\u7855\u65e0\u7ebf\u8def\u7531\u5668\uff0c\u8fd9\u4e0e\u201c\u5d4c\u5165\u5f0f\u8bbe\u5907\u201d\u7684\u573a\u666f\u9ad8\u5ea6\u543b\u5408\u3002\u8fd9\u4e2a\u529f\u80fd\u5728\u8bc6\u522b IoT \u8bbe\u5907\u3001\u5de5\u4e1a\u63a7\u5236\u7cfb\u7edf\u7b49\u975e\u6807\u51c6\u7cfb\u7edf\u65f6\u6781\u4e3a\u6709\u7528\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>4. \u9ad8\u7ea7\u4fe1\u606f\uff1a\u8fd0\u884c\u65f6\u95f4\u4e0e\u5e8f\u5217\u53f7\u9884\u6d4b<\/strong><br>\u64cd\u4f5c\u7cfb\u7edf\u63a2\u6d4b\u8fc7\u7a0b\u4f1a\u987a\u5e26\u5206\u6790\u5176\u4ed6\u5b89\u5168\u76f8\u5173\u4fe1\u606f\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u67e5\u770b\u8be6\u7ec6\u8f93\u51fa<\/strong>\uff1a <code>bash nmap -O -v 192.168.1.1<\/code>\n<ul class=\"wp-block-list\">\n<li><strong>\u5728\u8be6\u7ec6\u8f93\u51fa\u4e2d\uff0c\u4f60\u53ef\u80fd\u4f1a\u770b\u5230<\/strong>\uff1a<br><code>TCP Sequence Prediction: Difficulty=258 (Good luck!) IP ID Sequence Generation: All zeros Uptime guess: 12.990 days (since Wed Jan 17 08:23:15 2024)<\/code><\/li>\n\n\n\n<li><strong>\u4fe1\u606f\u89e3\u8bfb<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>TCP\u5e8f\u5217\u53f7\u9884\u6d4b\u96be\u5ea6<\/strong>\uff1a<code>Difficulty=258<\/code> \u610f\u5473\u7740\u9884\u6d4b\u4e0b\u4e00\u4e2aTCP\u5e8f\u5217\u53f7\u975e\u5e38\u56f0\u96be\uff08\u201c\u795d\u4f60\u597d\u8fd0\uff01\u201d\uff09\uff0c\u8fd9\u8868\u660e\u7cfb\u7edf\u4e0d\u6613\u53d7\u5230\u57fa\u4e8eTCP\u5e8f\u5217\u53f7\u9884\u6d4b\u7684\u6b3a\u9a97\u653b\u51fb\uff08\u5982\u65e7\u5f0fIP\u6b3a\u9a97\uff09\u3002\u5982\u679c\u663e\u793a <code>Difficulty=0<\/code>\uff0c\u5219\u98ce\u9669\u6781\u9ad8\u3002<\/li>\n\n\n\n<li><strong>IP ID \u751f\u6210\u65b9\u5f0f<\/strong>\uff1a<code>All zeros<\/code> \u8868\u793a\u8be5\u4e3b\u673a\u53d1\u51fa\u7684IP\u5305\u4e2d\uff0cID\u5b57\u6bb5\u603b\u662f0\u3002\u8fd9\u662f\u67d0\u4e9b\u7cfb\u7edf\uff08\u5982\u65e7\u7684Linux\u5185\u6838\u914d\u7f6e\uff09\u7684\u7279\u6027\uff0c\u53ef\u80fd\u7528\u4e8e\u4fe1\u606f\u6536\u96c6\u3002<\/li>\n\n\n\n<li><strong>\u8fd0\u884c\u65f6\u95f4\u731c\u6d4b<\/strong>\uff1a\u901a\u8fc7TCP\u65f6\u95f4\u6233\u9009\u9879\u4f30\u7b97\u3002<code>12.990\u5929<\/code> \u8868\u793a\u4e3b\u673a\u5df2\u8fde\u7eed\u8fd0\u884c\u8fd113\u5929\uff0c\u8fd9\u5bf9\u4e8e\u8bc4\u4f30\u7cfb\u7edf\u8865\u4e01\u66f4\u65b0\uff08\u66f4\u65b0\u901a\u5e38\u9700\u8981\u91cd\u542f\uff09\u548c\u7a33\u5b9a\u6027\u6709\u53c2\u8003\u4ef7\u503c\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>5. \u7efc\u5408\u626b\u63cf\u793a\u4f8b (<code>-A<\/code>)<\/strong><br><code>-A<\/code> \u9009\u9879\u96c6\u6210\u4e86\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u3001\u7248\u672c\u68c0\u6d4b\u3001\u811a\u672c\u626b\u63cf\u548c\u8ddf\u8e2a\u8def\u7531\uff0c\u662f\u201c\u5168\u529b\u8fdb\u653b\u201d\u7684\u4fe1\u606f\u6536\u96c6\u6a21\u5f0f\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u793a\u4f8b<\/strong>\uff1a <code>bash nmap -A 192.168.48.1<\/code>\n<ul class=\"wp-block-list\">\n<li><strong>\u8f93\u51fa\u5c06\u5305\u542b<\/strong>\uff1a\n<ol class=\"wp-block-list\">\n<li>\u5f00\u653e\u7684\u7aef\u53e3\u53ca\u72b6\u6001\u3002<\/li>\n\n\n\n<li>\u670d\u52a1\u7684\u5177\u4f53\u7248\u672c\uff08\u5982 <code>OpenSSH 8.4p1<\/code>\uff09\u3002<\/li>\n\n\n\n<li>\u64cd\u4f5c\u7cfb\u7edf\u7684\u8be6\u7ec6\u7c7b\u578b\uff08\u5982 <code>Linux 5.4<\/code>\uff09\u3002<\/li>\n\n\n\n<li>\u53ef\u80fd\u8fd0\u884c\u9ed8\u8ba4\u811a\u672c (<code>-sC<\/code>) \u53d1\u73b0\u7684\u989d\u5916\u4fe1\u606f\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li><strong>\u6ce8\u610f<\/strong>\uff1a<code>-A<\/code> \u626b\u63cf\u4f1a\u4ea7\u751f\u5927\u91cf\u6d41\u91cf\u548c\u65e5\u5fd7\uff0c\u5728\u9690\u79d8\u6027\u8981\u6c42\u9ad8\u7684\u73af\u5883\u4e2d\u5e94\u614e\u7528\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>D:\\Program\\Professional\\01_Offensive_Security\\01_Reconnaissance\\Nmap&gt;nmap -A 192.168.48.1\nStarting Nmap 7.98 ( https:\/\/nmap.org ) at 2026-01-30 21:21 +0800\nNmap scan report for 192.168.48.1\nHost is up (0.00052s latency).\nNot shown: 995 closed tcp ports (reset)\nPORT     STATE SERVICE         VERSION\n139\/tcp  open  netbios-ssn     Microsoft Windows netbios-ssn\n445\/tcp  open  microsoft-ds?\n902\/tcp  open  ssl\/vmware-auth VMware Authentication Daemon 1.10 (Uses VNC, SOAP)\n912\/tcp  open  vmware-auth     VMware Authentication Daemon 1.0 (Uses VNC, SOAP)\n2179\/tcp open  vmrdp?\nDevice type: general purpose\nRunning: Microsoft Windows 10\nOS CPE: cpe:\/o:microsoft:windows_10\nOS details: Microsoft Windows 10 1511 - 1607\nNetwork Distance: 0 hops\nService Info: OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nHost script results:\n| smb2-security-mode:\n|   3.1.1:\n|_    Message signing enabled and required\n|_clock-skew: -1s\n| smb2-time:\n|   date: 2026-01-30T13:21:55\n|_  start_date: N\/A\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 39.51 seconds<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u65f6\u95f4\u4f18\u5316\u4e0e\u6027\u80fd\u8c03\u8be6\uff1a\u573a\u666f\u4e0e\u793a\u4f8b<\/h2>\n\n\n\n<p>\u7406\u89e3\u53c2\u6570\u53ea\u662f\u7b2c\u4e00\u6b65\uff0c\u77e5\u9053\u5728\u4ec0\u4e48\u60c5\u51b5\u4e0b\u4f7f\u7528\u5b83\u4eec\u624d\u662f\u5173\u952e\u3002\u4ee5\u4e0b\u901a\u8fc7\u51e0\u4e2a\u5178\u578b\u573a\u666f\u6765\u8bf4\u660e\u3002<\/p>\n\n\n\n<p><strong>\u573a\u666f\u4e00\uff1a\u95ea\u7535\u626b\u63cf\u2014\u2014\u5bf9\u672c\u5730\/\u6570\u636e\u4e2d\u5fc3\u9ad8\u901f\u7f51\u7edc\u8fdb\u884c\u8d44\u4ea7\u6e05\u70b9<\/strong><br>\u5047\u8bbe\u9700\u8981\u5feb\u901f\u626b\u63cf <code>192.168.1.0\/24<\/code> \u8fd9\u4e2a\u5c40\u57df\u7f51\u6bb5\uff0c\u627e\u51fa\u6240\u6709\u5728\u7ebf\u4e3b\u673a\u53ca\u5176\u5f00\u653e\u7684\u5e38\u7528\u7aef\u53e3\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -T4 -F 192.168.48.0\/24<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>-T4 (Aggressive)<\/code><\/strong>: \u4f7f\u7528\u6fc0\u8fdb\u6a21\u677f\uff0c\u8fd9\u662f\u6838\u5fc3\u3002\u5b83\u81ea\u52a8\u8bbe\u5b9a\u4e86\u66f4\u77ed\u7684\u8d85\u65f6\uff08<code>--max-rtt-timeout 1250ms<\/code>\uff09\u548c\u66f4\u9ad8\u7684\u5e76\u884c\u5ea6\uff0c\u975e\u5e38\u9002\u5408\u4f4e\u5ef6\u8fdf\u3001\u9ad8\u5e26\u5bbd\u7684\u53ef\u9760\u7f51\u7edc\u3002<\/li>\n\n\n\n<li><strong><code>-F (Fast scan)<\/code><\/strong>: \u5feb\u901f\u6a21\u5f0f\uff0c\u53ea\u626b\u63cf\u7ea6100\u4e2a\u6700\u5e38\u89c1\u7aef\u53e3\uff0c\u800c\u975e\u9ed8\u8ba4\u76841000\u4e2a\u7aef\u53e3\u3002\u8fd9\u80fd\u6781\u5927\u51cf\u5c11\u603b\u63a2\u6d4b\u5305\u6570\u3002<\/li>\n\n\n\n<li><strong>\u6548\u679c<\/strong>\uff1a\u8fd9\u662f\u901f\u5ea6\u4e0e\u4fe1\u606f\u91cf\u4e4b\u95f4\u6700\u4f73\u7684\u5e73\u8861\u547d\u4ee4\u4e4b\u4e00\uff0c\u80fd\u5728\u51e0\u79d2\u5185\u5b8c\u6210\u4e00\u4e2aC\u7c7b\u7f51\u6bb5\u7684\u57fa\u7840\u626b\u63cf\u3002<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap21-1024x385.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"385\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap21-1024x385.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1518\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p><strong>\u66f4\u8fdb\u4e00\u6b65\uff0c\u5982\u679c\u53ea\u5173\u5fc3\u4e3b\u673a\u662f\u5426\u5728\u7ebf\uff08\u53d1\u73b0\u9636\u6bb5\uff09\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -T5 -sn -n 192.168.1.0\/24<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>-T5 (Insane)<\/code><\/strong>: \u4e3a\u4e86\u8ffd\u6c42\u6781\u81f4\u7684\u53d1\u73b0\u901f\u5ea6\uff0c\u5728\u7f51\u7edc\u6781\u4f73\u7684\u60c5\u51b5\u4e0b\u53ef\u4ee5\u5c1d\u8bd5\u3002\u4f46\u9700\u6ce8\u610f\uff0c<code>-T5<\/code>\u8bbe\u7f6e\u7684\u8d85\u65f6\u6781\u77ed\uff08<code>--max-rtt-timeout 300ms<\/code>\uff09\uff0c\u5728\u8de8\u7f51\u6bb5\u6216\u7a0d\u6709\u5ef6\u8fdf\u7684\u7f51\u7edc\u4e2d\u4f1a\u9020\u6210\u5927\u91cf\u8bef\u5224\uff08\u5c06\u5728\u7ebf\u4e3b\u673a\u5224\u4e3a\u79bb\u7ebf\uff09\u3002<\/li>\n\n\n\n<li><strong><code>-sn (No port scan)<\/code><\/strong>: \u4ec5\u8fdb\u884c\u4e3b\u673a\u53d1\u73b0\uff08Ping\u626b\u63cf\uff09\uff0c\u4e0d\u626b\u63cf\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><strong><code>-n (No DNS resolution)<\/code><\/strong>: \u4e0d\u8fdb\u884cDNS\u53cd\u5411\u89e3\u6790\uff0c\u8282\u7701\u65f6\u95f4\u3002<\/li>\n\n\n\n<li><strong>\u5efa\u8bae<\/strong>\uff1a\u5bf9\u4e8e\u4e3b\u673a\u53d1\u73b0\uff0c\u66f4\u7a33\u59a5\u4e14\u4f9d\u7136\u6781\u5feb\u7684\u7ec4\u5408\u662f <code>nmap -T4 -sn --min-parallelism 100 192.168.1.0\/24<\/code>\u3002\u901a\u8fc7\u624b\u52a8\u5c06 <code>--min-parallelism<\/code> \u8bbe\u9ad8\uff0c\u5f3a\u5236Nmap\u540c\u65f6\u53d1\u9001\u5927\u91cf\u63a2\u6d4b\u5305\uff0c\u5145\u5206\u5229\u7528\u672c\u5730\u7f51\u7edc\u7684\u6027\u80fd\u3002<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap22-1024x217.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"217\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap22-1024x217.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1519\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p><strong>\u573a\u666f\u4e8c\uff1a\u6c89\u7a33\u6e17\u900f\u2014\u2014\u626b\u63cf\u53d7\u9632\u706b\u5899\u4fdd\u62a4\u6216\u9ad8\u5ef6\u8fdf\u7684\u4e92\u8054\u7f51\u4e3b\u673a<\/strong><br>\u76ee\u6807\u662f\u4e00\u4e2a\u8de8\u4e92\u8054\u7f51\u7684\u4f01\u4e1a\u670d\u52a1\u5668\uff0c\u53ef\u80fd\u5b58\u5728\u5305\u8fc7\u6ee4\u3001\u901f\u7387\u9650\u5236\u6216\u8f83\u9ad8\u7684\u7f51\u7edc\u5ef6\u8fdf\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -T2 --max-rtt-timeout 1500ms --script-args http.useragent=\"Mozilla\/5.0\" example.com<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>-T2 (Polite)<\/code><\/strong>: \u964d\u4f4e\u53d1\u9001\u901f\u7387\uff0c\u51cf\u5c11\u88ab\u76ee\u6807\u9632\u706b\u5899\u6216IDS\u6807\u8bb0\u4e3a\u201c\u626b\u63cf\u653b\u51fb\u201d\u7684\u98ce\u9669\u3002<\/li>\n\n\n\n<li><strong><code>--max-rtt-timeout 1500ms<\/code><\/strong>: \u624b\u52a8\u653e\u5bbd\u8d85\u65f6\u4e0a\u9650\uff0c\u7ed9\u8de8\u7f51\u6bb5\u3001\u9ad8\u5ef6\u8fdf\u7684\u54cd\u5e94\u7559\u51fa\u8db3\u591f\u65f6\u95f4\u3002\u8fd9\u662f\u907f\u514d\u6f0f\u62a5\u7684\u5173\u952e\u3002<\/li>\n\n\n\n<li><strong><code>--script-args http.useragent=\"...\"<\/code><\/strong>: \u8fd9\u662f\u4e00\u4e2a<strong>\u8f83\u5c11\u63d0\u53ca\u4f46\u81f3\u5173\u91cd\u8981\u7684\u6280\u5de7<\/strong>\u3002\u5728\u4f7f\u7528NSE\u811a\u672c\uff08\u5982<code>http-title<\/code>\uff09\u65f6\uff0c\u4f7f\u7528\u5e38\u89c1\u7684\u6d4f\u89c8\u5668User-Agent\u53ef\u4ee5\u907f\u514d\u88abWAF\uff08Web\u5e94\u7528\u9632\u706b\u5899\uff09\u8f7b\u6613\u62e6\u622a\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u5982\u679c\u9700\u8981\u7a7f\u900f\u4e25\u683c\u7684\u9632\u706b\u5899\u8fdb\u884c\u7aef\u53e3\u63a2\u6d4b\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -T3 -sS -Pn --scan-delay 500ms --max-parallelism 1 --max-retries 2 xxx.xxx.com<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>-Pn (Treat all hosts as online)<\/code><\/strong>: \u8df3\u8fc7\u4e3b\u673a\u53d1\u73b0\u9636\u6bb5\u3002\u56e0\u4e3a\u9632\u706b\u5899\u53ef\u80fd\u5c4f\u853dICMP\uff0c\u5bfc\u81f4Ping\u4e0d\u901a\u4f46\u4e3b\u673a\u5b9e\u9645\u5728\u7ebf\u3002<\/li>\n\n\n\n<li><strong><code>-sS (Stealth SYN scan)<\/code><\/strong>: TCP SYN\u626b\u63cf\uff0c\u6bd4\u5168\u8fde\u63a5\u626b\u63cf\uff08<code>-sT<\/code>\uff09\u66f4\u9690\u853d\u3002<\/li>\n\n\n\n<li><strong><code>--scan-delay 500ms<\/code><\/strong> \u548c <strong><code>--max-parallelism 1<\/code><\/strong>: \u7ec4\u5408\u4f7f\u7528\uff0c\u5f3a\u5236\u626b\u63cf\u5728\u6bcf\u53d1\u9001\u4e00\u4e2a\u63a2\u6d4b\u5305\u540e\u7b49\u5f85\u534a\u79d2\uff0c\u4e14\u4e0d\u540c\u65f6\u53d1\u9001\u5176\u4ed6\u5305\u3002\u8fd9\u80fd\u5c06\u626b\u63cf\u6d41\u91cf\u964d\u5230\u6781\u4f4e\uff0c\u6a21\u62df\u6162\u901f\u7684\u6b63\u5e38\u8fde\u63a5\u5c1d\u8bd5\uff0c\u6709\u6548\u89c4\u907f\u57fa\u4e8e\u6d41\u91cf\u7684\u9608\u503c\u68c0\u6d4b\u3002<\/li>\n\n\n\n<li><strong><code>--max-retries 2<\/code><\/strong>: \u51cf\u5c11\u91cd\u8bd5\u6b21\u6570\uff0c\u9ed8\u8ba4\u662f10\u6b21\u3002\u5728\u660e\u786e\u7f51\u7edc\u88ab\u4e25\u683c\u8fc7\u6ee4\u65f6\uff0c\u8fc7\u591a\u7684\u91cd\u8bd5\u662f\u5f92\u52b3\u7684\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u573a\u666f\u4e09\uff1a\u5927\u89c4\u6a21\u8c03\u67e5\u2014\u2014\u626b\u63cf\u6574\u4e2aIP\u6bb5\uff08\u5982<code>10.0.0.0\/16<\/code>\uff0c\u542b65536\u4e2aIP\uff09<\/strong><br>\u8fd9\u662f\u5bf9Nmap\u6027\u80fd\u548c\u7b56\u7565\u7684\u771f\u6b63\u8003\u9a8c\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -T4 -sS -Pn -n --min-hostgroup 256 --max-retries 1 --min-parallelism 50 -oA mass_scan_10.0.0.0 10.0.0.0\/16<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>-Pn -n<\/code><\/strong>: \u540c\u6837\uff0c\u8df3\u8fc7Ping\u548cDNS\u89e3\u6790\uff0c\u4e13\u6ce8\u4e8e\u7aef\u53e3\u626b\u63cf\u3002<\/li>\n\n\n\n<li><strong><code>--min-hostgroup 256<\/code><\/strong>: <strong>\u8fd9\u662f\u5927\u89c4\u6a21\u626b\u63cf\u7684\u7075\u9b42\u53c2\u6570<\/strong>\u3002\u5f3a\u5236Nmap\u4e00\u6b21\u6027\u5c06\u81f3\u5c11256\u4e2aIP\u4f5c\u4e3a\u4e00\u4e2a\u7ec4\u8fdb\u884c\u5e76\u884c\u626b\u63cf\u3002\u8fd9\u6781\u5927\u5730\u51cf\u5c11\u4e86\u7ba1\u7406\u5f00\u9500\uff0c\u63d0\u5347\u4e86\u6574\u4f53\u541e\u5410\u91cf\u3002\u5bf9\u4e8e<code>\/16<\/code>\u7f51\u7edc\uff0c\u8fd9\u4e2a\u547d\u4ee4\u4f1a\u521b\u5efa\u7ea6256\u4e2a\u5e76\u884c\u626b\u63cf\u4efb\u52a1\uff0c\u6548\u7387\u8fdc\u9ad8\u4e8e\u9ed8\u8ba4\u7684\u5c0f\u7ec4\u5f00\u59cb\u3002<\/li>\n\n\n\n<li><strong><code>--max-retries 1<\/code><\/strong>: \u9762\u5bf9\u6570\u4e07\u4e2aIP\uff0c\u603b\u6709\u90e8\u5206\u4e0d\u54cd\u5e94\u3002\u5c06\u91cd\u8bd5\u6b21\u6570\u51cf\u81f31\uff0c\u53ef\u4ee5\u5927\u5e45\u8282\u7701\u5728\u201c\u6b7b\u201dIP\u4e0a\u7684\u7b49\u5f85\u65f6\u95f4\u3002<\/li>\n\n\n\n<li><strong><code>-oA &lt;basename&gt;<\/code><\/strong>: \u5c06\u7ed3\u679c\u4ee5\u4e09\u79cd\u683c\u5f0f\uff08\u6807\u51c6\u3001Grepable\u3001XML\uff09\u540c\u65f6\u8f93\u51fa\uff0c\u4fbf\u4e8e\u540e\u7eed\u5206\u6790\u3002<strong>\u8fd9\u662f\u751f\u4ea7\u73af\u5883\u626b\u63cf\u7684\u5fc5\u5907\u64cd\u4f5c<\/strong>\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u573a\u666f\u56db\uff1a\u7cbe\u51c6\u8bc4\u4f30\u4e0e\u8eb2\u907f\u2014\u2014\u9488\u5bf9\u7279\u5b9aIDS\/IPS\u7684\u6162\u901f\u626b\u63cf<\/strong><br>\u6a21\u62df\u4e00\u4e2a\u9ad8\u7ea7\u6301\u7eed\u6027\u5a01\u80c1(APT)\u98ce\u683c\u7684\u3001\u6781\u96be\u88ab\u68c0\u6d4b\u7684\u626b\u63cf\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -T1 -sS -Pn --scan-delay 5-10s --max-scan-delay 10s --max-retries 3 --randomize-hosts xxx.xxx.com\/24<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>-T1 (Sneaky)<\/code><\/strong>: \u672c\u8eab\u5c31\u589e\u52a0\u4e86\u5ef6\u8fdf\u3002<\/li>\n\n\n\n<li><strong><code>--scan-delay 5-10s<\/code><\/strong>: \u4f7f\u7528<strong>\u968f\u673a\u5ef6\u8fdf<\/strong>\uff085\u523010\u79d2\u4e4b\u95f4\uff09\uff0c\u8fd9\u6bd4\u56fa\u5b9a\u5ef6\u8fdf\u66f4\u96be\u88ab\u89c4\u5219\u5339\u914d\u3002<\/li>\n\n\n\n<li><strong><code>--max-scan-delay 10s<\/code><\/strong>: \u786e\u4fdd\u968f\u673a\u5ef6\u8fdf\u4e0d\u4f1a\u8d85\u8fc7\u6b64\u503c\u3002<\/li>\n\n\n\n<li><strong><code>--randomize-hosts<\/code><\/strong>: <strong>\u53e6\u4e00\u4e2a\u5173\u952e\u6280\u5de7<\/strong>\u3002\u968f\u673a\u6253\u4e71\u626b\u63cf\u76ee\u6807\u7684\u987a\u5e8f\u3002\u5982\u679c\u4e0d\u8fd9\u6837\u505a\uff0c\u6309\u987a\u5e8f\u626b\u63cf\u4e00\u4e2a\u7f51\u6bb5\u7684\u884c\u4e3a\u6a21\u5f0f\u672c\u8eab\u5c31\u4f1a\u89e6\u53d1\u8b66\u62a5\u3002<\/li>\n\n\n\n<li><strong>\u6ce8\u610f<\/strong>\uff1a\u8fd9\u4e2a\u626b\u63cf\u4f1a\u975e\u5e38\u3001\u975e\u5e38\u6162\u3002\u626b\u63cf\u4e00\u4e2aC\u6bb5\uff08254\u4e2aIP\uff09\u7684\u5c11\u91cf\u7aef\u53e3\u53ef\u80fd\u9700\u8981\u6570\u5c0f\u65f6\u3002\u5b83\u53ea\u5728\u7279\u5b9a\u6e17\u900f\u6d4b\u8bd5\u9636\u6bb5\u6709\u4f7f\u7528\u4ef7\u503c\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u603b\u7ed3<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u6a21\u677f\u4f18\u5148\uff0c\u5fae\u8c03\u5728\u540e<\/strong>\uff1a\u603b\u662f\u5148\u6307\u5b9a\u65f6\u95f4\u6a21\u677f\uff08\u5982&nbsp;<code>-T3<\/code>&nbsp;\u6216&nbsp;<code>-T4<\/code>\uff09\uff0c\u518d\u6dfb\u52a0\u5176\u4ed6\u5fae\u8c03\u9009\u9879\u3002\u56e0\u4e3a\u6a21\u677f\u4f1a\u8986\u76d6\u5b83\u4e4b\u524d\u7684\u624b\u52a8\u53c2\u6570\u3002<\/li>\n\n\n\n<li><strong>\u5c40\u57df\u7f51\u7528&nbsp;<code>-T4<\/code>\uff0c\u4e92\u8054\u7f51\u7528&nbsp;<code>-T3<\/code>&nbsp;\u6216\u624b\u52a8\u8c03\u6574<\/strong>\uff1a<code>-T4<\/code>\u662f\u53ef\u9760\u9ad8\u901f\u7f51\u7edc\u7684\u901a\u7528\u9009\u62e9\u3002\u8de8\u4e92\u8054\u7f51\u626b\u63cf\u65f6\uff0c\u9ed8\u8ba4\u7684<code>-T3<\/code>\u6216\u624b\u52a8\u8c03\u6574\u8d85\u65f6\uff08<code>--max-rtt-timeout<\/code>\uff09\u548c\u5ef6\u8fdf\uff08<code>--scan-delay<\/code>\uff09\u66f4\u4e3a\u7a33\u59a5\u3002<\/li>\n\n\n\n<li><strong>\u5927\u89c4\u6a21\u626b\u63cf\uff0c\u7ec4\u5927\u5c0f\u662f\u5173\u952e<\/strong>\uff1a\u4f7f\u7528&nbsp;<code>--min-hostgroup<\/code>\uff08\u5982256\u6216512\uff09\u6765\u63d0\u5347\u7ba1\u7406\u6548\u7387\u3002<\/li>\n\n\n\n<li><strong>\u60f3\u9690\u853d\uff0c\u5fc5\u968f\u673a<\/strong>\uff1a\u7ed3\u5408&nbsp;<code>--scan-delay<\/code>\uff08\u5e26\u8303\u56f4\u503c\uff09\u548c&nbsp;<code>--randomize-hosts<\/code>&nbsp;\u662f\u89c4\u907f\u57fa\u4e8e\u9608\u503c\u68c0\u6d4b\u7684\u4e3b\u8981\u624b\u6bb5\u3002<\/li>\n\n\n\n<li><strong>\u5584\u7528\u8f93\u51fa\u548c\u72b6\u6001<\/strong>\uff1a\u4f7f\u7528&nbsp;<code>-oA<\/code>&nbsp;\u4fdd\u5b58\u7ed3\u679c\u3002\u5728\u626b\u63cf\u8fd0\u884c\u65f6\uff0c<strong>\u6309&nbsp;<code>\u56de\u8f66\u952e<\/code>&nbsp;\u6216&nbsp;<code>d<\/code>\/<code>D<\/code>&nbsp;\u952e<\/strong>\uff0cNmap\u4f1a\u52a8\u6001\u663e\u793a\u8be6\u7ec6\u7684\u8fdb\u5ea6\u548c\u7edf\u8ba1\u4fe1\u606f\uff08\u5df2\u5b8c\u6210\u6bd4\u4f8b\u3001\u9884\u8ba1\u5269\u4f59\u65f6\u95f4\uff09\uff0c\u8fd9\u662f\u4e00\u4e2a\u975e\u5e38\u5b9e\u7528\u7684\u5185\u7f6e\u529f\u80fd\u3002<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u9632\u706b\u5899\/IDS\u8eb2\u907f\u548c\u54c4\u9a97<\/h2>\n\n\n\n<p>\u6838\u5fc3\u601d\u60f3\u5728\u4e8e<strong>\u589e\u52a0\u626b\u63cf\u884c\u4e3a\u7684\u201c\u566a\u97f3\u201d<\/strong>\u3001<strong>\u4f2a\u88c5\u626b\u63cf\u6e90<\/strong>\u6216<strong>\u5229\u7528\u76ee\u6807\u7f51\u7edc\u7684\u5b89\u5168\u914d\u7f6e\u5f31\u70b9<\/strong>\uff0c\u4ece\u800c\u964d\u4f4e\u88ab\u7cbe\u51c6\u8bc6\u522b\u548c\u5c4f\u853d\u7684\u6982\u7387\u3002\u4e0b\u9762\u901a\u8fc7\u5177\u4f53\u793a\u4f8b\u6765\u9610\u660e\u8fd9\u4e9b\u6280\u672f\u7684\u5e94\u7528\u3002<\/p>\n\n\n\n<p><strong>1. <code>-f<\/code>&nbsp;(\u62a5\u6587\u5206\u6bb5);&nbsp;<code>--mtu<\/code>&nbsp;(\u4f7f\u7528\u6307\u5b9a\u7684MTU)<\/strong><br>\u6b64\u6280\u672f\u65e8\u5728\u5c06\u4e00\u4e2a\u5b8c\u6574\u7684TCP\u5934\u90e8\u62c6\u5206\u6210\u591a\u4e2a\u66f4\u5c0f\u7684IP\u5206\u7247\uff0c\u4ece\u800c\u53ef\u80fd\u7ed5\u8fc7\u90a3\u4e9b<strong>\u6ca1\u6709\u6b63\u786e\u5b9e\u73b0\u5206\u7247\u91cd\u7ec4\u68c0\u6d4b\u903b\u8f91<\/strong>\u7684\u7b80\u5355\u5305\u8fc7\u6ee4\u5668\u548c\u8001\u5f0fIDS\u3002<br><strong>\u547d\u4ee4\u793a\u4f8b<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u4f7f\u7528\u9ed8\u8ba4\u76848\u5b57\u8282\u504f\u79fb\u8fdb\u884c\u5206\u7247\u626b\u63cf\n   nmap -f &lt;\u76ee\u6807IP&gt;\n\n   # \u4f7f\u7528\u81ea\u5b9a\u4e49\u7684MTU\u503c\uff08\u5fc5\u987b\u662f8\u7684\u500d\u6570\uff09\uff0c\u8fd9\u91cc16\u5b57\u8282\u4e00\u5206\u7247\n   nmap --mtu 16 &lt;\u76ee\u6807IP&gt;<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u89e3\u91ca\u4e0e\u6ce8\u610f<\/strong>\uff1a\u73b0\u4ee3\u4e0b\u4e00\u4ee3\u9632\u706b\u5899\uff08NGFW\uff09\u548cIDS\u901a\u5e38\u5177\u5907\u5f3a\u5927\u7684\u6d41\u91cd\u7ec4\u4e0e\u6df1\u5ea6\u5305\u68c0\u6d4b\uff08DPI\uff09\u80fd\u529b\uff0c\u7b80\u5355\u7684\u5206\u7247\u626b\u63cf\u5df2\u5f88\u96be\u594f\u6548\u3002\u5b83\u66f4\u4e3b\u8981\u7684\u4f5c\u7528\u662f\u7528\u4e8e\u6d4b\u8bd5\u76ee\u6807\u7f51\u7edc\u8bbe\u5907\u5728\u5904\u7406\u5f02\u5e38\u5206\u7247\u5305\u65f6\u7684\u884c\u4e3a\uff08\u662f\u5426\u5d29\u6e83\u6216\u51fa\u9519\uff09\uff0c\u8fd9\u5c5e\u4e8e\u201c\u6a21\u7cca\u6d4b\u8bd5\u201d\u8303\u7574\u3002\u5982\u60a8\u6240\u8ff0\uff0c\u52a1\u5fc5\u5728\u6388\u6743\u73af\u5883\u4e0b\u6d4b\u8bd5\uff0c\u56e0\u4e3a\u90e8\u5206\u8001\u65e7\u7cfb\u7edf\u53ef\u80fd\u56e0\u5904\u7406\u5f02\u5e38\u5206\u7247\u800c\u5b95\u673a\u3002<\/p>\n\n\n\n<p><strong>2. <code>-D &lt;decoy1 [\uff0cdecoy2][\uff0cME]\uff0c...&gt;<\/code>&nbsp;(\u4f7f\u7528\u8bf1\u9975\u9690\u853d\u626b\u63cf)<\/strong><br>\u6b64\u9009\u9879\u901a\u8fc7\u5728\u626b\u63cf\u6d41\u91cf\u4e2d\u6df7\u5165\u5927\u91cf\u865a\u5047\u6e90IP\uff08\u8bf1\u9975\uff09\uff0c\u4f7f\u9632\u5fa1\u65b9\u96be\u4ee5\u8fa8\u522b\u771f\u5b9e\u7684\u653b\u51fb\u6e90\u3002\u5982\u679c\u5728\u7b2c6\u4e2a\u4f4d\u7f6e\u6216 \u66f4\u540e\u7684\u4f4d\u7f6e\u4f7f\u7528<code>ME<\/code>\u9009\u9879\uff0c\u4e00\u4e9b\u5e38\u7528 \u7aef\u53e3\u626b\u63cf\u68c0\u6d4b\u5668(\u5982Solar Designer&#8217;s excellent scanlogd)\u5c31\u4e0d\u4f1a\u62a5\u544a \u8fd9\u4e2a\u771f\u5b9eIP\u3002\u5982\u679c\u4e0d\u4f7f\u7528<code>ME<\/code>\u9009\u9879\uff0cNmap \u5c06\u771f\u5b9eIP\u653e\u5728\u4e00\u4e2a\u968f\u673a\u7684\u4f4d\u7f6e<br><strong>\u547d\u4ee4\u793a\u4f8b<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u4f7f\u75283\u4e2a\u8bf1\u9975IP\uff0c\u5e76\u5c06\u771f\u5b9e\u626b\u63cfIP\uff08ME\uff09\u968f\u673a\u63d2\u5165\u5217\u8868\u4e2d\uff08\u4f8b\u5982\u6392\u5728\u7b2c\u4e8c\u4f4d\uff09\n   nmap -D RND:3 &lt;\u76ee\u6807IP&gt;\n\n   # \u7cbe\u786e\u6307\u5b9a\u8bf1\u9975IP\uff0c\u5e76\u5c06\u771f\u5b9eIP\uff08ME\uff09\u56fa\u5b9a\u5728\u5217\u8868\u7b2c\u56db\u4f4d\u3002\u8bf1\u9975IP\u5e94\u5c3d\u91cf\u9009\u62e9\u6d3b\u8dc3\u7684\u4e3b\u673a\u3002\n   nmap -D 192.168.1.99,10.0.0.1,172.16.31.254,ME,203.0.113.5 &lt;\u76ee\u6807IP&gt;<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u89e3\u91ca\u4e0e\u6ce8\u610f<\/strong>\uff1a\u8bf1\u9975\u626b\u63cf\u4f1a\u663e\u8457\u589e\u52a0\u7f51\u7edc\u6d41\u91cf\uff0c\u56e0\u4e3a\u6bcf\u4e2a\u63a2\u6d4b\u5305\u90fd\u4f1a\u4ee5\u6bcf\u4e2a\u8bf1\u9975IP\u7684\u540d\u4e49\u53d1\u9001\u4e00\u6b21\u3002\u5982\u679c\u8bf1\u9975\u4e3b\u673a\u4e0d\u5728\u7ebf\uff0c\u76ee\u6807\u56de\u590d\u7684SYN-ACK\u6216RST\u5305\u5c06\u5f97\u4e0d\u5230\u54cd\u5e94\uff0c\u8fd9\u53ef\u80fd\u65e0\u610f\u4e2d\u5bf9\u8bf1\u9975IP\u9020\u6210\u4e00\u6b21\u8f7b\u5fae\u7684\u201cSYN\u6d2a\u6c34\u201d\u53cd\u5c04\u3002\u56e0\u6b64\uff0c\u9009\u62e9\u516c\u53f8\u5916\u90e8\u5df2\u77e5\u7684\u3001\u7a33\u5b9a\u7684Web\u670d\u52a1\u5668\u6216\u7f51\u5173\u4f5c\u4e3a\u8bf1\u9975\u6bd4\u9009\u62e9\u968f\u673a\u5185\u7f51\u5730\u5740\u66f4\u201c\u793c\u8c8c\u201d\u4e14\u6709\u6548\u3002<code>RND<\/code> \u662f\u4e00\u4e2aNmap\u5185\u7f6e\u7684\u5feb\u6377\u65b9\u5f0f\uff0c\u7528\u4e8e\u751f\u6210\u968f\u673a\u3001\u672a\u5206\u914d\u7684\u4e92\u8054\u7f51IP\u4f5c\u4e3a\u8bf1\u9975\u3002<\/p>\n\n\n\n<p><strong>3. \u6e90\u5730\u5740\u6b3a\u9a97 (<code>-S<\/code>) \u4e0e\u63a5\u53e3\u7ed1\u5b9a (<code>-e<\/code>)<\/strong><br>\u8fd9\u4e24\u4e2a\u9009\u9879\u901a\u5e38\u7ed3\u5408\u4f7f\u7528\uff0c\u7528\u4e8e\u5b8c\u5168\u4f2a\u9020\u626b\u63cf\u62a5\u6587\u7684\u6e90IP\uff0c\u5e76\u6307\u5b9a\u4ece\u54ea\u4e2a\u7f51\u7edc\u63a5\u53e3\u53d1\u51fa\u3002<br><strong>\u547d\u4ee4\u793a\u4f8b<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u5047\u8bbe\u653b\u51fb\u8005\u62e5\u6709IP 10.0.0.5\uff0c\u4f46\u60f3\u4f2a\u88c5\u6210\u6765\u81ea 192.168.100.100 \u7684\u626b\u63cf\n   # \u540c\u65f6\uff0c\u6307\u5b9a\u4ece\u672c\u673a\u7684 eth0 \u63a5\u53e3\u53d1\u9001\u8fd9\u4e9b\u6b3a\u9a97\u5305\n   nmap -S 192.168.100.100 -e eth0 -Pn &lt;\u76ee\u6807IP&gt;<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u89e3\u91ca\u4e0e\u6ce8\u610f<\/strong>\uff1a\u7eaf\u7cb9\u7684\u6b3a\u9a97\u626b\u63cf\uff08<code>-S<\/code>\uff09<strong>\u65e0\u6cd5\u5efa\u7acb\u5b8c\u6574\u7684TCP\u8fde\u63a5\u6216\u63a5\u6536\u4efb\u4f55\u56de\u590d\u4fe1\u606f<\/strong>\uff0c\u56e0\u4e3a\u56de\u590d\u5305\u4f1a\u53d1\u9001\u5230\u88ab\u6b3a\u9a97\u7684IP\u5730\u5740\uff08192.168.100.100\uff09\uff0c\u800c\u975e\u626b\u63cf\u8005\u3002\u56e0\u6b64\uff0c\u5b83\u901a\u5e38\u4e0e\u4e0d\u9700\u8981\u5efa\u7acb\u5b8c\u6574\u8fde\u63a5\u7684\u626b\u63cf\u7c7b\u578b\uff08\u5982 <code>-sN<\/code> NULL\u626b\u63cf\u3001<code>-sF<\/code> FIN\u626b\u63cf\uff09\u6216\u4ec5\u9700\u8981\u53d1\u9001\u63a2\u6d4b\u5305\uff08<code>-Pn<\/code> \u8df3\u8fc7\u4e3b\u673a\u53d1\u73b0\uff09\u7ed3\u5408\u4f7f\u7528\uff0c\u7528\u4e8e\u63a2\u6d4b\u76ee\u6807\u4e3b\u673a\u7684\u201c\u9759\u9ed8\u4e22\u5f03\u201d\u6216\u201c\u54cd\u5e94\u201d\u884c\u4e3a\uff0c\u8fd9\u662f\u4e00\u79cd<strong>\u76f2\u626b\u63cf<\/strong>\u6280\u672f\u3002<code>-e<\/code> \u9009\u9879\u5728\u4e3b\u673a\u6709\u591a\u4e2a\u7f51\u5361\uff08\u5982\u540c\u65f6\u8fde\u63a5\u6709\u7ebf\u3001\u65e0\u7ebf\u548cVPN\uff09\u65f6\u81f3\u5173\u91cd\u8981\uff0c\u5b83\u80fd\u786e\u4fdd\u626b\u63cf\u6d41\u91cf\u4ece\u6b63\u786e\u7684\u8def\u5f84\u53d1\u51fa\u3002<\/p>\n\n\n\n<p><strong>4. <code>--source-port &lt;portnumber&gt;;<\/code>&nbsp;<code>-g &lt;portnumber&gt;<\/code>&nbsp;(\u6e90\u7aef\u53e3\u54c4\u9a97)<\/strong><br><strong><em>\u6ce8\u610f\u5230DNS\u54cd\u5e94\u6765\u81ea\u4e8e53\u7aef\u53e3\uff0cFTP\u8fde\u63a5 \u6765\u81ea\u4e8e20\u7aef\u53e3\uff0c\u5f88\u591a\u7ba1\u7406\u5458\u4f1a\u6389\u5165\u4e00\u4e2a\u9677\u9631\uff0c\u5373\u5141\u8bb8\u6765\u81ea\u4e8e\u8fd9\u4e9b\u7aef\u53e3\u7684\u6570\u636e\u8fdb\u5165 \u7f51\u7edc\u3002\u4ed6\u4eec\u8ba4\u4e3a\u8fd9\u4e9b\u7aef\u53e3\u91cc\u4e0d\u4f1a\u6709\u503c\u5f97\u6ce8\u610f\u7684\u653b\u51fb\u548c\u6f0f\u6d1e\u5229\u7528<\/em><\/strong>\uff0c<strong><em>Windows 2000\u548cWindows XP\u4e2d\u5305\u542b\u7684IPsec\u8fc7\u6ee4 \u5668\u4e5f\u5305\u542b\u4e86\u4e00\u4e9b\u9690\u542b\u89c4\u5219\uff0c\u5141\u8bb8\u6240\u6709\u6765\u81ea88\u7aef\u53e3(Kerberos)\u7684TCP\u548cUDP\u6570\u636e\u6d41\u3002\u53e6 \u4e00\u4e2a\u5e38\u89c1\u7684\u4f8b\u5b50\u662fZone Alarm\u4e2a\u4eba\u9632\u706b\u5899\u52302.1.25\u7248\u672c\u4ecd\u7136\u5141\u8bb8\u6e90\u7aef\u53e353(DNS)\u6216 67(DHCP)\u7684UDP\u5305\u8fdb\u5165\u3002\u6b64\u6280\u672f\u5229\u7528\u4e86\u7ba1\u7406\u5458\u4e3a\u7279\u5b9a\u670d\u52a1\uff08\u5982DNS\u3001FTP-DATA\uff09\u9519\u8bef\u5730\u5f00\u653e\u5bbd\u677e<\/em><\/strong>\u3002\u9632\u706b\u5899\u89c4\u5219\u8fd9\u4e00\u5e38\u89c1\u914d\u7f6e\u5931\u8bef\u3002<br><strong>\u547d\u4ee4\u793a\u4f8b<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u5047\u8bbe\u76ee\u6807\u9632\u706b\u5899\u4fe1\u4efb\u6765\u81ea53\u7aef\u53e3\uff08DNS\uff09\u7684UDP\u6d41\u91cf\uff0c\u53ef\u7528\u4e8e\u63a2\u6d4b\u5176\u540e\u7684UDP\u670d\u52a1\n   nmap -sU -g 53 --data-length 32 &lt;\u76ee\u6807IP&gt;\n\n   # \u5047\u8bbe\u76ee\u6807\u4fe1\u4efb\u6765\u81ea20\u7aef\u53e3\uff08FTP\u6570\u636e\u7aef\u53e3\uff09\u7684TCP\u8fde\u63a5\uff0c\u53ef\u7528\u4e8e\u8fdb\u884cSYN\u626b\u63cf\n   nmap -sS -g 20 &lt;\u76ee\u6807IP&gt;<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u89e3\u91ca<\/strong>\uff1a\u8fd9\u91cc\u7684\u6838\u5fc3\u662f<strong>\u4fe1\u4efb\u8f6c\u79fb<\/strong>\u3002Nmap\u672c\u8eab<strong><em>\u5e76\u4e0d\u53d1\u9001\u771f\u6b63\u7684DNS\u6216FTP\u6d41\u91cf\uff0c\u5b83\u53ea\u662f\u5c06\u626b\u63cf\u63a2\u9488\u7684\u6e90\u7aef\u53e3\u53f7\u8bbe\u7f6e\u4e3a\u8fd9\u4e9b\u53d7\u4fe1\u4efb\u7684\u7aef\u53e3\u3002<\/em><\/strong>\u5982\u679c\u9632\u706b\u5899\u89c4\u5219\u662f\u57fa\u4e8e\u201c\u6e90\u7aef\u53e3\u7b49\u4e8e53\u5219\u653e\u884c\u201d\u8fd9\u79cd\u4e0d\u5b89\u5168\u7684\u5047\u8bbe\uff0c\u90a3\u4e48Nmap\u7684\u626b\u63cf\u5305\u5c31\u80fd\u987a\u5229\u901a\u8fc7\u3002<code>--data-length<\/code> \u9009\u9879\u5728\u8fd9\u91cc\u4e0e <code>-g<\/code> \u7ed3\u5408\u4f7f\u7528\uff0c\u53ef\u4ee5\u4f7f\u4f2a\u9020\u7684DNS\u67e5\u8be2\uff08UDP 53\u7aef\u53e3\uff09\u770b\u8d77\u6765\u66f4\u201c\u50cf\u201d\u4e00\u4e9b\uff0c\u56e0\u4e3a\u771f\u5b9e\u7684DNS\u67e5\u8be2\u5305\u4e5f\u6709\u4e00\u5b9a\u957f\u5ea6\u3002<\/p>\n\n\n\n<p><strong>5. <code>--data-length &lt;number&gt;<\/code>&nbsp;(\u53d1\u9001\u62a5\u6587\u65f6 \u9644\u52a0\u968f\u673a\u6570\u636e)<\/strong><br>\u6b64\u9009\u9879\u901a\u8fc7\u6539\u53d8\u626b\u63cf\u5305\u7684\u201c\u5f62\u72b6\u201d\uff0c\u4f7f\u5176\u66f4\u63a5\u8fd1\u67d0\u4e9b\u6b63\u5e38\u5e94\u7528\u6570\u636e\u6d41\uff0c\u4ece\u800c\u89c4\u907f\u57fa\u4e8e\u56fa\u5b9a\u5305\u957f\u7279\u5f81\u7684IDS\u89c4\u5219\u3002<br><strong>\u547d\u4ee4\u793a\u4f8b<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u5728TCP SYN\u626b\u63cf\u7684\u6bcf\u4e2a\u63a2\u9488\u5305\u540e\u9644\u52a0100\u5b57\u8282\u7684\u968f\u673a\u6570\u636e\n   nmap -sS --data-length 100 &lt;\u76ee\u6807IP&gt;<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u89e3\u91ca<\/strong>\uff1a\u4e00\u4e9b\u7b80\u5355\u7684\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf\u53ef\u80fd\u6709\u4e00\u6761\u89c4\u5219\uff1a\u201c\u5982\u679c\u4e00\u4e2aIP\u5728\u77ed\u65f6\u95f4\u5185\u53d1\u9001\u4e86\u5927\u91cf\u4ec5\u6709TCP\u5934\u90e8\uff0840\u5b57\u8282\uff09\u7684SYN\u5305\uff0c\u5219\u89c6\u4e3a\u7aef\u53e3\u626b\u63cf\u201d\u3002\u901a\u8fc7\u9644\u52a0\u968f\u673a\u6570\u636e\uff0c\u5305\u7684\u957f\u5ea6\u53d8\u6210\u4e86140\u5b57\u8282\uff0c\u53ef\u80fd\u5c31\u4e0d\u518d\u5339\u914d\u90a3\u6761\u89c4\u5219\u3002\u8fd9\u589e\u52a0\u4e86\u626b\u63cf\u6d41\u91cf\u4e0e\u6b63\u5e38HTTP\u8bf7\u6c42\uff08\u643a\u5e26User-Agent\u7b49\u5934\u90e8\uff09\u7b49\u4e1a\u52a1\u7684\u76f8\u4f3c\u6027\u3002<\/p>\n\n\n\n<p><strong>6. <code>--ttl &lt;value&gt;<\/code>&nbsp;(\u8bbe\u7f6eIP time-to-live\u57df)<\/strong><br>\u4fee\u6539IP\u5305\u7684\u751f\u5b58\u65f6\u95f4\uff0c\u53ef\u4ee5\u7528\u4e8e\u6a21\u4eff\u6765\u81ea\u4e0d\u540c\u7f51\u7edc\u8ddd\u79bb\u7684\u4e3b\u673a\uff0c\u6216\u6d4b\u8bd5\u7f51\u7edc\u8def\u5f84\u3002<br><strong>\u547d\u4ee4\u793a\u4f8b<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u5c06\u626b\u63cf\u5305\u7684TTL\u8bbe\u7f6e\u4e3a1\uff0c\u8fd9\u4e9b\u5305\u5728\u79bb\u5f00\u7b2c\u4e00\u8df3\u8def\u7531\u5668\u540e\u5c31\u4f1a\u88ab\u4e22\u5f03\u3002\n   # \u8fd9\u53ef\u7528\u4e8e\u63a2\u6d4b\u672c\u5730\u7f51\u5173\uff0c\u6216\u8005\u4f7f\u8fdc\u7a0bIDS\u770b\u5230\u7684TTL\u503c\u5f02\u5e38\u3002\n   nmap --ttl 1 &lt;\u76ee\u6807IP&gt;<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u89e3\u91ca<\/strong>\uff1aTTL\u503c\u6bcf\u7ecf\u8fc7\u4e00\u4e2a\u8def\u7531\u5668\u51cf1\u3002\u901a\u8fc7\u8bbe\u7f6e\u4e00\u4e2a\u8f83\u5c0f\u7684TTL\uff0c\u53ef\u4ee5\u8ba9\u626b\u63cf\u5305\u5728\u5230\u8fbe\u76ee\u6807\u524d\u5c31\u8fc7\u671f\uff0c\u8fd9\u5728\u67d0\u4e9b\u7279\u5b9a\u6d4b\u8bd5\u4e2d\u6709\u7528\u3002\u53cd\u4e4b\uff0c\u8bbe\u7f6e\u4e00\u4e2a\u8f83\u5927\u7684\u3001\u4e0d\u5e38\u89c1\u7684TTL\u503c\uff08\u5982200\uff09\uff0c\u6709\u65f6\u4e5f\u80fd\u4f5c\u4e3a\u4e00\u4e2a\u5fae\u5c0f\u7684\u6df7\u6dc6\u56e0\u7d20\uff0c\u56e0\u4e3a\u64cd\u4f5c\u7cfb\u7edf\u7684\u9ed8\u8ba4\u521d\u59cbTTL\u901a\u5e38\u662f64\u3001128\u6216255\u3002<\/p>\n\n\n\n<p><strong>7. \u968f\u673a\u5316\u4e3b\u673a\u987a\u5e8f (<code>--randomize-hosts<\/code>)<\/strong><br>\u907f\u514d\u6309IP\u5730\u5740\u987a\u5e8f\uff08\u5982 192.168.1.1, 192.168.1.2, 192.168.1.3\u2026\uff09\u8fdb\u884c\u626b\u63cf\uff0c\u8fd9\u79cd\u6a21\u5f0f\u6781\u6613\u88ab\u8bc6\u522b\u4e3a\u81ea\u52a8\u5316\u626b\u63cf\u3002<br><strong>\u547d\u4ee4\u793a\u4f8b<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u5bf9\u4e00\u4e2aC\u7c7b\u5b50\u7f51\uff08254\u4e2a\u4e3b\u673a\uff09\u8fdb\u884c\u968f\u673a\u987a\u5e8f\u7684ping\u626b\u63cf\u548cSYN\u626b\u63cf\n   nmap -sn  --randomize-hosts 192.168.1.0\/24<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u89e3\u91ca<\/strong>\uff1a\u8fd9\u662f\u4e00\u4e2a\u975e\u5e38\u5b9e\u7528\u4e14\u4f4e\u6210\u672c\u7684\u89c4\u907f\u6280\u5de7\u3002\u5b83\u5c06\u7ebf\u6027\u7684\u3001\u53ef\u9884\u6d4b\u7684\u626b\u63cf\u6a21\u5f0f\uff0c\u53d8\u6210\u4e86\u4e00\u4e2a\u770b\u4f3c\u968f\u673a\u7684\u3001\u5bf9\u591a\u4e2a\u4e3b\u673a\u7684\u201c\u70b9\u72b6\u201d\u8bbf\u95ee\u6a21\u5f0f\uff0c\u66f4\u7c7b\u4f3c\u4e8e\u6b63\u5e38\u7528\u6237\u6216\u670d\u52a1\u5668\u7684\u884c\u4e3a\uff0c\u53ef\u4ee5\u6709\u6548\u7ed5\u8fc7\u90a3\u4e9b\u57fa\u4e8e\u201c\u5bf9\u8fde\u7eedIP\u5730\u5740\u8fdb\u884c\u5feb\u901f\u7aef\u53e3\u63a2\u6d4b\u201d\u8fd9\u4e00\u6a21\u5f0f\u7684\u7b80\u5355\u68c0\u6d4b\u7b97\u6cd5\u3002<\/p>\n\n\n\n<p><strong>8. MAC\u5730\u5740\u6b3a\u9a97 (<code>--spoof-mac<\/code>)<\/strong><br>\u5728\u5c40\u57df\u7f51\uff08\u4e8c\u5c42\uff09\u5c42\u9762\u4f2a\u88c5\u8eab\u4efd\uff0c\u4e3b\u8981\u7528\u4e8e\u7ed5\u8fc7\u57fa\u4e8eMAC\u5730\u5740\u7684\u8bbf\u95ee\u63a7\u5236\u5217\u8868\uff08ACL\uff09\u6216\u907f\u514d\u5728\u4ea4\u6362\u673a\u7684CAM\u8868\u65e5\u5fd7\u4e2d\u7559\u4e0b\u771f\u5b9eMAC\u8bb0\u5f55\u3002<br><strong>\u547d\u4ee4\u793a\u4f8b<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u4f2a\u88c5\u6210\u4e00\u53f0Cisco\u8bbe\u5907\u7684MAC\u5730\u5740\uff08\u524d\u7f00\u4e3a00:40:96\uff09\n   nmap --spoof-mac Cisco &lt;\u76ee\u6807IP&gt;\n\n   # \u4f7f\u7528\u4e00\u4e2a\u5b8c\u5168\u968f\u673a\u7684MAC\u5730\u5740\n   nmap --spoof-mac 0 &lt;\u76ee\u6807IP&gt;\n\n   # \u4f7f\u7528\u6307\u5b9a\u7684MAC\u5730\u5740\n   nmap --spoof-mac 00:1A:2B:3C:4D:5E &lt;\u76ee\u6807IP&gt;<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u89e3\u91ca<\/strong>\uff1a\u6b64\u9009\u9879\u4ec5\u5728\u540c\u7f51\u6bb5\u626b\u63cf\u65f6\u6709\u610f\u4e49\u3002\u5b83\u8feb\u4f7fNmap\u5728\u94fe\u8def\u5c42\u6784\u9020\u4ee5\u592a\u7f51\u5e27\uff0c\u8fd9\u9690\u542b\u4e86 <code>--send-eth<\/code> \u9009\u9879\u3002\u5982\u679c\u76ee\u6807\u7f51\u7edc\u4f7f\u7528\u4e86\u201cIP+MAC\u7ed1\u5b9a\u201d\u6216\u57fa\u4e8eMAC\u7684\u7aef\u53e3\u5b89\u5168\u7b56\u7565\uff0c\u6b3a\u9a97\u4e00\u4e2a\u5df2\u6388\u6743\u8bbe\u5907\u7684MAC\u5730\u5740\u53ef\u80fd\u5141\u8bb8\u626b\u63cf\u901a\u8fc7\u3002\u4f46\u8bf7\u6ce8\u610f\uff0c\u8fd9\u53ef\u80fd\u5bfc\u81f4\u77ed\u6682\u7684\u5730\u5740\u51b2\u7a81\uff0c\u4e14<strong>\u5728\u540c\u4e00\u5e7f\u64ad\u57df\u5185\uff0c\u4e24\u4e2a\u76f8\u540cMAC\u5730\u5740\u7684\u8bbe\u5907\u901a\u4fe1\u4f1a\u51fa\u95ee\u9898<\/strong>\uff0c\u56e0\u6b64\u9700\u8c28\u614e\u4f7f\u7528\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u7efc\u5408\u5b9e\u6218\u793a\u4f8b<\/h3>\n\n\n\n<p>\u4e00\u4e2a\u8c28\u614e\u7684\u653b\u51fb\u8005\u6216\u6e17\u900f\u6d4b\u8bd5\u5458\u53ef\u80fd\u4f1a\u7ec4\u5408\u4f7f\u7528\u591a\u79cd\u6280\u672f\uff0c\u53d1\u8d77\u4e00\u6b21\u9690\u853d\u6027\u8f83\u5f3a\u7684\u626b\u63cf\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u7ec4\u5408\u4f7f\u7528\uff1a\u8bf1\u9975\u626b\u63cf\u3001\u6e90\u7aef\u53e3\u6b3a\u9a97\u3001\u62a5\u6587\u5206\u6bb5\u3001\u968f\u673a\u5316\u4e3b\u673a\u3001\u9644\u52a0\u968f\u673a\u6570\u636e\nnmap -sS -D 8.8.8.8,1.1.1.1,ME -g 53 -f --randomize-hosts --data-length 64 --max-rate 50 -oN stealth_scan.log &lt;\u76ee\u6807\u7f51\u6bb5&gt;<\/code><\/pre>\n\n\n\n<p><strong>\u8fd9\u6761\u547d\u4ee4\u7684\u610f\u56fe\u662f<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>-sS<\/code>: \u4f7f\u7528\u534a\u5f00SYN\u626b\u63cf\u3002<\/li>\n\n\n\n<li><code>-D ...<\/code>: \u6df7\u5165\u4e24\u4e2a\u77e5\u540d\u516c\u5171DNS\u670d\u52a1\u5668\u4f5c\u4e3a\u8bf1\u9975\uff0c\u771f\u5b9eIP\u968f\u673a\u63d2\u5165\u3002<\/li>\n\n\n\n<li><code>-g 53<\/code>: \u6240\u6709SYN\u5305\u4f2a\u88c5\u6210\u6765\u81eaDNS\u67e5\u8be2\u7684\u56de\u590d\u6d41\u91cf\uff08\u6e90\u7aef\u53e353\uff09\u3002<\/li>\n\n\n\n<li><code>-f<\/code>: \u5bf9\u62a5\u6587\u8fdb\u884c\u5206\u6bb5\uff0c\u589e\u52a0\u5206\u6790\u96be\u5ea6\u3002<\/li>\n\n\n\n<li><code>--randomize-hosts<\/code>: \u4e0d\u6253\u8349\u60ca\u86c7\uff0c\u4e0d\u6309\u987a\u5e8f\u626b\u63cf\u3002<\/li>\n\n\n\n<li><code>--data-length 64<\/code>: \u8ba9\u6bcf\u4e2a\u5305\u770b\u8d77\u6765\u90fd\u50cf\u643a\u5e26\u4e86\u4e00\u70b9\u6570\u636e\u3002<\/li>\n\n\n\n<li><code>--max-rate 50<\/code>: \u4e25\u683c\u63a7\u5236\u53d1\u5305\u901f\u7387\uff0c\u907f\u514d\u89e6\u53d1\u57fa\u4e8e\u6d41\u91cf\u7684\u9608\u503c\u8b66\u62a5\u3002<\/li>\n\n\n\n<li><code>-oN ...<\/code>: \u5c06\u7ed3\u679c\u4fdd\u5b58\u5230\u6587\u4ef6\u3002<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap23-1024x461.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"461\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap23-1024x461.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1521\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><figcaption class=\"wp-element-caption\">stealth_scan.log<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap24-1024x425.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"425\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap24-1024x425.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1523\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u8f93\u51fa\u529f\u80fd\u7684\u8865\u5145\u4e0e\u793a\u4f8b<\/h3>\n\n\n\n<p>Nmap\u7684\u8f93\u51fa\u9009\u9879\u4e0d\u4ec5\u4ec5\u662f\u4fdd\u5b58\u626b\u63cf\u7ed3\u679c\u7684\u7b80\u5355\u529f\u80fd\uff0c\u5b83\u4eec\u6784\u6210\u4e86\u4e13\u4e1a\u6e17\u900f\u6d4b\u8bd5\u548c\u7f51\u7edc\u5ba1\u8ba1\u4e2d<strong>\u6587\u6863\u5316\u3001\u53ef\u8ffd\u6eaf\u3001\u53ef\u5206\u6790<\/strong>\u5de5\u4f5c\u6d41\u7a0b\u7684\u6838\u5fc3\u3002\u5408\u7406\u4f7f\u7528\u8fd9\u4e9b\u9009\u9879\u53ef\u4ee5\u6781\u5927\u63d0\u9ad8\u5de5\u4f5c\u6548\u7387\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u8f93\u51fa\u683c\u5f0f<\/h4>\n\n\n\n<p><strong><code>-oN &lt;filespec&gt;<\/code>&nbsp;(\u6807\u51c6\u8f93\u51fa)<\/strong><br>\u8fd9\u662f\u6700\u5e38\u7528\u7684\u53ef\u8bfb\u683c\u5f0f\uff0c\u9002\u5408\u76f4\u63a5\u67e5\u770b\u548c\u5feb\u901f\u5206\u6790\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u4fdd\u5b58\u8be6\u7ec6\u626b\u63cf\u7ed3\u679c\u5230\u6587\u4ef6\uff0c\u540c\u65f6\u5c4f\u5e55\u4e0a\u4ecd\u4f1a\u663e\u793a\nnmap -sS -p 1-1000 -oN basic_scan.txt 192.168.48.1\n\n# \u53ea\u4fdd\u5b58\u7ed3\u679c\u5230\u6587\u4ef6\uff0c\u4e0d\u663e\u793a\u5728\u5c4f\u5e55\u4e0a\uff08\u91cd\u5b9a\u5411\u6807\u51c6\u8f93\u51fa\uff09\nnmap -sS -p 1-1000 -oN silent_scan.txt 192.168.1.1 &gt; \/dev\/null<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u6280\u5de7<\/strong>\uff1a\u6807\u51c6\u8f93\u51fa\u6587\u4ef6\u975e\u5e38\u9002\u5408\u7528<code>grep<\/code>\u5feb\u901f\u67e5\u627e\u4fe1\u606f\u3002\u4f8b\u5982\uff0c\u67e5\u627e\u6240\u6709\u5f00\u653e\u4e86SSH\u670d\u52a1\u7684\u4e3b\u673a\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>grep -E \"22\/open.*ssh\" scan_results.nmap<\/code><\/pre>\n\n\n\n<p><strong>2.<code>-oX &lt;filespec&gt;<\/code>&nbsp;(XML\u8f93\u51fa)<\/strong><br>\u8fd9\u662f\u6700\u5f3a\u5927\u7684\u7ed3\u6784\u5316\u683c\u5f0f\uff0c\u9002\u5408\u81ea\u52a8\u5316\u5904\u7406\u548c\u751f\u6210\u62a5\u544a\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u751f\u6210XML\u683c\u5f0f\u7684\u8f93\u51fa\nnmap -sV -O -oX detailed_scan.xml 192.168.1.0\/24\n\n# \u4f7f\u7528XSLT\u6837\u5f0f\u8868\u8f6c\u6362\u4e3aHTML\u62a5\u544a\nxsltproc -o report.html \/usr\/share\/nmap\/nmap.xsl detailed_scan.xml\n\n# \u5982\u679cnmap.xsl\u4e0d\u5728\u9ed8\u8ba4\u8def\u5f84\uff0c\u53ef\u4ee5\u8fd9\u6837\u6307\u5b9a\nnmap -sV -oX scan.xml --stylesheet https:\/\/nmap.org\/data\/nmap.xsl target<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u89e3\u91ca<\/strong>\uff1aXML\u683c\u5f0f\u5305\u542b\u4e86\u6700\u5b8c\u6574\u7684\u4fe1\u606f\uff0c\u5305\u62ec\u670d\u52a1\u7248\u672c\u3001\u64cd\u4f5c\u7cfb\u7edf\u6307\u7eb9\u3001\u811a\u672c\u8f93\u51fa\u7b49\u6240\u6709\u7ec6\u8282\u3002\u5f88\u591a\u5b89\u5168\u5de5\u5177\uff08\u5982Metasploit\u3001OpenVAS\uff09\u90fd\u53ef\u4ee5\u76f4\u63a5\u5bfc\u5165Nmap\u7684XML\u683c\u5f0f\u8fdb\u884c\u540e\u7eed\u5904\u7406\u3002\u51e0\u4e4e\u6240\u6709\u4e3b\u6d41\u7f16\u7a0b\u8bed\u8a00\uff08C\/C++\u3001Python\u3001Java\u3001Perl\uff09\u90fd\u6709\u514d\u8d39\u7684 \u201cXML \u89e3\u6790\u5668\u201d\uff08\u73b0\u6210\u7684\u5de5\u5177\u5e93\uff09\uff0c\u80fd\u8f7b\u677e\u8bfb\u53d6\u3001\u63d0\u53d6\u3001\u5206\u6790 XML \u91cc\u7684\u4fe1\u606f\u3002\u6bd4\u5982\u4f60\u60f3\u5199\u4e2a Python \u811a\u672c\uff0c\u81ea\u52a8\u4ece\u626b\u63cf\u7ed3\u679c\u91cc\u6311\u51fa\u6240\u6709\u5f00\u653e\u7684 80\/443 \u7aef\u53e3\uff0c\u89e3\u6790 XML \u6bd4\u89e3\u6790\u6742\u4e71\u7684\u7eaf\u6587\u672c\u5bb9\u6613\u5f97\u591a\uff1b\u8fd8\u53ef\u4ee5\u4f7f\u7528Python\u7684<code>xml.etree.ElementTree<\/code>\u5e93\u7f16\u5199\u81ea\u5b9a\u4e49\u89e3\u6790\u811a\u672c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>import xml.etree.ElementTree as ET\ntree = ET.parse('scan.xml')\nroot = tree.getroot()\nfor host in root.findall('host'):\n    ip = host.find('address&#91;@addrtype=\"ipv4\"]').get('addr')\n    print(f\"Host: {ip}\")<\/code><\/pre>\n\n\n\n<p><strong>Grepable\u8f93\u51fa (<code>-oG<\/code>)<\/strong><br>\u867d\u7136\u5b98\u65b9\u5df2\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u4f46\u5728\u67d0\u4e9b\u5feb\u901f\u5206\u6790\u573a\u666f\u4e2d\u4ecd\u6709\u5176\u4ef7\u503c\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u751f\u6210grepable\u683c\u5f0f\nnmap -F -oG quick_scan.gnmap 192.168.1.0\/24\n\n# \u5feb\u901f\u63d0\u53d6\u6240\u6709\u5f00\u653e80\u7aef\u53e3\u7684\u4e3b\u673a\ngrep \"80\/open\" quick_scan.gnmap | cut -d' ' -f2\n\n# \u63d0\u53d6\u8fd0\u884c\u7279\u5b9a\u670d\u52a1\u7684\u4e3b\u673a\ngrep -i \"http\" quick_scan.gnmap | awk '{print $2}'<\/code><\/pre>\n\n\n\n<p><strong>\u91cd\u8981\u8bf4\u660e<\/strong>\uff1a\u8fd9\u79cd\u683c\u5f0f\u5728\u5904\u7406\u590d\u6742\u626b\u63cf\u7ed3\u679c\uff08\u5982\u591a\u4e2a\u7aef\u53e3\u3001\u591a\u4e2a\u4e3b\u673a\uff09\u65f6\u5bb9\u6613\u51fa\u9519\uff0c\u4e14\u4e0d\u652f\u6301Nmap\u7684\u6240\u6709\u529f\u80fd\uff08\u5982NSE\u811a\u672c\u8f93\u51fa\uff09\u3002\u5bf9\u4e8e\u91cd\u8981\u9879\u76ee\uff0c<strong>\u5f3a\u70c8\u5efa\u8bae\u4f7f\u7528XML\u683c\u5f0f<\/strong>\u3002<\/p>\n\n\n\n<p><strong>\u6240\u6709\u683c\u5f0f (<code>-oA<\/code>)<\/strong><br>\u8fd9\u662f\u6700\u65b9\u4fbf\u7684\u4e00\u952e\u8f93\u51fa\u9009\u9879\uff0c\u7279\u522b\u9002\u5408\u9700\u8981\u591a\u79cd\u683c\u5f0f\u7684\u573a\u666f\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u4e00\u6b21\u6027\u751f\u6210\u4e09\u79cd\u683c\u5f0f\u7684\u6587\u4ef6\uff1ascan_base.nmap, scan_base.xml, scan_base.gnmap\nnmap -sS -sV -oA scan_base 192.168.1.0\/24\n\n# \u6307\u5b9a\u8f93\u51fa\u76ee\u5f55\nmkdir -p scans\/2023-10-01\nnmap -sS -oA scans\/2023-10-01\/internal_scan 192.168.1.0\/24<\/code><\/pre>\n\n\n\n<p><strong>\u6700\u4f73\u5b9e\u8df5<\/strong>\uff1a\u5728\u6e17\u900f\u6d4b\u8bd5\u4e2d\uff0c\u59cb\u7ec8\u4f7f\u7528<code>-oA<\/code>\u4fdd\u5b58\u6240\u6709\u683c\u5f0f\u7684\u7ed3\u679c\uff0c\u8fd9\u6837\u65e2\u6709\u4eba\u7c7b\u53ef\u8bfb\u7684\u7248\u672c\uff0c\u4e5f\u6709\u673a\u5668\u53ef\u5904\u7406\u7684\u7248\u672c\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u8f93\u51fa\u63a7\u5236\u9009\u9879\u8be6\u89e3<\/h4>\n\n\n\n<p><strong>\u8be6\u7ec6\u8f93\u51fa (<code>-v<\/code> \/ <code>-vv<\/code>)<\/strong><br>\u63a7\u5236\u8f93\u51fa\u8be6\u7ec6\u7a0b\u5ea6\uff0c\u5bf9\u4e8e\u76d1\u63a7\u626b\u63cf\u8fdb\u5ea6\u548c\u4e86\u89e3Nmap\u5185\u90e8\u5de5\u4f5c\u975e\u5e38\u6709\u5e2e\u52a9\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u4e00\u7ea7\u8be6\u7ec6\uff1a\u663e\u793a\u53d1\u73b0\u7684\u5f00\u653e\u7aef\u53e3\u548c\u4f30\u8ba1\u5b8c\u6210\u65f6\u95f4\nnmap -v 192.168.48.1\n\n# \u4e8c\u7ea7\u8be6\u7ec6\uff1a\u663e\u793a\u66f4\u591a\u7ec6\u8282\uff0c\u5305\u62ec\u53d1\u9001\u7684\u6bcf\u4e2a\u6570\u636e\u5305\u7c7b\u578b\nnmap -vv -p 80 192.168.1.0\/24\n\n# \u7ed3\u5408\u8be6\u7ec6\u8f93\u51fa\u548c\u6587\u4ef6\u4fdd\u5b58\nnmap -v -v -oN verbose_scan.txt 192.168.1.0\/24<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap25-1024x621.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"621\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap25-1024x621.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1526\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><figcaption class=\"wp-element-caption\">nmap -v 192.168.48.1<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/\u5c4f\u5e55\u622a\u56fe-2026-01-31-104505-1024x548.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"548\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/\u5c4f\u5e55\u622a\u56fe-2026-01-31-104505-1024x548.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1527\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><figcaption class=\"wp-element-caption\">nmap -vv -p 80 192.168.1.0\/24<\/figcaption><\/figure>\n\n\n\n<p><strong>\u5b9e\u9645\u5e94\u7528<\/strong>\uff1a\u5728\u957f\u65f6\u95f4\u626b\u63cf\u4e2d\uff0c\u4f7f\u7528<code>-v<\/code>\u53ef\u4ee5\u5b9e\u65f6\u4e86\u89e3\u8fdb\u5ea6\uff1b\u5728\u8c03\u8bd5\u626b\u63cf\u95ee\u9898\u65f6\uff0c<code>-vv<\/code>\u53ef\u4ee5\u63d0\u4f9b\u66f4\u591a\u7ebf\u7d22\u3002<\/p>\n\n\n\n<p><strong>\u8c03\u8bd5\u8f93\u51fa (<code>-d<\/code> \/ <code>-d9<\/code>)<\/strong><br>\u63d0\u4f9bNmap\u5185\u90e8\u5de5\u4f5c\u7684\u8be6\u7ec6\u4fe1\u606f\uff0c\u4e3b\u8981\u7528\u4e8e\u6545\u969c\u6392\u9664\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u4e2d\u7ea7\u8c03\u8bd5\uff08\u7ea7\u522b3\uff09\nnmap -d3 192.168.1.1\n\n# \u6700\u9ad8\u7ea7\u522b\u8c03\u8bd5\uff08\u4f1a\u751f\u6210\u5927\u91cf\u8f93\u51fa\uff09\nnmap -d9 -p 22 192.168.1.1 2&gt;&amp;1 | head -100\n\n# \u5c06\u8c03\u8bd5\u8f93\u51fa\u4fdd\u5b58\u5230\u6587\u4ef6\u4ee5\u4fbf\u5206\u6790\nnmap -d9 192.168.1.1 2&gt; debug_log.txt<\/code><\/pre>\n\n\n\n<p><strong>\u6ce8\u610f<\/strong>\uff1a\u8c03\u8bd5\u8f93\u51fa\u53d1\u9001\u5230\u6807\u51c6\u9519\u8bef(stderr)\uff0c\u9700\u8981\u4f7f\u7528<code>2&gt;<\/code>\u91cd\u5b9a\u5411\u3002\u7ea7\u522b\u8d8a\u9ad8\u8f93\u51fa\u8d8a\u8be6\u7ec6\uff0c\u4f46\u53ef\u80fd\u5305\u542b\u6570\u5343\u884c\u6280\u672f\u7ec6\u8282\u3002<\/p>\n\n\n\n<p><strong>\u5305\u8ffd\u8e2a (<code>--packet-trace<\/code>)<\/strong><br>\u663e\u793aNmap\u53d1\u9001\u548c\u63a5\u6536\u7684\u6bcf\u4e2a\u6570\u636e\u5305\u7684\u6458\u8981\uff0c\u662f\u7406\u89e3Nmap\u5de5\u4f5c\u539f\u7406\u7684\u6700\u4f73\u65b9\u5f0f\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u8ffd\u8e2a\u9488\u5bf9\u5c11\u91cf\u7aef\u53e3\u7684\u626b\u63cf\u6570\u636e\u5305\nnmap --packet-trace -p 22,80,443 192.168.1.1\n\n# \u7ed3\u5408\u7aef\u53e3\u626b\u63cf\u548c\u7248\u672c\u68c0\u6d4b\u7684\u5305\u8ffd\u8e2a\nnmap -sS -sV --packet-trace -p 80 192.168.1.1<\/code><\/pre>\n\n\n\n<p><strong>\u5b66\u4e60\u4ef7\u503c<\/strong>\uff1a\u901a\u8fc7\u89c2\u5bdf\u5305\u8ffd\u8e2a\u8f93\u51fa\uff0c\u60a8\u53ef\u4ee5\u4e86\u89e3\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Nmap\u5982\u4f55\u53d1\u9001SYN\u5305\u8fdb\u884c\u7aef\u53e3\u626b\u63cf<\/li>\n\n\n\n<li>\u5982\u4f55\u6839\u636e\u54cd\u5e94\u5224\u65ad\u7aef\u53e3\u72b6\u6001<\/li>\n\n\n\n<li>\u7248\u672c\u68c0\u6d4b\u9636\u6bb5\u53d1\u9001\u4e86\u54ea\u4e9b\u63a2\u6d4b\u5305<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u9ad8\u7ea7\u8f93\u51fa\u7ba1\u7406\u6280\u5de7<\/h4>\n\n\n\n<p><strong>\u6062\u590d\u4e2d\u65ad\u7684\u626b\u63cf (<code>--resume<\/code>)<\/strong><br>\u8fd9\u662f\u5904\u7406\u957f\u65f6\u95f4\u626b\u63cf\u7684\u5173\u952e\u529f\u80fd\uff0c\u786e\u4fdd\u610f\u5916\u4e2d\u65ad\u540e\u53ef\u4ee5\u7ee7\u7eed\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u5f00\u59cb\u4e00\u4e2a\u5927\u578b\u626b\u63cf\u5e76\u4fdd\u5b58\u6807\u51c6\u8f93\u51fa\nnmap -p- -oN full_port_scan.txt 192.168.1.1\n\n# \u5982\u679c\u626b\u63cf\u4e2d\u65ad\uff08\u5982\u7f51\u7edc\u95ee\u9898\u3001\u7cfb\u7edf\u91cd\u542f\uff09\uff0c\u53ef\u4ee5\u8fd9\u6837\u6062\u590d\nnmap --resume full_port_scan.txt\n\n# \u6062\u590d\u626b\u63cf\u65f6\u4e5f\u53ef\u4ee5\u66f4\u6539\u8f93\u51fa\u6587\u4ef6\u540d\nnmap --resume full_port_scan.txt -oN resumed_scan.txt<\/code><\/pre>\n\n\n\n<p><strong>\u91cd\u8981\u9650\u5236<\/strong>\uff1a\u53ea\u80fd\u6062\u590d\u4f7f\u7528<code>-oN<\/code>\u6216<code>-oG<\/code>\u4fdd\u5b58\u7684\u626b\u63cf\u3002XML\u683c\u5f0f\u4e0d\u652f\u6301\u6062\u590d\u529f\u80fd\u3002\u6062\u590d\u65f6\u4f1a\u4ece\u4e0a\u6b21\u6210\u529f\u626b\u63cf\u7684\u6700\u540e\u4e00\u4e2a\u4e3b\u673a\u7ee7\u7eed\u3002<\/p>\n\n\n\n<p><strong>\u63a5\u53e3\u548c\u8def\u7531\u4fe1\u606f (<code>--iflist<\/code>)<\/strong><br>\u5728\u590d\u6742\u7f51\u7edc\u73af\u5883\u4e2d\uff0c\u4e86\u89e3Nmap\u5982\u4f55\u770b\u5230\u7f51\u7edc\u63a5\u53e3\u81f3\u5173\u91cd\u8981\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u663e\u793a\u6240\u6709\u7f51\u7edc\u63a5\u53e3\u548c\u8def\u7531\u8868\nnmap --iflist\n\n# \u7ed3\u5408\u63a5\u53e3\u9009\u62e9\u8fdb\u884c\u626b\u63cf\nnmap --iflist\n# \u6839\u636e\u8f93\u51fa\u9009\u62e9\u6b63\u786e\u7684\u63a5\u53e3\nnmap -e eth1 -oN scan.txt 192.168.2.0\/24<\/code><\/pre>\n\n\n\n<p><strong>\u5e94\u7528\u573a\u666f<\/strong>\uff1a\u5f53\u4e3b\u673a\u6709\u591a\u4e2a\u7f51\u7edc\u63a5\u53e3\uff08\u7269\u7406\u7f51\u5361\u3001VPN\u3001\u865a\u62df\u673a\u7f51\u7edc\uff09\u65f6\uff0c\u786e\u4fddNmap\u4f7f\u7528\u6b63\u786e\u7684\u63a5\u53e3\u53d1\u9001\u6570\u636e\u5305\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u5b9e\u6218\u7efc\u5408\u793a\u4f8b<\/h4>\n\n\n\n<p><strong>\u5b8c\u6574\u7684\u6e17\u900f\u6d4b\u8bd5\u626b\u63cf\u5de5\u4f5c\u6d41\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># 1. \u521d\u59cb\u53d1\u73b0\u626b\u63cf\uff0c\u4fdd\u5b58\u6240\u6709\u683c\u5f0f\nnmap -sn -oA phase1_discovery 10.0.0.0\/24\n\n# 2. \u4ece\u53d1\u73b0\u7ed3\u679c\u4e2d\u63d0\u53d6\u6d3b\u8dc3\u4e3b\u673a\ngrep \"Status: Up\" phase1_discovery.gnmap | cut -d' ' -f2 &gt; live_hosts.txt\n\n# 3. \u5bf9\u6d3b\u8dc3\u4e3b\u673a\u8fdb\u884c\u8be6\u7ec6\u626b\u63cf\nnmap -sS -sV -O -p- --min-rate 500 -oA phase2_full_scan -iL live_hosts.txt\n\n# 4. \u4f7f\u7528NSE\u811a\u672c\u8fdb\u884c\u6f0f\u6d1e\u68c0\u6d4b\nnmap -sV --script vuln -oA phase3_vuln_scan -iL live_hosts.txt\n\n# 5. \u5408\u5e76\u6240\u6709\u7ed3\u679c\u751f\u6210\u62a5\u544a\nxsltproc -o final_report.html phase2_full_scan.xml<\/code><\/pre>\n\n\n\n<p><strong>\u81ea\u52a8\u5316\u62a5\u544a\u751f\u6210\u811a\u672c\u793a\u4f8b\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#!\/bin\/bash\n# auto_nmap_scan.sh - \u81ea\u52a8\u5316\u626b\u63cf\u548c\u62a5\u544a\u751f\u6210\n\nTARGET=$1\nDATE=$(date +%Y%m%d_%H%M%S)\nOUTPUT_DIR=\"scans\/$DATE\"\n\nmkdir -p $OUTPUT_DIR\n\necho \"&#91;*] \u5f00\u59cb\u626b\u63cf $TARGET\"\nnmap -sS -sV -O -p- --min-rate 1000 -oA $OUTPUT_DIR\/scan $TARGET\n\necho \"&#91;*] \u751f\u6210HTML\u62a5\u544a\"\nxsltproc -o $OUTPUT_DIR\/report.html \/usr\/share\/nmap\/nmap.xsl $OUTPUT_DIR\/scan.xml\n\necho \"&#91;*] \u63d0\u53d6\u5173\u952e\u4fe1\u606f\"\necho \"=== \u5f00\u653e\u7aef\u53e3\u6c47\u603b ===\" &gt; $OUTPUT_DIR\/summary.txt\ngrep -E \"^&#91;0-9]+\/(tcp|udp)\" $OUTPUT_DIR\/scan.nmap &gt;&gt; $OUTPUT_DIR\/summary.txt\n\necho \"&#91;+] \u626b\u63cf\u5b8c\u6210\uff01\u7ed3\u679c\u4fdd\u5b58\u5728 $OUTPUT_DIR\/\"<\/code><\/pre>\n\n\n\n<p>\u6839\u636e\u60a8\u63d0\u4f9b\u7684\u6587\u672c\uff0c\u8fd9\u90e8\u5206\u5185\u5bb9\u6db5\u76d6\u4e86Nmap\u7684\u4e00\u4e9b\u5176\u4ed6\u91cd\u8981\u9009\u9879\uff0c\u5305\u62ecIPv6\u652f\u6301\u3001\u6fc0\u70c8\u626b\u63cf\u6a21\u5f0f\u3001\u6570\u636e\u6587\u4ef6\u4f4d\u7f6e\u3001\u6570\u636e\u53d1\u9001\u65b9\u5f0f\u3001\u6743\u9650\u63a7\u5236\u4ee5\u53ca\u57fa\u672c\u7684\u7248\u672c\u548c\u5e2e\u52a9\u4fe1\u606f\u3002\u4e0b\u9762\u6211\u5c06\u5bf9\u8fd9\u4e9b\u9009\u9879\u8fdb\u884c\u8be6\u7ec6\u7684\u8865\u5145\u8bf4\u660e\uff0c\u91cd\u70b9\u662f<strong>\u6dfb\u52a0\u5b9e\u9645\u5e94\u7528\u793a\u4f8b\u3001\u4f7f\u7528\u573a\u666f\u548c\u6ce8\u610f\u4e8b\u9879<\/strong>\uff0c\u4ee5\u5e2e\u52a9\u60a8\u66f4\u597d\u5730\u7406\u89e3\u548c\u5e94\u7528\u8fd9\u4e9b\u529f\u80fd\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u5176\u4ed6\u9009\u9879<\/h3>\n\n\n\n<p>\u8fd9\u4e9b\u9009\u9879\u867d\u7136\u4e0d\u50cf\u7aef\u53e3\u626b\u63cf\u6216\u811a\u672c\u5f15\u64ce\u90a3\u6837\u5e38\u7528\uff0c\u4f46\u5728\u7279\u5b9a\u7684\u7f51\u7edc\u73af\u5883\u548c\u626b\u63cf\u9700\u6c42\u4e0b\u5374\u975e\u5e38\u5173\u952e\u3002\u5408\u7406\u4f7f\u7528\u8fd9\u4e9b\u9009\u9879\u53ef\u4ee5\u89e3\u51b3\u8bb8\u591a\u5b9e\u9645\u626b\u63cf\u4e2d\u9047\u5230\u7684\u95ee\u9898\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. IPv6\u626b\u63cf (<code>-6<\/code>)<\/h4>\n\n\n\n<p>\u968f\u7740IPv6\u7684\u9010\u6e10\u666e\u53ca\uff0c\u5bf9IPv6\u7f51\u7edc\u7684\u626b\u63cf\u53d8\u5f97\u65e5\u76ca\u91cd\u8981\u3002Nmap\u5bf9IPv6\u7684\u652f\u6301\u867d\u7136\u6709\u9650\uff0c\u4f46\u8986\u76d6\u4e86\u6838\u5fc3\u529f\u80fd\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u793a\u4f8b\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u57fa\u672c\u7684IPv6\u4e3b\u673a\u53d1\u73b0\nnmap -6 -sn 2001:db8::1\n\n# IPv6\u7aef\u53e3\u626b\u63cf\nnmap -6 -sT 2001:db8::1\n\n# IPv6 SYN\u626b\u63cf\uff08\u9700\u8981root\u6743\u9650\uff09\nsudo nmap -6 -sS 2001:db8::1\n\n# \u5b8c\u6574\u7684IPv6\u626b\u63cf\uff0c\u5305\u62ec\u7248\u672c\u548c\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\nsudo nmap -6 -A 2001:db8::\/64<\/code><\/pre>\n\n\n\n<p><strong>\u8865\u5145\u8bf4\u660e\u4e0e\u6280\u5de7\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>IPv6\u5730\u5740\u8868\u793a<\/strong>\uff1aIPv6\u5730\u5740\u53ef\u4ee5\u7528\u591a\u79cd\u683c\u5f0f\u8868\u793a\uff0cNmap\u652f\u6301\u6240\u6709\u6807\u51c6\u683c\u5f0f\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u5b8c\u6574\u683c\u5f0f\n   nmap -6 2001:0db8:0000:0000:0000:0000:0000:0001\n\n   # \u538b\u7f29\u683c\u5f0f\uff08\u63a8\u8350\uff09\n   nmap -6 2001:db8::1\n\n   # \u6df7\u5408\u683c\u5f0f\uff08IPv4\u6620\u5c04\u7684IPv6\u5730\u5740\uff09\n   nmap -6 ::ffff:192.168.1.1<\/code><\/pre>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>\u626b\u63cf\u8303\u56f4<\/strong>\uff1aIPv6\u5730\u5740\u7a7a\u95f4\u6781\u5176\u5e9e\u5927\uff082^128\u4e2a\u5730\u5740\uff09\uff0c\u4e0d\u80fd\u50cfIPv4\u90a3\u6837\u626b\u63cf\u6574\u4e2a\u5b50\u7f51\u3002\u901a\u5e38\u9700\u8981\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u901a\u8fc7DNS\u53d1\u73b0\u76ee\u6807<\/li>\n\n\n\n<li>\u4f7f\u7528\u90bb\u5c45\u53d1\u73b0\u534f\u8bae(NDP)\u83b7\u53d6\u672c\u5730\u94fe\u8def\u5730\u5740<\/li>\n\n\n\n<li>\u626b\u63cf\u5df2\u77e5\u7684\u670d\u52a1\u5668\u5730\u5740<\/li>\n<\/ul>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>\u5b9e\u9645\u5e94\u7528\u573a\u666f<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u626b\u63cfIPv6 Web\u670d\u52a1\u5668\n   nmap -6 -p 80,443 -sV www.ipv6.google.com\n\n   # \u53d1\u73b0\u672c\u5730\u94fe\u8def\u5730\u5740\n   nmap -6 --script targets-ipv6-multicast-echo<\/code><\/pre>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li><strong>\u96a7\u9053\u914d\u7f6e<\/strong>\uff1a\u5982\u679c\u7f51\u7edc\u4e0d\u652f\u6301\u539f\u751fIPv6\uff0c\u53ef\u4ee5\u4f7f\u75286to4\u6216Teredo\u96a7\u9053\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u5728\u914d\u7f6e\u4e866to4\u96a7\u9053\u7684\u7cfb\u7edf\u4e0a\n   ip tunnel add tun6to4 mode sit remote any local 192.168.1.100\n   ip link set tun6to4 up\n   ip addr add 2002:c0a8:0164::1\/16 dev tun6to4\n   nmap -6 -e tun6to4 2002:c0a8:0164::2<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u6fc0\u70c8\u626b\u63cf\u6a21\u5f0f (<code>-A<\/code>)<\/h4>\n\n\n\n<p>\u8fd9\u662f\u4e00\u4e2a&#8221;\u4e00\u952e\u5f0f&#8221;\u9ad8\u7ea7\u626b\u63cf\u9009\u9879\uff0c\u96c6\u6210\u4e86\u591a\u4e2a\u5e38\u7528\u529f\u80fd\uff0c\u975e\u5e38\u9002\u5408\u5feb\u901f\u5168\u9762\u7684\u5b89\u5168\u8bc4\u4f30\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u793a\u4f8b\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u57fa\u672c\u6fc0\u70c8\u626b\u63cf\nnmap -A 192.168.1.1\n\n# \u7ed3\u5408\u65f6\u95f4\u548c\u8f93\u51fa\u9009\u9879\nnmap -A -T4 -v -oA full_scan 192.168.1.1\n\n# \u5bf9\u591a\u4e2a\u76ee\u6807\u4f7f\u7528\u6fc0\u70c8\u626b\u63cf\nnmap -A 192.168.1.1,2,3\n\n# \u4ece\u6587\u4ef6\u4e2d\u8bfb\u53d6\u76ee\u6807\u5217\u8868\nnmap -A -iL targets.txt<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap27-1024x629.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"629\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/01\/Nmap27-1024x629.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1528\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p><strong><code>-A<\/code>\u9009\u9879\u5b9e\u9645\u542f\u7528\u7684\u529f\u80fd\uff1a<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b (<code>-O<\/code>)<\/li>\n\n\n\n<li>\u7248\u672c\u68c0\u6d4b (<code>-sV<\/code>)<\/li>\n\n\n\n<li>\u811a\u672c\u626b\u63cf (<code>-sC<\/code>) &#8211; \u4f7f\u7528\u9ed8\u8ba4\u811a\u672c\u96c6<\/li>\n\n\n\n<li>\u8def\u7531\u8ffd\u8e2a (<code>--traceroute<\/code>) &#8211; \u5982\u679c\u53ef\u80fd\u7684\u8bdd<\/li>\n<\/ul>\n\n\n\n<p><strong>\u8865\u5145\u8bf4\u660e\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6027\u80fd\u5f71\u54cd<\/strong>\uff1a<code>-A<\/code>\u4f1a\u663e\u8457\u589e\u52a0\u626b\u63cf\u65f6\u95f4\uff0c\u56e0\u4e3a\u5b83\u6267\u884c\u4e86\u591a\u4e2a\u9636\u6bb5\u7684\u68c0\u6d4b\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u5bf9\u6bd4\u666e\u901a\u626b\u63cf\u548c\u6fc0\u70c8\u626b\u63cf\u7684\u65f6\u95f4\n   time nmap -sS 192.168.1.1\n   time nmap -A 192.168.1.1<\/code><\/pre>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>\u81ea\u5b9a\u4e49\u6fc0\u70c8\u626b\u63cf<\/strong>\uff1a\u5982\u679c\u9700\u8981\u66f4\u591a\u63a7\u5236\uff0c\u53ef\u4ee5\u624b\u52a8\u7ec4\u5408\u9009\u9879\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u76f8\u5f53\u4e8e -A \u4f46\u66f4\u53ef\u63a7\n   nmap -sS -sV -O --traceroute --script=default 192.168.1.1\n\n   # \u589e\u5f3a\u7248\u6fc0\u70c8\u626b\u63cf\uff0c\u5305\u542b\u66f4\u591a\u811a\u672c\n   nmap -A --script=vuln,auth,intrusive 192.168.1.1<\/code><\/pre>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><strong>\u5728\u6e17\u900f\u6d4b\u8bd5\u4e2d\u7684\u5e94\u7528<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u7b2c\u4e00\u9636\u6bb5\uff1a\u5feb\u901f\u53d1\u73b0\n   nmap -sn 10.0.0.0\/24 -oA discovery\n\n   # \u7b2c\u4e8c\u9636\u6bb5\uff1a\u5bf9\u53d1\u73b0\u7684\u4e3b\u673a\u8fdb\u884c\u6fc0\u70c8\u626b\u63cf\n   grep \"Status: Up\" discovery.gnmap | cut -d' ' -f2 &gt; live_hosts.txt\n   nmap -A -T4 -iL live_hosts.txt -oA detailed_scan<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">3. <code>--datadir &lt;directoryname&gt;<\/code>&nbsp;(\u8bf4\u660e\u7528\u6237Nmap\u6570\u636e\u6587\u4ef6\u4f4d\u7f6e)<\/h4>\n\n\n\n<p>Nmap\u4f7f\u7528\u591a\u4e2a\u6570\u636e\u6587\u4ef6\u6765\u652f\u6301\u5176\u529f\u80fd\uff0c\u81ea\u5b9a\u4e49\u8fd9\u4e9b\u6587\u4ef6\u53ef\u4ee5\u6269\u5c55Nmap\u7684\u80fd\u529b\u3002<\/p>\n\n\n\n<p><strong>\u6570\u636e\u6587\u4ef6\u8be6\u89e3\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5173\u952e\u6570\u636e\u6587\u4ef6<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>nmap-service-probes<\/code>\uff1a\u670d\u52a1\u7248\u672c\u68c0\u6d4b\u7684\u63a2\u9488<\/li>\n\n\n\n<li><code>nmap-services<\/code>\uff1a\u7aef\u53e3\u5230\u670d\u52a1\u7684\u6620\u5c04<\/li>\n\n\n\n<li><code>nmap-os-db<\/code>\uff1a\u64cd\u4f5c\u7cfb\u7edf\u6307\u7eb9\u6570\u636e\u5e93<\/li>\n\n\n\n<li><code>nmap-mac-prefixes<\/code>\uff1aMAC\u5730\u5740\u5382\u5546\u524d\u7f00<\/li>\n\n\n\n<li><code>nmap-rpc<\/code>\uff1aRPC\u7a0b\u5e8f\u53f7\u6620\u5c04<\/li>\n\n\n\n<li><code>nmap-protocols<\/code>\uff1aIP\u534f\u8bae\u53f7\u6620\u5c04<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u547d\u4ee4\u793a\u4f8b<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u4f7f\u7528\u81ea\u5b9a\u4e49\u6570\u636e\u76ee\u5f55\n   nmap --datadir \/path\/to\/my\/nmap-data\/ 192.168.1.1\n\n   # \u521b\u5efa\u81ea\u5b9a\u4e49\u670d\u52a1\u63a2\u9488\n   cp \/usr\/share\/nmap\/nmap-service-probes ~\/.nmap\/\n   vim ~\/.nmap\/nmap-service-probes  # \u6dfb\u52a0\u81ea\u5b9a\u4e49\u63a2\u9488\n   nmap --datadir ~\/.nmap\/ -sV 192.168.1.1<\/code><\/pre>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><strong>\u5b9e\u9645\u5e94\u7528\u573a\u666f<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u573a\u666f1\uff1a\u6dfb\u52a0\u81ea\u5b9a\u4e49\u670d\u52a1\u7684\u7248\u672c\u68c0\u6d4b\n   # \u5728nmap-service-probes\u4e2d\u6dfb\u52a0\uff1a\n   # Probe TCP MyApp q|GET \/version HTTP\/1.0\\r\\n\\r\\n|\n   # ports 8080\n   # match myapp m|^MyApp v(&#91;\\d.]+)| p\/$1\/\n\n   # \u573a\u666f2\uff1a\u81ea\u5b9a\u4e49\u64cd\u4f5c\u7cfb\u7edf\u6307\u7eb9\n   # \u5c06\u65b0\u7684\u6307\u7eb9\u6dfb\u52a0\u5230nmap-os-db\u6587\u4ef6\u4e2d\n\n   # \u573a\u666f3\uff1a\u4e3a\u5185\u90e8\u7f51\u7edc\u6dfb\u52a0\u81ea\u5b9a\u4e49\u7aef\u53e3\u670d\u52a1\u6620\u5c04\n   echo \"9999\/tcp  myinternal\" &gt;&gt; ~\/.nmap\/nmap-services<\/code><\/pre>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u6587\u4ef6\u641c\u7d22\u987a\u5e8f<\/strong><br>Nmap\u6309\u4ee5\u4e0b\u987a\u5e8f\u67e5\u627e\u6570\u636e\u6587\u4ef6\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   1. --datadir\u6307\u5b9a\u7684\u76ee\u5f55\n   2. NMAPDIR\u73af\u5883\u53d8\u91cf\u6307\u5b9a\u7684\u76ee\u5f55\n   3. ~\/.nmap\/\uff08\u7528\u6237\u5bb6\u76ee\u5f55\uff09\n   4. \u53ef\u6267\u884c\u6587\u4ef6\u6240\u5728\u76ee\u5f55\u7684..\/share\/nmap\/\n   5. \u7f16\u8bd1\u65f6\u6307\u5b9a\u7684\u6570\u636e\u76ee\u5f55\uff08\u901a\u5e38\u662f\/usr\/share\/nmap\uff09\n   6. \u5f53\u524d\u5de5\u4f5c\u76ee\u5f55<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u6570\u636e\u53d1\u9001\u9009\u9879 (<code>--send-eth<\/code>, <code>--send-ip<\/code>)<\/h4>\n\n\n\n<p>\u8fd9\u4e24\u4e2a\u9009\u9879\u63a7\u5236Nmap\u5728OSI\u6a21\u578b\u7684\u54ea\u4e00\u5c42\u53d1\u9001\u6570\u636e\u5305\uff0c\u5bf9\u4e8e\u8c03\u8bd5\u548c\u7279\u6b8a\u7f51\u7edc\u73af\u5883\u975e\u5e38\u6709\u7528\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u793a\u4f8b\u4e0e\u89e3\u91ca\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u5f3a\u5236\u4f7f\u7528\u4ee5\u592a\u7f51\u5e27\uff08\u6570\u636e\u94fe\u8def\u5c42\uff09\nsudo nmap --send-eth 192.168.1.1\n\n# \u5f3a\u5236\u4f7f\u7528\u539f\u59cbIP\u5305\uff08\u7f51\u7edc\u5c42\uff09\nsudo nmap --send-ip 192.168.1.1\n\n# \u67e5\u770b\u5b9e\u9645\u4f7f\u7528\u7684\u53d1\u9001\u65b9\u5f0f\uff08\u7ed3\u5408--packet-trace\uff09\nsudo nmap --send-eth --packet-trace -p 80 192.168.1.1\nsudo nmap --send-ip --packet-trace -p 80 192.168.1.1<\/code><\/pre>\n\n\n\n<p><strong>\u4f7f\u7528\u573a\u666f\u5bf9\u6bd4\uff1a<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u573a\u666f<\/th><th>\u63a8\u8350\u9009\u9879<\/th><th>\u539f\u56e0<\/th><\/tr><\/thead><tbody><tr><td>\u5e38\u89c4Linux\u626b\u63cf<\/td><td>\u9ed8\u8ba4\uff08&#8211;send-ip\uff09<\/td><td>\u66f4\u9ad8\u6548\uff0c\u4f7f\u7528\u539f\u59cb\u5957\u63a5\u5b57<\/td><\/tr><tr><td>Windows\u626b\u63cf<\/td><td>\u9ed8\u8ba4\uff08&#8211;send-eth\uff09<\/td><td>Windows\u9650\u5236\u539f\u59cb\u5957\u63a5\u5b57<\/td><\/tr><tr><td>\u865a\u62df\u5316\u73af\u5883<\/td><td>&#8211;send-eth<\/td><td>\u865a\u62df\u673a\u7f51\u7edc\u6808\u53ef\u80fd\u5f02\u5e38<\/td><\/tr><tr><td>VPN\u8fde\u63a5<\/td><td>&#8211;send-ip<\/td><td>VPN\u5de5\u4f5c\u5728IP\u5c42<\/td><\/tr><tr><td>\u8c03\u8bd5\u7f51\u7edc\u95ee\u9898<\/td><td>\u4e24\u8005\u90fd\u8bd5<\/td><td>\u786e\u5b9a\u95ee\u9898\u6240\u5728\u5c42<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>\u6280\u672f\u7ec6\u8282\uff1a<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>--send-eth<\/code>\uff1a\u4f7f\u7528PF_PACKET\u5957\u63a5\u5b57\u76f4\u63a5\u64cd\u4f5c\u4ee5\u592a\u7f51\u5e27<\/li>\n\n\n\n<li><code>--send-ip<\/code>\uff1a\u4f7f\u7528\u539f\u59cb\u5957\u63a5\u5b57(RAW_SOCKET)\u64cd\u4f5cIP\u5305<\/li>\n\n\n\n<li>\u5728Linux\u4e0a\uff0c\u975eroot\u7528\u6237\u53ef\u80fd\u9700\u8981\u7279\u6b8a\u6743\u9650\uff1a<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>  # \u7ed9nmap\u7a0b\u5e8f\u6dfb\u52a0CAP_NET_RAW\u80fd\u529b\n  sudo setcap cap_net_raw,cap_net_admin,cap_net_bind_service+eip \/usr\/bin\/nmap\n\n  # \u9a8c\u8bc1\u80fd\u529b\n  getcap \/usr\/bin\/nmap<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">5. \u7279\u6743\u6a21\u5f0f (<code>--privileged<\/code>)<\/h4>\n\n\n\n<p>\u8fd9\u4e2a\u9009\u9879\u5bf9\u4e8e\u5728\u975eroot\u4f46\u5177\u6709\u7279\u6b8a\u6743\u9650\u7684\u73af\u5883\u4e2d\u8fd0\u884cNmap\u975e\u5e38\u6709\u7528\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u793a\u4f8b\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u5047\u8bbe\u7528\u6237\u6709raw socket\u6743\u9650\u4f46\u975eroot\nnmap --privileged -sS 192.168.1.1\n\n# \u5728\u5bb9\u5668\u73af\u5883\u4e2d\u53ef\u80fd\u9700\u8981\u7684\u914d\u7f6e\ndocker run --cap-add=NET_RAW --cap-add=NET_ADMIN nmap --privileged -sS target<\/code><\/pre>\n\n\n\n<p><strong>\u5b9e\u9645\u5e94\u7528\u573a\u666f\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Docker\u5bb9\u5668<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # Dockerfile\u793a\u4f8b\n   FROM alpine:latest\n   RUN apk add --no-cache nmap\n   RUN addgroup -S nmapgroup &amp;&amp; adduser -S nmapuser -G nmapgroup\n   USER nmapuser\n   ENTRYPOINT &#91;\"nmap\", \"--privileged\"]<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u8fd0\u884c\u5bb9\u5668\n   docker run --cap-add=NET_RAW mynmap -sS 192.168.1.1<\/code><\/pre>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>Linux\u80fd\u529b(Capabilities)<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u67e5\u770b\u5f53\u524d\u8fdb\u7a0b\u7684\u80fd\u529b\n   cat \/proc\/$$\/status | grep Cap\n\n   # \u4e3a\u7279\u5b9a\u7528\u6237\u914d\u7f6e\u80fd\u529b\n   sudo setcap cap_net_raw+ep \/usr\/bin\/nmap<\/code><\/pre>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><strong>SELinux\/AppArmor\u73af\u5883<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u68c0\u67e5SELinux\u72b6\u6001\n   getenforce\n\n   # \u5982\u679cSELinux\u963b\u6b62\uff0c\u53ef\u4ee5\u521b\u5efa\u7b56\u7565\u6a21\u5757\n   audit2allow -a -M nmap_local\n   semodule -i nmap_local.pp<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">6. \u7248\u672c\u548c\u5e2e\u52a9\u4fe1\u606f (<code>-V<\/code>, <code>-h<\/code>)<\/h4>\n\n\n\n<p>\u867d\u7136\u7b80\u5355\uff0c\u4f46\u8fd9\u4e9b\u9009\u9879\u5728\u5b9e\u9645\u5de5\u4f5c\u4e2d\u975e\u5e38\u5b9e\u7528\u3002<\/p>\n\n\n\n<p><strong>\u547d\u4ee4\u793a\u4f8b\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u68c0\u67e5Nmap\u7248\u672c\nnmap -V\n\n# \u663e\u793a\u7b80\u77ed\u5e2e\u52a9\nnmap -h\n\n# \u7ed3\u5408\u5176\u4ed6\u547d\u4ee4\u4f7f\u7528\nnmap --version | grep \"Nmap version\"<\/code><\/pre>\n\n\n\n<p><strong>\u5b9e\u7528\u6280\u5de7\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u7248\u672c\u6bd4\u8f83<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u5728\u811a\u672c\u4e2d\u68c0\u67e5Nmap\u7248\u672c\n   REQUIRED_VERSION=\"7.80\"\n   CURRENT_VERSION=$(nmap -V | grep -oP 'Nmap \\K&#91;0-9]+\\.&#91;0-9]+')\n\n   if &#91;&#91; $(echo \"$CURRENT_VERSION &gt;= $REQUIRED_VERSION\" | bc) -eq 1 ]]; then\n       echo \"Nmap\u7248\u672c\u7b26\u5408\u8981\u6c42\"\n   else\n       echo \"\u9700\u8981\u5347\u7ea7Nmap\"\n   fi<\/code><\/pre>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>\u5e2e\u52a9\u4fe1\u606f\u8fc7\u6ee4<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   # \u67e5\u627e\u7279\u5b9a\u9009\u9879\u7684\u5e2e\u52a9\n   nmap -h | grep -i \"version\"\n   nmap -h | grep -A2 -B2 \"scan\"\n\n   # \u751f\u6210\u5b8c\u6574\u7684\u9009\u9879\u5217\u8868\n   nmap -h | grep -E \"^-\" | sort<\/code><\/pre>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><strong>\u81ea\u52a8\u5316\u811a\u672c\u4e2d\u7684\u4f7f\u7528<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>   #!\/bin\/bash\n   # \u68c0\u67e5\u5fc5\u8981\u7684\u5de5\u5177\n   if ! command -v nmap &amp;&gt; \/dev\/null; then\n       echo \"\u9519\u8bef\uff1a\u672a\u627e\u5230Nmap\"\n       exit 1\n   fi\n\n   # \u68c0\u67e5\u7248\u672c\u517c\u5bb9\u6027\n   NMAP_VERSION=$(nmap -V | head -1)\n   echo \"\u4f7f\u7528 $NMAP_VERSION\"\n\n   # \u663e\u793a\u57fa\u672c\u7528\u6cd5\n   if &#91;&#91; $1 == \"--help\" ]]; then\n       echo \"=== \u81ea\u5b9a\u4e49\u626b\u63cf\u811a\u672c ===\"\n       nmap -h | grep -A5 \"SCAN TECHNIQUES\"\n       exit 0\n   fi<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">7. \u7efc\u5408\u5e94\u7528\u793a\u4f8b<\/h4>\n\n\n\n<p><strong>\u5b8c\u6574\u7684\u7f51\u7edc\u8bc4\u4f30\u811a\u672c\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#!\/bin\/bash\n# comprehensive_network_scan.sh\n\nTARGET=$1\nSCAN_DATE=$(date +%Y%m%d)\nOUTPUT_DIR=\"scans\/${SCAN_DATE}\"\n\n# \u521b\u5efa\u8f93\u51fa\u76ee\u5f55\nmkdir -p $OUTPUT_DIR\n\n# \u68c0\u67e5IPv6\u652f\u6301\necho \"=== \u68c0\u67e5IPv6\u652f\u6301 ===\"\nif ping6 -c 1 $TARGET &amp;&gt; \/dev\/null; then\n    echo \"\u76ee\u6807\u652f\u6301IPv6\uff0c\u5c06\u8fdb\u884cIPv6\u626b\u63cf\"\n    IPV6_SCAN=\"yes\"\nelse\n    echo \"\u76ee\u6807\u4e0d\u652f\u6301IPv6\uff0c\u4ec5\u8fdb\u884cIPv4\u626b\u63cf\"\n    IPV6_SCAN=\"no\"\nfi\n\n# \u57fa\u672c\u626b\u63cf\necho \"=== \u6267\u884c\u57fa\u672c\u626b\u63cf ===\"\nnmap -sS -p- -T4 -oA ${OUTPUT_DIR}\/basic_scan $TARGET\n\n# \u6fc0\u70c8\u626b\u63cf\necho \"=== \u6267\u884c\u6fc0\u70c8\u626b\u63cf ===\"\nnmap -A -T4 -oA ${OUTPUT_DIR}\/aggressive_scan $TARGET\n\n# IPv6\u626b\u63cf\uff08\u5982\u679c\u652f\u6301\uff09\nif &#91;&#91; $IPV6_SCAN == \"yes\" ]]; then\n    echo \"=== \u6267\u884cIPv6\u626b\u63cf ===\"\n    nmap -6 -A -T4 -oA ${OUTPUT_DIR}\/ipv6_scan $TARGET\nfi\n\n# \u751f\u6210\u62a5\u544a\necho \"=== \u751f\u6210HTML\u62a5\u544a ===\"\nxsltproc -o ${OUTPUT_DIR}\/report.html \/usr\/share\/nmap\/nmap.xsl ${OUTPUT_DIR}\/aggressive_scan.xml\n\necho \"\u626b\u63cf\u5b8c\u6210\uff01\u7ed3\u679c\u4fdd\u5b58\u5728 ${OUTPUT_DIR}\/\"<\/code><\/pre>\n\n\n\n<p><strong>\u8c03\u8bd5\u7f51\u7edc\u95ee\u9898\u7684\u8bca\u65ad\u811a\u672c\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#!\/bin\/bash\n# network_diagnosis.sh\n\nTARGET=$1\n\necho \"=== \u7f51\u7edc\u63a5\u53e3\u4fe1\u606f ===\"\nnmap --iflist\n\necho -e \"\\n=== \u6570\u636e\u5305\u53d1\u9001\u6d4b\u8bd5\uff08IP\u5c42\uff09===\"\nsudo nmap --send-ip --packet-trace -p 80 -T5 $TARGET 2&gt;&amp;1 | head -20\n\necho -e \"\\n=== \u6570\u636e\u5305\u53d1\u9001\u6d4b\u8bd5\uff08\u4ee5\u592a\u7f51\u5c42\uff09===\"\nsudo nmap --send-eth --packet-trace -p 80 -T5 $TARGET 2&gt;&amp;1 | head -20\n\necho -e \"\\n=== \u8def\u7531\u8ffd\u8e2a ===\"\nnmap --traceroute -p 80 $TARGET\n\necho -e \"\\n=== \u4f7f\u7528\u81ea\u5b9a\u4e49\u6570\u636e\u76ee\u5f55 ===\"\nif &#91;&#91; -d ~\/.nmap-custom ]]; then\n    nmap --datadir ~\/.nmap-custom -sV $TARGET\nelse\n    echo \"\u81ea\u5b9a\u4e49\u6570\u636e\u76ee\u5f55\u4e0d\u5b58\u5728\uff0c\u4f7f\u7528\u9ed8\u8ba4\u8bbe\u7f6e\"\n    nmap -sV $TARGET\nfi<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e00\u3001\u4e3a\u4ec0\u4e48\u5b66 Nmap \u4e4b\u524d\u5fc5\u987b\u5148\u61c2 TCP\/IP\uff1f<\/h2>\n\n\n\n<p><strong>Nmap \u2248 \u5728\u201c\u7f51\u7edc\u534f\u8bae\u89c4\u5219\u201d\u5141\u8bb8\u7684\u8303\u56f4\u5185\uff0c\u548c\u76ee\u6807\u4e3b\u673a\u5bf9\u8bdd\u3001\u8bd5\u63a2\u3001\u5077\u542c\u53cd\u5e94<\/strong>\uff0c\u5b83\u53ea\u662f<strong>\u975e\u5e38\u61c2\u7f51\u7edc\u534f\u8bae<\/strong>\u3002<\/p>\n\n\n\n<p>\u5982\u679c\u4f60\u4e0d\u77e5\u9053\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4ec0\u4e48\u662f TCP \/ UDP<\/li>\n\n\n\n<li>\u4ec0\u4e48\u662f\u7aef\u53e3<\/li>\n\n\n\n<li>\u4ec0\u4e48\u662f\u63e1\u624b\u3001\u6325\u624b<\/li>\n\n\n\n<li>\u4e3a\u4ec0\u4e48\u201c\u6ca1\u8fd4\u56de \u2260 \u6ca1\u6709\u7aef\u53e3\u201d<\/li>\n\n\n\n<li>\u4e3a\u4ec0\u4e48 SYN \u626b\u63cf\u4f1a\u201c\u66f4\u9690\u853d\u201d<\/li>\n<\/ul>\n\n\n\n<p>\u90a3\u4f60\u5c31<strong>\u770b\u4e0d\u61c2 Nmap \u7684\u626b\u63cf\u7ed3\u679c<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e8c\u3001\u4ece\u201c\u7f51\u7edc\u901a\u4fe1\u201d\u6700\u672c\u8d28\u7684\u6982\u5ff5\u8bf4\u8d77<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">2.1 \u4ec0\u4e48\u662f\u7f51\u7edc\u901a\u4fe1\uff1f\uff08\u4e00\u53e5\u8bdd\u7248\u672c\uff09<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u7f51\u7edc\u901a\u4fe1 = \u4e24\u53f0\u8bbe\u5907\uff0c\u6309\u7167\u7ea6\u5b9a\u597d\u7684\u89c4\u5219\uff0c\u4e92\u76f8\u53d1\u9001\u6570\u636e<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u8fd9\u5957\u201c\u7ea6\u5b9a\u597d\u7684\u89c4\u5219\u201d\uff0c\u5c31\u53eb <strong>\u7f51\u7edc\u534f\u8bae\uff08Protocol\uff09<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">2.2 \u534f\u8bae\u4e3a\u4ec0\u4e48\u8981\u201c\u5206\u5c42\u201d\uff1f<\/h2>\n\n\n\n<p>\u60f3\u8c61\u4f60\u5bc4\u4e00\u5c01\u5feb\u9012\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u73b0\u5b9e\u4e16\u754c<\/th><th>\u7f51\u7edc\u4e16\u754c<\/th><\/tr><\/thead><tbody><tr><td>\u5199\u5185\u5bb9<\/td><td>\u5e94\u7528\u5c42<\/td><\/tr><tr><td>\u88c5\u4fe1\u5c01<\/td><td>\u4f20\u8f93\u5c42<\/td><\/tr><tr><td>\u586b\u5730\u5740<\/td><td>\u7f51\u7edc\u5c42<\/td><\/tr><tr><td>\u4ea4\u7ed9\u5feb\u9012\u5458<\/td><td>\u7f51\u7edc\u63a5\u53e3\u5c42<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>\u6bcf\u4e00\u5c42\u53ea\u5e72\u4e00\u4ef6\u4e8b\uff0c\u4e92\u4e0d\u5e72\u6270<\/strong>\uff0c\u8fd9\u5c31\u662f <strong>TCP\/IP \u534f\u8bae\u6808<\/strong> \u7684\u6838\u5fc3\u601d\u60f3\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e09\u3001TCP\/IP \u534f\u8bae\u6808\u6574\u4f53\u7ed3\u6784\uff08\u91cd\u70b9\uff09<\/h2>\n\n\n\n<p>\u6211\u4eec\u7528\u6700\u5e38\u89c1\u3001\u4e5f\u662f <strong>Nmap \u76f4\u63a5\u6253\u4ea4\u9053\u7684 TCP\/IP \u56db\u5c42\u6a21\u578b<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n\u2502 \u5e94\u7528\u5c42\uff08Application\uff09 \u2502 \u2190 HTTP \/ FTP \/ SSH \/ DNS\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 \u4f20\u8f93\u5c42\uff08Transport\uff09   \u2502 \u2190 TCP \/ UDP\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 \u7f51\u7edc\u5c42\uff08Internet\uff09    \u2502 \u2190 IP \/ ICMP\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 \u7f51\u7edc\u63a5\u53e3\u5c42\uff08Link\uff09    \u2502 \u2190 Ethernet \/ ARP\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\n<\/code><\/pre>\n\n\n\n<p><strong>Nmap \u6700\u4e3b\u8981\u5de5\u4f5c\u5728\uff1a<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4f20\u8f93\u5c42\uff08TCP \/ UDP\uff09<\/li>\n\n\n\n<li>\u7f51\u7edc\u5c42\uff08IP \/ ICMP\uff09<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u56db\u3001\u6bcf\u4e00\u5c42\u8be6\u7ec6\u5256\u6790\uff08\u7ed3\u5408 Nmap\uff09<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">4.1 \u7f51\u7edc\u63a5\u53e3\u5c42\uff08\u6700\u5e95\u5c42\uff0c\u901a\u5e38\u88ab\u5ffd\u7565\uff09<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u5b83\u8d1f\u8d23\u4ec0\u4e48\uff1f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5728<strong>\u540c\u4e00\u5c40\u57df\u7f51\u5185<\/strong>\u627e\u5230\u76ee\u6807\u8bbe\u5907<\/li>\n\n\n\n<li>\u628a\u6570\u636e\u53d8\u6210\u7535\u4fe1\u53f7 \/ \u65e0\u7ebf\u4fe1\u53f7<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u6838\u5fc3\u534f\u8bae<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Ethernet<\/strong><\/li>\n\n\n\n<li><strong>ARP\uff08\u5730\u5740\u89e3\u6790\u534f\u8bae\uff09<\/strong><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">ARP \u662f\u4ec0\u4e48\uff1f\uff08\u975e\u5e38\u91cd\u8981\uff09<\/h3>\n\n\n\n<p>\u95ee\u9898\uff1a\u201c\u6211\u77e5\u9053\u4f60\u7684 IP\uff0c\u4f46\u4e0d\u77e5\u9053\u4f60\u7684 MAC \u5730\u5740\uff0c\u600e\u4e48\u53d1\u6570\u636e\uff1f\u201d<\/p>\n\n\n\n<p>\u7b54\u6848\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u53d1\u9001 <strong>ARP \u8bf7\u6c42<\/strong><\/li>\n\n\n\n<li>\u5c40\u57df\u7f51\u5185\u5e7f\u64ad\uff1a\u201c\u8c01\u662f 192.168.1.1\uff1f\u201d<\/li>\n\n\n\n<li>\u76ee\u6807\u56de\u590d MAC \u5730\u5740<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u548c Nmap \u7684\u5173\u7cfb<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>nmap -sn 192.168.1.0\/24<\/code><\/li>\n\n\n\n<li>\u5c40\u57df\u7f51\u4e3b\u673a\u53d1\u73b0\u65f6\uff0c<strong>\u5927\u91cf\u4f9d\u8d56 ARP<\/strong><\/li>\n\n\n\n<li>\u6bd4 ICMP \u66f4\u5feb\u3001\u66f4\u51c6<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">4.2 \u7f51\u7edc\u5c42\uff08IP &amp; ICMP\uff09<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">IP \u534f\u8bae\u662f\u5e72\u561b\u7684\uff1f<\/h3>\n\n\n\n<p>\u4e00\u53e5\u8bdd\uff1a<strong>\u8d1f\u8d23\u201c\u628a\u6570\u636e\u9001\u5230\u54ea\u53f0\u4e3b\u673a\u201d<\/strong>,IP \u5730\u5740 \u2248 \u73b0\u5b9e\u4e2d\u7684\u201c\u5bb6\u5ead\u4f4f\u5740\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u7279\u70b9<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4e0d\u4fdd\u8bc1\u5230\u8fbe<\/strong><\/li>\n\n\n\n<li><strong>\u4e0d\u4fdd\u8bc1\u987a\u5e8f<\/strong><\/li>\n\n\n\n<li><strong>\u4e0d\u4fdd\u8bc1\u4e0d\u4e22\u5305<\/strong><\/li>\n<\/ul>\n\n\n\n<p>IP \u672c\u8eab\u5f88\u201c\u51b7\u6f20\u201d\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">ICMP\uff08\u5f88\u591a\u65b0\u624b\u8bef\u4f1a\u5b83\uff09<\/h3>\n\n\n\n<p>\u4f60\u53ef\u80fd\u542c\u8fc7\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ping<\/li>\n\n\n\n<li>TTL exceeded<\/li>\n\n\n\n<li>Destination unreachable<\/li>\n<\/ul>\n\n\n\n<p>\u8fd9\u4e9b\u90fd\u662f <strong>ICMP<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">ping \u7684\u771f\u5b9e\u672c\u8d28<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>ICMP Echo Request  \u2192  \nICMP Echo Reply\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u548c Nmap \u7684\u5173\u7cfb<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4e3b\u673a\u662f\u5426\u5b58\u6d3b\uff08Host Discovery\uff09<\/li>\n\n\n\n<li>\u9632\u706b\u5899\u662f\u5426\u62e6\u622a ICMP\uff0c\u4f1a\u5f71\u54cd\u626b\u63cf\u7ed3\u679c<\/li>\n<\/ul>\n\n\n\n<p>\u6ce8\u610f\uff1a<strong>ping \u4e0d\u901a \u2260 \u4e3b\u673a\u4e0d\u5b58\u5728<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">4.3 \u4f20\u8f93\u5c42\uff08Nmap \u7684\u6838\u5fc3\uff09<\/h2>\n\n\n\n<p>\u8fd9\u91cc\u53ea\u6709\u4e24\u4e2a\u4e3b\u89d2\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u534f\u8bae<\/th><th>\u7279\u70b9<\/th><\/tr><\/thead><tbody><tr><td>TCP<\/td><td>\u9762\u5411\u8fde\u63a5\u3001\u53ef\u9760<\/td><\/tr><tr><td>UDP<\/td><td>\u65e0\u8fde\u63a5\u3001\u4e0d\u53ef\u9760<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e94\u3001TCP \u534f\u8bae\u6df1\u5ea6\u5256\u6790\uff08\u91cd\u4e2d\u4e4b\u91cd\uff09<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">5.1 TCP \u662f\u4ec0\u4e48\uff1f<\/h2>\n\n\n\n<p><strong>TCP \u662f\u4e00\u79cd\u201c\u6253\u7535\u8bdd\u5f0f\u201d\u7684\u901a\u4fe1\u65b9\u5f0f<\/strong><\/p>\n\n\n\n<p>\u7279\u70b9\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5148\u5efa\u7acb\u8fde\u63a5<\/li>\n\n\n\n<li>\u518d\u4f20\u6570\u636e<\/li>\n\n\n\n<li>\u7ed3\u675f\u65f6\u793c\u8c8c\u65ad\u5f00<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">5.2 TCP \u62a5\u6587\u4e2d\u7684\u5173\u952e\u6807\u5fd7\u4f4d\uff08Flags\uff09<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u6807\u5fd7<\/th><th>\u542b\u4e49<\/th><\/tr><\/thead><tbody><tr><td>SYN<\/td><td>\u8bf7\u6c42\u5efa\u7acb\u8fde\u63a5<\/td><\/tr><tr><td>ACK<\/td><td>\u786e\u8ba4<\/td><\/tr><tr><td>FIN<\/td><td>\u8bf7\u6c42\u5173\u95ed\u8fde\u63a5<\/td><\/tr><tr><td>RST<\/td><td>\u5f3a\u5236\u4e2d\u65ad<\/td><\/tr><tr><td>PSH<\/td><td>\u63a8\u9001\u6570\u636e<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p> <strong>Nmap \u672c\u8d28\u5c31\u662f\u5728\u201c\u73a9\u8fd9\u4e9b\u6807\u5fd7\u4f4d\u201d<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">5.3 TCP \u4e09\u6b21\u63e1\u624b\uff08\u5efa\u7acb\u8fde\u63a5\uff09<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u7c7b\u6bd4<\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>A\uff1a\u6211\u80fd\u548c\u4f60\u8bf4\u8bdd\u5417\uff1f<br>B\uff1a\u53ef\u4ee5\uff0c\u4f60\u80fd\u542c\u89c1\u6211\u5417\uff1f<br>A\uff1a\u80fd\uff0c\u5f00\u59cb\u8bf4\u6b63\u4e8b\u5427<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u6280\u672f\u6d41\u7a0b\uff08\u6807\u51c6\uff09<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>\u5ba2\u6237\u7aef \u2192 \u670d\u52a1\u7aef\uff1aSYN\n\u670d\u52a1\u7aef \u2192 \u5ba2\u6237\u7aef\uff1aSYN + ACK\n\u5ba2\u6237\u7aef \u2192 \u670d\u52a1\u7aef\uff1aACK\n<\/code><\/pre>\n\n\n\n<p>\u81f3\u6b64\uff0c\u8fde\u63a5\u5efa\u7acb\u5b8c\u6210\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e3a\u4ec0\u4e48\u662f\u4e09\u6b21\uff1f<\/h3>\n\n\n\n<p>\u6838\u5fc3\u539f\u56e0\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9632\u6b62\u65e7\u8fde\u63a5\u5e72\u6270<\/strong><\/li>\n\n\n\n<li><strong>\u786e\u8ba4\u53cc\u65b9\u7684\u53d1\u9001 &amp; \u63a5\u6536\u80fd\u529b<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Nmap \u5982\u4f55\u201c\u5229\u7528\u201d\u4e09\u6b21\u63e1\u624b\uff1f<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\"> 1.TCP Connect \u626b\u63cf\uff08-sT\uff09<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5b8c\u6574\u8d70\u4e09\u6b21\u63e1\u624b<\/li>\n\n\n\n<li>\u5bb9\u6613\u88ab\u65e5\u5fd7\u8bb0\u5f55<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"> 2.TCP SYN \u626b\u63cf\uff08-sS\uff0c\u534a\u8fde\u63a5\u626b\u63cf\uff09<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN \u2192\n\u2190 SYN+ACK\nRST \u2192\n<\/code><\/pre>\n\n\n\n<p><strong>\u4e0d\u53d1\u9001\u6700\u540e\u4e00\u6b21 ACK<\/strong><br>\u8fde\u63a5\u6ca1\u771f\u6b63\u5efa\u7acb<br>\u66f4\u9690\u853d<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">5.4 TCP \u56db\u6b21\u6325\u624b\uff08\u65ad\u5f00\u8fde\u63a5\uff09<\/h2>\n\n\n\n<p>\u65ad\u5f00\u8fde\u63a5\u6bd4\u5efa\u7acb\u590d\u6742\uff0c\u8fd9\u662f TCP \u7684\u201c\u793c\u8c8c\u201d\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u6807\u51c6\u6d41\u7a0b<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>\u5ba2\u6237\u7aef \u2192 \u670d\u52a1\u7aef\uff1aFIN\n\u670d\u52a1\u7aef \u2192 \u5ba2\u6237\u7aef\uff1aACK\n\u670d\u52a1\u7aef \u2192 \u5ba2\u6237\u7aef\uff1aFIN\n\u5ba2\u6237\u7aef \u2192 \u670d\u52a1\u7aef\uff1aACK\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e3a\u4ec0\u4e48\u662f\u56db\u6b21\uff1f<\/h3>\n\n\n\n<p>\u56e0\u4e3a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>TCP \u662f<strong>\u5168\u53cc\u5de5<\/strong><\/li>\n\n\n\n<li>\u4e24\u4e2a\u65b9\u5411\u5fc5\u987b<strong>\u5206\u522b\u5173\u95ed<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">TIME_WAIT \u72b6\u6001\uff08\u5f88\u591a\u65b0\u624b\u4e0d\u61c2\uff09<\/h3>\n\n\n\n<p>\u65ad\u5f00\u540e\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5ba2\u6237\u7aef\u4f1a\u7b49\u5f85\u4e00\u6bb5\u65f6\u95f4\uff08\u901a\u5e38 2MSL\uff09<\/li>\n\n\n\n<li>\u9632\u6b62\u65e7\u6570\u636e\u5e72\u6270\u65b0\u8fde\u63a5<\/li>\n<\/ul>\n\n\n\n<p><strong>\u7aef\u53e3\u626b\u63cf\u65f6\u770b\u5230\u201c\u5947\u602a\u7684\u7b49\u5f85\u72b6\u6001\u201d\uff0c\u522b\u614c<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u516d\u3001UDP \u534f\u8bae\uff08Nmap \u65b0\u624b\u6700\u5bb9\u6613\u8bef\u89e3\uff09<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">6.1 UDP \u7684\u672c\u8d28<\/h2>\n\n\n\n<p>\u4e00\u53e5\u8bdd\uff1a<strong>UDP = \u53d1\u6d88\u606f\uff0c\u4e0d\u7b49\u56de\u590d<\/strong><\/p>\n\n\n\n<p>\u7279\u70b9\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u65e0\u8fde\u63a5<\/li>\n\n\n\n<li>\u4e0d\u4fdd\u8bc1\u5230\u8fbe<\/li>\n\n\n\n<li>\u6ca1\u6709\u63e1\u624b<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">6.2 UDP \u626b\u63cf\u4e3a\u4ec0\u4e48\u201c\u6162\u53c8\u4e0d\u51c6\u201d\uff1f<\/h2>\n\n\n\n<p>\u56e0\u4e3a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6ca1\u6709 ACK<\/li>\n\n\n\n<li>\u6ca1\u6709 SYN\/FIN<\/li>\n\n\n\n<li><strong>\u6c89\u9ed8 \u2260 \u5173\u95ed<\/strong><\/li>\n<\/ul>\n\n\n\n<p>Nmap \u7684\u903b\u8f91\u662f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6536\u5230 ICMP Port Unreachable \u2192 \u7aef\u53e3\u5173\u95ed<\/li>\n\n\n\n<li>\u4ec0\u4e48\u90fd\u6ca1\u6536\u5230 \u2192 open | filtered<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">6.3 \u5e38\u89c1 UDP \u670d\u52a1<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7aef\u53e3<\/th><th>\u670d\u52a1<\/th><\/tr><\/thead><tbody><tr><td>53<\/td><td>DNS<\/td><\/tr><tr><td>67\/68<\/td><td>DHCP<\/td><\/tr><tr><td>123<\/td><td>NTP<\/td><\/tr><tr><td>161<\/td><td>SNMP<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>\u5f88\u591a <strong>\u4fe1\u606f\u6cc4\u9732\u578b\u670d\u52a1\u90fd\u5728 UDP<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e03\u3001\u628a\u201c\u534f\u8bae\u539f\u7406\u201d\u76f4\u63a5\u6620\u5c04\u5230 Nmap \u601d\u7ef4<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">7.1 Nmap \u5230\u5e95\u5728\u5e72\u561b\uff1f<\/h2>\n\n\n\n<p>\u4f60\u53ef\u4ee5\u628a Nmap \u60f3\u6210\uff1a<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u4e00\u4e2a<strong>\u975e\u5e38\u61c2\u793c\u8c8c\u3001\u4e5f\u61c2\u800d\u6d41\u6c13\u7684\u201c\u7f51\u7edc\u8bbf\u5ba2\u201d<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u5b83\u4f1a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6b63\u5e38\u6572\u95e8\uff08Connect\uff09<\/li>\n\n\n\n<li>\u53ea\u6572\u4e00\u4e0b\u5c31\u8d70\uff08SYN\uff09<\/li>\n\n\n\n<li>\u5728\u95e8\u53e3\u542c\u58f0\u97f3\uff08ACK \/ Window\uff09<\/li>\n\n\n\n<li>\u5bf9\u6ca1\u56de\u5e94\u7684\u95e8\u53cd\u590d\u786e\u8ba4\uff08UDP\uff09<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7.2 \u4e3a\u4ec0\u4e48\u201c\u7406\u89e3\u534f\u8bae = \u770b\u61c2\u626b\u63cf\u7ed3\u679c\u201d<\/h2>\n\n\n\n<p>\u6bd4\u5982\u4f60\u770b\u5230\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>80\/tcp  open   http\n443\/tcp filtered https\n<\/code><\/pre>\n\n\n\n<p>\u4f60\u5e94\u8be5\u7acb\u523b\u60f3\u5230\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>open\uff1aSYN \u2192 SYN+ACK<\/li>\n\n\n\n<li>filtered\uff1aSYN \u2192 \u6ca1\u56de\u5e94\uff08\u88ab\u9632\u706b\u5899\u62e6\uff09<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u516b\u3001\u8fd9\u4e00\u7ae0\u4f60\u771f\u6b63\u5e94\u8be5\u638c\u63e1\u7684\u201c\u786c\u6838\u7406\u89e3\u201d<\/h2>\n\n\n\n<p>\u5982\u679c\u4f60\u80fd\u56de\u7b54\u4e0b\u9762\u95ee\u9898\uff0c\u8bf4\u660e\u4f60\u5df2\u7ecf<strong>\u8d85\u8fc7 70% \u7684 Nmap \u521d\u5b66\u8005<\/strong>\uff1a<\/p>\n\n\n\n<p>\u4e3a\u4ec0\u4e48 SYN \u626b\u63cf\u4e0d\u7b97\u5b8c\u6574\u8fde\u63a5\uff1f<br>\u4e3a\u4ec0\u4e48 ping \u4e0d\u901a\u4e3b\u673a\u4ecd\u53ef\u80fd\u5b58\u5728\uff1f<br>\u4e3a\u4ec0\u4e48 UDP \u626b\u63cf\u7ecf\u5e38\u663e\u793a open|filtered\uff1f<br>\u4e3a\u4ec0\u4e48 TCP \u6bd4 UDP \u201c\u53ef\u9760\u201d\uff1f<br>\u4e3a\u4ec0\u4e48\u7aef\u53e3\u626b\u63cf\u672c\u8d28\u662f\u201c\u534f\u8bae\u4ea4\u4e92\u8bd5\u63a2\u201d\uff1f<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c2\u7ae0\uff1aUDP\u3001ICMP\u3001SCTP \u7b49\u534f\u8bae\u7684\u6838\u5fc3\u7279\u6027\u4e0e\u626b\u63cf\u76f8\u5173\u6027<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u6838\u5fc3\u76ee\u6807\uff1a<\/strong>\u660e\u767d<em>\u4e3a\u4ec0\u4e48\u4e0d\u540c\u534f\u8bae\uff0cNmap \u7684\u626b\u63cf\u65b9\u5f0f\u3001\u901f\u5ea6\u3001\u51c6\u786e\u6027\u3001\u7ed3\u679c\u542b\u4e49\u5b8c\u5168\u4e0d\u4e00\u6837<\/em><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e00\u3001\u5148\u7ed9\u4f60\u4e00\u4e2a\u201c\u5168\u5c40\u5730\u56fe\u201d<\/h3>\n\n\n\n<p>\u5728\u5f00\u59cb\u4e4b\u524d\uff0c\u5148\u628a\u8fd9\u51e0\u4e2a\u534f\u8bae\u653e\u5728\u4e00\u5f20\u56fe\u91cc<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u534f\u8bae<\/th><th>\u6240\u5728\u5c42<\/th><th>\u662f\u5426\u6709\u8fde\u63a5<\/th><th>\u626b\u63cf\u96be\u5ea6<\/th><th>Nmap \u4e2d\u7684\u4f5c\u7528<\/th><\/tr><\/thead><tbody><tr><td>TCP<\/td><td>\u4f20\u8f93\u5c42<\/td><td>\u6709<\/td><td>1<\/td><td>\u4e3b\u6d41\u7aef\u53e3\u626b\u63cf<\/td><\/tr><tr><td>UDP<\/td><td>\u4f20\u8f93\u5c42<\/td><td>\u65e0<\/td><td>4<\/td><td>\u4fe1\u606f\u6536\u96c6\u3001\u6162<\/td><\/tr><tr><td>ICMP<\/td><td>\u7f51\u7edc\u5c42<\/td><td>\u65e0<\/td><td>2<\/td><td>\u4e3b\u673a\u53d1\u73b0\u3001\u9632\u706b\u5899\u5224\u65ad<\/td><\/tr><tr><td>SCTP<\/td><td>\u4f20\u8f93\u5c42<\/td><td>\u6709\uff08\u7c7b\u4f3c TCP\uff09<\/td><td>3<\/td><td>\u7535\u4fe1\/\u4e13\u7528\u7cfb\u7edf<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Nmap \u7684\u626b\u63cf\u662f\uff1a<\/strong>\u4e0d\u540c\u534f\u8bae = \u4e0d\u540c\u201c\u56de\u5e94\u89c4\u5219\u201d = \u4e0d\u540c\u201c\u5224\u65ad\u903b\u8f91\u201d<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e8c\u3001UDP \u534f\u8bae\uff1a\u6700\u8ba9\u521d\u5b66\u8005\u201c\u5d29\u6e83\u201d\u7684\u534f\u8bae<\/h3>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">2.1 UDP \u7684\u672c\u8d28<\/h4>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>UDP = \u6211\u53d1\u7ed9\u4f60\u4e86\uff0c\u81f3\u4e8e\u4f60\u6536\u6ca1\u6536\uff0c\u6211\u4e0d\u7ba1<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u5bf9\u6bd4\u4e00\u4e0b\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5bf9\u6bd4\u9879<\/th><th>TCP<\/th><th>UDP<\/th><\/tr><\/thead><tbody><tr><td>\u5efa\u7acb\u8fde\u63a5<\/td><td>\u4e09\u6b21\u63e1\u624b<\/td><td>no<\/td><\/tr><tr><td>\u786e\u8ba4\u673a\u5236<\/td><td>ACK<\/td><td>no<\/td><\/tr><tr><td>\u91cd\u4f20<\/td><td>\u6709<\/td><td>no<\/td><\/tr><tr><td>\u53ef\u9760\u6027<\/td><td>\u9ad8<\/td><td>\u4f4e<\/td><\/tr><tr><td>\u626b\u63cf\u96be\u5ea6<\/td><td>\u4f4e<\/td><td>\u9ad8<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">2.2 UDP \u4e3a\u4ec0\u4e48\u201c\u6ca1\u6709\u7aef\u53e3\u72b6\u6001\u611f\u201d\uff1f<\/h4>\n\n\n\n<p>TCP \u626b\u63cf\u65f6\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN \u2192 SYN+ACK = open\nSYN \u2192 RST     = closed\n\u975e\u5e38\u6e05\u6670\u3002<\/code><\/pre>\n\n\n\n<p>\u800c UDP\uff1aUDP \u6570\u636e \u2192 \uff08\u53ef\u80fd\u4ec0\u4e48\u90fd\u6ca1\u6709\uff09<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">2.3 \u90a3 Nmap \u600e\u4e48\u5224\u65ad UDP \u7aef\u53e3\u72b6\u6001\uff1f<\/h4>\n\n\n\n<p>\u9760\u7684\u662f <strong>\u201c\u95f4\u63a5\u8bc1\u636e\u201d<\/strong>\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u4e09\u79cd\u5178\u578b\u60c5\u51b5<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">\u60c5\u51b5 1\uff1a\u6536\u5230 ICMP Port Unreachable<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>UDP \u2192  \n\u2190 ICMP Destination Unreachable (Port)\n<strong>\u7aef\u53e3\u5173\u95ed\uff08closed\uff09<\/strong><\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h5 class=\"wp-block-heading\">\u60c5\u51b5 2\uff1a\u6536\u5230\u5e94\u7528\u5c42\u54cd\u5e94\uff08\u6781\u5c11\uff09<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>UDP \u2192  \n\u2190 DNS \/ SNMP \/ NTP \u54cd\u5e94\n<strong>\u7aef\u53e3\u5f00\u653e\uff08open\uff09<\/strong><\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h5 class=\"wp-block-heading\">\u60c5\u51b5 3\uff1a\u4ec0\u4e48\u90fd\u6ca1\u6536\u5230\uff08\u6700\u5e38\u89c1\uff09<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>UDP \u2192  \n\uff08\u6c89\u9ed8\uff09\n<\/code><\/pre>\n\n\n\n<p><strong>open | filtered<\/strong><\/p>\n\n\n\n<p>\u53ef\u80fd\u662f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u670d\u52a1\u5728\uff0c\u4f46\u4e0d\u56de<\/li>\n\n\n\n<li>\u9632\u706b\u5899\u4e22\u5305<\/li>\n\n\n\n<li>\u771f\u7684\u6ca1\u4e1c\u897f\uff0c\u4f46\u6ca1 ICMP<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">2.4 \u4e3a\u4ec0\u4e48 UDP \u626b\u63cf\u201c\u6162\u5f97\u8981\u547d\u201d\uff1f<\/h4>\n\n\n\n<p>\u539f\u56e0\u53ea\u6709\u4e00\u4e2a\uff1a<strong>Nmap \u5fc5\u987b\u201c\u7b49\u8d85\u65f6\u201d\u624d\u80fd\u4e0b\u7ed3\u8bba<\/strong><\/p>\n\n\n\n<p>TCP\uff1aRST \u7acb\u523b\u77e5\u9053 closed<\/p>\n\n\n\n<p>UDP\uff1a\u4e0d\u56de\u5e94 = \u7b49\u5230\u4f60\u5fc3\u6001\u7206\u70b8<\/p>\n\n\n\n<p>\u8fd9\u4e5f\u662f\u4e3a\u4ec0\u4e48\uff1a-sU\uff0c\u9ed8\u8ba4\u975e\u5e38\u6162\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.5 UDP \u5728\u6e17\u900f\u548c\u4fe1\u606f\u6536\u96c6\u4e2d\u4e3a\u4ec0\u4e48\u91cd\u8981\uff1f<\/h3>\n\n\n\n<p>\u56e0\u4e3a\u5f88\u591a<strong>\u9ad8\u4ef7\u503c\u670d\u52a1<\/strong>\u7528 UDP\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u670d\u52a1<\/th><th>\u98ce\u9669\u70b9<\/th><\/tr><\/thead><tbody><tr><td>DNS<\/td><td>\u533a\u57df\u4f20\u9001\u3001\u7f13\u5b58\u6295\u6bd2<\/td><\/tr><tr><td>SNMP<\/td><td>\u660e\u6587\u793e\u533a\u5b57\u7b26\u4e32<\/td><\/tr><tr><td>NTP<\/td><td>\u653e\u5927\u653b\u51fb<\/td><\/tr><tr><td>TFTP<\/td><td>\u65e0\u8ba4\u8bc1\u6587\u4ef6\u4e0b\u8f7d<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>UDP \u4e0d\u591a\uff0c\u4f46\u4e00\u65e6\u5f00\uff0c\u5f80\u5f80\u201c\u5f88\u80a5\u201d<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e09\u3001ICMP \u534f\u8bae\uff1a\u4e0d\u53ea\u662f ping \u90a3\u4e48\u7b80\u5355<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">3.1 ICMP \u662f\u4ec0\u4e48\uff1f<\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>ICMP = IP \u5c42\u7684\u201c\u9519\u8bef\u62a5\u544a\u5458 + \u7f51\u7edc\u56de\u58f0\u201d<\/strong>\uff0c\u5b83\u4e0d\u4f20\u6570\u636e\uff0c\u53ea\u4f20<strong>\u72b6\u6001\u4fe1\u606f<\/strong>\u3002<\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">3.2 \u5e38\u89c1 ICMP \u7c7b\u578b\uff08\u4f60\u5fc5\u987b\u8ba4\u8bc6\uff09<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7c7b\u578b<\/th><th>\u4f5c\u7528<\/th><\/tr><\/thead><tbody><tr><td>Echo Request<\/td><td>ping \u8bf7\u6c42<\/td><\/tr><tr><td>Echo Reply<\/td><td>ping \u56de\u590d<\/td><\/tr><tr><td>Destination Unreachable<\/td><td>\u65e0\u6cd5\u5230\u8fbe<\/td><\/tr><tr><td>Time Exceeded<\/td><td>TTL \u8d85\u65f6<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">3.3 ping \u7684\u201c\u771f\u5b9e\u626b\u63cf\u610f\u4e49\u201d<\/h3>\n\n\n\n<p>\u5f53\u4f60\u6267\u884c\uff1aping \u76ee\u6807<br>\u4f60\u5728\u95ee\u7684\u662f\uff1a\u201c\u4f60\u8fd9\u53f0\u4e3b\u673a\uff0cIP \u5c42\u8fd8\u6d3b\u7740\u5417\uff1f\u201d<\/p>\n\n\n\n<p>\u6ce8\u610f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ping \u901a \u2260 \u7aef\u53e3\u5f00\u653e<\/li>\n\n\n\n<li>ping \u4e0d\u901a \u2260 \u4e3b\u673a\u4e0d\u5b58\u5728<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">3.4 Nmap \u4e2d ICMP \u7684\u771f\u5b9e\u7528\u9014<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e3b\u673a\u53d1\u73b0\uff08Host Discovery\uff09<\/h3>\n\n\n\n<p>Nmap \u9ed8\u8ba4\u4f1a\u5148\u505a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ICMP Echo<\/li>\n\n\n\n<li>TCP ACK<\/li>\n\n\n\n<li>TCP SYN\uff0880,443\uff09<\/li>\n<\/ul>\n\n\n\n<p>\u5224\u65ad\u201c\u8fd9\u53f0\u4e3b\u673a\u503c\u4e0d\u503c\u5f97\u7ee7\u7eed\u626b\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. \u9632\u706b\u5899\u5224\u65ad\uff08\u975e\u5e38\u91cd\u8981\uff09<\/h3>\n\n\n\n<p>\u4e0d\u540c ICMP \u8fd4\u56de\uff0c\u542b\u4e49\u4e0d\u540c\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>ICMP \u7c7b\u578b<\/th><th>\u6697\u793a<\/th><\/tr><\/thead><tbody><tr><td>Host Unreachable<\/td><td>\u7f51\u7edc\u5c42\u963b\u65ad<\/td><\/tr><tr><td>Port Unreachable<\/td><td>UDP \u7aef\u53e3\u5173\u95ed<\/td><\/tr><tr><td>Time Exceeded<\/td><td>\u53ef\u80fd\u5728\u8def\u5f84\u4e2d<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p> <strong>ICMP \u662f\u201c\u7f51\u7edc\u6001\u5ea6\u201d\u7684\u4f53\u73b0<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3.5 \u4e3a\u4ec0\u4e48\u5f88\u591a\u670d\u52a1\u5668\u7981 ping\uff1f<\/h2>\n\n\n\n<p>\u56e0\u4e3a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4f1a\u88ab\u7528\u6765\u63a2\u6d4b<\/li>\n\n\n\n<li>\u4f1a\u88ab\u7528\u5728 DDoS<\/li>\n\n\n\n<li>\u4f1a\u6cc4\u9732\u7f51\u7edc\u7ed3\u6784<\/li>\n<\/ul>\n\n\n\n<p> <strong>\u4f46\u7981 ICMP \u2260 \u5b89\u5168<\/strong>\uff0cNmap \u8fd8\u6709\u5f88\u591a\u201c\u65c1\u8def\u786e\u8ba4\u624b\u6bb5\u201d\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u56db\u3001SCTP \u534f\u8bae\uff1a\u88ab\u5ffd\u89c6\uff0c\u4f46\u4f60\u5fc5\u987b\u77e5\u9053<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">4.1 SCTP \u662f\u4ec0\u4e48\uff1f\uff08\u4e00\u53e5\u8bdd\u7248\uff09<\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>SCTP = \u878d\u5408 TCP \u53ef\u9760\u6027 + UDP \u7075\u6d3b\u6027\u7684\u4f20\u8f93\u534f\u8bae<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u4e3b\u8981\u7528\u4e8e\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7535\u4fe1\u4fe1\u4ee4<\/li>\n\n\n\n<li>\u6838\u5fc3\u7f51\u7edc<\/li>\n\n\n\n<li>\u4e13\u7528\u7cfb\u7edf<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.2 SCTP \u548c TCP \u6709\u4ec0\u4e48\u50cf\uff1f<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7279\u6027<\/th><th>TCP<\/th><th>SCTP<\/th><\/tr><\/thead><tbody><tr><td>\u9762\u5411\u8fde\u63a5<\/td><td>yes<\/td><td>yes<\/td><\/tr><tr><td>\u6709\u63e1\u624b<\/td><td>yes<\/td><td>yes<\/td><\/tr><tr><td>\u53ef\u9760\u4f20\u8f93<\/td><td>yes<\/td><td>yes<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">4.3 SCTP \u7684\u201c\u72ec\u95e8\u7edd\u6280\u201d<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">\u56db\u6b21\u63e1\u624b\uff08Cookie \u673a\u5236\uff09<\/h3>\n\n\n\n<p>\u76ee\u7684\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u9632 SYN Flood<\/li>\n\n\n\n<li>\u65e0\u9700\u4fdd\u5b58\u534a\u8fde\u63a5\u72b6\u6001<\/li>\n<\/ul>\n\n\n\n<p><strong>\u5929\u751f\u6bd4 TCP \u6297\u653b\u51fb<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4.4 Nmap \u5982\u4f55\u626b\u63cf SCTP\uff1f<\/h3>\n\n\n\n<p>\u5e38\u89c1\u65b9\u5f0f\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>-sY   # SCTP INIT \u626b\u63cf\n-sZ   # SCTP COOKIE-ECHO \u626b\u63cf\n<\/code><\/pre>\n\n\n\n<p>\u5224\u65ad\u903b\u8f91\u7c7b\u4f3c TCP\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6709\u54cd\u5e94 \u2192 open<\/li>\n\n\n\n<li>Abort \u2192 closed<\/li>\n\n\n\n<li>\u6c89\u9ed8 \u2192 filtered<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.5 \u4e3a\u4ec0\u4e48\u5f88\u5c11\u89c1\u5230 SCTP\uff1f<\/h3>\n\n\n\n<p>\u56e0\u4e3a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Web \u4e0d\u7528<\/li>\n\n\n\n<li>\u666e\u901a\u670d\u52a1\u5668\u4e0d\u7528<\/li>\n\n\n\n<li>\u4f46<strong>\u8fd0\u8425\u5546\u7f51\u7edc\u3001\u6838\u5fc3\u8bbe\u5907\u5e38\u89c1<\/strong><\/li>\n<\/ul>\n\n\n\n<p> \u5982\u679c\u626b\u5230 SCTP\uff0c\u8bf4\u660e\uff1a\u5f88\u53ef\u80fd\u5df2\u7ecf\u8fdb\u5165\u201c\u975e\u666e\u901a IT \u7f51\u7edc\u201d<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e94\u3001\u628a\u4e09\u79cd\u534f\u8bae\u653e\u5728\u4e00\u8d77\u5bf9\u6bd4\uff08\u6838\u5fc3\u603b\u7ed3\uff09<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u534f\u8bae<\/th><th>\u626b\u63cf\u4fe1\u53f7<\/th><th>\u5224\u65ad\u4f9d\u636e<\/th><th>\u8bef\u5224\u7387<\/th><\/tr><\/thead><tbody><tr><td>TCP<\/td><td>SYN \/ ACK \/ RST<\/td><td>\u660e\u786e<\/td><td>\u4f4e<\/td><\/tr><tr><td>UDP<\/td><td>ICMP \/ \u5e94\u7528\u54cd\u5e94<\/td><td>\u95f4\u63a5<\/td><td>\u9ad8<\/td><\/tr><tr><td>ICMP<\/td><td>Echo \/ Error<\/td><td>\u72b6\u6001<\/td><td>\u4e2d<\/td><\/tr><tr><td>SCTP<\/td><td>INIT \/ ABORT<\/td><td>\u660e\u786e<\/td><td>\u4f4e<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>\u5982\u679c\u770b\u5230\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>UDP open|filtered<\/strong><em>\u201c\u4e0d\u662f Nmap \u4e0d\u884c\uff0c\u662f\u534f\u8bae\u672c\u6765\u5c31\u4e0d\u8bf4\u8bdd\u201d<\/em><\/li>\n\n\n\n<li><strong>ICMP \u5168\u7981\uff0c\u4f46 TCP \u6709\u56de\u5e94<\/strong><em>\u201c\u9632\u706b\u5899\u5728\u88c5\u6b7b\uff0c\u4e0d\u662f\u771f\u6b7b\u201d<\/em><\/li>\n\n\n\n<li><strong>SCTP \u54cd\u5e94<\/strong><em>\u201c\u8fd9\u4e0d\u662f\u666e\u901a\u670d\u52a1\u5668\u201d<\/em><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>\u4e3a\u4ec0\u4e48 UDP \u626b\u63cf\u5fc5\u987b\u6162<br>\u4e3a\u4ec0\u4e48 ICMP \u662f\u201c\u4fa7\u4fe1\u9053\u4fe1\u606f\u201d<br>\u4e3a\u4ec0\u4e48 Nmap \u4e0d\u540c\u534f\u8bae\u7528\u4e0d\u540c\u626b\u63cf\u53c2\u6570<br>\u4e3a\u4ec0\u4e48\u6c89\u9ed8\u672c\u8eab\u4e5f\u662f\u4e00\u79cd\u201c\u4fe1\u53f7\u201d<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c 3 \u7ae0\uff1a\u7f51\u7edc\u5305\u7ed3\u6784\u8be6\u89e3<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">\u2014\u2014TCP \u62a5\u6587\u5934 &amp; SYN \/ ACK \/ RST \u7b49\u6807\u5fd7\u4f4d\u7684\u771f\u5b9e\u542b\u4e49<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u5148\u8bf4\u4e00\u53e5\u975e\u5e38\u91cd\u8981\u7684\u8bdd<\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>Nmap \u7684\u672c\u8d28\u4e0d\u662f\u201c\u626b\u7aef\u53e3\u201d\uff0c\u800c\u662f\u201c\u6784\u9020\u4e0d\u540c\u7684\u7f51\u7edc\u5305\uff0c\u89c2\u5bdf\u5bf9\u65b9\u5982\u4f55\u56de\u5e94\u201d\u3002<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u800c\u201c\u5982\u4f55\u56de\u5e94\u201d\uff0c<strong>\u5b8c\u5168\u7531\u7f51\u7edc\u5305\u91cc\u7684\u5b57\u6bb5\u548c\u6807\u5fd7\u4f4d\u51b3\u5b9a<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e8c\u3001\u4ec0\u4e48\u662f\u201c\u7f51\u7edc\u5305\u201d\uff1f\uff08\u76f4\u89c9\u7248\uff09<\/h3>\n\n\n\n<p>\u4f60\u53ef\u4ee5\u628a\u4e00\u4e2a\u7f51\u7edc\u5305\u7406\u89e3\u4e3a\uff1a<strong>\u4e00\u5c01\u6709\u56fa\u5b9a\u683c\u5f0f\u7684\u4fe1\u4ef6<\/strong><\/p>\n\n\n\n<p>\u5b83\u5206\u6210\u4e24\u90e8\u5206\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n\u2502   \u62a5\u6587\u5934     \u2502  \u2190 \u63a7\u5236\u4fe1\u606f\uff08\u8c01\u53d1\u7684\uff1f\u5e72\u561b\uff1f\uff09\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502   \u6570\u636e\u90e8\u5206   \u2502  \u2190 \u771f\u6b63\u7684\u5185\u5bb9\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\n<\/code><\/pre>\n\n\n\n<p><strong>Nmap \u7edd\u5927\u591a\u6570\u65f6\u5019\u53ea\u5173\u5fc3\u201c\u62a5\u6587\u5934\u201d<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e09\u3001TCP \u62a5\u6587\u6574\u4f53\u7ed3\u6784\uff08\u53ea\u4fdd\u7559\u91cd\u70b9\uff09<\/h3>\n\n\n\n<p>\u4e00\u4e2a TCP \u62a5\u6587\u5927\u81f4\u957f\u8fd9\u6837\uff08\u7b80\u5316\u7248\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n\u2502 \u6e90\u7aef\u53e3        | \u76ee\u7684\u7aef\u53e3        \u2502\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 \u5e8f\u5217\u53f7\uff08Sequence Number\uff09      \u2502\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 \u786e\u8ba4\u53f7\uff08Acknowledgment Number\uff09\u2502\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 \u5934\u957f\u5ea6 | \u4fdd\u7559 | Flags | \u7a97\u53e3\u5927\u5c0f \u2502\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 \u6821\u9a8c\u548c        | \u7d27\u6025\u6307\u9488        \u2502\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502            \u53ef\u9009\u5b57\u6bb5            \u2502\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502              \u6570\u636e             \u2502\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\n<\/code><\/pre>\n\n\n\n<p><strong>\u53ea\u6293\u548c\u626b\u63cf\u76f4\u63a5\u76f8\u5173\u7684\u5b57\u6bb5<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u56db\u3001\u7aef\u53e3\u5b57\u6bb5\uff1a\u626b\u63cf\u7684\u201c\u5165\u53e3\u201d<\/h3>\n\n\n\n<p><strong>\u6e90\u7aef\u53e3 &amp; \u76ee\u7684\u7aef\u53e3<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5b57\u6bb5<\/th><th>\u542b\u4e49<\/th><\/tr><\/thead><tbody><tr><td>\u6e90\u7aef\u53e3<\/td><td>\u8c01\u53d1\u7684<\/td><\/tr><tr><td>\u76ee\u7684\u7aef\u53e3<\/td><td>\u627e\u8c01<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>\u5728 Nmap \u4e2d\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u76ee\u7684\u7aef\u53e3 = \u4f60\u5728\u626b\u63cf\u7684\u7aef\u53e3<\/strong><\/li>\n\n\n\n<li>Nmap \u4f1a\u968f\u673a\u5316\u6e90\u7aef\u53e3\uff08\u9632\u68c0\u6d4b\uff09<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e94\u3001Sequence \/ Acknowledgment\uff1a\u4e3a\u4ec0\u4e48\u8981\u6709\u5b83\u4eec\uff1f<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">5.1 \u5e8f\u5217\u53f7\uff08Sequence Number\uff09<\/h3>\n\n\n\n<p><strong>\u544a\u8bc9\u5bf9\u65b9\uff1a\u6211\u53d1\u7684\u6570\u636e\u4ece\u54ea\u4e00\u5b57\u8282\u5f00\u59cb<\/strong><\/p>\n\n\n\n<p>\u4f5c\u7528\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4fdd\u8bc1\u987a\u5e8f<\/li>\n\n\n\n<li>\u9632\u6b62\u4e22\u5305<\/li>\n\n\n\n<li>\u9632\u6b62\u91cd\u653e<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">5.2 \u786e\u8ba4\u53f7\uff08ACK Number\uff09<\/h3>\n\n\n\n<p><strong>\u544a\u8bc9\u5bf9\u65b9\uff1a\u4f60\u53d1\u5230\u54ea\u4e00\u5b57\u8282\uff0c\u6211\u5df2\u7ecf\u6536\u5230\u4e86<\/strong><\/p>\n\n\n\n<p> \u6ce8\u610f\uff1a<strong>\u53ea\u6709 ACK \u6807\u5fd7\u4f4d\u88ab\u7f6e\u4f4d\u65f6\uff0c\u8fd9\u4e2a\u5b57\u6bb5\u624d\u6709\u6548<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u516d\u3001TCP Flags\uff1a\u8fd9\u4e00\u7ae0\u7684\u201c\u7075\u9b42\u201d<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">6.1 Flags \u662f\u4ec0\u4e48\uff1f<\/h3>\n\n\n\n<p>Flags \u662f\u4e00\u7ec4 <strong>1 bit \u7684\u5f00\u5173<\/strong>\uff0c\u6bcf\u4e00\u4f4d\u4ee3\u8868\u4e00\u4e2a\u201c\u610f\u56fe\u201d\u3002<\/p>\n\n\n\n<p>\u4f60\u53ef\u4ee5\u7406\u89e3\u4e3a\uff1a<strong>\u201c\u6211\u53d1\u8fd9\u4e2a\u5305\uff0c\u662f\u60f3\u5e72\u4ec0\u4e48\u201d<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6.2 \u5e38\u89c1 TCP \u6807\u5fd7\u4f4d\u603b\u89c8<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u6807\u5fd7\u4f4d<\/th><th>\u542b\u4e49<\/th><th>\u6838\u5fc3\u7528\u9014<\/th><\/tr><\/thead><tbody><tr><td>SYN<\/td><td>Synchronize<\/td><td>\u8bf7\u6c42\u5efa\u7acb\u8fde\u63a5<\/td><\/tr><tr><td>ACK<\/td><td>Acknowledgment<\/td><td>\u786e\u8ba4\u6536\u5230<\/td><\/tr><tr><td>FIN<\/td><td>Finish<\/td><td>\u6b63\u5e38\u5173\u95ed\u8fde\u63a5<\/td><\/tr><tr><td>RST<\/td><td>Reset<\/td><td>\u5f3a\u5236\u4e2d\u65ad<\/td><\/tr><tr><td>PSH<\/td><td>Push<\/td><td>\u7acb\u5373\u4ea4\u7ed9\u5e94\u7528<\/td><\/tr><tr><td>URG<\/td><td>Urgent<\/td><td>\u7d27\u6025\u6570\u636e<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Nmap \u4e3b\u8981\u7528\u7684\u662f\u524d\u56db\u4e2a<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e03\u3001\u9010\u4e2a\u62c6\u89e3\u5173\u952e\u6807\u5fd7\u4f4d\uff08\u7ed3\u5408\u626b\u63cf\uff09<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">7.1 SYN\uff1a\u8fde\u63a5\u7684\u201c\u6572\u95e8\u58f0\u201d<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">SYN \u7684\u771f\u5b9e\u542b\u4e49\uff1a\u201c\u6211\u60f3\u548c\u4f60\u5efa\u7acb\u4e00\u4e2a TCP \u8fde\u63a5\u201d<\/h3>\n\n\n\n<p>\u7279\u5f81\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u8fde\u63a5\u7684\u7b2c\u4e00\u4e2a\u5305<\/li>\n\n\n\n<li>\u4e0d\u643a\u5e26\u6570\u636e<\/li>\n\n\n\n<li>\u6d88\u8017\u7cfb\u7edf\u8d44\u6e90\uff08\u534a\u8fde\u63a5\uff09<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">SYN \u5728\u626b\u63cf\u4e2d\u7684\u610f\u4e49<\/h3>\n\n\n\n<p>\u6b63\u5e38\u60c5\u51b5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN  \u2192\n\u2190 SYN + ACK\n<\/code><\/pre>\n\n\n\n<p>\u8bf4\u660e\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7aef\u53e3\u5f00\u653e<\/li>\n\n\n\n<li>\u670d\u52a1\u5728\u76d1\u542c<\/li>\n<\/ul>\n\n\n\n<p>\u7aef\u53e3\u5173\u95ed\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN  \u2192\n\u2190 RST\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Nmap \u5982\u4f55\u5229\u7528 SYN\uff1f<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -sS\n<\/code><\/pre>\n\n\n\n<p><strong>\u53ea\u53d1 SYN\uff0c\u770b\u56de\u5e94\uff0c\u4e0d\u5b8c\u6210\u8fde\u63a5<\/strong><\/p>\n\n\n\n<p>\u4f18\u70b9\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5feb<\/li>\n\n\n\n<li>\u9690\u853d<\/li>\n\n\n\n<li>\u4e0d\u6613\u88ab\u8bb0\u5f55\u5b8c\u6574\u4f1a\u8bdd<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">7.2 ACK\uff1a\u4e0d\u662f\u201c\u540c\u610f\u201d\uff0c\u800c\u662f\u201c\u786e\u8ba4\u201d<\/h2>\n\n\n\n<p> \u5f88\u591a\u65b0\u624b\u8bef\u4f1a ACK = \u540c\u610f\uff0c\u8fd9\u662f\u9519\u7684\u3002ACK \u7684\u771f\u5b9e\u542b\u4e49\uff1a<strong>\u201c\u6211\u786e\u8ba4\u4f60\u521a\u624d\u53d1\u7684\u4e1c\u897f\u201d<\/strong>\u5b83\u672c\u8eab<strong>\u4e0d\u8868\u793a\u8fde\u63a5\u72b6\u6001<\/strong>\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">ACK \u5728\u626b\u63cf\u4e2d\u7684\u4f5c\u7528\uff08\u975e\u5e38\u9ad8\u7ea7\uff09<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -sA\n<\/code><\/pre>\n\n\n\n<p>ACK \u626b\u63cf\u903b\u8f91\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u8fd4\u56de<\/th><th>\u542b\u4e49<\/th><\/tr><\/thead><tbody><tr><td>RST<\/td><td>\u672a\u88ab\u8fc7\u6ee4<\/td><\/tr><tr><td>\u65e0\u56de\u5e94<\/td><td>\u88ab\u9632\u706b\u5899\u8fc7\u6ee4<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>ACK \u626b\u63cf\u662f\u7528\u6765\u63a2\u6d4b\u9632\u706b\u5899\u89c4\u5219\u7684<\/strong>,\u4e0d\u662f\u4e3a\u4e86\u5224\u65ad\u7aef\u53e3\u5f00\u4e0d\u5f00\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7.3 RST\uff1a\u7f51\u7edc\u4e2d\u7684\u201c\u6302\u7535\u8bdd\u201d<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">RST \u7684\u771f\u5b9e\u542b\u4e49\u201c\u522b\u8bf4\u4e86\uff0c\u9a6c\u4e0a\u65ad\uff01\u201d<\/h3>\n\n\n\n<p>\u51fa\u73b0\u573a\u666f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7aef\u53e3\u4e0d\u5b58\u5728<\/li>\n\n\n\n<li>\u975e\u6cd5\u5305<\/li>\n\n\n\n<li>\u5f02\u5e38\u8fde\u63a5<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">RST \u5728\u626b\u63cf\u4e2d\u7684\u5730\u4f4d<\/h3>\n\n\n\n<p><strong>RST = \u975e\u5e38\u5f3a\u7684\u4fe1\u53f7<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u6536\u5230 RST<\/th><th>\u901a\u5e38\u8bf4\u660e<\/th><\/tr><\/thead><tbody><tr><td>SYN \u2192 RST<\/td><td>\u7aef\u53e3\u5173\u95ed<\/td><\/tr><tr><td>ACK \u2192 RST<\/td><td>\u9632\u706b\u5899\u672a\u62e6<\/td><\/tr><tr><td>\u5efa\u8fde\u4e2d RST<\/td><td>\u88ab\u62d2\u7edd<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e3a\u4ec0\u4e48 RST \u5bf9\u626b\u63cf\u8fd9\u4e48\u91cd\u8981\uff1f<\/h3>\n\n\n\n<p>\u56e0\u4e3a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5feb<\/li>\n\n\n\n<li>\u660e\u786e<\/li>\n\n\n\n<li>\u4e0d\u9700\u8981\u7b49\u5f85\u8d85\u65f6<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7.4 FIN\uff1a\u793c\u8c8c\u7684\u201c\u6211\u8bf4\u5b8c\u4e86\u201d<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">FIN \u7684\u771f\u5b9e\u542b\u4e49<\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201c\u6211\u8fd9\u8fb9\u4e0d\u53d1\u6570\u636e\u4e86\uff0c\u4f46\u8fd8\u80fd\u6536\u4f60\u7684\u201d\uff0cTCP \u662f\u5168\u53cc\u5de5\uff0c\u6240\u4ee5\u9700\u8981 <strong>\u56db\u6b21\u6325\u624b<\/strong>\u3002<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">FIN \u5728\u626b\u63cf\u4e2d\u7684\u5999\u7528\uff08\u7ecf\u5178\uff09<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -sF\n<\/code><\/pre>\n\n\n\n<p>\u903b\u8f91\u6765\u6e90\u4e8e RFC\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7aef\u53e3\u72b6\u6001<\/th><th>\u5bf9 FIN \u7684\u56de\u5e94<\/th><\/tr><\/thead><tbody><tr><td>open<\/td><td>\u5ffd\u7565<\/td><\/tr><tr><td>closed<\/td><td>RST<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>\u8fd9\u5c31\u662f FIN \/ NULL \/ Xmas \u626b\u63cf\u7684\u7406\u8bba\u57fa\u7840<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u516b\u3001\u7279\u6b8a\u626b\u63cf\u7684\u201c\u5305\u7ed3\u6784\u601d\u7ef4\u201d<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">8.1 NULL \u626b\u63cf\uff08\u65e0\u6807\u5fd7\u4f4d\uff09<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Flags = 0\n<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>open\uff1a\u6c89\u9ed8<\/li>\n\n\n\n<li>closed\uff1aRST<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">8.2 Xmas \u626b\u63cf<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>FIN + PSH + URG<\/code><\/pre>\n\n\n\n<p>\u201c\u50cf\u5723\u8bde\u6811\u4e00\u6837\u5168\u4eae\u201d\u5229\u7528\u7684\u662f\uff1a<strong>\u201c\u5f02\u5e38\u5305 + RFC \u884c\u4e3a\u5dee\u5f02\u201d<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e5d\u3001\u4e3a\u4ec0\u4e48\u201c\u6c89\u9ed8\u201d\u672c\u8eab\u662f\u4fe1\u606f\uff1f<\/h2>\n\n\n\n<p><strong>\u5728\u7f51\u7edc\u626b\u63cf\u4e2d\uff0c\u4e0d\u56de\u5e94 \u2260 \u6ca1\u6709\u4fe1\u606f<\/strong><\/p>\n\n\n\n<p>\u53ef\u80fd\u610f\u5473\u7740\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7aef\u53e3\u5f00\u653e\uff08UDP \/ FIN \u7c7b\u626b\u63cf\uff09<\/li>\n\n\n\n<li>\u9632\u706b\u5899\u8fc7\u6ee4<\/li>\n\n\n\n<li>IDS \u4e22\u5f03\u5f02\u5e38\u5305<\/li>\n<\/ul>\n\n\n\n<p> <strong>Nmap \u7684\u5f88\u591a\u5224\u65ad\uff0c\u6765\u81ea\u201c\u9884\u671f vs \u5b9e\u9645\u201d<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u5341\u3001\u628a\u4e00\u5207\u8fde\u8d77\u6765\uff08\u4ece\u5305 \u2192 \u534f\u8bae \u2192 Nmap\uff09<\/h2>\n\n\n\n<p>\u5e94\u8be5\u5f62\u6210\u8fd9\u6837\u7684\u94fe\u8def\u601d\u7ef4\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>TCP \u5305\u7ed3\u6784\n   \u2193\nFlags \u8868\u8fbe\u610f\u56fe\n   \u2193\n\u76ee\u6807\u7cfb\u7edf\u7684 RFC \u884c\u4e3a\n   \u2193\n\u8fd4\u56de\u5305 or \u6c89\u9ed8\n   \u2193\nNmap \u72b6\u6001\u5224\u65ad\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>SYN \u548c ACK \u5404\u81ea\u8868\u8fbe\u4ec0\u4e48\u201c\u610f\u56fe\u201d\uff1f<br>\u4e3a\u4ec0\u4e48 ACK \u626b\u63cf\u4e0d\u80fd\u5224\u65ad\u7aef\u53e3\u662f\u5426\u5f00\u653e\uff1f<br>\u4e3a\u4ec0\u4e48 RST \u662f\u626b\u63cf\u4e2d\u6700\u201c\u503c\u94b1\u201d\u7684\u54cd\u5e94\uff1f<br>\u4e3a\u4ec0\u4e48 FIN \u626b\u63cf\u5bf9 open \u7aef\u53e3\u53cd\u800c\u6ca1\u56de\u5e94\uff1f<br>\u4e3a\u4ec0\u4e48\u5f02\u5e38\u5305\u80fd\u7ed5\u8fc7\u90e8\u5206\u9632\u706b\u5899\uff1f<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c 4 \u7ae0\uff1a\u7aef\u53e3\u72b6\u6001\u673a\u7406<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">\u2014\u2014open \/ closed \/ filtered \u7684\u5e95\u5c42\u5224\u65ad\u903b\u8f91\uff08Nmap \u89c6\u89d2\uff09<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e00\u3001\u5148\u6253\u7834\u4e00\u4e2a\u65b0\u624b\u6700\u5e38\u89c1\u7684\u8bef\u89e3<\/h3>\n\n\n\n<p>\u5f88\u591a\u521d\u5b66\u8005\u4ee5\u4e3a\uff1aNmap \u80fd\u201c\u770b\u5230\u201d\u7aef\u53e3\u7aef\u53e3\u662f\u4e00\u4e2a\u201c\u771f\u5b9e\u5b58\u5728\u7684\u4e1c\u897f\u201d<strong>\u8fd9\u662f\u5b8c\u5168\u9519\u8bef\u7684\u3002<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u7aef\u53e3\u72b6\u6001\u4e0d\u662f\u201c\u88ab\u770b\u5230\u7684\u201d\uff0c\u800c\u662f\u201c\u88ab\u63a8\u65ad\u51fa\u6765\u7684\u201d\u3002<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>Nmap \u505a\u7684\u4e8b\u53ea\u6709\u4e09\u6b65\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u53d1\u9001\u7279\u5b9a\u7f51\u7edc\u5305\n\u2193\n\u89c2\u5bdf\u56de\u5e94\uff08\u6216\u6c89\u9ed8\uff09\n\u2193\n\u6839\u636e\u534f\u8bae\u89c4\u5219\u63a8\u65ad\u72b6\u6001<\/code><\/pre>\n\n\n\n<p><strong>\u7aef\u53e3\u72b6\u6001 = \u903b\u8f91\u63a8\u7406\u7ed3\u679c\uff0c\u4e0d\u662f\u4e8b\u5b9e\u62cd\u7167<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e8c\u3001Nmap \u80fd\u7ed9\u51fa\u7684\u201c\u6807\u51c6\u7aef\u53e3\u72b6\u6001\u201d<\/h3>\n\n\n\n<p>\u5148\u628a\u5168\u91cf\u72b6\u6001\u5217\u51fa\u6765\uff08\u540e\u9762\u9010\u4e2a\u62c6\uff09\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u72b6\u6001<\/th><th>\u542b\u4e49<\/th><\/tr><\/thead><tbody><tr><td>open<\/td><td>\u6709\u670d\u52a1\u5728\u76d1\u542c<\/td><\/tr><tr><td>closed<\/td><td>\u6ca1\u670d\u52a1\u76d1\u542c<\/td><\/tr><tr><td>filtered<\/td><td>\u88ab\u8fc7\u6ee4\uff0c\u65e0\u6cd5\u5224\u65ad<\/td><\/tr><tr><td>unfiltered<\/td><td>\u672a\u88ab\u8fc7\u6ee4\uff08\u4f46\u662f\u5426\u5f00\u653e\u672a\u77e5\uff09<\/td><\/tr><tr><td>open|filtered<\/td><td>\u5f00\u653e\u6216\u88ab\u8fc7\u6ee4<\/td><\/tr><tr><td>closed|filtered<\/td><td>\u5173\u95ed\u6216\u88ab\u8fc7\u6ee4\uff08\u5c11\u89c1\uff09<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>\u521d\u5b66\u9636\u6bb5\uff0c<strong>\u5fc5\u987b\u5403\u900f\u524d\u4e09\u4e2a\uff1aopen \/ closed \/ filtered<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e09\u3001open\uff08\u5f00\u653e\uff09\uff1a\u6700\u201c\u5e72\u8106\u201d\u7684\u72b6\u6001<\/h3>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>3.1 open \u7684\u672c\u8d28\u542b\u4e49<\/strong><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u76ee\u6807\u4e3b\u673a\u4e0a\uff0c\u6709\u8fdb\u7a0b\u5728\u76d1\u542c\u8be5\u7aef\u53e3\uff0c\u5e76\u613f\u610f\u56de\u5e94\u4f60<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u6ce8\u610f\u5173\u952e\u8bcd\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6709\u8fdb\u7a0b<\/li>\n\n\n\n<li>\u5728\u76d1\u542c<\/li>\n\n\n\n<li>\u613f\u610f\u56de\u5e94<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>3.2 TCP \u4e2d open \u662f\u600e\u4e48\u201c\u88ab\u786e\u8ba4\u201d\u7684\uff1f<\/strong><\/p>\n\n\n\n<p>\u5178\u578b SYN \u626b\u63cf\u6d41\u7a0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u4f60 \u2192 SYN \u2192\n\u76ee\u6807 \u2192 SYN+ACK \u2192\n<\/code><\/pre>\n\n\n\n<p>Nmap \u7acb\u523b\u5f97\u51fa\u7ed3\u8bba\uff1a<strong>ope<\/strong>,<strong>\u4e3a\u4ec0\u4e48\uff1fSYN+ACK \u53ea\u80fd\u7531\u201c\u6b63\u5728\u76d1\u542c\u7684\u7aef\u53e3\u201d\u53d1\u51fa<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>TCP Connect \u626b\u63cf<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN \u2192\n\u2190 SYN+ACK\nACK \u2192<\/code><\/pre>\n\n\n\n<p>\u8fde\u63a5\u6210\u529f = open<\/p>\n\n\n\n<p><strong>3.3 UDP \u4e2d open \u4e3a\u4ec0\u4e48\u201c\u5f88\u96be\u786e\u8ba4\u201d\uff1f<\/strong><\/p>\n\n\n\n<p>UDP \u6ca1\u6709\u63e1\u624b\u3002<\/p>\n\n\n\n<p>\u53ea\u6709\u4e24\u79cd\u60c5\u51b5\u80fd\u786e\u8ba4 open\uff1a<\/p>\n\n\n\n<p>\u60c5\u51b5 1\uff1a\u6536\u5230\u5e94\u7528\u5c42\u54cd\u5e94<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>UDP \u2192  \n\u2190 DNS \/ SNMP \/ NTP \u54cd\u5e94\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u60c5\u51b5 2\uff1a\u5df2\u77e5\u534f\u8bae\u7684\u201c\u6b63\u786e\u56de\u5e94\u6a21\u5f0f\u201d<\/h3>\n\n\n\n<p><strong>\u6240\u4ee5 UDP open \u5f88\u201c\u91d1\u8d35\u201d<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3.4 \u91cd\u8981\u7ed3\u8bba\uff08\u5fc5\u987b\u8bb0\u4f4f\uff09<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>open = \u660e\u786e\u7684\u3001\u6b63\u5411\u7684\u534f\u8bae\u54cd\u5e94<\/strong><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u56db\u3001closed\uff08\u5173\u95ed\uff09\uff1a\u6700\u201c\u76f4\u767d\u201d\u7684\u72b6\u6001<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">4.1 closed \u7684\u771f\u5b9e\u542b\u4e49<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u76ee\u6807\u4e3b\u673a\u5b58\u5728\uff0c\u4f46\u8be5\u7aef\u53e3\u6ca1\u6709\u8fdb\u7a0b\u76d1\u542c<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u6ce8\u610f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4e3b\u673a\u662f\u6d3b\u7684<\/li>\n\n\n\n<li>\u53ea\u662f\u7aef\u53e3\u6ca1\u4eba\u63a5\u7535\u8bdd<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">4.2 TCP \u4e2d closed \u7684\u5224\u5b9a\u903b\u8f91<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u6807\u51c6\u60c5\u51b5<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN \u2192\n\u2190 RST\n<\/code><\/pre>\n\n\n\n<p>RST \u7684\u610f\u601d\u662f\uff1a\u201c\u522b\u627e\u4e86\uff0c\u8fd9\u4e2a\u7aef\u53e3\u6ca1\u4eba\u201d, <strong>RST = closed \u7684\u94c1\u8bc1<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">4.3 UDP \u4e2d closed \u7684\u5224\u5b9a\u903b\u8f91<\/h2>\n\n\n\n<p>UDP \u6ca1 RST\uff0c\u7528\u7684\u662f ICMP\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>UDP \u2192\n\u2190 ICMP Destination Unreachable (Port)\n<\/code><\/pre>\n\n\n\n<p> \u660e\u786e\u544a\u8bc9\u4f60\uff1a\u7aef\u53e3\u4e0d\u53ef\u8fbe<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">4.4 \u4e00\u4e2a\u975e\u5e38\u91cd\u8981\u7684\u73b0\u5b9e\u5224\u65ad<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u9632\u706b\u5899\u5f88\u5c11\u201c\u4f2a\u9020 RST \u6216 ICMP\u201d<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u56e0\u4e3a\uff1a\u5bb9\u6613\u88ab\u8bc6\u522b,\u6210\u672c\u9ad8,\u6240\u4ee5\uff1aclosed \u901a\u5e38\u662f<strong>\u9ad8\u7f6e\u4fe1\u5ea6\u7ed3\u8bba<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e94\u3001filtered\uff08\u88ab\u8fc7\u6ee4\uff09\uff1a\u6700\u8ba9\u4eba\u56f0\u60d1\u7684\u72b6\u6001<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">5.1 filtered \u7684\u4e00\u53e5\u8bdd\u5b9a\u4e49<\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>Nmap \u7684\u63a2\u6d4b\u5305\uff0c\u6ca1\u80fd\u5230\u8fbe\u76ee\u6807\u7aef\u53e3\uff0c\u6216\u8005\u56de\u5e94\u88ab\u62e6\u622a<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u5173\u952e\u70b9\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4e0d\u662f\u7aef\u53e3\u72b6\u6001<\/li>\n\n\n\n<li>\u662f\u201c\u901a\u4fe1\u8def\u5f84\u72b6\u6001\u201d<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">5.2 filtered \u662f\u600e\u4e48\u201c\u88ab\u63a8\u65ad\u201d\u7684\uff1f<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u6838\u5fc3\u7279\u5f81\u53ea\u6709\u4e00\u4e2a\uff1a<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>\u53d1\u4e86\u5305\n\u2193\n\u4ec0\u4e48\u90fd\u6ca1\u56de\u6765\n<\/code><\/pre>\n\n\n\n<p>\u6ce8\u610f\uff1a<strong>\u6c89\u9ed8 \u2260 \u65e0\u4fe1\u606f<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">5.3 \u5e38\u89c1\u5bfc\u81f4 filtered \u7684\u539f\u56e0<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u539f\u56e0<\/th><th>\u89e3\u91ca<\/th><\/tr><\/thead><tbody><tr><td>\u9632\u706b\u5899<\/td><td>\u4e22\u5f03\u5305<\/td><\/tr><tr><td>ACL<\/td><td>\u62d2\u7edd\u7b56\u7565<\/td><\/tr><tr><td>IDS\/IPS<\/td><td>\u9759\u9ed8\u62e6\u622a<\/td><\/tr><tr><td>\u8def\u7531\u9650\u5236<\/td><td>\u5230\u4e0d\u4e86<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">5.4 TCP \u4e2d filtered \u7684\u5178\u578b\u573a\u666f<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN \u2192\n\uff08\u65e0\u56de\u5e94\uff09\n<\/code><\/pre>\n\n\n\n<p>Nmap \u7684\u63a8\u7406\u662f\uff1a\u201c\u6211\u4e0d\u77e5\u9053\u7aef\u53e3\u5f00\u6ca1\u5f00\uff0c\u4f46\u6211\u88ab\u6321\u4f4f\u4e86\u201d,<strong>filtered<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">5.5 UDP \u4e2d filtered \u66f4\u5e38\u89c1\uff08\u4e5f\u66f4\u75db\u82e6\uff09<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>UDP \u2192\n\uff08\u6c89\u9ed8\uff09\n<\/code><\/pre>\n\n\n\n<p>\u8fd9\u65f6 Nmap \u53ea\u80fd\u8bf4\uff1a<strong>open | filtered<\/strong><\/p>\n\n\n\n<p>\u56e0\u4e3a\uff1aopen \u7aef\u53e3\u53ef\u80fd\u4e0d\u56de,filtered \u4e5f\u4e0d\u56de<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u516d\u3001unfiltered\uff1a\u65b0\u624b\u6700\u5bb9\u6613\u8bef\u89e3\u7684\u72b6\u6001<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">6.1 unfiltered \u662f\u4ec0\u4e48\u610f\u601d\uff1f<\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u6570\u636e\u5305\u6ca1\u6709\u88ab\u9632\u706b\u5899\u62e6\u622a<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p> \u4f46\u6ce8\u610f\uff1a<strong>\u5e76\u4e0d\u7b49\u4e8e open<\/strong>,\u662f\u5426\u6709\u670d\u52a1\uff0c\u4e0d\u77e5\u9053<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">6.2 ACK \u626b\u63cf\u4e2d\u7684\u5178\u578b\u4f8b\u5b50<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>ACK \u2192\n\u2190 RST\n<\/code><\/pre>\n\n\n\n<p>\u8bf4\u660e\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5305\u8fdb\u53bb\u4e86<\/li>\n\n\n\n<li>\u9632\u706b\u5899\u6ca1\u6321<\/li>\n\n\n\n<li>\u81f3\u4e8e\u7aef\u53e3\u6709\u6ca1\u6709\u670d\u52a1\uff1a\u672a\u77e5<\/li>\n<\/ul>\n\n\n\n<p>\u72b6\u6001 = <strong>unfiltered<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e03\u3001open|filtered\uff1a\u4e0d\u662f Nmap \u201c\u4e0d\u786e\u5b9a\u201d\uff0c\u800c\u662f\u534f\u8bae\u5982\u6b64<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7.1 open|filtered \u51fa\u73b0\u7684\u771f\u5b9e\u539f\u56e0<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u534f\u8bae\u5141\u8bb8\u201c\u6c89\u9ed8\u5373\u5408\u7406\u201d<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u5178\u578b\u534f\u8bae\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>UDP<\/li>\n\n\n\n<li>TCP FIN \/ NULL \/ Xmas \u626b\u63cf<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7.2 \u5e94\u8be5\u5982\u4f55\u201c\u89e3\u8bfb\u201d open|filtered\uff1f<\/h2>\n\n\n\n<p>\u4e0d\u662f\u95ee\uff1a\u201c\u5b83\u5230\u5e95\u5f00\u6ca1\u5f00\uff1f\u201d\u800c\u662f\u95ee\uff1a\u201c\u6211\u8fd8\u80fd\u7528\u4ec0\u4e48\u65b9\u5f0f\u518d\u786e\u8ba4\uff1f\u201d<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u516b\u3001\u628a\u6240\u6709\u72b6\u6001\u653e\u8fdb\u4e00\u4e2a\u201c\u5224\u65ad\u77e9\u9635\u201d<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">TCP SYN \u626b\u63cf\u4e3a\u4f8b<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u8fd4\u56de<\/th><th>\u72b6\u6001<\/th><\/tr><\/thead><tbody><tr><td>SYN+ACK<\/td><td>open<\/td><\/tr><tr><td>RST<\/td><td>closed<\/td><\/tr><tr><td>\u65e0\u56de\u5e94<\/td><td>filtered<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">UDP \u626b\u63cf\u4e3a\u4f8b<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u8fd4\u56de<\/th><th>\u72b6\u6001<\/th><\/tr><\/thead><tbody><tr><td>\u5e94\u7528\u5c42\u54cd\u5e94<\/td><td>open<\/td><\/tr><tr><td>ICMP Port Unreachable<\/td><td>closed<\/td><\/tr><tr><td>\u65e0\u56de\u5e94<\/td><td>open|filtered<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e5d\u3001\u4e3a\u4ec0\u4e48\u201c\u7aef\u53e3\u72b6\u6001\u201d\u4e0d\u662f\u7edd\u5bf9\u771f\u7406\uff1f<\/h2>\n\n\n\n<p>\u4e00\u4e2a\u73b0\u5b9e\uff1a<strong>\u7aef\u53e3\u72b6\u6001 = \u5728\u5f53\u524d\u65f6\u95f4\u3001\u5f53\u524d\u8def\u5f84\u3001\u5f53\u524d\u89c4\u5219\u4e0b\u7684\u7ed3\u679c<\/strong><\/p>\n\n\n\n<p>\u6539\u53d8\u4efb\u4f55\u4e00\u4e2a\u53d8\u91cf\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u626b\u63cf\u65b9\u5f0f<\/li>\n\n\n\n<li>\u6e90 IP<\/li>\n\n\n\n<li>\u65f6\u95f4<\/li>\n\n\n\n<li>\u5305\u7279\u5f81<\/li>\n<\/ul>\n\n\n\n<p>\u7ed3\u679c\u90fd\u53ef\u80fd\u53d8\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u5341\u3001\u626b\u63cf\u601d\u7ef4\u6a21\u578b<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>\u6211\u53d1\u4e86\u4ec0\u4e48\u5305\uff1f\n\u2193\n\u534f\u8bae\u89c4\u5b9a\u5e94\u8be5\u5982\u4f55\u56de\u5e94\uff1f\n\u2193\n\u5b9e\u9645\u53d1\u751f\u4e86\u4ec0\u4e48\uff1f\n\u2193\n\u54ea\u4e2a\u72b6\u6001\u6700\u7b26\u5408\uff1f\n<\/code><\/pre>\n\n\n\n<p>\u800c\u4e0d\u662f\uff1a\u201cNmap \u8bf4 open\uff0c\u90a3\u5c31\u662f open\u3002\u201d<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p> \u533a\u5206\u201c\u7aef\u53e3\u72b6\u6001\u201d\u548c\u201c\u9632\u706b\u5899\u72b6\u6001\u201d<br> \u7406\u89e3\u6c89\u9ed8\u672c\u8eab\u5c31\u662f\u5224\u65ad\u4f9d\u636e<br> \u660e\u767d\u4e3a\u4ec0\u4e48 UDP \u7ed3\u679c\u603b\u662f\u6a21\u7cca<br> \u77e5\u9053\u4ec0\u4e48\u65f6\u5019\u8981\u201c\u6362\u626b\u63cf\u65b9\u5f0f\u9a8c\u8bc1\u201d<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c 5 \u7ae0\uff1aRTT\uff08Round-Trip Time\uff09\u8ba1\u7b97\u4e0e\u8d85\u65f6\u673a\u5236<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">\u2014\u2014Nmap \u4e3a\u4ec0\u4e48\u201c\u7b49\u591a\u4e45\u201d\u3001\u4ec0\u4e48\u65f6\u5019\u201c\u8be5\u653e\u5f03\u201d<\/h2>\n\n\n\n<p><em>Nmap \u662f\u5982\u4f55\u201c\u4f30\u7b97\u7f51\u7edc\u53cd\u5e94\u901f\u5ea6\u201d\u7684<\/em>\uff0c<em>\u8d85\u65f6\u4e0d\u662f\u62cd\u8111\u888b\uff0c\u800c\u662f\u57fa\u4e8e RTT \u7684\u52a8\u6001\u8ba1\u7b97<\/em>\u3002\u4e3a\u4ec0\u4e48\u540c\u6837\u7684\u547d\u4ee4\uff0c\u6709\u65f6\u98de\u5feb\uff0c\u6709\u65f6\u6162\u5230\u6000\u7591\u4eba\u751f\uff1b\u4e3a\u4ec0\u4e48 Nmap \u6709\u65f6\u201c\u8bef\u5224 filtered\u201d\uff1b\u4e3a\u4ec0\u4e48 <code>-T4<\/code> \u65e2\u9999\u53c8\u5371\u9669\u3002 <\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e00\u3001\u5148\u628a RTT \u8bf4\u5230\u201c\u4e00\u773c\u5c31\u61c2\u201d<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1.1 RTT \u662f\u4ec0\u4e48\uff1f<\/h4>\n\n\n\n<p>RTT\uff08Round-Trip Time\uff09= <strong>\u5f80\u8fd4\u65f6\u5ef6<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u4f60 \u2192 \u53d1\u5305 \u2192 \u76ee\u6807\n\u4f60 \u2190 \u56de\u5305 \u2190 \u76ee\u6807\n<\/code><\/pre>\n\n\n\n<p><strong>\u4ece\u201c\u53d1\u51fa\u201d\u5230\u201c\u6536\u5230\u56de\u5e94\u201d\u7684\u603b\u65f6\u95f4<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">1.2 \u751f\u6d3b\u5316\u7c7b\u6bd4\uff08\u975e\u5e38\u91cd\u8981\uff09<\/h4>\n\n\n\n<p>\u4f60\u6572\u95e8\u95ee\u4e00\u53e5\u8bdd\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u5bf9\u65b9 1 \u79d2\u5185\u56de\u5e94 \u2192 \u5f88\u8fd1<\/li>\n\n\n\n<li>5 \u79d2\u624d\u56de \u2192 \u5f88\u8fdc \/ \u5f88\u6162<\/li>\n\n\n\n<li>\u4e00\u76f4\u4e0d\u56de \u2192 \u4eba\u4e0d\u5728 \/ \u88ab\u4fdd\u5b89\u62e6\u4e86<\/li>\n<\/ol>\n\n\n\n<p><strong>Nmap \u505a\u7684\u4e8b\u60c5\u4e00\u6a21\u4e00\u6837<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e8c\u3001\u4e3a\u4ec0\u4e48 RTT \u662f\u201c\u626b\u63cf\u51c6\u786e\u6027\u201d\u7684\u57fa\u7840\uff1f<\/h3>\n\n\n\n<p>\u5148\u8bf4\u7ed3\u8bba\uff1a<strong>\u6240\u6709\u7aef\u53e3\u72b6\u6001\u5224\u65ad\uff0c\u90fd\u4f9d\u8d56\u4e8e\u201c\u6211\u7b49\u4e86\u591a\u4e45\u201d<\/strong><\/p>\n\n\n\n<p>\u5982\u679c\u4f60\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7b49\u592a\u77ed \u2192 \u628a\u201c\u6162\u56de\u5e94\u201d\u5f53\u6210 filtered<\/li>\n\n\n\n<li>\u7b49\u592a\u4e45 \u2192 \u626b\u63cf\u6162\u5230\u7206\u70b8<\/li>\n<\/ul>\n\n\n\n<p> <strong>RTT = \u51c6\u786e\u6027 vs \u901f\u5ea6\u7684\u5e73\u8861\u70b9<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e09\u3001RTT \u5728 TCP \u626b\u63cf\u4e2d\u7684\u771f\u5b9e\u8ba1\u7b97<\/h3>\n\n\n\n<p>\u6211\u4eec\u7528\u6700\u7ecf\u5178\u7684 <strong>TCP SYN \u626b\u63cf<\/strong> \u6765\u62c6\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">3.1 \u4e00\u4e2a\u6700\u57fa\u7840\u7684 RTT \u6837\u672c<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>t0\uff1a\u53d1\u9001 SYN\nt1\uff1a\u6536\u5230 SYN+ACK\nRTT = t1 - t0\n<\/code><\/pre>\n\n\n\n<p><strong>\u8fd9\u662f\u4e00\u4e2a\u201c\u5e72\u51c0\u201d\u7684 RTT \u6837\u672c<\/strong><\/p>\n\n\n\n<p>Nmap \u4f1a\uff1a\u8bb0\u5f55\u591a\u4e2a RTT\uff0c\u505a\u7edf\u8ba1\u8ba1\u7b97\uff08\u4e0d\u662f\u53ea\u4fe1\u4e00\u6b21\uff09<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">3.2 \u4e3a\u4ec0\u4e48\u8981\u201c\u591a\u6b21\u53d6\u6837\u201d\uff1f<\/h4>\n\n\n\n<p>\u56e0\u4e3a\u7f51\u7edc\u662f<strong>\u4e0d\u7a33\u5b9a\u7684<\/strong>\uff1a\u62e5\u585e\uff0c\u6296\u52a8\uff0c\u6392\u961f\uff0c\u8def\u7531\u53d8\u5316<\/p>\n\n\n\n<p> <strong>\u4e00\u6b21 RTT \u2260 \u771f\u5b9e RTT<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u56db\u3001Nmap \u5982\u4f55\u201c\u806a\u660e\u5730\u201d\u8ba1\u7b97 RTT\uff1f<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">4.1 Nmap \u4e0d\u662f\u7528\u201c\u5e73\u5747\u503c\u201d<\/h4>\n\n\n\n<p>\u800c\u662f\u7c7b\u4f3c\uff1a\u5e73\u6ed1 RTT\uff08Smoothed RTT\uff09\uff0cRTT \u65b9\u5dee\uff08RTT Variance\uff09<\/p>\n\n\n\n<p>\u539f\u7406\u548c TCP \u7684 <strong>RTO\uff08Retransmission Timeout\uff09<\/strong> \u975e\u5e38\u50cf\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">4.2 \u4e00\u4e2a\u76f4\u89c9\u516c\u5f0f\uff08\u4e0d\u7528\u6b7b\u8bb0\uff09<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>\u8d85\u65f6\u65f6\u95f4 \u2248 RTT + \u5b89\u5168\u4f59\u91cf\n<\/code><\/pre>\n\n\n\n<p>\u5b89\u5168\u4f59\u91cf\u53d6\u51b3\u4e8e\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>RTT \u6ce2\u52a8\u5927\u5c0f<\/li>\n\n\n\n<li>\u5f53\u524d\u626b\u63cf\u8d1f\u8f7d<\/li>\n\n\n\n<li>\u626b\u63cf\u7b56\u7565\uff08T0~T5\uff09<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e94\u3001\u8d85\u65f6\uff08Timeout\uff09\u673a\u5236\u7684\u6838\u5fc3\u903b\u8f91<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">5.1 \u4ec0\u4e48\u662f\u201c\u8d85\u65f6\u201d\uff1f<\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u5728\u9884\u671f\u65f6\u95f4\u5185\u6ca1\u7b49\u5230\u56de\u5e94\uff0c\u5c31\u8ba4\u4e3a\u201c\u8fd9\u6b21\u5931\u8d25\u4e86\u201d<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>\u6ce8\u610f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u8d85\u65f6 \u2260 \u7aef\u53e3\u4e00\u5b9a\u88ab\u8fc7\u6ee4<\/li>\n\n\n\n<li>\u8d85\u65f6 = <strong>\u8fd9\u6b21\u63a2\u6d4b\u6ca1\u5f97\u5230\u4fe1\u606f<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">5.2 TCP \u4e2d\u7684\u4e09\u79cd\u5178\u578b\u8d85\u65f6\u60c5\u5f62<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u60c5\u5f62 1\uff1a\u7aef\u53e3\u771f\u7684 filtered<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN \u2192\n\uff08\u9632\u706b\u5899\u4e22\u5f03\uff09\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u60c5\u5f62 2\uff1a\u7aef\u53e3 open\uff0c\u4f46\u7f51\u7edc\u6162<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN \u2192\n\uff08\u5ef6\u8fdf\u5f88\u4e45\uff09\n\u2190 SYN+ACK\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u60c5\u5f62 3\uff1a\u4e22\u5305<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN \u2192\n\uff08\u5305\u4e22\u4e86\uff09\n<\/code><\/pre>\n\n\n\n<p><strong>Nmap \u53ea\u80fd\u901a\u8fc7\u201c\u7b49\u5f85\u7b56\u7565\u201d\u6765\u533a\u5206<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u516d\u3001\u91cd\u4f20\uff08Retransmission\uff09\uff1aNmap \u7684\u201c\u518d\u95ee\u4e00\u6b21\u201d<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">6.1 \u4e3a\u4ec0\u4e48\u8981\u91cd\u4f20\uff1f<\/h3>\n\n\n\n<p>\u56e0\u4e3a\uff1a\u7f51\u7edc\u4e0d\u53ef\u9760\uff0c\u4e00\u6b21\u5931\u8d25\u4e0d\u80fd\u4e0b\u7ed3\u8bba<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">6.2 Nmap \u7684\u57fa\u672c\u7b56\u7565<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>\u53d1\u5305\n\u2193\n\u7b49\u8d85\u65f6\n\u2193\n\u91cd\u53d1\uff08\u6709\u9650\u6b21\u6570\uff09\n\u2193\n\u4ecd\u65e0\u56de\u5e94 \u2192 \u63a8\u65ad\u72b6\u6001\n<\/code><\/pre>\n\n\n\n<p><strong>\u4e0d\u662f\u65e0\u9650\u91cd\u8bd5<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">6.3 \u91cd\u4f20\u6b21\u6570\u7684\u5f71\u54cd<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u6b21\u6570<\/th><th>\u5f71\u54cd<\/th><\/tr><\/thead><tbody><tr><td>\u5c11<\/td><td>\u5feb\uff0c\u4f46\u8bef\u5224\u591a<\/td><\/tr><tr><td>\u591a<\/td><td>\u51c6\uff0c\u4f46\u6162<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e03\u3001RTT \u4e0e\u7aef\u53e3\u72b6\u6001\u201c\u8bef\u5224\u201d\u7684\u76f4\u63a5\u5173\u7cfb<\/h2>\n\n\n\n<p>\u8fd9\u662f\u65b0\u624b<strong>\u6700\u5bb9\u6613\u8e29\u5751\u7684\u5730\u65b9<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">7.1 RTT \u4f30\u5f97\u592a\u5c0f\uff0c\u4f1a\u53d1\u751f\u4ec0\u4e48\uff1f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6162\u94fe\u8def<\/li>\n\n\n\n<li>\u8de8\u56fd\u7f51\u7edc<\/li>\n\n\n\n<li>\u536b\u661f \/ \u79fb\u52a8\u7f51\u7edc<\/li>\n<\/ul>\n\n\n\n<p>\u7ed3\u679c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN \u2192\n\uff08\u8fd8\u5728\u8def\u4e0a\uff09\nNmap\uff1a\u8d85\u65f6 \u2192 filtered\n<\/code><\/pre>\n\n\n\n<p><strong>\u5047 filtered<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">7.2 RTT \u4f30\u5f97\u592a\u5927\uff0c\u4f1a\u53d1\u751f\u4ec0\u4e48\uff1f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u672c\u5730\u7f51\u7edc<\/li>\n\n\n\n<li>\u9ad8\u901f\u94fe\u8def<\/li>\n<\/ul>\n\n\n\n<p>\u7ed3\u679c\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6bcf\u4e2a\u7aef\u53e3\u90fd\u7b49\u5f88\u4e45<\/li>\n\n\n\n<li>\u626b\u63cf\u6548\u7387\u66b4\u8dcc<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u516b\u3001Nmap \u7684 Timing Template\uff08T0~T5\uff09\u672c\u8d28\u662f\u4ec0\u4e48\uff1f<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u4e00\u53e5\u8bdd\u771f\u76f8\uff1a<\/strong><br><code>-T<\/code> \u4e0d\u662f\u201c\u5feb\u6162\u5f00\u5173\u201d\uff0c\u800c\u662f <strong>RTT \/ \u8d85\u65f6 \/ \u5e76\u53d1 \/ \u91cd\u4f20\u7684\u7ec4\u5408\u9884\u8bbe<\/strong><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">8.1 \u5404 T \u6a21\u5f0f\u7684\u201c\u5e95\u5c42\u6027\u683c\u201d<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u6a21\u5f0f<\/th><th>RTT &amp; \u8d85\u65f6<\/th><th>\u6027\u683c<\/th><\/tr><\/thead><tbody><tr><td>T0<\/td><td>\u6781\u957f<\/td><td>\u975e\u5e38\u4fdd\u5b88<\/td><\/tr><tr><td>T1<\/td><td>\u5f88\u957f<\/td><td>\u6781\u6162<\/td><\/tr><tr><td>T2<\/td><td>\u7a33\u59a5<\/td><td>\u4f4e\u566a\u58f0<\/td><\/tr><tr><td>T3<\/td><td>\u5e73\u8861<\/td><td>\u9ed8\u8ba4<\/td><\/tr><tr><td>T4<\/td><td>\u8f83\u6fc0\u8fdb<\/td><td>\u5e38\u7528<\/td><\/tr><tr><td>T5<\/td><td>\u6781\u77ed<\/td><td>\u5bb9\u6613\u8bef\u5224<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">8.2 \u4e3a\u4ec0\u4e48 T5 \u7ecf\u5e38\u201c\u7ffb\u8f66\u201d\uff1f<\/h3>\n\n\n\n<p>\u56e0\u4e3a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>RTT \u4f30\u7b97\u4e0d\u8db3<\/li>\n\n\n\n<li>\u8d85\u65f6\u592a\u77ed<\/li>\n\n\n\n<li>\u91cd\u4f20\u6b21\u6570\u5c11<\/li>\n<\/ul>\n\n\n\n<p> <strong>\u201c\u6ca1\u56de \u2260 \u88ab\u8fc7\u6ee4\u201d\u88ab\u653e\u5927\u4e86<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e5d\u3001RTT \u4e0e UDP \u626b\u63cf\uff1a\u707e\u96be\u7ea7\u7ec4\u5408<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">9.1 UDP \u6ca1\u6709\u201c\u786e\u8ba4\u5305\u201d<\/h3>\n\n\n\n<p>TCP\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SYN \u2192 SYN+ACK\n<\/code><\/pre>\n\n\n\n<p>UDP\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>UDP \u2192\n\uff08\u6c89\u9ed8\u662f\u5408\u6cd5\u7684\uff09\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">9.2 UDP \u4e2d RTT \u7684\u5c34\u5c2c\u73b0\u5b9e<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6ca1\u6709\u660e\u786e\u201c\u6210\u529f\u4fe1\u53f7\u201d<\/li>\n\n\n\n<li>\u53ea\u80fd\u9760 ICMP \u6216\u5e94\u7528\u56de\u5e94<\/li>\n\n\n\n<li>RTT \u53ea\u80fd\u7528\u4e8e\u201c\u7b49\u591a\u4e45\u653e\u5f03\u201d<\/li>\n<\/ul>\n\n\n\n<p><strong>\u6240\u4ee5 UDP \u626b\u63cf\u5fc5\u7136\u6162<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u5341\u3001RTT\u3001\u5e76\u53d1\uff08Parallelism\uff09\u4e0e\u201c\u81ea\u6211 DDoS\u201d<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">10.1 \u5e76\u53d1\u626b\u63cf\u610f\u5473\u7740\u4ec0\u4e48\uff1f<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>\u540c\u65f6\u53d1\u5f88\u591a\u5305\n\u2193\n\u7f51\u7edc\u6392\u961f\n\u2193\nRTT \u4eba\u4e3a\u53d8\u5927\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">10.2 Nmap \u7684\u81ea\u9002\u5e94\u8c03\u8282<\/h3>\n\n\n\n<p>\u5f53 Nmap \u53d1\u73b0\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>RTT \u7a81\u7136\u4e0a\u5347<\/li>\n\n\n\n<li>\u4e22\u5305\u53d8\u591a<\/li>\n<\/ul>\n\n\n\n<p>\u5b83\u4f1a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u964d\u4f4e\u5e76\u53d1<\/li>\n\n\n\n<li>\u62c9\u957f\u8d85\u65f6<\/li>\n<\/ul>\n\n\n\n<p> <strong>Nmap \u4f1a\u201c\u8e29\u5239\u8f66\u201d<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u8de8\u56fd\u626b\u63cf\u6162<\/strong>\uff0cRTT \u9ad8\uff0c\u8d85\u65f6\u5e94\u653e\u5bbd<\/li>\n\n\n\n<li><strong>filtered \u7279\u522b\u591a<\/strong>\uff0c\u53ef\u80fd RTT \u4f30\u7b97\u8fc7\u5c0f<\/li>\n\n\n\n<li><strong>UDP \u51e0\u4e4e\u5168\u662f open|filtered<\/strong>\uff0c\u6b63\u5e38\uff0c\u4e0d\u662f\u5931\u8d25<\/li>\n\n\n\n<li><strong>T5 \u5f88\u723d\u4f46\u7ed3\u679c\u602a<\/strong>\uff0c\u8d85\u65f6\u4e0e\u91cd\u4f20\u4e0d\u591f<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>Nmap \u4e0d\u662f\u5728\u201c\u5224\u65ad\u7aef\u53e3\u201d\uff0c\u800c\u662f\u5728\u201c\u548c\u7f51\u7edc\u505a\u535a\u5f08\u201d\u3002<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>RTT \u548c\u8d85\u65f6\u673a\u5236= Nmap \u5224\u65ad\u4e16\u754c\u7684\u201c\u65f6\u95f4\u611f\u201d\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c 5 \u7ae0\uff1aIPv4 vs IPv6 \u57fa\u7840\u5dee\u5f02\u53ca\u5176\u5728\u626b\u63cf\u4e2d\u7684\u5f71\u54cd<\/h2>\n\n\n\n<p><strong><em>IPv4 \u548c IPv6 \u4e4b\u95f4\u7684\u5dee\u5f02\uff0c\u5982\u4f55\u5f71\u54cd\u7aef\u53e3\u626b\u63cf<\/em>,<em>Nmap \u5982\u4f55\u5904\u7406\u8fd9\u4e24\u79cd\u534f\u8bae\uff0c\u5982\u4f55\u5e94\u5bf9 IPv6 \u626b\u63cf\u7684\u590d\u6742\u6027<\/em>\u2014\u2014\u4e3a\u4ec0\u4e48 IPv6 \u626b\u63cf\u6311\u6218\u66f4\u5927\uff0c\u5982\u4f55\u5e94\u5bf9\uff1f<\/strong><br><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e00\u3001IPv4 \u548c IPv6 \u57fa\u7840\u5dee\u5f02<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1.1 IPv4 \u7b80\u5355\u5b9a\u4e49<\/h4>\n\n\n\n<p>IPv4\uff08Internet Protocol version 4\uff09\u662f\u6700\u5e7f\u6cdb\u4f7f\u7528\u7684\u534f\u8bae\uff0cIPv4 \u5730\u5740\u662f<strong>32 \u4f4d<\/strong>\uff084 \u5b57\u8282\uff09\uff0c\u8868\u793a\u4e3a\u56db\u7ec4\u5341\u8fdb\u5236\u6570\uff0c\u6bcf\u7ec4 0~255\uff0c\u4f8b\u5982\uff1a192.168.1.1<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u7279\u70b9\uff1a<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5730\u5740\u603b\u6570\uff1a<strong>\u7ea6 43 \u4ebf<\/strong>\u4e2a\uff082^32\uff09<\/li>\n\n\n\n<li>\u7528\u4e8e\u5168\u7403\u4e92\u8054\u7f51\u901a\u4fe1<\/li>\n\n\n\n<li>\u76f8\u5bf9\u7b80\u6d01\uff0c\u4f46\u56e0\u5730\u5740\u67af\u7aed\u95ee\u9898\uff0c\u9010\u6e10\u88ab IPv6 \u66ff\u4ee3<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">1.2 IPv6 \u7b80\u5355\u5b9a\u4e49<\/h2>\n\n\n\n<p>IPv6\uff08Internet Protocol version 6\uff09\u662f\u4e3a\u4e86\u89e3\u51b3 IPv4 \u5730\u5740\u67af\u7aed\u95ee\u9898\u800c\u63a8\u51fa\u7684\u4e0b\u4e00\u4ee3\u534f\u8bae\u3002IPv6 \u5730\u5740\u662f <strong>128 \u4f4d<\/strong>\uff0816 \u5b57\u8282\uff09\uff0c\u8868\u793a\u4e3a\u516b\u7ec4 16 \u8fdb\u5236\u6570\uff0c\u6bcf\u7ec4 4 \u4e2a\u5b57\u7b26\uff0c\u4f8b\u5982\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>2001:0db8:85a3:0000:0000:8a2e:0370:7334\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u7279\u70b9\uff1a<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5730\u5740\u603b\u6570\uff1a<strong>\u7ea6 3.4 \u00d7 10^38<\/strong>\uff082^128\uff09<\/li>\n\n\n\n<li>\u66f4\u590d\u6742\u7684\u5730\u5740\u4f53\u7cfb\uff0c\u8bbe\u8ba1\u66f4\u73b0\u4ee3\uff0c\u5305\u542b\u66f4\u591a\u7684\u529f\u80fd\uff08\u5982\u81ea\u52a8\u914d\u7f6e\u3001\u5185\u7f6e\u5b89\u5168\u6027\u7b49\uff09<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e8c\u3001IPv4 \u4e0e IPv6 \u7684\u5173\u952e\u533a\u522b<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7279\u6027<\/th><th>IPv4<\/th><th>IPv6<\/th><\/tr><\/thead><tbody><tr><td>\u5730\u5740\u957f\u5ea6<\/td><td>32 \u4f4d<\/td><td>128 \u4f4d<\/td><\/tr><tr><td>\u5730\u5740\u8868\u793a<\/td><td>\u70b9\u5206\u5341\u8fdb\u5236\uff08\u4f8b\u5982 192.168.1.1\uff09<\/td><td>\u5341\u516d\u8fdb\u5236\uff1a\u7528\u5192\u53f7\u5206\u9694\uff08\u4f8b\u5982 2001:0db8:&#8230;\uff09<\/td><\/tr><tr><td>\u5730\u5740\u7c7b\u578b<\/td><td>\u5355\u64ad\u3001\u5e7f\u64ad\u3001\u591a\u64ad<\/td><td>\u5355\u64ad\u3001\u7ec4\u64ad\uff08\u65e0\u5e7f\u64ad\uff09<\/td><\/tr><tr><td>\u5730\u5740\u5206\u914d<\/td><td>\u9759\u6001\u6216\u52a8\u6001\uff08DHCP\uff09<\/td><td>\u9759\u6001\u5206\u914d\u6216\u81ea\u52a8\u914d\u7f6e\uff08SLAAC\uff09<\/td><\/tr><tr><td>\u6821\u9a8c\u548c<\/td><td>\u5fc5\u987b\u8ba1\u7b97<\/td><td>\u65e0\u9700\u8ba1\u7b97<\/td><\/tr><tr><td>\u8def\u7531\u8868\u5927\u5c0f<\/td><td>\u8f83\u5c0f<\/td><td>\u8f83\u5927\uff08\u56e0\u5730\u5740\u7a7a\u95f4\u5de8\u5927\uff09<\/td><\/tr><tr><td>\u5b89\u5168\u7279\u6027<\/td><td>\u9700\u8981\u5916\u90e8\u52a0\u5bc6\uff08\u5982 IPSec\uff09<\/td><td>\u5185\u5efa IPSec<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e09\u3001Nmap \u5bf9 IPv4 \u4e0e IPv6 \u626b\u63cf\u7684\u652f\u6301\u5dee\u5f02<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">3.1 Nmap \u5bf9 IPv4 \u7684\u626b\u63cf<\/h4>\n\n\n\n<p>Nmap \u9ed8\u8ba4\u626b\u63cf IPv4 \u5730\u5740\uff0c\u901a\u8fc7 <strong>TCP\u3001UDP\u3001ICMP<\/strong> \u7b49\u534f\u8bae\u6765\u5b8c\u6210\u4e3b\u673a\u53d1\u73b0\u548c\u7aef\u53e3\u626b\u63cf\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u5df2\u7ecf\u7ecf\u8fc7\u591a\u5e74\u7684\u4f18\u5316\uff0c<strong>\u652f\u6301\u7684\u534f\u8bae\u3001\u626b\u63cf\u65b9\u5f0f\u975e\u5e38\u4e30\u5bcc<\/strong>\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u57fa\u672c\u64cd\u4f5c\uff1a<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap 192.168.1.1       # IPv4 \u626b\u63cf<\/code><\/pre>\n\n\n\n<p>Nmap \u4f1a\u53d1\u9001 SYN\u3001ACK\u3001FIN\u3001UDP \u7b49\u7c7b\u578b\u7684\u5305\u6765\u5224\u65ad\u7aef\u53e3\u72b6\u6001\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">3.2 Nmap \u5bf9 IPv6 \u7684\u626b\u63cf<\/h4>\n\n\n\n<p>\u5bf9\u4e8e IPv6\uff0cNmap \u540c\u6837\u652f\u6301\uff0c\u4f46\u76f8\u6bd4 IPv4\uff0c\u5b83<strong>\u9762\u4e34\u66f4\u591a\u7684\u6311\u6218<\/strong>\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5730\u5740\u7a7a\u95f4\u5de8\u5927<\/strong><br>IPv6 \u5730\u5740\u7a7a\u95f4\u6781\u5927\uff0c\u4f20\u7edf\u7684 <strong>ping \u626b\u63cf<\/strong>\uff08\u4f7f\u7528 ICMP\uff09\u53d8\u5f97\u4e0d\u90a3\u4e48\u9002\u7528\uff0c\u56e0\u4e3a\u626b\u63cf\u8303\u56f4\u975e\u5e38\u5e9e\u5927\u3002<\/li>\n\n\n\n<li><strong>\u9632\u706b\u5899\u548c\u8def\u7531\u5668\u8fc7\u6ee4\u95ee\u9898<\/strong><br>IPv6 \u7684 <strong>\u9632\u706b\u5899\u548c\u8def\u7531\u5668<\/strong>\u901a\u5e38\u6bd4 IPv4 \u66f4\u4e25\u683c\uff0c\u5c24\u5176\u5728 <strong>\u81ea\u52a8\u914d\u7f6e<\/strong>\u548c <strong>\u94fe\u8def\u672c\u5730\u5730\u5740<\/strong>\u7684\u60c5\u51b5\u4e0b\uff0c<strong>\u9632\u706b\u5899\u7684\u62e6\u622a\u66f4\u52a0\u9891\u7e41<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u5e7f\u64ad\u95ee\u9898<\/strong><br>IPv6 \u4e0d\u652f\u6301\u5e7f\u64ad\uff0c\u53ea\u652f\u6301\u5355\u64ad\u548c\u7ec4\u64ad\uff0c\u56e0\u6b64<strong>\u5e7f\u64ad\u626b\u63cf<\/strong>\uff08Nmap \u7684\u4e00\u4e9b\u626b\u63cf\u65b9\u5f0f\uff09\u5728 IPv6 \u4e2d\u4e0d\u518d\u9002\u7528\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">IPv6 \u626b\u63cf\u7684\u57fa\u672c\u64cd\u4f5c\uff1a<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -6 2001:0db8:85a3:0000:0000:8a2e:0370:7334   # IPv6 \u626b\u63cf\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u56db\u3001IPv6 \u626b\u63cf\u4e2d\u7684\u5e38\u89c1\u6311\u6218<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">4.1 \u5730\u5740\u7a7a\u95f4\u7684\u6311\u6218<\/h4>\n\n\n\n<p><strong>IPv6 \u5730\u5740\u7a7a\u95f4\u5de8\u5927\uff0c\u5982\u4f55\u6709\u6548\u626b\u63cf\uff1f<\/strong><\/p>\n\n\n\n<p>\u7531\u4e8e <strong>IPv6 \u7684\u5730\u5740\u7a7a\u95f4\u4e3a 128 \u4f4d<\/strong>\uff0c\u5728\u626b\u63cf\u65f6\uff0c<strong>Nmap \u65e0\u6cd5\u50cf IPv4 \u90a3\u6837\u76f4\u63a5\u626b\u4e00\u6574\u4e2a\u7f51\u7edc\u8303\u56f4<\/strong>\u3002\u56e0\u6b64\uff0cNmap \u5bf9 IPv6 \u7f51\u7edc\u7684\u626b\u63cf\u4e3b\u8981\u4f9d\u8d56\u4e8e\u4ee5\u4e0b\u65b9\u5f0f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u6307\u5b9a\u8303\u56f4<\/strong>\uff1a\u4f8b\u5982\u626b\u63cf\u67d0\u4e2a\u7279\u5b9a\u7684\u7f51\u7edc\u6bb5\u3002<\/li>\n\n\n\n<li><strong>\u4f7f\u7528\u57df\u540d\u89e3\u6790<\/strong>\uff1a\u4f7f\u7528 <code>-6<\/code> \u53c2\u6570\u548c\u57df\u540d\u89e3\u6790\uff0c\u4f7f Nmap \u80fd\u591f\u626b\u63cf\u4e0e\u4e4b\u76f8\u5173\u7684 IPv6 \u5730\u5740\u3002<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -6 example.com    # \u4f7f\u7528\u57df\u540d\u89e3\u6790 IPv6 \u5730\u5740\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">4.2 \u81ea\u52a8\u914d\u7f6e\u4e0e SLAAC\uff08Stateless Address Autoconfiguration\uff09<\/h4>\n\n\n\n<h3 class=\"wp-block-heading\">IPv6 \u5730\u5740\u5206\u914d<\/h3>\n\n\n\n<p>IPv6 \u652f\u6301 <strong>SLAAC\uff08\u65e0\u72b6\u6001\u5730\u5740\u81ea\u52a8\u914d\u7f6e\uff09<\/strong>\uff0c\u5373\u8bbe\u5907\u5728\u65e0 DHCP \u670d\u52a1\u5668\u7684\u60c5\u51b5\u4e0b\u6839\u636e\u7f51\u7edc\u524d\u7f00\u81ea\u52a8\u751f\u6210\u5730\u5740\uff0c\u8fd9\u5bfc\u81f4\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u52a8\u6001\u751f\u6210\u7684\u5730\u5740<\/strong>\uff1a\u4f7f\u5f97\u7f51\u7edc\u626b\u63cf\u9762\u4e34\u66f4\u591a\u7684\u6311\u6218\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u62d3\u6251\u7684\u53d8\u5316<\/strong>\uff1aIPv6 \u7f51\u7edc\u62d3\u6251\u53ef\u80fd\u9891\u7e41\u53d8\u5316\uff0c\u8bbe\u5907\u79bb\u7ebf\u540e\u5f88\u53ef\u80fd\u7acb\u5373\u88ab\u5176\u4ed6\u8bbe\u5907\u63a5\u7ba1\u5176\u5730\u5740\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">4.3 \u9632\u706b\u5899\u4e0e\u8def\u7531\u95ee\u9898<\/h4>\n\n\n\n<p>IPv6 \u9632\u706b\u5899\u7684\u8fc7\u6ee4\u673a\u5236\u548cNAT\uff08\u7f51\u7edc\u5730\u5740\u8f6c\u6362\uff09\u7684\u7f3a\u5931\uff0c\u4f7f\u5f97\u626b\u63cf\u9762\u4e34\u66f4\u9ad8\u7684\u6311\u6218\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>NAT \u4e0d\u518d\u4f7f\u7528<\/strong>\uff0c\u56e0\u6b64\u6bcf\u53f0\u8bbe\u5907\u7684\u6bcf\u4e2a\u5730\u5740\u5728\u516c\u7f51\u90fd\u53ef\u4ee5\u76f4\u63a5\u8bbf\u95ee\uff0c\u8fd9\u53ef\u80fd\u5bfc\u81f4\u626b\u63cf\u65f6 <strong>\u7aef\u53e3\u8fc7\u6ee4\u89c4\u5219\u66f4\u52a0\u4e25\u683c<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u7aef\u53e3\u626b\u63cf\u7684\u9690\u853d\u6027<\/strong>\uff1a\u4e00\u4e9b\u9632\u706b\u5899\u4f1a\u5728 IPv6 \u4e0a\u4f7f\u7528\u66f4\u52a0\u590d\u6742\u7684\u89c4\u5219\uff0c\u751a\u81f3\u662f\u57fa\u4e8e IPsec \u7684\u52a0\u5bc6\u548c\u9a8c\u8bc1\uff0c\u9020\u6210 <strong>\u626b\u63cf\u65f6\u96be\u4ee5\u5224\u65ad\u7aef\u53e3\u72b6\u6001<\/strong>\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e94\u3001\u5982\u4f55\u6709\u6548\u5730\u8fdb\u884c IPv6 \u626b\u63cf\uff1f<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>5.1 \u8bbe\u7f6e\u626b\u63cf\u76ee\u6807\u8303\u56f4<\/strong><\/h4>\n\n\n\n<p><strong>\u626b\u63cf\u67d0\u4e2a\u7279\u5b9a\u7684 IPv6 \u5730\u5740\u6bb5\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -6 2001:0db8:85a3::\/64   # \u626b\u63cf\u6574\u4e2a\u5b50\u7f51\n<\/code><\/pre>\n\n\n\n<p>\u8fd9\u79cd\u65b9\u5f0f\u53ef\u4ee5\u76f4\u63a5\u626b\u63cf\u6574\u4e2a IPv6 \u5b50\u7f51\uff0c<strong>\u4f46\u662f\u6ce8\u610f<\/strong>\uff1a\u7531\u4e8e IPv6 \u5730\u5740\u8303\u56f4\u7684\u5de8\u5927\uff0c\u8fd9\u4e2a\u8fc7\u7a0b <strong>\u975e\u5e38\u6162<\/strong>\uff0c\u4e14\u901a\u5e38\u4f1a<strong>\u53d7\u5230\u8def\u7531\u548c\u9632\u706b\u5899\u9650\u5236<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">5.2 ICMP \u63a2\u6d4b\uff08\u4e3b\u673a\u53d1\u73b0\uff09<\/h4>\n\n\n\n<p>IPv6 \u7684\u4e3b\u673a\u53d1\u73b0\u901a\u5e38\u4f9d\u8d56 <strong>ICMPv6<\/strong>\uff0c\u56e0\u4e3a <strong>IPv6 \u6ca1\u6709\u5e7f\u64ad<\/strong>\uff0c\u56e0\u6b64\u53ea\u80fd\u4f7f\u7528 <strong>\u90bb\u5c45\u53d1\u73b0\u534f\u8bae\uff08NDP\uff09<\/strong> \u6765\u53d1\u73b0\u4e3b\u673a\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -6 -sn 2001:0db8:85a3::\/64   # \u4ec5\u505a\u4e3b\u673a\u53d1\u73b0\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">5.3 \u626b\u63cf IPv6 \u4e2d\u7684\u7279\u5b9a\u670d\u52a1<\/h4>\n\n\n\n<p>\u548c IPv4 \u4e00\u6837\uff0c\u53ef\u4ee5\u4f7f\u7528\u4e0d\u540c\u7684\u626b\u63cf\u65b9\u5f0f\u6765\u5bf9 IPv6 \u5730\u5740\u4e0a\u7684\u670d\u52a1\u8fdb\u884c\u8bc6\u522b\uff0c\u4f46\u9700\u8981\u6ce8\u610f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u591a\u6b21\u5c1d\u8bd5<\/strong>\uff1aIPv6 \u7684\u914d\u7f6e\u548c\u8def\u7531\u53ef\u80fd\u5bfc\u81f4\u4e00\u4e9b\u670d\u52a1\u53d8\u5f97\u4e0d\u53ef\u8bbf\u95ee\uff0c\u56e0\u6b64\u53ef\u80fd\u9700\u8981 <strong>\u591a\u6b21\u626b\u63cf<\/strong> \u6216 <strong>\u589e\u52a0\u8d85\u65f6\u65f6\u95f4<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u66f4\u591a\u914d\u7f6e<\/strong>\uff1a\u56e0\u4e3a IPv6 \u7684\u8def\u7531\u5668\u548c\u9632\u706b\u5899\u901a\u5e38\u6bd4 IPv4 \u66f4\u4e25\u683c\uff0c\u53ef\u80fd\u9700\u8981\u8c03\u6574\u626b\u63cf\u7684\u53c2\u6570\uff0c\u5982\u4f7f\u7528 <code>-T4<\/code> \u6216 <code>-T5<\/code>\uff08\u5feb\u901f\u626b\u63cf\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u516d\u3001IPv4 \u548c IPv6 \u5728\u7aef\u53e3\u626b\u63cf\u4e2d\u7684\u6838\u5fc3\u5dee\u5f02<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7279\u6027<\/th><th>IPv4<\/th><th>IPv6<\/th><\/tr><\/thead><tbody><tr><td>\u5730\u5740\u8868\u793a<\/td><td>32 \u4f4d\uff0c\u70b9\u5206\u5341\u8fdb\u5236\uff08\u4f8b\u5982 192.168.1.1\uff09<\/td><td>128 \u4f4d\uff0c\u5341\u516d\u8fdb\u5236\uff0c\u5192\u53f7\u5206\u9694\uff08\u4f8b\u5982 2001:0db8:&#8230;\uff09<\/td><\/tr><tr><td>\u5730\u5740\u6570\u91cf<\/td><td>\u7ea6 43 \u4ebf<\/td><td>\u7ea6 3.4 \u00d7 10^38<\/td><\/tr><tr><td>\u4e3b\u673a\u53d1\u73b0<\/td><td>ICMP Echo Request \/ ARP<\/td><td>ICMPv6 Neighbor Solicitation<\/td><\/tr><tr><td>\u7f51\u7edc\u626b\u63cf\u65b9\u5f0f<\/td><td>\u5e7f\u64ad\u3001\u5355\u64ad\u3001\u591a\u64ad<\/td><td>\u65e0\u5e7f\u64ad\uff0c\u53ea\u80fd\u4f7f\u7528\u5355\u64ad\u548c\u7ec4\u64ad<\/td><\/tr><tr><td>\u9632\u706b\u5899\u8bbe\u7f6e<\/td><td>NAT\uff0c\u79c1\u6709\u5730\u5740\uff0c\u7aef\u53e3\u6620\u5c04<\/td><td>\u65e0 NAT\uff0c\u5168\u7403\u552f\u4e00\u5730\u5740\uff0c\u6bcf\u4e2a\u8bbe\u5907\u516c\u5f00\u53ef\u89c1<\/td><\/tr><tr><td>\u626b\u63cf\u65b9\u5f0f\u7684\u96be\u5ea6<\/td><td>\u4f20\u7edf\u7684\u7aef\u53e3\u626b\u63cf\u76f8\u5bf9\u7b80\u5355<\/td><td>\u5730\u5740\u5206\u914d\u52a8\u6001\u3001\u626b\u63cf\u96be\u5ea6\u8f83\u5927<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>\u597d\uff0c\u8fd9\u4e00\u90e8\u5206<strong>\u975e\u5e38\u5173\u952e<\/strong>\uff0c\u800c\u4e14\u4f60\u6293\u7684\u70b9\u5f88\u51c6\uff1a<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u201c\u626b\u63cf\u5931\u8d25 \u2260 \u7528\u9519\u5de5\u5177\uff0c\u800c\u662f\u4e0d\u4f1a\u6392\u9519\u201d<\/strong><br>\u5bf9\u521d\u5b66\u8005\u6765\u8bf4\uff0cNmap \u7684\u5b66\u4e60\u66f2\u7ebf\u5f80\u5f80\u4e0d\u662f\u201c\u4e0d\u4f1a\u7528\u201d\uff0c\u800c\u662f\u201c\u7528\u4e86\u5374\u6ca1\u7ed3\u679c\u3001\u770b\u4e0d\u61c2\u3001\u4e0d\u77e5\u9053\u54ea\u91cc\u51fa\u95ee\u9898\u201d\u3002<\/p>\n<\/blockquote>\n\n\n\n<p>\u4e0b\u9762\u6211\u4f1a<strong>\u4ee5\u201c\u5199\u8fdb\u6559\u7a0b\u5373\u53ef\u7528\u201d\u7684\u6807\u51c6<\/strong>\uff0c\u5e2e\u4f60\u8865\u5168 <strong>\u7b2c 2 \u7ae0\uff1a\u6545\u969c\u6392\u9664\u4e0e\u5e38\u89c1\u95ee\u9898\u5904\u7406<\/strong>\u3002<br>\u98ce\u683c\u4e0a\u6211\u4f1a\u523b\u610f <strong>\u6162\u3001\u767d\u8bdd\u3001\u6b65\u9aa4\u5316<\/strong>\uff0c\u786e\u4fdd<strong>\u96f6\u57fa\u7840\u4e5f\u80fd\u8ddf\u7740\u6392<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6545\u969c\u6392\u9664\u4e0e\u5e38\u89c1\u95ee\u9898\u5904\u7406\uff08Troubleshooting\uff09<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u672c\u7ae0\u8282\u7528\u4e8e\u89e3\u51b3\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u626b\u63cf\u6ca1\u6709\u7ed3\u679c<\/li>\n\n\n\n<li>\u626b\u63cf\u76f4\u63a5\u5931\u8d25<\/li>\n\n\n\n<li>\u8f93\u51fa\u770b\u4e0d\u61c2<\/li>\n\n\n\n<li>\u62a5\u9519\u4f46\u4e0d\u77e5\u9053\u95ee\u9898\u5728\u54ea<\/li>\n<\/ul>\n\n\n\n<p><strong>\u5982\u679c\u4f60\u5728\u4f7f\u7528 Nmap \u65f6\u201c\u611f\u89c9\u5b83\u574f\u4e86\u201d\uff0c\u8bf7\u5148\u8bfb\u8fd9\u4e00\u7ae0\u3002<\/strong><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.1 \u5e38\u89c1\u9519\u8bef\u8bca\u65ad\uff08\u521d\u5b66\u8005\u5fc5\u770b\uff09<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">2.1.1 \u6743\u9650\u4e0d\u8db3\uff08\u6700\u5e38\u89c1\u9519\u8bef\u4e4b\u4e00\uff09<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u5178\u578b\u8868\u73b0<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>You requested a scan type which requires root privileges.\n<\/code><\/pre>\n\n\n\n<p>\u6216\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>WARNING: TCP SYN Scan requires root privileges.\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u539f\u56e0<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Nmap \u7684<strong>\u67d0\u4e9b\u626b\u63cf\u65b9\u5f0f<\/strong>\uff08\u5982 SYN \u626b\u63cf\uff09<\/li>\n\n\n\n<li>\u9700\u8981<strong>\u76f4\u63a5\u6784\u9020\u5e95\u5c42\u7f51\u7edc\u6570\u636e\u5305<\/strong><\/li>\n\n\n\n<li><strong>\u666e\u901a\u7528\u6237\u6ca1\u6709\u6743\u9650<\/strong><\/li>\n<\/ul>\n\n\n\n<p> \u8fd9\u4e0d\u662f Nmap \u7684\u95ee\u9898\uff0c\u800c\u662f<strong>\u64cd\u4f5c\u7cfb\u7edf\u7684\u5b89\u5168\u9650\u5236<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u89e3\u51b3\u65b9\u6cd5<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">Linux \/ macOS<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap &lt;target&gt;\n<\/code><\/pre>\n\n\n\n<p>\u4f8b\u5982\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap -sS 192.168.1.1\n<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">Windows<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5fc5\u987b <strong>\u201c\u4ee5\u7ba1\u7406\u5458\u8eab\u4efd\u8fd0\u884c\u201d<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>CMD<\/li>\n\n\n\n<li>PowerShell<\/li>\n\n\n\n<li>\u6216 Nmap Zenmap<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u5982\u679c\u4e0d\u662f\u7ba1\u7406\u5458\u6743\u9650\uff0c\u5f88\u591a\u626b\u63cf\u4f1a <strong>\u201c\u770b\u4f3c\u6267\u884c\u4e86\uff0c\u5b9e\u9645\u4e0a\u4ec0\u4e48\u90fd\u6ca1\u626b\u5230\u201d<\/strong><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.1.2 \u201cHost seems down\u201d \u9519\u8bef<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u62a5\u9519\u793a\u4f8b<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u6700\u5bb9\u6613\u8bef\u89e3\u7684\u5730\u65b9\u5f88\u591a\u4eba\u770b\u5230\u8fd9\u53e5\u8bdd\u4f1a\u4ee5\u4e3a\uff1a\u201c\u76ee\u6807\u4e3b\u673a\u4e0d\u5728\u7ebf\u201d\u201cIP \u5730\u5740\u8f93\u9519\u4e86\u201d<strong>\u5176\u5b9e\u901a\u5e38\u4e0d\u662f\u3002<\/strong><\/h4>\n\n\n\n<h4 class=\"wp-block-heading\">\u771f\u6b63\u539f\u56e0\uff0890% \u60c5\u51b5\uff09<\/h4>\n\n\n\n<p>Nmap \u9ed8\u8ba4\u4f1a\u5148\u505a <strong>\u4e3b\u673a\u5b58\u6d3b\u63a2\u6d4b\uff08Ping Scan\uff09<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ICMP Ping<\/li>\n\n\n\n<li>TCP ACK<\/li>\n\n\n\n<li>TCP SYN<\/li>\n<\/ul>\n\n\n\n<p>\u5982\u679c\u76ee\u6807\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u9632\u706b\u5899\u5c4f\u853d Ping<\/li>\n\n\n\n<li>\u4e91\u670d\u52a1\u5668\u7981 ICMP<\/li>\n\n\n\n<li>\u5185\u7f51\u8bbe\u5907\u7981\u56de\u5e94<\/li>\n<\/ul>\n\n\n\n<p> <strong>Nmap \u4f1a\u201c\u4ee5\u4e3a\u201d\u4e3b\u673a\u4e0d\u5728\u7ebf<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6b63\u786e\u89e3\u51b3\u65b9\u6cd5<\/h4>\n\n\n\n<p>\u4f7f\u7528 <code>-Pn<\/code>\uff08\u8df3\u8fc7\u4e3b\u673a\u53d1\u73b0\uff09<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -Pn 192.168.1.100<\/code><\/pre>\n\n\n\n<p>\u6216\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -Pn example.com<\/code><\/pre>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u5982\u679c\u4f60\u786e\u5b9a\u76ee\u6807\u662f\u5728\u7ebf\u7684\uff0c\u4f46 Nmap \u8bf4 \u201cHost seems down\u201d\uff0c<strong>\u7b2c\u4e00\u53cd\u5e94\uff1a\u52a0 <code>-Pn<\/code> \u518d\u626b\u4e00\u6b21\u3002<\/strong><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.1.3 \u626b\u63cf\u8d85\u65f6\uff08Timeout\uff09<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u73b0\u8c61<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u626b\u63cf\u5361\u5f88\u4e45<\/li>\n\n\n\n<li>\u626b\u63cf\u7ed3\u675f\u4f46\u51e0\u4e4e\u6ca1\u6709\u7aef\u53e3\u4fe1\u606f<\/li>\n\n\n\n<li>\u63d0\u793a\u8d85\u65f6\u3001\u91cd\u8bd5\u6b21\u6570\u8fc7\u591a<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u539f\u56e0<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u539f\u56e0<\/th><th>\u8bf4\u660e<\/th><\/tr><\/thead><tbody><tr><td>\u7f51\u7edc\u5ef6\u8fdf\u9ad8<\/td><td>VPN\u3001\u8de8\u56fd\u626b\u63cf<\/td><\/tr><tr><td>\u9632\u706b\u5899\u4e22\u5305<\/td><td>\u4e22\u5f03\u626b\u63cf\u5305<\/td><\/tr><tr><td>\u626b\u63cf\u53c2\u6570\u8fc7\u6fc0<\/td><td>\u626b\u592a\u591a\u7aef\u53e3<\/td><\/tr><tr><td>\u76ee\u6807\u6027\u80fd\u4f4e<\/td><td>\u5d4c\u5165\u5f0f\u8bbe\u5907<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">\u57fa\u7840\u89e3\u51b3\u65b9\u6848\uff08\u65b0\u624b\u53ef\u7528\uff09<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">1. \u964d\u4f4e\u626b\u63cf\u5f3a\u5ea6<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -T3 &lt;target&gt;\n<\/code><\/pre>\n\n\n\n<p>\u6216\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -T2 &lt;target&gt;\n<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">2\u3002\u7f29\u5c0f\u626b\u63cf\u8303\u56f4<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -p 80,443 &lt;target&gt;\n<\/code><\/pre>\n\n\n\n<p>\u800c\u4e0d\u662f\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -p- &lt;target&gt;\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">2.2 \u626b\u63cf\u5931\u8d25\u539f\u56e0\u5206\u6790\uff08\u4e3a\u4ec0\u4e48\u201c\u4ec0\u4e48\u90fd\u626b\u4e0d\u5230\u201d\uff09<\/h2>\n\n\n\n<p><strong>\u5206\u6790\u95ee\u9898\u201d\uff0c\u800c\u4e0d\u662f\u76f2\u76ee\u6362\u547d\u4ee4<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.2.1 \u9632\u706b\u5899\u62e6\u622a<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u8868\u73b0\u7279\u5f81<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6240\u6709\u7aef\u53e3\u663e\u793a\u4e3a <code>filtered<\/code><\/li>\n\n\n\n<li>\u65e0\u670d\u52a1\u6307\u7eb9<\/li>\n\n\n\n<li>\u65e0\u7248\u672c\u4fe1\u606f<\/li>\n<\/ul>\n\n\n\n<p>\u793a\u4f8b\u8f93\u51fa\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>PORT   STATE    SERVICE\n80\/tcp filtered http\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u539f\u56e0\u89e3\u91ca<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u9632\u706b\u5899\u4e22\u5f03\u626b\u63cf\u5305<\/li>\n\n\n\n<li>IDS\/IPS \u68c0\u6d4b\u5230\u626b\u63cf\u884c\u4e3a<\/li>\n\n\n\n<li>\u4e91\u5382\u5546\u5b89\u5168\u7ec4\u62e6\u622a<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u6392\u67e5\u601d\u8def<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u786e\u8ba4\u76ee\u6807\u662f\u5426\u5141\u8bb8\u8bbf\u95ee<\/strong><\/li>\n\n\n\n<li>\u5c1d\u8bd5 <strong>\u5e38\u89c1\u7aef\u53e3<\/strong><\/li>\n\n\n\n<li>\u5207\u6362\u626b\u63cf\u65b9\u5f0f\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -sT &lt;target&gt;\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.2.2 \u7f51\u7edc\u914d\u7f6e\u95ee\u9898\uff08\u672c\u5730\uff09<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u573a\u666f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u865a\u62df\u673a\u65e0\u6cd5\u626b\u63cf\u5916\u7f51<\/li>\n\n\n\n<li>\u626b\u63cf\u540c\u7f51\u6bb5\u5931\u8d25<\/li>\n\n\n\n<li>\u516c\u53f8 \/ \u5b66\u6821\u7f51\u7edc<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u6392\u67e5\u6e05\u5355\uff08\u5199\u8fdb\u6559\u7a0b\u975e\u5e38\u5b9e\u7528\uff09<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u662f\u5426\u5728 <strong>NAT \/ \u6865\u63a5\u6a21\u5f0f<\/strong><\/li>\n\n\n\n<li>\u662f\u5426\u5f00\u542f VPN<\/li>\n\n\n\n<li>\u662f\u5426\u6709\u4ee3\u7406\u8f6f\u4ef6<\/li>\n\n\n\n<li>\u9632\u706b\u5899\u662f\u5426\u542f\u7528<\/li>\n<\/ul>\n\n\n\n<p> \u6559\u7a0b\u4e2d\u53ef\u4ee5\u7ed9\u4e00\u53e5\u7ecf\u9a8c\u603b\u7ed3\uff1a<strong>\u5982\u679c\u4f60\u8fde\u6d4f\u89c8\u5668\u90fd\u8bbf\u95ee\u4e0d\u4e86\u76ee\u6807\u5730\u5740\uff0cNmap \u4e5f\u4e0d\u53ef\u80fd\u626b\u5230\u3002<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.2.3 Windows \u7684 Npcap \u9a71\u52a8\u95ee\u9898<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u8868\u73b0<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Nmap \u80fd\u8fd0\u884c<\/li>\n\n\n\n<li>\u4f46 SYN \u626b\u63cf\u65e0\u7ed3\u679c<\/li>\n\n\n\n<li>Zenmap \u62a5\u9519<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u89e3\u51b3\u65b9\u6848<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u91cd\u65b0\u5b89\u88c5 Npcap<\/li>\n\n\n\n<li>\u5b89\u88c5\u65f6\u52fe\u9009\uff1a\n<ul class=\"wp-block-list\">\n<li>\u2714 \u201cWinPcap API-compatible Mode\u201d<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u91cd\u542f\u7cfb\u7edf<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">2.3 \u65e5\u5fd7\u89e3\u8bfb\u4e0e\u8c03\u8bd5\u9009\u9879\uff08\u4ece\u8f93\u51fa\u4e2d\u201c\u5b66\u4f1a\u6392\u9519\u201d\uff09<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.3.1 <code>-v<\/code>\uff08Verbose\uff1a\u8be6\u7ec6\u8f93\u51fa\uff09<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u793a\u4f8b<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -v 192.168.1.1\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u80fd\u770b\u5230\u4ec0\u4e48\uff1f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5f53\u524d\u626b\u63cf\u9636\u6bb5<\/li>\n\n\n\n<li>\u6b63\u5728\u63a2\u6d4b\u7684\u7aef\u53e3<\/li>\n\n\n\n<li>\u91cd\u8bd5\u60c5\u51b5<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u65b0\u624b\u8c03\u8bd5\u7b2c\u4e00\u6b65\uff1a\u6c38\u8fdc\u5148\u52a0 <code>-v<\/code><\/strong><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.3.2 <code>-vv<\/code>\uff08\u66f4\u8be6\u7ec6\uff09<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -vv &lt;target&gt;\n<\/code><\/pre>\n\n\n\n<p>\u9002\u5408\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u626b\u63cf\u5361\u4f4f<\/li>\n\n\n\n<li>\u626b\u63cf\u6162<\/li>\n\n\n\n<li>\u4e0d\u786e\u5b9a\u626b\u5230\u54ea\u4e00\u6b65<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.3.3 <code>-d<\/code>\uff08\u8c03\u8bd5\u6a21\u5f0f\uff09<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u793a\u4f8b<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -d &lt;target&gt;\n<\/code><\/pre>\n\n\n\n<p>\u6216\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -d2 &lt;target&gt;\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u4f5c\u7528<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u663e\u793a\u5185\u90e8\u51b3\u7b56<\/li>\n\n\n\n<li>\u663e\u793a\u63a2\u6d4b\u903b\u8f91<\/li>\n\n\n\n<li>\u9002\u5408 <strong>\u8fdb\u9636\u6392\u9519<\/strong><\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><code>-d<\/code> \u8f93\u51fa\u5f88\u591a\uff0c\u65b0\u624b\u53ea\u9700\u77e5\u9053\uff1a<br><strong>\u201c\u5b83\u5728\u544a\u8bc9\u4f60 Nmap \u5728\u5e72\u4ec0\u4e48\u201d<\/strong><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.3.4 <code>--log-errors<\/code>\uff08\u9519\u8bef\u65e5\u5fd7\uff09<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u793a\u4f8b<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap --log-errors 192.168.1.1\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u9002\u5408\u573a\u666f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6279\u91cf\u626b\u63cf<\/li>\n\n\n\n<li>\u540e\u671f\u5206\u6790<\/li>\n\n\n\n<li>\u4fdd\u5b58\u9519\u8bef\u4fe1\u606f<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2.3.5 \u7ec4\u5408\u4f7f\u7528\u793a\u4f8b<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap -Pn -v --log-errors 192.168.1.1\n<\/code><\/pre>\n\n\n\n<p>\u6559\u5b66\u610f\u4e49\uff1a<strong>\u4e0d\u662f\u9760\u201c\u591a\u8bd5\u51e0\u6b21\u201d\uff0c\u800c\u662f\u9760\u201c\u770b\u8f93\u51fa\u627e\u95ee\u9898\u201d\u3002<\/strong><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nmap\uff08Network Mapper\uff09\u662f\u4e00\u6b3e\u5f00\u6e90\u7684\u7f51\u7edc\u63a2\u6d4b\u548c\u5b89\u5168\u5ba1\u8ba1\u5de5\u5177\u3002\u4f60\u53ef\u4ee5\u628a\u5b83\u60f3\u8c61\u6210\u7f51\u7edc\u4e16\u754c\u91cc\u7684\u201c\u5730\u56fe [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[54],"tags":[],"class_list":["post-1466","post","type-post","status-publish","format-standard","hentry","category-text"],"_links":{"self":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts\/1466","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/comments?post=1466"}],"version-history":[{"count":33,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts\/1466\/revisions"}],"predecessor-version":[{"id":1555,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts\/1466\/revisions\/1555"}],"wp:attachment":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/media?parent=1466"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/categories?post=1466"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/tags?post=1466"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}