{"id":27,"date":"2023-03-18T03:08:25","date_gmt":"2022-11-25T21:21:34","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/index.php\/2023\/11\/30\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/"},"modified":"2025-07-31T21:32:29","modified_gmt":"2025-07-31T13:32:29","slug":"%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/","title":{"rendered":"Nmap\u4e0eTcpdump\u5b9e\u6218\uff1a\u6df1\u5ea6\u68c0\u6d4b\u9632\u706b\u5899\u914d\u7f6e\u4e0e\u5b89\u5168\u6027"},"content":{"rendered":"<h3>\u5f15\u8a00<\/h3>\n<p>\u4e3a\u60a8\u7684\u57fa\u7840\u8bbe\u65bd\u8bbe\u7f6e\u9632\u706b\u5899\u662f\u63d0\u4f9b\u670d\u52a1\u5b89\u5168\u7684\u597d\u65b9\u6cd5\u3002\u4e00\u65e6\u60a8\u5236\u5b9a\u4e86\u6ee1\u610f\u7684\u7b56\u7565\uff0c\u4e0b\u4e00\u6b65\u5c31\u662f\u6d4b\u8bd5\u60a8\u7684\u9632\u706b\u5899\u89c4\u5219\u3002\u91cd\u8981\u7684\u662f\u8981\u4e86\u89e3\u60a8\u7684\u9632\u706b\u5899\u89c4\u5219\u662f\u5426\u5982\u60a8\u6240\u60f3\uff0c\u4ee5\u53ca\u5916\u754c\u5bf9\u60a8\u7684\u57fa\u7840\u8bbe\u65bd\u7684\u5370\u8c61\u5982\u4f55\u3002<\/p>\n<p>\u5728\u672c\u6307\u5357\u4e2d\uff0c\u6211\u4eec\u5c06\u4ecb\u7ecd\u4e00\u4e9b\u5de5\u5177\u548c\u6280\u672f\uff0c\u60a8\u53ef\u4ee5\u4f7f\u7528\u5b83\u4eec\u6765\u9a8c\u8bc1\u9632\u706b\u5899\u89c4\u5219\u3002\u8fd9\u4e9b\u5de5\u5177\u4e0e\u6076\u610f\u7528\u6237\u53ef\u80fd\u4f7f\u7528\u7684\u5de5\u5177\u76f8\u540c\uff0c\u56e0\u6b64\u60a8\u5c06\u80fd\u591f\u67e5\u770b\u4ed6\u4eec\u901a\u8fc7\u5411\u60a8\u7684\u670d\u52a1\u5668\u53d1\u51fa\u8bf7\u6c42\u65f6\u53ef\u4ee5\u83b7\u53d6\u5230\u54ea\u4e9b\u4fe1\u606f\u3002<\/p>\n<h2>\u5148\u51b3\u6761\u4ef6<\/h2>\n<p>\u5728\u672c\u6307\u5357\u4e2d\uff0c\u6211\u4eec\u5c06\u5047\u8bbe\u60a8\u81f3\u5c11\u5728\u4e00\u53f0\u670d\u52a1\u5668\u4e0a\u914d\u7f6e\u4e86\u9632\u706b\u5899\u3002\u60a8\u53ef\u4ee5\u6309\u7167\u8fd9\u4e9b\u6307\u5357\u4e2d\u7684\u4e00\u4e2a\u6216\u591a\u4e2a\u5f00\u59cb\u6784\u5efa\u60a8\u7684\u9632\u706b\u5899\u7b56\u7565\u3002<\/p>\n<ul class=\"post-ul\">\n<li>Iptables\uff1a<a href=\"#\">Iptables Essentials: Common Firewall Rules and Commands<\/a><\/li>\n<li>UFW\uff1a<a href=\"#\">How To Set Up a Firewall with UFW on Ubuntu 22.04<\/a>\u3001<a href=\"#\">UFW Essentials: Common Firewall Rules and Commands<\/a><\/li>\n<li>FirewallD\uff1a<a href=\"#\">How To Set Up a Firewall Using FirewallD on Rocky Linux 9<\/a><\/li>\n<\/ul>\n<p>\u60a8\u4e5f\u53ef\u4ee5\u914d\u7f6eSilicon Cloud\u7684\u4e91\u9632\u706b\u5899\uff0c\u5728Silicon Cloud\u57fa\u7840\u8bbe\u65bd\u4e0a\u4f5c\u4e3a\u9644\u52a0\u7684\u5916\u90e8\u5c42\u6765\u8fd0\u884c\u3002\u8fd9\u6837\uff0c\u60a8\u5c31\u4e0d\u5fc5\u5728\u670d\u52a1\u5668\u672c\u8eab\u4e0a\u914d\u7f6e\u9632\u706b\u5899\u4e86\u3002<\/p>\n<p>\u5728\u672c\u6307\u5357\u4e2d\uff0c\u6211\u4eec\u5c06\u79f0\u60a8\u5e0c\u671b\u6d4b\u8bd5\u7684\u9632\u706b\u5899\u7b56\u7565\u6240\u5728\u7684\u670d\u52a1\u5668\u4e3a\u201c\u76ee\u6807\u670d\u52a1\u5668\u201d\u3002\u9664\u4e86\u76ee\u6807\u670d\u52a1\u5668\uff0c\u60a8\u8fd8\u9700\u8981\u4e00\u4e2a\u4f4d\u4e8e\u60a8\u7684\u9632\u706b\u5899\u4fdd\u62a4\u8303\u56f4\u4e4b\u5916\u7684\u7f51\u7edc\u4e2d\u7684\u670d\u52a1\u5668\u8fdb\u884c\u6d4b\u8bd5\u3002\u5728\u672c\u6307\u5357\u4e2d\uff0c\u60a8\u5c06\u4f7f\u7528\u4e00\u53f0Ubuntu 22.04\u670d\u52a1\u5668\u4f5c\u4e3a\u60a8\u7684\u201c\u5ba1\u8ba1\u673a\u5668\u201d\u3002<\/p>\n<p>\u4e00\u65e6\u60a8\u6709\u4e00\u53f0\u7528\u4e8e\u6d4b\u8bd5\u7684\u670d\u52a1\u5668\u548c\u60a8\u60f3\u8981\u8bc4\u4f30\u7684\u76ee\u6807\uff0c\u60a8\u5c31\u53ef\u4ee5\u7ee7\u7eed\u4f7f\u7528\u672c\u6307\u5357\u3002<\/p>\n<div class=\"post-conf-warning\">\n<p class=\"post-conf-desc\"><strong>\u8b66\u544a\uff1a<\/strong>\u60a8\u5e94\u8be5\u4ec5\u5728\u60a8\u63a7\u5236\u7684\u57fa\u7840\u8bbe\u65bd\u4e0a\u6267\u884c\u6b64\u6307\u5357\u4e2d\u89c4\u5b9a\u7684\u6d3b\u52a8\uff0c\u76ee\u7684\u662f\u8fdb\u884c\u5b89\u5168\u5ba1\u8ba1\u3002\u5728\u8bb8\u591a\u53f8\u6cd5\u7ba1\u8f96\u533a\uff0c\u5173\u4e8e\u7aef\u53e3\u626b\u63cf\u7684\u6cd5\u5f8b\u4e0d\u660e\u786e\u3002\u5df2\u77e5\u6709\u4e9b\u4e92\u8054\u7f51\u670d\u52a1\u63d0\u4f9b\u5546\u548c\u5176\u4ed6\u4f9b\u5e94\u5546\u4f1a\u5c01\u7981\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\u7684\u7528\u6237\u3002<\/p>\n<\/div>\n<h2>\u6211\u4eec\u5c06\u4f7f\u7528\u7684\u5de5\u5177<\/h2>\n<p>\u6709\u5f88\u591a\u4e0d\u540c\u7684\u5de5\u5177\u53ef\u4ee5\u7528\u6765\u6d4b\u8bd5\u6211\u4eec\u7684\u9632\u706b\u5899\u7b56\u7565\u3002\u5176\u4e2d\u4e00\u4e9b\u5de5\u5177\u6709\u91cd\u53e0\u7684\u529f\u80fd\u3002\u6211\u4eec\u4e0d\u4f1a\u6db5\u76d6\u6240\u6709\u53ef\u80fd\u7684\u5de5\u5177\u3002\u76f8\u53cd\uff0c\u6211\u4eec\u5c06\u6db5\u76d6\u4e00\u4e9b\u5e38\u89c1\u7684\u5ba1\u8ba1\u5de5\u5177\u7c7b\u522b\uff0c\u5e76\u4ecb\u7ecd\u672c\u6307\u5357\u4e2d\u5c06\u4f7f\u7528\u7684\u5de5\u5177\u3002<\/p>\n<h3>\u6570\u636e\u5305\u5206\u6790\u5668<\/h3>\n<p>\u6570\u636e\u5305\u5206\u6790\u5668\u53ef\u4ee5\u7528\u6765\u8be6\u7ec6\u89c2\u5bdf\u901a\u8fc7\u63a5\u53e3\u4f20\u8f93\u7684\u6240\u6709\u7f51\u7edc\u6d41\u91cf\u3002\u5927\u591a\u6570\u6570\u636e\u5305\u5206\u6790\u5668\u90fd\u53ef\u4ee5\u9009\u62e9\u5b9e\u65f6\u64cd\u4f5c\uff0c\u663e\u793a\u53d1\u9001\u6216\u63a5\u6536\u7684\u6570\u636e\u5305\uff0c\u6216\u5c06\u6570\u636e\u5305\u4fe1\u606f\u5199\u5165\u6587\u4ef6\uff0c\u7a0d\u540e\u8fdb\u884c\u5904\u7406\u3002\u6570\u636e\u5305\u5206\u6790\u8ba9\u60a8\u80fd\u591f\u4ee5\u7ec6\u7c92\u5ea6\u7684\u65b9\u5f0f\u67e5\u770b\u76ee\u6807\u673a\u5668\u5411\u5f00\u653e\u7f51\u7edc\u4e0a\u7684\u4e3b\u673a\u53d1\u9001\u7684\u54cd\u5e94\u7c7b\u578b\u3002<\/p>\n<p>\u4e3a\u4e86\u672c\u6307\u5357\u7684\u76ee\u7684\uff0c\u6211\u4eec\u5c06\u4f7f\u7528<code>tcpdump<\/code>\u5de5\u5177\u3002\u8fd9\u662f\u4e00\u4e2a\u597d\u9009\u62e9\uff0c\u56e0\u4e3a\u5b83\u5728Linux\u7cfb\u7edf\u4e0a\u529f\u80fd\u5f3a\u5927\u3001\u7075\u6d3b\uff0c\u5e76\u4e14\u65e0\u5904\u4e0d\u5728\u3002\u60a8\u5c06\u4f7f\u7528\u5b83\u6765\u6355\u83b7\u6211\u4eec\u5728\u8fd0\u884c\u6d4b\u8bd5\u65f6\u7684\u539f\u59cb\u6570\u636e\u5305\uff0c\u4ee5\u5907\u540e\u7eed\u5206\u6790\u65f6\u4f7f\u7528\u3002\u5176\u4ed6\u4e00\u4e9b\u53d7\u6b22\u8fce\u7684\u9009\u9879\u5305\u62ecWireshark\uff08\u6216\u5176\u547d\u4ee4\u884c\u7248\u672ctshark\uff09\u548ctcpflow\uff0c\u540e\u8005\u53ef\u4ee5\u6709\u6761\u7406\u5730\u7ec4\u5408\u6574\u4e2aTCP\u5bf9\u8bdd\u3002<\/p>\n<h3>\u7aef\u53e3\u626b\u63cf\u5668<\/h3>\n<p>\u4e3a\u4e86\u4ea7\u751f\u6570\u636e\u5305\u5206\u6790\u5668\u6355\u83b7\u7684\u6d41\u91cf\u548c\u54cd\u5e94\uff0c\u60a8\u5c06\u4f7f\u7528\u7aef\u53e3\u626b\u63cf\u5668\u3002\u7aef\u53e3\u626b\u63cf\u5668\u53ef\u4ee5\u7528\u6765\u6784\u5efa\u5e76\u53d1\u9001\u5404\u79cd\u7c7b\u578b\u7684\u6570\u636e\u5305\u5230\u8fdc\u7a0b\u4e3b\u673a\uff0c\u4ee5\u53d1\u73b0\u670d\u52a1\u5668\u63a5\u53d7\u7684\u6d41\u91cf\u7c7b\u578b\u3002\u6076\u610f\u7528\u6237\u7ecf\u5e38\u5c06\u5176\u4f5c\u4e3a\u4e00\u79cd\u63a2\u6d4b\u5de5\u5177\uff0c\u8bd5\u56fe\u627e\u5230\u53ef\u5229\u7528\u7684\u6709\u6f0f\u6d1e\u670d\u52a1\uff08\u8fd9\u4e5f\u662f\u4f7f\u7528\u9632\u706b\u5899\u7684\u4e00\u90e8\u5206\u539f\u56e0\uff09\uff0c\u56e0\u6b64\u60a8\u5c06\u4f7f\u7528\u5b83\u6765\u5c1d\u8bd5\u67e5\u770b\u653b\u51fb\u8005\u53ef\u80fd\u53d1\u73b0\u7684\u5185\u5bb9\u3002<\/p>\n<p>\u5bf9\u4e8e\u672c\u6307\u5357\uff0c\u60a8\u5c06\u4f7f\u7528<code>nmap<\/code>\u7f51\u7edc\u6620\u5c04\u548c\u7aef\u53e3\u626b\u63cf\u5de5\u5177\u3002\u60a8\u53ef\u4ee5\u4f7f\u7528<code>nmap<\/code>\u53d1\u9001\u4e0d\u540c\u7c7b\u578b\u7684\u6570\u636e\u5305\uff0c\u5c1d\u8bd5\u786e\u5b9a\u76ee\u6807\u673a\u5668\u4e0a\u6709\u54ea\u4e9b\u670d\u52a1\u4ee5\u53ca\u5b83\u6240\u53d7\u5230\u7684\u9632\u706b\u5899\u89c4\u5219\u662f\u4ec0\u4e48\u3002<\/p>\n<h2>\u8bbe\u7f6e\u5ba1\u8ba1\u673a<\/h2>\n<p>\u5728\u5f00\u59cb\u4e4b\u524d\uff0c\u8bf7\u786e\u4fdd\u6211\u4eec\u5df2\u5b89\u88c5\u6240\u9700\u5de5\u5177\u3002\u60a8\u53ef\u4ee5\u4eceUbuntu\u7684\u8f6f\u4ef6\u5b58\u50a8\u5e93\u4e2d\u83b7\u53d6<code>tcpdump<\/code>\u548c<code>nmap<\/code>\u3002\u8fd0\u884c<code>apt update<\/code>\u547d\u4ee4\u6765\u66f4\u65b0\u60a8\u672c\u5730\u7684\u8f6f\u4ef6\u5305\u5217\u8868\uff0c\u7136\u540e\u4f7f\u7528<code>apt install<\/code>\u547d\u4ee4\u6765\u5b89\u88c5\u5b83\u4eec\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"token function\">sudo<\/span> <span class=\"token function\">apt<\/span> update\r\n<span class=\"token function\">sudo<\/span> <span class=\"token function\">apt<\/span> <span class=\"token function\">install<\/span> tcpdump nmap<\/code><\/pre>\n<p>\u63a5\u4e0b\u6765\uff0c\u521b\u5efa\u4e00\u4e2a\u76ee\u5f55\u6765\u5b58\u50a8\u60a8\u7684\u626b\u63cf\u7ed3\u679c\uff1a<\/p>\n<pre class=\"post-pre\"><code><span class=\"token function\">mkdir<\/span> ~\/scan_results<\/code><\/pre>\n<p>\u4e3a\u786e\u4fdd\u60a8\u83b7\u53d6\u5e72\u51c0\u7684\u7ed3\u679c\uff0c\u8bf7\u9000\u51fa\u60a8\u7684\u5ba1\u8ba1\u7cfb\u7edf\u548c\u76ee\u6807\u7cfb\u7edf\u4e4b\u95f4\u53ef\u80fd\u6253\u5f00\u7684\u4efb\u4f55\u4f1a\u8bdd\u3002\u5305\u62ecSSH\u4f1a\u8bdd\u3001\u60a8\u5728Web\u6d4f\u89c8\u5668\u4e2d\u5efa\u7acb\u7684\u4efb\u4f55HTTP(S)\u8fde\u63a5\u7b49\u3002<\/p>\n<h2>\u626b\u63cf\u60a8\u7684\u76ee\u6807\u4ee5\u67e5\u627e\u5f00\u653e\u7684TCP\u7aef\u53e3<\/h2>\n<p>\u65e2\u7136\u6211\u4eec\u5df2\u7ecf\u51c6\u5907\u597d\u4e86\u670d\u52a1\u5668\u548c\u6587\u4ef6\uff0c\u60a8\u73b0\u5728\u53ef\u4ee5\u5f00\u59cb\u626b\u63cf\u76ee\u6807\u4e3b\u673a\u7684\u5f00\u653eTCP\u7aef\u53e3\u3002<\/p>\n<p>\u5b9e\u9645\u4e0a\uff0c<code>nmap<\/code>\u77e5\u9053\u5982\u4f55\u8fdb\u884c\u51e0\u79cdTCP\u626b\u63cf\u3002\u901a\u5e38\u6700\u597d\u5f00\u59cb\u4f7f\u7528\u7684\u662fSYN\u626b\u63cf\uff0c\u4e5f\u79f0\u4e3a\u201c\u534a\u5f00\u653e\u626b\u63cf\u201d\uff0c\u56e0\u4e3a\u5b83\u5b9e\u9645\u4e0a\u6ca1\u6709\u8fdb\u884c\u5b8c\u6574\u7684TCP\u8fde\u63a5\u534f\u5546\u3002\u653b\u51fb\u8005\u7ecf\u5e38\u4f7f\u7528\u6b64\u65b9\u6cd5\uff0c\u56e0\u4e3a\u5b83\u4e0d\u4f1a\u5728\u67d0\u4e9b\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf\u4e0a\u6ce8\u518c\uff0c\u56e0\u4e3a\u5b83\u4ece\u672a\u5b8c\u6210\u5b8c\u6574\u7684\u63e1\u624b\u8fc7\u7a0b\u3002<\/p>\n<h3>\u8bbe\u7f6e\u6570\u636e\u5305\u6355\u83b7<\/h3>\n<p>\u5728\u8fdb\u884c\u626b\u63cf\u4e4b\u524d\uff0c\u60a8\u9700\u8981\u5148\u8bbe\u7f6e<code>tcpdump<\/code>\u6765\u6355\u83b7\u6d4b\u8bd5\u751f\u6210\u7684\u6d41\u91cf\u3002\u5982\u679c\u9700\u8981\u7684\u8bdd\uff0c\u8fd9\u5c06\u5e2e\u52a9\u60a8\u66f4\u6df1\u5165\u5730\u5206\u6790\u53d1\u9001\u548c\u63a5\u6536\u7684\u6570\u636e\u5305\u3002\u5728<code>~\/scan_results<\/code>\u76ee\u5f55\u4e2d\u521b\u5efa\u4e00\u4e2a\u6587\u4ef6\u5939\uff0c\u4ee5\u4fbf\u5c06\u4e0e\u60a8\u7684SYN\u626b\u63cf\u76f8\u5173\u7684\u6587\u4ef6\u653e\u5728\u4e00\u8d77\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"token function\">mkdir<\/span> ~\/scan_results\/syn_scan<\/code><\/pre>\n<p>\u60a8\u53ef\u4ee5\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u542f\u52a8<code>tcpdump<\/code>\u6293\u5305\uff0c\u5e76\u5c06\u7ed3\u679c\u5199\u5165\u5230\u60a8\u7684<code>~\/scan_results\/syn_scan<\/code>\u76ee\u5f55\u4e2d\u7684\u6587\u4ef6\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"token function\">sudo<\/span> tcpdump <span class=\"token function\">host<\/span> <mark>target_ip_addr<\/mark> <span class=\"token parameter variable\">-w<\/span> ~\/scan_results\/syn_scan\/packets<\/code><\/pre>\n<p>\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c<code>tcpdump<\/code>\u5c06\u5728\u524d\u53f0\u8fd0\u884c\u3002\u4e3a\u4e86\u5728\u540c\u4e00\u7a97\u53e3\u4e2d\u8fd0\u884c\u60a8\u7684<code>nmap<\/code>\u626b\u63cf\uff0c\u60a8\u9700\u8981\u6682\u505c<code>tcpdump<\/code>\u8fdb\u7a0b\uff0c\u7136\u540e\u5c06\u5176\u5728\u540e\u53f0\u91cd\u65b0\u542f\u52a8\u3002<\/p>\n<p>\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7\u6309\u4e0b<code>CTRL-Z<\/code>\u6765\u6682\u505c\u8fd0\u884c\u4e2d\u7684\u8fdb\u7a0b\u3002<\/p>\n<div class=\"secondary-code-label\" title=\"Output\">\u8f93\u51fa<\/div>\n<pre class=\"post-pre\"><code>^Z\r\n[1]+ Stopped sudo tcpdump host <mark>target_ip_addr<\/mark> -w ~\/scan_results\/syn_scan\/packets<\/code><\/pre>\n<p>\u73b0\u5728\uff0c\u60a8\u53ef\u4ee5\u8f93\u5165\u201cbg\u201d\u6765\u5728\u540e\u53f0\u91cd\u65b0\u542f\u52a8\u5de5\u4f5c\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"token function\">bg<\/span><\/code><\/pre>\n<p>\u60a8\u5e94\u8be5\u5f97\u5230\u4e00\u884c\u7c7b\u4f3c\u7684\u8f93\u51fa\uff0c\u8fd9\u6b21\u6ca1\u6709\u201c\u505c\u6b62\u201d\u6807\u7b7e\uff0c\u5e76\u4e14\u5728\u7ed3\u5c3e\u6709\u4e00\u4e2a\u201c&amp;\u201d\u7b26\u53f7\u6765\u8868\u793a\u8be5\u8fdb\u7a0b\u5c06\u5728\u540e\u53f0\u8fd0\u884c\uff08\u5373\u4e0d\u518d\u963b\u585e\u60a8\u7684\u7ec8\u7aef\uff09\u3002<\/p>\n<div class=\"secondary-code-label\" title=\"Output\">\u8f93\u51fa<\/div>\n<pre class=\"post-pre\"><code>[1]+ sudo tcpdump host <mark>target_ip_addr<\/mark> -w ~\/scan_results\/syn_scan\/packets &amp;<\/code><\/pre>\n<p>\u547d\u4ee4\u76ee\u524d\u6b63\u5728\u540e\u53f0\u8fd0\u884c\uff0c\u76d1\u542c\u60a8\u7684\u5ba1\u8ba1\u548c\u76ee\u6807\u673a\u5668\u4e4b\u95f4\u7684\u4efb\u4f55\u6570\u636e\u5305\u3002\u73b0\u5728\u6211\u4eec\u53ef\u4ee5\u8fdb\u884cSYN\u626b\u63cf\u4e86\u3002<\/p>\n<h3>\u8fdb\u884c SYN \u626b\u63cf<\/h3>\n<p>\u8fd9\u662f\u6587\u7ae0\u300a\u5982\u4f55\u4f7f\u7528Nmap\u548cTcpdump\u6d4b\u8bd5\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\u300b\u7684\u7b2c2\u90e8\u5206\uff08\u51717\u90e8\u5206\uff09\u3002<\/p>\n<p>\u4f7f\u7528tcpdump\u5c06\u6d41\u91cf\u8bb0\u5f55\u5230\u76ee\u6807\u673a\u5668\u540e\uff0c\u60a8\u53ef\u4ee5\u5f00\u59cb\u8fd0\u884cnmap\u3002\u60a8\u53ef\u4ee5\u4f7f\u7528\u4ee5\u4e0b\u6807\u5fd7\u8fd0\u884cnmap\uff1a<\/p>\n<ul class=\"post-ul\">\n<li>-sS: \u8fd9\u5c06\u542f\u52a8\u4e00\u4e2aSYN\u626b\u63cf\u3002\u5982\u679c\u672a\u6307\u5b9a\u626b\u63cf\u7c7b\u578b\uff0c\u8fd9\u5728\u6280\u672f\u4e0a\u662fnmap\u5c06\u6267\u884c\u7684\u9ed8\u8ba4\u626b\u63cf\uff0c\u4f46\u6211\u4eec\u5728\u6b64\u660e\u786e\u6307\u51fa\u3002<\/li>\n<li>-Pn: \u8fd9\u544a\u8bc9nmap\u8df3\u8fc7\u4e3b\u673a\u53d1\u73b0\u6b65\u9aa4\uff0c\u5982\u679c\u4e3b\u673a\u4e0d\u54cd\u5e94ping\uff0c\u8be5\u6b65\u9aa4\u5c06\u63d0\u524d\u4e2d\u6b62\u6d4b\u8bd5\u3002\u7531\u4e8e\u60a8\u77e5\u9053\u76ee\u6807\u5728\u7ebf\uff0c\u56e0\u6b64\u53ef\u4ee5\u8df3\u8fc7\u6b64\u6b65\u9aa4\u3002<\/li>\n<li>-p-: \u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cSYN\u626b\u63cf\u53ea\u4f1a\u5c1d\u8bd51000\u4e2a\u6700\u5e38\u7528\u7684\u7aef\u53e3\u3002\u6b64\u6807\u5fd7\u544a\u8bc9nmap\u68c0\u67e5\u6240\u6709\u53ef\u7528\u7aef\u53e3\u3002<\/li>\n<li>-T4: \u8fd9\u4e3anmap\u8bbe\u7f6e\u4e86\u4e00\u4e2a\u65f6\u5e8f\u914d\u7f6e\u6587\u4ef6\uff0c\u6307\u793a\u5b83\u52a0\u5feb\u6d4b\u8bd5\u901f\u5ea6\uff0c\u4f46\u53ef\u80fd\u4f1a\u727a\u7272\u4e00\u70b9\u7ed3\u679c\u51c6\u786e\u6027\u30020\u662f\u6700\u6162\u7684\uff0c5\u662f\u6700\u5feb\u7684\u3002\u7531\u4e8e\u60a8\u6b63\u5728\u626b\u63cf\u6240\u6709\u7aef\u53e3\uff0c\u60a8\u53ef\u4ee5\u5c06\u5176\u4f5c\u4e3a\u57fa\u51c6\uff0c\u7a0d\u540e\u91cd\u65b0\u68c0\u67e5\u4efb\u4f55\u53ef\u80fd\u62a5\u544a\u4e0d\u6b63\u786e\u7684\u7aef\u53e3\u3002<\/li>\n<li>-vv: \u8fd9\u4f1a\u589e\u52a0\u8f93\u51fa\u7684\u8be6\u7ec6\u7a0b\u5ea6\u3002<\/li>\n<li>&#8211;reason: \u8fd9\u544a\u8bc9nmap\u63d0\u4f9b\u7aef\u53e3\u72b6\u6001\u62a5\u544a\u4e3a\u67d0\u79cd\u65b9\u5f0f\u7684\u539f\u56e0\u3002<\/li>\n<li>-oN: \u8fd9\u4f1a\u5c06\u7ed3\u679c\u5199\u5165\u4e00\u4e2a\u6587\u4ef6\uff0c\u4ee5\u4fbf\u60a8\u4ee5\u540e\u8fdb\u884c\u5206\u6790\u3002<\/li>\n<\/ul>\n<div class=\"post-conf-note\">\n<p class=\"post-conf-desc\">\u6ce8\u610f\uff1a\u8981\u68c0\u67e5IPv6\uff0c\u60a8\u9700\u8981\u5728\u547d\u4ee4\u4e2d\u6dfb\u52a0\u201c-6\u201d\u6807\u5fd7\u3002\u5b8c\u6574\u7684\u6307\u4ee4\u5c06\u662f\u4ee5\u4e0b\u5f62\u5f0f\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> nmap <span class=\"token parameter variable\">-sS<\/span> <span class=\"token parameter variable\">-Pn<\/span> -p- <span class=\"token parameter variable\">-T4<\/span> <span class=\"token parameter variable\">-vv<\/span> <span class=\"token parameter variable\">&#8211;reason<\/span> <span class=\"token parameter variable\">-oN<\/span> ~\/scan_results\/syn_scan\/nmap.results <mark>\u76ee\u6807IP\u5730\u5740<\/mark><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u5c3d\u7ba1\u5c06\u65f6\u5e8f\u6a21\u677f\u8bbe\u5b9a\u4e3a4\uff0c\u4f46\u7531\u4e8e\u8981\u626b\u63cf65535\u4e2a\u7aef\u53e3\uff0c\u626b\u63cf\u5f88\u53ef\u80fd\u9700\u8981\u76f8\u5f53\u957f\u7684\u65f6\u95f4\u3002\u5c06\u4f1a\u9010\u6e10\u5f00\u59cb\u6253\u5370\u51fa\u7c7b\u4f3c\u8fd9\u6837\u7684\u7ed3\u679c\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div class=\"secondary-code-label\" title=\"\u8f93\u51fa\">\u8f93\u51fa<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>Starting Nmap 6.49BETA4 ( https:\/\/nmap.org ) at 2022-12-19 16:54 EDT<br \/>\nInitiating Parallel DNS resolution of 1 host. at 16:54<br \/>\nCompleted Parallel DNS resolution of 1 host. at 16:54, 0.12s elapsed<br \/>\nInitiating SYN Stealth Scan at 16:54<br \/>\nScanning 198.51.100.15 [65535 ports]<br \/>\nDiscovered open port 22\/tcp on 198.51.100.15<br \/>\nDiscovered open port 80\/tcp on 198.51.100.15<br \/>\nSYN Stealth Scan Timing: About 6.16% done; ETC: 17:02 (0:07:52 remaining)<br \/>\nSYN Stealth Scan Timing: About 8.60% done; ETC: 17:06 (0:10:48 remaining)<br \/>\n. . .<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<h3>\u505c\u6b62tcpdump\u7684\u6570\u636e\u5305\u6355\u83b7<\/h3>\n<p>\u626b\u63cf\u5b8c\u6210\u540e\uff0c\u60a8\u53ef\u4ee5\u5c06tcpdump\u8fdb\u7a0b\u8c03\u81f3\u524d\u53f0\u5e76\u505c\u6b62\u5b83\u3002<\/p>\n<p>\u901a\u8fc7\u8fd0\u884cfg\u547d\u4ee4\u5c06\u5176\u4ece\u540e\u53f0\u8c03\u81f3\u524d\u53f0\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">fg<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u6309\u4e0b Ctrl+C \u952e\u6765\u505c\u6b62\u6b63\u5728\u8fd0\u884c\u7684\u8fdb\u7a0b\u3002<\/p>\n<h3>\u5206\u6790\u7ed3\u679c<\/h3>\n<p>\u73b0\u5728\u60a8\u7684<code>~\/scan_results\/syn_scan<\/code>\u76ee\u5f55\u4e2d\u5e94\u8be5\u6709\u4e24\u4e2a\u6587\u4ef6\u3002\u4e00\u4e2a\u662f\u7531tcpdump\u8fd0\u884c\u751f\u6210\u7684\u540d\u4e3a<code>packets<\/code>\u7684\u6587\u4ef6\uff0c\u53e6\u4e00\u4e2a\u662f\u7531nmap\u751f\u6210\u7684\u540d\u4e3a<code>nmap.results<\/code>\u7684\u6587\u4ef6\u3002<\/p>\n<p>\u8ba9\u6211\u4eec\u9996\u5148\u770b\u4e00\u4e0b<code>nmap.results<\/code>\u6587\u4ef6\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">less<\/span> ~\/scan_results\/syn_scan\/nmap.results<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div><code>~\/scan_results\/syn_scan\/nmap.results<\/code><\/p>\n<pre class=\"post-pre\"><code># Nmap 6.49BETA4 scan initiated Mon Dec 19 17:05:13 2022 as: nmap -sS -Pn -p- -T4 -vv --reason -oN \/home\/user\/scan_results\/syn_scan\/nmap.results 198.51.100.15\r\nIncreasing send delay for 198.51.100.15 from 0 to 5 due to 9226 out of 23064 dropped probes since last increase.\r\nIncreasing send delay for 198.51.100.15 from 5 to 10 due to 14 out of 34 dropped probes since last increase.\r\nNmap scan report for 198.51.100.15\r\nHost is up, received user-set (0.00097s latency).\r\nScanned at 2022-12-19 17:05:13 EDT for 2337s\r\n<mark>Not shown: 65533 closed ports<\/mark>\r\n<mark>Reason: 65533 resets<\/mark>\r\n<mark>PORT   STATE SERVICE REASON<\/mark>\r\n<mark>22\/tcp open  ssh     syn-ack ttl 63<\/mark>\r\n<mark>80\/tcp open  http    syn-ack ttl 63<\/mark>\r\n\r\nRead data files from: \/usr\/local\/bin\/..\/share\/nmap\r\n# Nmap done at Mon Dec 19 17:44:10 2022 -- 1 IP address (1 host up) scanned in 2336.85 seconds\r\n<\/code><\/pre>\n<p>\u4e0a\u9762\u7684\u9ad8\u4eae\u533a\u57df\u5305\u542b\u4e86\u626b\u63cf\u7684\u4e3b\u8981\u7ed3\u679c\u3002\u901a\u8fc7\u8fd9\u4e9b\u7ed3\u679c\uff0c\u6211\u4eec\u53ef\u4ee5\u63a8\u65ad\u626b\u63cf\u7684\u4e3b\u673a\u5f00\u653e\u4e8622\u7aef\u53e3\u548c80\u7aef\u53e3\uff0c\u4ee5\u4fbf\u5141\u8bb8SSH\u548cHTTP\u6d41\u91cf\u3002\u6211\u4eec\u8fd8\u53ef\u4ee5\u89c2\u5bdf\u5230\uff0c\u5171\u670965,533\u4e2a\u7aef\u53e3\u5904\u4e8e\u5173\u95ed\u72b6\u6001\u3002<\/p>\n<p>\u53e6\u4e00\u4e2a\u53ef\u80fd\u7684\u7ed3\u679c\u662f\u201cfiltered\u201d\uff08\u5df2\u8fc7\u6ee4\uff09\uff0c\u8fd9\u610f\u5473\u7740\u8fd9\u4e9b\u7aef\u53e3\u88ab\u8bc6\u522b\u4e3a\u5728\u7f51\u7edc\u8def\u5f84\u4e0a\u88ab\u67d0\u79cd\u56e0\u7d20\u963b\u6b62\u4e86\u3002\u8fd9\u53ef\u80fd\u662f\u76ee\u6807\u4e3b\u673a\u4e0a\u7684\u9632\u706b\u5899\uff0c\u4e5f\u53ef\u80fd\u662f\u5ba1\u8ba1\u673a\u5668\u548c\u76ee\u6807\u673a\u5668\u4e4b\u95f4\u7684\u4efb\u4f55\u4e2d\u95f4\u4e3b\u673a\u4e0a\u7684\u8fc7\u6ee4\u89c4\u5219\u3002<\/p>\n<p>\u8981\u67e5\u770b\u53d1\u9001\u548c\u63a5\u6536\u5230\u76ee\u6807\u7684\u5b9e\u9645\u6570\u636e\u5305\u6d41\u91cf\uff0c\u60a8\u53ef\u4ee5\u5c06\u6570\u636e\u5305\u6587\u4ef6\u91cd\u65b0\u8bfb\u5165tcpdump\uff0c\u5982\u4e0b\u6240\u793a\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> tcpdump <span class=\"token parameter variable\">-nn<\/span> <span class=\"token parameter variable\">-r<\/span> ~\/scan_results\/syn_scan\/packets <span class=\"token operator\">|<\/span> <span class=\"token function\">less<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u8fd9\u4e2a\u6587\u4ef6\u5305\u542b\u4e86\u4e24\u4e2a\u4e3b\u673a\u4e4b\u95f4\u5b8c\u6574\u7684\u5bf9\u8bdd\u5185\u5bb9\u3002\u4f60\u53ef\u4ee5\u901a\u8fc7\u591a\u79cd\u65b9\u5f0f\u8fdb\u884c\u7b5b\u9009\u3002<\/p>\n<p>\u4f8b\u5982\uff0c\u5982\u679c\u8981\u67e5\u770b\u4ec5\u53d1\u9001\u5230\u76ee\u6807\u7684\u6d41\u91cf\uff0c\u53ef\u4ee5\u8f93\u5165\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> tcpdump <span class=\"token parameter variable\">-nn<\/span> <span class=\"token parameter variable\">-r<\/span> ~\/scan_results\/syn_scan\/packets <span class=\"token string\">&#8216;dst <mark>target_ip_addr<\/mark>&#8216;<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">less<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u540c\u6837\u5730\uff0c\u4f60\u53ef\u4ee5\u5c06\u76ee\u7684\u5730\uff08dst\uff09\u6539\u4e3a\u6e90\u5730\u5740\uff08src\uff09\uff0c\u53ea\u67e5\u770b\u54cd\u5e94\u6d41\u91cf\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> tcpdump <span class=\"token parameter variable\">-nn<\/span> <span class=\"token parameter variable\">-r<\/span> ~\/scan_results\/syn_scan\/packets <span class=\"token string\">&#8216;src <mark>target_ip_addr<\/mark>&#8216;<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">less<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u5f00\u653e\u7684TCP\u7aef\u53e3\u4f1a\u7528SYN-ACK\u5305\u54cd\u5e94\u8fd9\u4e9b\u8bf7\u6c42\u3002\u6211\u4eec\u53ef\u4ee5\u76f4\u63a5\u901a\u8fc7\u7c7b\u4f3c\u8fd9\u6837\u7684\u8fc7\u6ee4\u5668\u641c\u7d22\u6b64\u7c7b\u578b\u7684\u54cd\u5e94\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> tcpdump <span class=\"token parameter variable\">-nn<\/span> <span class=\"token parameter variable\">-r<\/span> ~\/scan_results\/syn_scan\/packets <span class=\"token string\">&#8216;src <mark>target_ip_addr<\/mark> and tcp[tcpflags] &amp; tcp-syn != 0&#8242;<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">less<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u8fd9\u5c06\u53ea\u663e\u793a\u6210\u529f\u7684SYN-ACK\u54cd\u5e94\uff0c\u5e76\u5e94\u4e0e\u60a8\u5728Nmap\u8fd0\u884c\u4e2d\u770b\u5230\u7684\u7aef\u53e3\u5339\u914d\u3002<\/p>\n<div class=\"secondary-code-label\" title=\"Output\">\u8f93\u51fa<\/div>\n<pre class=\"post-pre\"><code>reading from file packets, link-type EN10MB (Ethernet) 17:05:13.557597 IP 198.51.100.15.22 &gt; 198.51.100.2.63872: Flags [S.], seq 2144564104, ack 4206039348, win 29200, options [mss 1460], length 0\r\n17:05:13.558085 IP 198.51.100.15.80 &gt; 198.51.100.2.63872: Flags [S.], seq 3550723926, ack 4206039348, win 29200, options [mss 1460], length 0\r\n<\/code><\/pre>\n<p>\u5728\u60a8\u8ba4\u4e3a\u5408\u9002\u7684\u60c5\u51b5\u4e0b\uff0c\u60a8\u53ef\u4ee5\u5bf9\u8fd9\u4e9b\u6570\u636e\u8fdb\u884c\u66f4\u591a\u7684\u5206\u6790\u3002\u8fd9\u4e9b\u6570\u636e\u5df2\u7ecf\u88ab\u6355\u83b7\u5e76\u7528\u4e8e\u5f02\u6b65\u5904\u7406\u548c\u5206\u6790\u3002<\/p>\n<h2>\u626b\u63cf\u60a8\u7684\u76ee\u6807\u4ee5\u67e5\u627e\u5f00\u653e\u7684UDP\u7aef\u53e3<\/h2>\n<p>\u65e2\u7136\u60a8\u5df2\u7ecf\u638c\u63e1\u4e86\u5982\u4f55\u8fd0\u884c\u8fd9\u4e9b\u6d4b\u8bd5\uff0c\u60a8\u53ef\u4ee5\u5b8c\u6210\u7c7b\u4f3c\u7684\u6d41\u7a0b\u6765\u626b\u63cf\u5f00\u653e\u7684UDP\u7aef\u53e3\u3002<\/p>\n<h3>\u8bbe\u7f6e\u6570\u636e\u5305\u6355\u83b7<\/h3>\n<p>\u518d\u6b21\u521b\u5efa\u4e00\u4e2a\u76ee\u5f55\u6765\u4fdd\u5b58\u60a8\u7684\u7ed3\u679c\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">mkdir<\/span> ~\/scan_results\/udp_scan<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u91cd\u65b0\u5f00\u59cb\u4e00\u4e2atcpdump\u7684\u6355\u83b7\u3002\u8fd9\u6b21\uff0c\u5c06\u6587\u4ef6\u5199\u5165\u65b0\u7684<code>~\/scan_results\/udp_scan<\/code>\u76ee\u5f55\u4e2d\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> tcpdump <span class=\"token function\">host<\/span> <mark>target_ip_addr<\/mark> <span class=\"token parameter variable\">-w<\/span> ~\/scan_results\/udp_scan\/packets<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u6682\u505c\u8fdb\u7a0b\u5e76\u5c06\u5176\u653e\u5165\u540e\u53f0\uff0c\u53ef\u901a\u8fc7\u8f93\u5165<code>Ctrl+Z<\/code>\u7136\u540e\u8fd0\u884c<code>bg<\/code>\u547d\u4ee4\u5b9e\u73b0\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">bg<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<h3>\u8fdb\u884cUDP\u626b\u63cf<\/h3>\n<h4>\u51c6\u5907\u8fdb\u884cUDP\u626b\u63cf<\/h4>\n<p>\u73b0\u5728\uff0c\u60a8\u5df2\u51c6\u5907\u597d\u8fdb\u884cUDP\u626b\u63cf\u3002\u7531\u4e8eUDP\u534f\u8bae\u7684\u7279\u6027\uff0c\u8fd9\u79cd\u626b\u63cf\u901a\u5e38\u6bd4SYN\u626b\u63cf\u8017\u65f6\u66f4\u957f\u3002\u4e8b\u5b9e\u4e0a\uff0c\u5982\u679c\u60a8\u6b63\u5728\u626b\u63cf\u7cfb\u7edf\u4e0a\u7684\u6bcf\u4e2a\u7aef\u53e3\uff0c\u53ef\u80fd\u9700\u8981\u8d85\u8fc7\u4e00\u5929\u7684\u65f6\u95f4\u3002UDP\u662f\u4e00\u79cd\u65e0\u8fde\u63a5\u534f\u8bae\uff0c\u56e0\u6b64\u672a\u6536\u5230\u54cd\u5e94\u53ef\u80fd\u610f\u5473\u7740\u76ee\u6807\u7aef\u53e3\u88ab\u963b\u585e\u3001\u5df2\u63a5\u53d7\u6570\u636e\u5305\u6216\u6570\u636e\u5305\u4e22\u5931\u3002\u4e3a\u4e86\u533a\u5206\u8fd9\u4e9b\u60c5\u51b5\uff0cNmap\u5fc5\u987b\u91cd\u65b0\u4f20\u8f93\u989d\u5916\u7684\u6570\u636e\u5305\u4ee5\u5c1d\u8bd5\u83b7\u5f97\u54cd\u5e94\u3002<\/p>\n<p>\u5927\u591a\u6570\u7684\u6807\u5fd7\u4e0e\u60a8\u7528\u4e8eSYN\u626b\u63cf\u65f6\u76f8\u540c\u3002\u5b9e\u9645\u4e0a\uff0c\u552f\u4e00\u65b0\u589e\u7684\u6807\u5fd7\u662f\uff1a<\/p>\n<ul class=\"post-ul\">\n<li><code>-sU<\/code>: \u6b64\u6807\u5fd7\u544a\u8bc9Nmap\u6267\u884cUDP\u626b\u63cf\u3002<\/li>\n<\/ul>\n<h4>\u52a0\u5febUDP\u6d4b\u8bd5\u901f\u5ea6<\/h4>\n<p>\u5982\u679c\u60a8\u62c5\u5fc3\u6b64\u6d4b\u8bd5\u6240\u9700\u7684\u65f6\u95f4\uff0c\u60a8\u53ef\u80fd\u53ea\u60f3\u5148\u6d4b\u8bd5\u4e00\u90e8\u5206UDP\u7aef\u53e3\u3002\u60a8\u53ef\u4ee5\u901a\u8fc7\u4e0d\u4f7f\u7528<code>-p-<\/code>\u6807\u5fd7\u6765\u4ec5\u6d4b\u8bd5\u6700\u5e38\u89c1\u76841000\u4e2a\u7aef\u53e3\u3002\u8fd9\u6837\u53ef\u4ee5\u5927\u5927\u7f29\u77ed\u626b\u63cf\u65f6\u95f4\u3002\u4f46\u5982\u679c\u60a8\u60f3\u8981\u5b8c\u6574\u7684\u7aef\u53e3\u72b6\u6001\uff0c\u60a8\u4e4b\u540e\u8fd8\u9700\u8981\u56de\u6765\u626b\u63cf\u6574\u4e2a\u7aef\u53e3\u8303\u56f4\u3002<\/p>\n<p>\u56e0\u4e3a\u60a8\u6b63\u5728\u626b\u63cf\u81ea\u5df1\u7684\u57fa\u7840\u8bbe\u65bd\uff0c\u52a0\u5febUDP\u626b\u63cf\u7684\u6700\u4f73\u9009\u62e9\u53ef\u80fd\u662f\u5728\u76ee\u6807\u7cfb\u7edf\u4e0a\u6682\u65f6\u7981\u7528ICMP\u901f\u7387\u9650\u5236\u3002\u901a\u5e38\uff0cLinux\u4e3b\u673a\u5c06ICMP\u54cd\u5e94\u9650\u5236\u4e3a\u6bcf\u79d21\u4e2a\uff08\u8fd9\u901a\u5e38\u662f\u597d\u4e8b\uff0c\u4f46\u4e0d\u9002\u7528\u4e8e\u6211\u4eec\u7684\u5ba1\u8ba1\uff09\uff0c\u8fd9\u610f\u5473\u7740\u5b8c\u6574\u7684UDP\u626b\u63cf\u5c06\u9700\u8981\u8d85\u8fc718\u4e2a\u5c0f\u65f6\u3002\u60a8\u53ef\u4ee5\u901a\u8fc7\u8f93\u5165\u4ee5\u4e0b\u547d\u4ee4\u6765\u68c0\u67e5\u76ee\u6807\u673a\u5668\u4e0a\u7684\u6b64\u8bbe\u7f6e\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"target_machine $\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">sysctl<\/span> net.ipv4.icmp_ratelimit<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div class=\"secondary-code-label\" title=\"Output\">\u8f93\u51fa<\/div>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>net.ipv4.icmp_ratelimit = 1000<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u201c1000\u201d\u662f\u54cd\u5e94\u4e4b\u95f4\u7684\u6beb\u79d2\u6570\u3002\u60a8\u53ef\u4ee5\u901a\u8fc7\u8f93\u5165\u4ee5\u4e0b\u547d\u4ee4\u5728\u76ee\u6807\u7cfb\u7edf\u4e0a\u6682\u65f6\u7981\u7528\u6b64\u901f\u7387\u9650\u5236\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"target_machine $\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">sysctl<\/span> <span class=\"token parameter variable\">-w<\/span> <span class=\"token assign-left variable\">net.ipv4.icmp_ratelimit<\/span><span class=\"token operator\">=<\/span><span class=\"token number\">0<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u5728\u60a8\u7684\u6d4b\u8bd5\u4e4b\u540e\uff0c\u6062\u590d\u8fd9\u4e2a\u503c\u975e\u5e38\u91cd\u8981\u3002<\/p>\n<h4>\u8fdb\u884c\u6d4b\u8bd5<\/h4>\n<p>\u786e\u4fdd\u5c06\u7ed3\u679c\u5199\u5165<code>~\/scan_results\/udp_scan<\/code>\u76ee\u5f55\u4e2d\u3002\u603b\u7684\u6765\u8bf4\uff0c\u547d\u4ee4\u5e94\u8be5\u662f\u8fd9\u6837\u7684\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> nmap <span class=\"token parameter variable\">-sU<\/span> <span class=\"token parameter variable\">-Pn<\/span> -p- <span class=\"token parameter variable\">-T4<\/span> <span class=\"token parameter variable\">-vv<\/span> <span class=\"token parameter variable\">&#8211;reason<\/span> <span class=\"token parameter variable\">-oN<\/span> ~\/scan_results\/udp_scan\/nmap.results <mark>target_ip_addr<\/mark><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u626b\u63cf\u5b8c\u6210\u540e\uff0c\u60a8\u5e94\u8be5\u5c06\u76ee\u6807\u673a\u5668\u4e0a\u7684ICMP\u901f\u7387\u9650\u5236\u6062\u590d\u5230\u539f\u6765\u7684\u8bbe\u7f6e\uff08\u5982\u679c\u60a8\u8fdb\u884c\u4e86\u4fee\u6539\uff09\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"target_machine $\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">sysctl<\/span> <span class=\"token parameter variable\">-w<\/span> <span class=\"token assign-left variable\">net.ipv4.icmp_ratelimit<\/span><span class=\"token operator\">=<\/span><span class=\"token number\">1000<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<h3>\u505c\u6b62Tcpdump\u6570\u636e\u5305\u6355\u83b7<\/h3>\n<p>\u901a\u8fc7\u8fd0\u884c<code>fg<\/code>\u547d\u4ee4\uff0c\u5c06Tcpdump\u8fdb\u7a0b\u6062\u590d\u5230\u60a8\u7684\u5ba1\u8ba1\u673a\u5668\u7684\u524d\u53f0\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">fg<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u7136\u540e\uff0c\u4f7f\u7528<code>Ctrl+C<\/code>\u505c\u6b62\u6570\u636e\u5305\u6355\u83b7\u3002<\/p>\n<h3>\u5206\u6790\u7ed3\u679c<\/h3>\n<p>\u73b0\u5728\uff0c\u60a8\u53ef\u4ee5\u67e5\u770b\u751f\u6210\u7684\u6587\u4ef6\u3002<\/p>\n<p>\u751f\u6210\u7684<code>nmap.results<\/code>\u6587\u4ef6\u5e94\u8be5\u4e0e\u4e0a\u6b21\u7684\u7ed3\u679c\u7c7b\u4f3c\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">less<\/span> ~\/scan_results\/udp_scan\/nmap.results<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div><code>~\/scan_results\/udp_scan\/nmap.results<\/code> \u6587\u4ef6\u4e2d\u7684\u5185\u5bb9<\/div>\n<p>\u8fd9\u662f\u6587\u7ae0\u300a\u5982\u4f55\u4f7f\u7528Nmap\u548cTcpdump\u6d4b\u8bd5\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\u300b\u7684\u7b2c5\u90e8\u5206\uff08\u51717\u90e8\u5206\uff09\u3002<\/p>\n<pre class=\"post-pre\"><code># Nmap 6.49BETA4 scan initiated Mon Dec 19 12:42:42 2022 as: nmap -sU -Pn -p- -T4 -vv --reason -oN \/home\/user\/scan_results\/udp_scan\/nmap.results 198.51.100.15\r\nIncreasing send delay for 198.51.100.15 from 0 to 50 due to 10445 out of 26111 dropped probes since last increase.\r\nIncreasing send delay for 198.51.100.15 from 50 to 100 due to 11 out of 23 dropped probes since last increase.\r\nIncreasing send delay for 198.51.100.15 from 100 to 200 due to 3427 out of 8567 dropped probes since last increase.\r\nNmap scan report for 198.51.100.15\r\nHost is up, received user-set (0.0010s latency).\r\nScanned at 2022-12-19 12:42:42 EDT for 9956s\r\nNot shown: 65532 closed ports\r\nReason: 65532 port-unreaches\r\nPORT    STATE         SERVICE REASON\r\n22\/udp  open|filtered ssh     no-response\r\n80\/udp  open|filtered http    no-response\r\n443\/udp open|filtered https   no-response\r\n\r\nRead data files from: \/usr\/local\/bin\/..\/share\/nmap\r\n# Nmap done at Mon Dec 19 15:28:39 2022 -- 1 IP address (1 host up) scanned in 9956.97 seconds\r\n<\/code><\/pre>\n<p>\u8fd9\u4e2a\u7ed3\u679c\u4e0e\u4e4b\u524d\u7684 SYN \u626b\u63cf\u7ed3\u679c\u4e4b\u95f4\u7684\u4e00\u4e2a\u5173\u952e\u5dee\u5f02\u53ef\u80fd\u662f\u6807\u8bb0\u4e3a\u201c\u5f00\u653e|\u8fc7\u6ee4\u201d\u7684\u7aef\u53e3\u6570\u91cf\u3002\u8fd9\u610f\u5473\u7740 Nmap \u65e0\u6cd5\u786e\u5b9a\u7f3a\u4e4f\u54cd\u5e94\u662f\u56e0\u4e3a\u670d\u52a1\u63a5\u53d7\u4e86\u6d41\u91cf\uff0c\u8fd8\u662f\u56e0\u4e3a\u6cbf\u9014\u5b58\u5728\u9632\u706b\u5899\u6216\u8fc7\u6ee4\u673a\u5236\u5bfc\u81f4\u6570\u636e\u5305\u88ab\u4e22\u5f03\u3002<\/p>\n<p>\u5206\u6790 Tcpdump \u8f93\u51fa\u4e5f\u66f4\u52a0\u56f0\u96be\uff0c\u56e0\u4e3a\u6ca1\u6709\u8fde\u63a5\u6807\u5fd7\uff0c\u5e76\u4e14\u60a8\u5fc5\u987b\u5c06 ICMP \u54cd\u5e94\u4e0e UDP \u8bf7\u6c42\u5339\u914d\u8d77\u6765\u3002<\/p>\n<p>\u60a8\u53ef\u4ee5\u901a\u8fc7\u67e5\u770b\u62a5\u544a\u7684\u7aef\u53e3\u4e4b\u4e00\u7684 UDP \u6d41\u91cf\u6765\u4e86\u89e3 Nmap \u9700\u8981\u53d1\u9001\u591a\u5c11\u4e2a\u6570\u636e\u5305\u624d\u80fd\u8fbe\u5230\u8fd9\u4e9b\u88ab\u62a5\u544a\u4e3a\u201c\u5f00\u653e|\u8fc7\u6ee4\u201d\u7684\u7aef\u53e3\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> tcpdump <span class=\"token parameter variable\">-nn<\/span> <span class=\"token parameter variable\">-Q<\/span> out <span class=\"token parameter variable\">-r<\/span> ~\/scan_results\/udp_scan\/packets <span class=\"token string\">&#8216;udp and port 22&#8217;<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div class=\"secondary-code-label\" title=\"Output\">\u8f93\u51fa<\/div>\n<pre class=\"post-pre\"><code>reading from file \/home\/user\/scan_results\/udp_scan\/packets, link-type EN10MB (Ethernet)\r\n14:57:40.801956 IP 198.51.100.2.60181 &gt; 198.51.100.15.22: UDP, length 0\r\n14:57:41.002364 IP 198.51.100.2.60182 &gt; 198.51.100.15.22: UDP, length 0\r\n14:57:41.202702 IP 198.51.100.2.60183 &gt; 198.51.100.15.22: UDP, length 0\r\n14:57:41.403099 IP 198.51.100.2.60184 &gt; 198.51.100.15.22: UDP, length 0\r\n14:57:41.603431 IP 198.51.100.2.60185 &gt; 198.51.100.15.22: UDP, length 0\r\n14:57:41.803885 IP 198.51.100.2.60186 &gt; 198.51.100.15.22: UDP, length 0\r\n<\/code><\/pre>\n<p>\u5c06\u6b64\u4e0e\u5176\u4e2d\u4e00\u4e2a\u6807\u8bb0\u4e3a\u201c\u5173\u95ed\u201d\u7684\u626b\u63cf\u7aef\u53e3\u7684\u7ed3\u679c\u8fdb\u884c\u6bd4\u8f83\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> tcpdump <span class=\"token parameter variable\">-nn<\/span> <span class=\"token parameter variable\">-Q<\/span> out <span class=\"token parameter variable\">-r<\/span> ~\/scan_results\/udp_scan\/packets <span class=\"token string\">&#8216;udp and port 53&#8217;<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div class=\"secondary-code-label\" title=\"Output\">\u8f93\u51fa<\/div>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>reading from file \/home\/user\/scan_results\/udp_scan\/packets, link-type EN10MB (Ethernet) 13:37:24.219270 IP 198.51.100.2.60181 &gt; 198.51.100.15.53: 0 stat [0q] (12)<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u4f60\u53ef\u4ee5\u5c1d\u8bd5\u624b\u52a8\u91cd\u6784Nmap\u7684\u8fc7\u7a0b\uff0c\u9996\u5148\u7f16\u8bd1\u4e00\u4e2a\u6211\u4eec\u53d1\u9001UDP\u6570\u636e\u5305\u7684\u6240\u6709\u7aef\u53e3\u7684\u5217\u8868\uff0c\u53ef\u4ee5\u50cf\u8fd9\u6837\u4f7f\u7528\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> tcpdump <span class=\"token parameter variable\">-nn<\/span> <span class=\"token parameter variable\">-Q<\/span> out <span class=\"token parameter variable\">-r<\/span> ~\/scan_results\/udp_scan\/packets <span class=\"token string\">&#8220;udp&#8221;<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">awk<\/span> <span class=\"token string\">&#8216;{print $5;}&#8217;<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">awk<\/span> <span class=\"token string\">&#8216;BEGIN { FS = &#8220;.&#8221; } ; { print $5 +0}&#8217;<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">sort<\/span> <span class=\"token parameter variable\">-u<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">tee<\/span> outgoing<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u7136\u540e\u4f60\u53ef\u4ee5\u770b\u5230\u6211\u4eec\u6536\u5230\u7684ICMP\u5305\uff0c\u5176\u4e2d\u8bf4\u660e\u4e86\u7aef\u53e3\u4e0d\u53ef\u8fbe\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> tcpdump <span class=\"token parameter variable\">-nn<\/span> <span class=\"token parameter variable\">-Q<\/span> <span class=\"token keyword\">in<\/span> <span class=\"token parameter variable\">-r<\/span> ~\/scan_results\/udp_scan\/packets <span class=\"token string\">&#8220;icmp&#8221;<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">awk<\/span> <span class=\"token string\">&#8216;{print $10,$11}&#8217;<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> unreachable <span class=\"token operator\">|<\/span> <span class=\"token function\">awk<\/span> <span class=\"token string\">&#8216;{print $1}&#8217;<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">sort<\/span> <span class=\"token parameter variable\">-u<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">tee<\/span> response<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u4f60\u53ef\u4ee5\u5c06\u8fd9\u4e24\u4e2a\u56de\u5e94\u8fdb\u884c\u6bd4\u5bf9\uff0c\u770b\u770b\u54ea\u4e9bUDP\u6570\u636e\u5305\u6ca1\u6709\u6536\u5230ICMP\u56de\u5e94\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">comm<\/span> <span class=\"token parameter variable\">-3<\/span> outgoing response<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u8fd9\u5e94\u8be5\u5927\u90e8\u5206\u4e0eNmap\u62a5\u544a\u7684\u7aef\u53e3\u5217\u8868\u76f8\u5339\u914d\uff08\u53ef\u80fd\u5305\u542b\u4e00\u4e9b\u4ece\u4e22\u5931\u7684\u8fd4\u56de\u6570\u636e\u5305\u4e2d\u4ea7\u751f\u7684\u865a\u62a5\uff09\u3002<\/p>\n<h2>\u4e3b\u673a\u548c\u670d\u52a1\u53d1\u73b0<\/h2>\n<p>\u60a8\u53ef\u4ee5\u5bf9\u76ee\u6807\u8fdb\u884c\u4e00\u4e9b\u989d\u5916\u7684\u6d4b\u8bd5\uff0c\u4ee5\u786e\u5b9aNmap\u662f\u5426\u80fd\u591f\u8bc6\u522b\u51fa\u64cd\u4f5c\u7cfb\u7edf\u6216\u670d\u52a1\u7248\u672c\u3002\u521b\u5efa\u4e00\u4e2a\u76ee\u5f55\u6765\u4fdd\u5b58\u60a8\u7684\u7248\u672c\u7ed3\u679c\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">mkdir<\/span> ~\/scan_results\/versions<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<h3>\u53d1\u73b0\u670d\u52a1\u5668\u4e0a\u7684\u670d\u52a1\u7248\u672c<\/h3>\n<p>\u4f60\u53ef\u4ee5\u5c1d\u8bd5\u901a\u8fc7\u4e00\u79cd\u88ab\u79f0\u4e3a\u6307\u7eb9\u8bc6\u522b\uff08fingerprinting\uff09\u7684\u8fc7\u7a0b\u6765\u731c\u6d4b\u76ee\u6807\u670d\u52a1\u7684\u7248\u672c\u3002\u4f60\u4ece\u670d\u52a1\u5668\u4e0a\u83b7\u53d6\u4fe1\u606f\uff0c\u5e76\u5c06\u5176\u4e0e\u6211\u4eec\u6570\u636e\u5e93\u4e2d\u7684\u5df2\u77e5\u7248\u672c\u8fdb\u884c\u6bd4\u8f83\u3002<\/p>\n<p>\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f7f\u7528Tcpdump\u53ef\u80fd\u6ca1\u6709\u592a\u5927\u7684\u7528\u5904\uff0c\u6240\u4ee5\u4f60\u53ef\u4ee5\u8df3\u8fc7\u5b83\u3002\u5982\u679c\u4f60\u4ecd\u7136\u60f3\u8981\u6355\u83b7\u5b83\uff0c\u53ef\u4ee5\u6309\u7167\u4e0a\u4e00\u6b21\u4f7f\u7528\u7684\u6b65\u9aa4\u8fdb\u884c\u3002<\/p>\n<p>\u60a8\u9700\u8981\u4f7f\u7528\u7684Nmap\u626b\u63cf\u662f\u901a\u8fc7<code>-sV<\/code>\u6807\u5fd7\u89e6\u53d1\u7684\u3002\u7531\u4e8e\u60a8\u5df2\u7ecf\u8fdb\u884c\u4e86SYN\u548cUDP\u626b\u63cf\uff0c\u53ef\u4ee5\u5c06\u9700\u8981\u67e5\u770b\u7684\u786e\u5207\u7aef\u53e3\u4f20\u9012\u7ed9<code>-p<\/code>\u6807\u5fd7\u3002\u5728\u8fd9\u91cc\uff0c\u60a8\u5c06\u67e5\u770b22\u548c80\u7aef\u53e3\uff08\u8fd9\u4e9b\u7aef\u53e3\u5728\u6211\u4eec\u7684SYN\u626b\u63cf\u4e2d\u663e\u793a\u51fa\u6765\uff09\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> nmap <span class=\"token parameter variable\">-sV<\/span> <span class=\"token parameter variable\">-Pn<\/span> <span class=\"token parameter variable\">-p<\/span> <span class=\"token number\">22,80<\/span> <span class=\"token parameter variable\">-vv<\/span> <span class=\"token parameter variable\">&#8211;reason<\/span> <span class=\"token parameter variable\">-oN<\/span> ~\/scan_results\/versions\/service_versions.nmap <mark>target_ip_addr<\/mark><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u5982\u679c\u60a8\u67e5\u770b\u751f\u6210\u7684\u6587\u4ef6\uff0c\u6839\u636e\u670d\u52a1\u7684\u54cd\u5e94\u7a0b\u5ea6\uff0c\u60a8\u53ef\u4ee5\u83b7\u53d6\u6709\u5173\u6b63\u5728\u8fd0\u884c\u7684\u670d\u52a1\u7684\u4fe1\u606f\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">less<\/span> ~\/scan_results\/versions\/service_versions.nmap<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div>~\/scan_results\/versions\/service_versions.nmap \u7684\u5185\u5bb9<\/div>\n<pre class=\"post-pre\"><code># Nmap 6.49BETA4 scan initiated Mon Dec 19 15:46:12 2022 as: nmap -sV -Pn -p 22,80 -vv --reason -oN \/home\/user\/scan_results\/versions\/service_versions.nmap 198.51.100.15\r\nNmap scan report for 198.51.100.15\r\nHost is up, received user-set (0.0011s latency).\r\nScanned at 2022-12-19 15:46:13 EDT for 8s\r\nPORT   STATE SERVICE REASON         VERSION\r\n22\/tcp open  ssh     syn-ack ttl 63 <mark>OpenSSH 6.6.1p1 Ubuntu 2ubuntu2 (Ubuntu Linux; protocol 2.0)<\/mark>\r\n80\/tcp open  http    syn-ack ttl 63 <mark>nginx 1.4.6 (Ubuntu)<\/mark>\r\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\r\n\r\nRead data files from: \/usr\/local\/bin\/..\/share\/nmap\r\nService detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\r\n# Nmap done at Mon Dec 19 15:46:21 2022 -- 1 IP address (1 host up) scanned in 8.81 seconds\r\n<\/code><\/pre>\n<p>\u5728\u8fd9\u91cc\uff0c\u4f60\u53ef\u4ee5\u770b\u5230\u6d4b\u8bd5\u80fd\u591f\u8bc6\u522b\u51faSSH\u670d\u52a1\u5668\u7684\u7248\u672c\u548c\u6253\u5305\u5b83\u7684Linux\u53d1\u884c\u7248\uff0c\u540c\u65f6\u4e5f\u8bc6\u522b\u51fa\u4e86\u6240\u63a5\u53d7\u7684SSH\u534f\u8bae\u7248\u672c\u3002\u5b83\u8fd8\u80fd\u591f\u8bc6\u522b\u51faNginx\u7684\u7248\u672c\uff0c\u5e76\u786e\u8ba4\u4e0eUbuntu\u7684\u4e00\u4e2a\u8f6f\u4ef6\u5305\u5339\u914d\u3002<\/p>\n<h3>\u53d1\u73b0\u4e3b\u673a\u64cd\u4f5c\u7cfb\u7edf<\/h3>\n<p>\u4f60\u53ef\u4ee5\u5c1d\u8bd5\u4f7f\u7528Nmap\u6839\u636e\u8f6f\u4ef6\u548c\u54cd\u5e94\u7279\u5f81\u6765\u731c\u6d4b\u4e3b\u673a\u64cd\u4f5c\u7cfb\u7edf\u3002\u8fd9\u4e0e\u670d\u52a1\u7248\u672c\u63a2\u6d4b\u7684\u65b9\u5f0f\u76f8\u540c\u3002\u540c\u6837\uff0c\u6211\u4eec\u5c06\u5728\u8fd9\u4e2a\u6d4b\u8bd5\u4e2d\u7701\u7565Tcpdump\u7684\u8fd0\u884c\uff0c\u4f46\u5982\u679c\u4f60\u613f\u610f\uff0c\u4f60\u53ef\u4ee5\u6267\u884c\u5b83\u3002<\/p>\n<p>\u4f60\u9700\u8981\u6267\u884c\u64cd\u4f5c\u7cfb\u7edf\u68c0\u6d4b\u7684\u6807\u5fd7\u662f<code>-O<\/code>\uff08\u5927\u5199\u5b57\u6bcd\u201cO\u201d\uff09\u3002\u5b8c\u6574\u7684\u547d\u4ee4\u53ef\u80fd\u662f\u8fd9\u6837\u7684\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> nmap <span class=\"token parameter variable\">-O<\/span> <span class=\"token parameter variable\">-Pn<\/span> <span class=\"token parameter variable\">-vv<\/span> <span class=\"token parameter variable\">&#8211;reason<\/span> <span class=\"token parameter variable\">-oN<\/span> ~\/scan_results\/versions\/os_version.nmap <mark>target_ip_addr<\/mark><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u5982\u679c\u60a8\u67e5\u770b\u8f93\u51fa\u6587\u4ef6\uff0c\u53ef\u80fd\u4f1a\u770b\u5230\u7c7b\u4f3c\u5982\u4e0b\u7684\u5185\u5bb9\uff1a<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">less<\/span> ~\/scan_results\/versions\/os_version.nmap<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div>~\/scan_results\/versions\/os_versions.nmap \u603b\u7ed3<\/div>\n<pre class=\"post-pre\"><code># Nmap 6.49BETA4 scan initiated Mon Dec 19 15:53:54 2022 as: nmap -O -Pn -vv --reason -oN \/home\/user\/scan_results\/versions\/os_version.nmap 198.51.100.15\r\nIncreasing send delay for 198.51.100.15 from 0 to 5 due to 65 out of 215 dropped probes since last increase.\r\nIncreasing send delay for 198.51.100.15 from 5 to 10 due to 11 out of 36 dropped probes since last increase.\r\nIncreasing send delay for 198.51.100.15 from 10 to 20 due to 11 out of 35 dropped probes since last increase.\r\nIncreasing send delay for 198.51.100.15 from 20 to 40 due to 11 out of 29 dropped probes since last increase.\r\nIncreasing send delay for 198.51.100.15 from 40 to 80 due to 11 out of 31 dropped probes since last increase.\r\nNmap scan report for 198.51.100.15\r\nHost is up, received user-set (0.0012s latency).\r\nScanned at 2022-12-19 15:53:54 EDT for 30s\r\nNot shown: 998 closed ports\r\nReason: 998 resets\r\nPORT   STATE SERVICE REASON\r\n22\/tcp open  ssh     syn-ack ttl 63\r\n80\/tcp open  http    syn-ack ttl 63\r\nNo exact OS matches for host (If you know what OS is running on it, see https:\/\/nmap.org\/submit\/ ).\r\nTCP\/IP fingerprint:\r\nOS:SCAN(V=6.49BETA4%E=4%D=8\/27%OT=22%CT=1%CU=40800%PV=N%DS=2%DC=I%G=Y%TM=55\r\nOS:DF6AF0%P=x86_64-unknown-linux-gnu)SEQ(SP=F5%GCD=1%ISR=106%TI=Z%CI=Z%TS=8\r\nOS:)OPS(O1=M5B4ST11NW8%O2=M5B4ST11NW8%O3=M5B4NNT11NW8%O4=M5B4ST11NW8%O5=M5B\r\nOS:4ST11NW8%O6=M5B4ST11)WIN(W1=7120%W2=7120%W3=7120%W4=7120%W5=7120%W6=7120\r\nOS:)ECN(R=Y%DF=Y%T=40%W=7210%O=M5B4NNSNW8%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+\r\nOS:%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)\r\nOS:T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A\r\nOS:=Z%F=R%O=%RD=0%Q=)T7(R=N)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPC\r\nOS:K=G%RUCK=G%RUD=G)U1(R=N)IE(R=N)\r\n\r\nUptime guess: 1.057 days (since Mon Dec 12 14:32:23 2022)\r\nNetwork Distance: 2 hops\r\nTCP Sequence Prediction: Difficulty=245 (Good luck!)\r\nIP ID Sequence Generation: All zeros\r\n\r\nRead data files from: \/usr\/local\/bin\/..\/share\/nmap\r\nOS detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\r\n# Nmap done at Mon Dec 12 15:54:24 2022 -- 1 IP address (1 host up) scanned in 30.94 seconds\r\n<\/code><\/pre>\n<p>\u6211\u4eec\u53ef\u4ee5\u770b\u5230\uff0c\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0cNmap\u6839\u636e\u5b83\u6240\u770b\u5230\u7684\u7279\u5f81\u4fe1\u606f\u65e0\u6cd5\u731c\u6d4b\u64cd\u4f5c\u7cfb\u7edf\u3002\u5982\u679c\u5b83\u6536\u5230\u66f4\u591a\u4fe1\u606f\uff0c\u53ef\u80fd\u4f1a\u663e\u793a\u5404\u79cd\u767e\u5206\u6bd4\uff0c\u8fd9\u4e9b\u767e\u5206\u6bd4\u8868\u793a\u76ee\u6807\u673a\u5668\u7684\u7279\u5f81\u4fe1\u606f\u4e0e\u5176\u6570\u636e\u5e93\u4e2d\u7684\u64cd\u4f5c\u7cfb\u7edf\u7279\u5f81\u4fe1\u606f\u7684\u5339\u914d\u7a0b\u5ea6\u3002\u60a8\u53ef\u4ee5\u5728\u201cTCP\/IP fingerprint:\u201d\u884c\u4e0b\u65b9\u770b\u5230Nmap\u4ece\u76ee\u6807\u5904\u6536\u5230\u7684\u6307\u7eb9\u7279\u5f81\u4fe1\u606f\u3002<\/p>\n<p>\u64cd\u4f5c\u7cfb\u7edf\u8bc6\u522b\u53ef\u4ee5\u5e2e\u52a9\u653b\u51fb\u8005\u786e\u5b9a\u7cfb\u7edf\u4e0a\u53ef\u80fd\u5b58\u5728\u7684\u6f0f\u6d1e\u3002\u5c06\u9632\u706b\u5899\u914d\u7f6e\u4e3a\u5bf9\u8f83\u5c11\u7684\u67e5\u8be2\u505a\u51fa\u54cd\u5e94\u53ef\u4ee5\u963b\u788d\u90e8\u5206\u8fd9\u4e9b\u68c0\u6d4b\u65b9\u6cd5\u7684\u51c6\u786e\u6027\u3002<\/p>\n<h2>\u7ed3\u8bba<\/h2>\n<p>\u901a\u8fc7\u6d4b\u8bd5\u60a8\u7684\u9632\u706b\u5899\u5e76\u4e86\u89e3\u60a8\u5185\u90e8\u7f51\u7edc\u5bf9\u5916\u90e8\u653b\u51fb\u8005\u7684\u60c5\u51b5\uff0c\u53ef\u4ee5\u5e2e\u52a9\u964d\u4f4e\u98ce\u9669\u3002\u4ece\u6d4b\u8bd5\u60a8\u81ea\u5df1\u7684\u57fa\u7840\u8bbe\u65bd\u4e2d\u83b7\u5f97\u7684\u4fe1\u606f\u53ef\u80fd\u4f1a\u5f15\u53d1\u5173\u4e8e\u662f\u5426\u9700\u8981\u91cd\u65b0\u5ba1\u67e5\u67d0\u4e9b\u7b56\u7565\u51b3\u5b9a\u4ee5\u589e\u52a0\u5b89\u5168\u6027\u7684\u8ba8\u8bba\u3002\u5b83\u8fd8\u53ef\u4ee5\u63ed\u793a\u7531\u4e8e\u89c4\u5219\u6392\u5e8f\u4e0d\u6b63\u786e\u6216\u9057\u5fd8\u6d4b\u8bd5\u7b56\u7565\u800c\u5bfc\u81f4\u7684\u5b89\u5168\u6f0f\u6d1e\u3002\u5efa\u8bae\u5b9a\u671f\u4f7f\u7528\u6700\u65b0\u7684\u626b\u63cf\u6570\u636e\u5e93\u6765\u6d4b\u8bd5\u60a8\u7684\u7b56\u7565\uff0c\u4ee5\u6539\u5584\u6216\u81f3\u5c11\u7ef4\u6301\u60a8\u5f53\u524d\u7684\u5b89\u5168\u7ea7\u522b\u3002<\/p>\n<p>\u68c0\u67e5\u8fd9\u4efd\u6307\u5357\uff0c\u4ee5\u83b7\u5f97\u4e00\u4e9b\u5173\u4e8e\u60a8\u7684\u9632\u706b\u5899\u7b56\u7565\u6539\u8fdb\u7684\u60f3\u6cd5\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5f15\u8a00 \u4e3a\u60a8\u7684\u57fa\u7840\u8bbe\u65bd\u8bbe\u7f6e\u9632\u706b\u5899\u662f\u63d0\u4f9b\u670d\u52a1\u5b89\u5168\u7684\u597d\u65b9\u6cd5\u3002\u4e00\u65e6\u60a8\u5236\u5b9a\u4e86\u6ee1\u610f\u7684\u7b56\u7565\uff0c\u4e0b\u4e00\u6b65\u5c31\u662f\u6d4b\u8bd5\u60a8\u7684\u9632\u706b\u5899\u89c4\u5219\u3002\u91cd [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[284,285,214,287,286],"class_list":["post-27","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-nmap","tag-tcpdump","tag-214","tag-287","tag-286"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Nmap\u4e0eTcpdump\u5b9e\u6218\uff1a\u6df1\u5ea6\u68c0\u6d4b\u9632\u706b\u5899\u914d\u7f6e\u4e0e\u5b89\u5168\u6027 - Blog - Silicon Cloud<\/title>\n<meta name=\"description\" content=\"\u60f3\u77e5\u9053\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\u662f\u5426\u5b89\u5168\u6709\u6548\uff1f\u672c\u6587\u5c06\u8be6\u7ec6\u6307\u5bfc\u60a8\u5982\u4f55\u5229\u7528Nmap\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\u548cTcpdump\u8fdb\u884c\u6d41\u91cf\u5206\u6790\uff0c\u5168\u9762\u68c0\u6d4b\u5e76\u4f18\u5316\u60a8\u7684\u9632\u706b\u5899\u89c4\u5219\uff0c\u63d0\u5347\u7f51\u7edc\u9632\u5fa1\u80fd\u529b\u3002\u7acb\u5373\u5b66\u4e60\uff0c\u638c\u63e1\u9632\u706b\u5899\u5b89\u5168\u6d4b\u8bd5\u6838\u5fc3\u6280\u80fd\uff01\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u5982\u4f55\u4f7f\u7528nmap\u548ctcpdump\u6d4b\u8bd5\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Nmap\u4e0eTcpdump\u5b9e\u6218\uff1a\u6df1\u5ea6\u68c0\u6d4b\u9632\u706b\u5899\u914d\u7f6e\u4e0e\u5b89\u5168\u6027\" \/>\n<meta property=\"og:description\" content=\"\u60f3\u77e5\u9053\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\u662f\u5426\u5b89\u5168\u6709\u6548\uff1f\u672c\u6587\u5c06\u8be6\u7ec6\u6307\u5bfc\u60a8\u5982\u4f55\u5229\u7528Nmap\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\u548cTcpdump\u8fdb\u884c\u6d41\u91cf\u5206\u6790\uff0c\u5168\u9762\u68c0\u6d4b\u5e76\u4f18\u5316\u60a8\u7684\u9632\u706b\u5899\u89c4\u5219\uff0c\u63d0\u5347\u7f51\u7edc\u9632\u5fa1\u80fd\u529b\u3002\u7acb\u5373\u5b66\u4e60\uff0c\u638c\u63e1\u9632\u706b\u5899\u5b89\u5168\u6d4b\u8bd5\u6838\u5fc3\u6280\u80fd\uff01\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u5982\u4f55\u4f7f\u7528nmap\u548ctcpdump\u6d4b\u8bd5\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-25T21:21:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-31T13:32:29+00:00\" \/>\n<meta name=\"author\" content=\"\u65b0, \u97f5\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u65b0, \u97f5\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/\",\"name\":\"Nmap\u4e0eTcpdump\u5b9e\u6218\uff1a\u6df1\u5ea6\u68c0\u6d4b\u9632\u706b\u5899\u914d\u7f6e\u4e0e\u5b89\u5168\u6027 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2022-11-25T21:21:34+00:00\",\"dateModified\":\"2025-07-31T13:32:29+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9\"},\"description\":\"\u60f3\u77e5\u9053\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\u662f\u5426\u5b89\u5168\u6709\u6548\uff1f\u672c\u6587\u5c06\u8be6\u7ec6\u6307\u5bfc\u60a8\u5982\u4f55\u5229\u7528Nmap\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\u548cTcpdump\u8fdb\u884c\u6d41\u91cf\u5206\u6790\uff0c\u5168\u9762\u68c0\u6d4b\u5e76\u4f18\u5316\u60a8\u7684\u9632\u706b\u5899\u89c4\u5219\uff0c\u63d0\u5347\u7f51\u7edc\u9632\u5fa1\u80fd\u529b\u3002\u7acb\u5373\u5b66\u4e60\uff0c\u638c\u63e1\u9632\u706b\u5899\u5b89\u5168\u6d4b\u8bd5\u6838\u5fc3\u6280\u80fd\uff01\",\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Nmap\u4e0eTcpdump\u5b9e\u6218\uff1a\u6df1\u5ea6\u68c0\u6d4b\u9632\u706b\u5899\u914d\u7f6e\u4e0e\u5b89\u5168\u6027\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9\",\"name\":\"\u65b0, \u97f5\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g\",\"caption\":\"\u65b0, \u97f5\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunxin\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Nmap\u4e0eTcpdump\u5b9e\u6218\uff1a\u6df1\u5ea6\u68c0\u6d4b\u9632\u706b\u5899\u914d\u7f6e\u4e0e\u5b89\u5168\u6027 - Blog - Silicon Cloud","description":"\u60f3\u77e5\u9053\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\u662f\u5426\u5b89\u5168\u6709\u6548\uff1f\u672c\u6587\u5c06\u8be6\u7ec6\u6307\u5bfc\u60a8\u5982\u4f55\u5229\u7528Nmap\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\u548cTcpdump\u8fdb\u884c\u6d41\u91cf\u5206\u6790\uff0c\u5168\u9762\u68c0\u6d4b\u5e76\u4f18\u5316\u60a8\u7684\u9632\u706b\u5899\u89c4\u5219\uff0c\u63d0\u5347\u7f51\u7edc\u9632\u5fa1\u80fd\u529b\u3002\u7acb\u5373\u5b66\u4e60\uff0c\u638c\u63e1\u9632\u706b\u5899\u5b89\u5168\u6d4b\u8bd5\u6838\u5fc3\u6280\u80fd\uff01","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u5982\u4f55\u4f7f\u7528nmap\u548ctcpdump\u6d4b\u8bd5\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\/","og_locale":"zh_CN","og_type":"article","og_title":"Nmap\u4e0eTcpdump\u5b9e\u6218\uff1a\u6df1\u5ea6\u68c0\u6d4b\u9632\u706b\u5899\u914d\u7f6e\u4e0e\u5b89\u5168\u6027","og_description":"\u60f3\u77e5\u9053\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\u662f\u5426\u5b89\u5168\u6709\u6548\uff1f\u672c\u6587\u5c06\u8be6\u7ec6\u6307\u5bfc\u60a8\u5982\u4f55\u5229\u7528Nmap\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\u548cTcpdump\u8fdb\u884c\u6d41\u91cf\u5206\u6790\uff0c\u5168\u9762\u68c0\u6d4b\u5e76\u4f18\u5316\u60a8\u7684\u9632\u706b\u5899\u89c4\u5219\uff0c\u63d0\u5347\u7f51\u7edc\u9632\u5fa1\u80fd\u529b\u3002\u7acb\u5373\u5b66\u4e60\uff0c\u638c\u63e1\u9632\u706b\u5899\u5b89\u5168\u6d4b\u8bd5\u6838\u5fc3\u6280\u80fd\uff01","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u5982\u4f55\u4f7f\u7528nmap\u548ctcpdump\u6d4b\u8bd5\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2022-11-25T21:21:34+00:00","article_modified_time":"2025-07-31T13:32:29+00:00","author":"\u65b0, \u97f5","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u65b0, \u97f5","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"4 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/","name":"Nmap\u4e0eTcpdump\u5b9e\u6218\uff1a\u6df1\u5ea6\u68c0\u6d4b\u9632\u706b\u5899\u914d\u7f6e\u4e0e\u5b89\u5168\u6027 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2022-11-25T21:21:34+00:00","dateModified":"2025-07-31T13:32:29+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9"},"description":"\u60f3\u77e5\u9053\u60a8\u7684\u9632\u706b\u5899\u914d\u7f6e\u662f\u5426\u5b89\u5168\u6709\u6548\uff1f\u672c\u6587\u5c06\u8be6\u7ec6\u6307\u5bfc\u60a8\u5982\u4f55\u5229\u7528Nmap\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\u548cTcpdump\u8fdb\u884c\u6d41\u91cf\u5206\u6790\uff0c\u5168\u9762\u68c0\u6d4b\u5e76\u4f18\u5316\u60a8\u7684\u9632\u706b\u5899\u89c4\u5219\uff0c\u63d0\u5347\u7f51\u7edc\u9632\u5fa1\u80fd\u529b\u3002\u7acb\u5373\u5b66\u4e60\uff0c\u638c\u63e1\u9632\u706b\u5899\u5b89\u5168\u6d4b\u8bd5\u6838\u5fc3\u6280\u80fd\uff01","breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"Nmap\u4e0eTcpdump\u5b9e\u6218\uff1a\u6df1\u5ea6\u68c0\u6d4b\u9632\u706b\u5899\u914d\u7f6e\u4e0e\u5b89\u5168\u6027"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9","name":"\u65b0, \u97f5","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g","caption":"\u65b0, \u97f5"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunxin\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8nmap%e5%92%8ctcpdump%e6%b5%8b%e8%af%95%e6%82%a8%e7%9a%84%e9%98%b2%e7%81%ab%e5%a2%99%e9%85%8d%e7%bd%ae\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/27","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=27"}],"version-history":[{"count":4,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/27\/revisions"}],"predecessor-version":[{"id":109479,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/27\/revisions\/109479"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=27"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=27"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=27"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}