Discovery/udp sweep
De www.metasploit-es.com.ar
El modulo "udp_sweep" escanea por un rango de hosts determinado para detectar servicios comunes UDP disponibles.
msf > use auxiliary/scanner/discovery/udp_sweep msf auxiliary(udp_sweep) > show options Module options: Name Current Setting Required Description ---- --------------- -------- ----------- BATCHSIZE 256 yes The number of hosts to probe in each set CHOST no The local client address RHOSTS yes The target address range or CIDR identifier THREADS 1 yes The number of concurrent threads VERBOSE false no Enable verbose output
Para configurar este modulo, simplemente necesitamos definir los valores RHOSTS y THREADS y ejecutarlo.
msf auxiliary(udp_sweep) > set RHOSTS 192.168.1.2-254 RHOSTS => 192.168.1.2-254 msf auxiliary(udp_sweep) > set THREADS 253 THREADS => 253 msf auxiliary(udp_sweep) > run [*] Sending 10 probes to 192.168.1.2->192.168.1.254 (253 hosts) [*] Discovered NetBIOS on 192.168.1.109:137 (SAMSUNG:<00>:U :SAMSUNG:<20>:U :00:15:99:3f:40:bd) [*] Discovered NetBIOS on 192.168.1.150:137 (XEN-WIN7-PROD:<00>:U :WORKGROUP:<00>:G :XEN-WIN7-PROD:<20>:U :WORKGROUP:<1e>:G :aa:e3:27:6e:3b:a5) [*] Discovered NetBIOS on 192.168.1.203:137 (XEN-XP-SPLOIT:<00>:U :WORKGROUP:<00>:G :XEN-XP-SPLOIT:<20>:U :WORKGROUP:<1e>:G :3e:ff:3c:4c:89:67) [*] Discovered NetBIOS on 192.168.1.201:137 (XEN-XP-SP2-BARE:<00>:U :HOTZONE:<00>:G :XEN-XP-SP2-BARE:<20>:U :HOTZONE:<1e>:G :HOTZONE:<1d>:U :__MSBROWSE__:<01>:G :c6:ce:4e:d9:c9:6e) [*] Discovered NetBIOS on 192.168.1.206:137 (XEN-XP-PATCHED:<00>:U :XEN-XP-PATCHED:<20>:U :HOTZONE:<00>:G :HOTZONE:<1e>:G :12:fa:1a:75:b8:a5) [*] Discovered NetBIOS on 192.168.1.250:137 (FREENAS:<20>:U :FREENAS:<00>:U :FREENAS:<03>:U :__MSBROWSE__:<01>:G :WORKGROUP:<1d>:U :WORKGROUP:<1e>:G :WORKGROUP:<00>:G :00:00:00:00:00:00) [*] Discovered SNMP on 192.168.1.2:161 (GSM7224 L2 Managed Gigabit Switch) [*] Discovered SNMP on 192.168.1.109:161 (Samsung CLX-3160 Series; OS V1.01.01.16 02-25-2008;Engine 6.01.00;NIC V4.03.08(CLX-3160) 02-25-2008;S/N 8Y61B1GP400065Y.) [*] Discovered NTP on 192.168.1.69:123 (NTP v4) [*] Discovered NTP on 192.168.1.99:123 (NTP v4) [*] Discovered NTP on 192.168.1.201:123 (Microsoft NTP) [*] Discovered NTP on 192.168.1.203:123 (Microsoft NTP) [*] Discovered NTP on 192.168.1.206:123 (Microsoft NTP) [*] Discovered MSSQL on 192.168.1.206:1434 (ServerName=XEN-XP-PATCHED InstanceName=SQLEXPRESS IsClustered=No Version=9.00.4035.00 tcp=1050 np=\\XEN-XP-PATCHED\pipe\MSSQL$SQLEXPRESS\sql\query ) [*] Discovered SNMP on 192.168.1.2:161 (GSM7224 L2 Managed Gigabit Switch) [*] Discovered SNMP on 192.168.1.109:161 (Samsung CLX-3160 Series; OS V1.01.01.16 02-25-2008;Engine 6.01.00;NIC V4.03.08(CLX-3160) 02-25-2008;S/N 8Y61B1GP400065Y.) [*] Scanned 253 of 253 hosts (100% complete) [*] Auxiliary module execution completed msf auxiliary(udp_sweep) >
Con minimo esfuerzo, tenemos una vez mas identificados un gran numero de servicios corriendo en plataformas muy diferentes dentro de nuestra red.
© Offensive Security 2009
Original de www.offensive-security.com Traducido por cbk999