Security Basics mailing list archives

Re: NMAP Accuracy vs. Speed


From: Mario Payán <mario () agora net mx>
Date: Mon, 29 Mar 2004 11:05:24 -0600

Hi,

maybe if you post the question to this mailling list you'll get a better
response:

---------------------
For help using this (nmap-hackers) mailing list, send a blank email to
nmap-hackers-help () insecure org . List run by ezmlm-idx (www.ezmlm.org).
---------------------

The list is at http://seclists.org/, where there are others about Nmap.

Hope this helps,

Mario


----- Original Message ----- 
From: <jburzenski () americanhm com>
To: <security-basics () securityfocus com>
Sent: Tuesday, March 23, 2004 9:14 AM
Subject: NMAP Accuracy vs. Speed


I'm looking for any recommended settings for scripting nmap to accurately
scan several large logically disperse networks.  My target list consists
of
about 5 c-class networks that do not respond to ICMP and about 40 single
Ips
that either do or do not respond to ICMP.

I would prefer accuracy over speed if the scan times are reasonable.  I
have
been -P0 on all scans since I can't reliably detect 100% of online hosts
(which generates about 1.5MB of output in -oG format due to all of the
filtered ports reported on).  Scans with -T 3 currently take about 8 days.
Scans on -T 4 take about 1 day.  T 3 are noticeably more accurate and some
networks report as no hosts online or ports open under T 4.

Here is my current scanning command:

nmap -T 4 -iL targetlist.txt -sT -P0 -oG output.log

My goal is to maintain an updated list of target networks and use nmap to
detect all open ports across the span monthly.  Then, another script will
diff the outputs and report on any changes.  Eventually, I'll get a udp
audit going as well.

Any help would be appreciated.


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: