Nmap Development mailing list archives

Re: Version scan using nmap log


From: Ron <ron () skullsecurity net>
Date: Wed, 10 Feb 2010 09:53:57 -0600

It's incredibly unlikely that anything else will work -- the data simply doesn't exist (the version tests aren't run). 

On Wed, 10 Feb 2010 19:10:26 +0530 chintan dave <davechintan () gmail com> wrote:
Hi Ron,

Thanks for your reply.

Yes If nothing else works, that's the last option.

On Wed, Feb 10, 2010 at 7:04 PM, Ron <ron () skullsecurity net> wrote:

Hello,

There's no way to do it without sending more traffic, but what you can do
is build a custom list of hosts/ports based on which ports were open in the
Nmap scan, then specify those specifically to scan. It would take some
shell-fu, but it's probably your best bet.

On Wed, 10 Feb 2010 12:17:06 +0530 chintan dave <davechintan () gmail com>
wrote:
Hi All,

I have performed a Syn Scan against some few thousand IP addresses,
however
didn't include the version detection switch when I performed the scan.

I have *.nmap & *.xml log formats for these scans (for some IP Addresses,
even grepable format is saved).

Is there a way I can feed these logs to nmap to perform the version scan
of
services running on open port.

I do know that we can feed in grepable format to --resume option, but i
am
not sure how to go about this one (since the scan has already completed).

Your input would be much appreciated. It could actually help me saving
effort worth multiple days, should I be supposed to rescan for versions
as a
last option.

Thanks in advance,

--
Regards,
Chintan Dave
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


--
Ron Bowes
http://www.skullsecurity.org
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/




-- 
Regards,
Chintan Dave,

LinkedIn Profile: http://www.linkedin.com/in/chintandave
Blog:http://www.chintandave.com
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


-- 
Ron Bowes
http://www.skullsecurity.org
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: