NSE Scripts Flashcards
Scan with default NSE scripts. Considered useful for discovery and safe
-sC
nmap 192.168.1.1 -sC
Scan with default NSE scripts. Considered useful for discovery and safe
–script default
nmap 192.168.1.1 –script default
Scan with a single script. Example banner
–script
nmap 192.168.1.1 –script=banner
Scan with a wildcard. Example http
–script
nmap 192.168.1.1 –script=http*
Scan with two scripts. Example http and banner
–script
nmap 192.168.1.1 –script=http,banner
Scan default, but remove intrusive scripts
–script
nmap 192.168.1.1 –script “not intrusive”
NSE script with arguments
–script-args
nmap –script snmp-sysdescr –script-args snmpcommunity=admin 192.168.1.1
http site map generator
nmap -Pn –script=http-sitemap-generator scanme.nmap.org
Fast search for random web servers
nmap -n -Pn -p 80 –open -sV -vvv –script banner,http-title -iR 1000
Brute forces DNS hostnames guessing subdomains
nmap -Pn –script=dns-brute domain.com
Safe SMB scripts to run
nmap -n -Pn -vv -O -sV –script smb-enum,smb-ls,smb-mbenum,smb-os-discovery,smb-s,smb-vuln,smbv2 -vv 192.168.1.1
Whois query
nmap –script whois* domain.com
Detect cross site scripting vulnerabilities
nmap -p80 –script http-unsafe-output-escaping scanme.nmap.org
Check for SQL injections
nmap -p80 –script http-sql-injection scanme.nmap.org