' |1 ~# l0 B; U. q: froot@bt:/usr/local/share/nmap/scripts# nmap –script=smb-enum-users.nse 202.103.242.241 & i" `- ^5 @& B: P8 A* \2 f; ~. r / N& m$ t# D" e* N7 U# T//此乃使用脚本扫描远程机器所存在的账户名; J: L5 w S) f) F! u
( W- i P9 b+ }& i8 N# c& TStarting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-28 22:12 CST. k1 K9 L+ R7 Q& j% Y
0 D2 y8 ~$ U+ a* ^! b4 G( s# J
Nmap scan report for bogon (202.103.242.241) , _5 r! J8 V" f! t: R+ u' X& U: L 3 A/ Z8 K& Y/ y# P" z2 `Host is up (0.00038s latency). , c" V e! d2 C! ?' b) ~# } * ]+ e4 b4 s2 w D& ONot shown: 993 closed ports ' c6 `" i* a0 R* i: s! G7 B( A , I% A, j2 m5 W0 ]) w9 IPORT STATE SERVICE& l) s: e# v: n
# \& M t) n* a) W9 S! M8 }135/tcp open msrpc 8 f( B. ?) x2 L& @" T% x/ O$ W$ s, V+ g7 R
139/tcp open netbios-ssn$ k' c/ c4 q( F/ h1 @; m
' m e; t% C" j# T
445/tcp open microsoft-ds) x. Y, p2 O! r! k" L( U0 S9 s5 D2 o
$ e% |! T) ]! V! k+ k- X2 x1025/tcp open NFS-or-IIS0 S2 ~: V, A6 z7 S# L
4 O+ |* Q% ` V ?: {1026/tcp open LSA-or-nterm 3 _) i2 z1 E2 M8 \! `# ~& M& \( x( X5 N% e; O% S e* P
3372/tcp open msdtc 8 P. Y0 e( E/ X9 _0 }2 e / t4 F7 U. Z5 I: V0 @4 M3389/tcp open ms-term-serv 4 z3 J( u: m5 @ \3 J: R5 b1 K2 x) b# O' aMAC Address: 08:00:277:2E:79 (Cadmus Computer Systems) * D- C5 v) a! t2 ]$ [7 L7 J. q% a3 M4 b' {$ ?) e- `* Z
Host script results: ) w: W7 L$ K+ l" X: m5 Q% E9 R, K1 P3 U
| smb-enum-users: $ i. s" s" \6 f ' s& T" X& L' K) ]9 i w. t0 O|_ Domain: PG-F289F9A8EF3E; Users:Administrator, Guest, test, TsInternetUser //扫描结果3 ?# E& y N$ L9 Z
6 Z* ]6 l5 @( s$ L) H
Nmap done: 1 IP address (1 host up) scanned in 1.09 seconds/ L& ]5 W u' D* G8 g, _
3 L. w% F; L; O x% `! v' ` q. u) ~
root@bt:/usr/local/share/nmap/scripts# nmap –script=smb-enum-shares.nse 202.103.242.241 - H# ?/ p; G: V- y * \9 C+ D2 S7 v) j" @: |0 Q0 U//查看共享 5 y7 ]' s3 U$ D* h, ] & k! m8 ^% x# E/ VStarting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-28 22:15 CST 1 q8 k9 T' B/ T _* \9 C) O 1 f4 D' B% }0 ^5 L- [$ I9 |Nmap scan report for bogon (202.103.242.241) % K, {9 z' S# z+ i( Z5 B) O 9 Q ~- T: a. O; C# lHost is up (0.00035s latency).3 W. U' S0 \- U- [8 I
; v5 v5 b0 O3 H& B* X; U/ QNot shown: 993 closed ports , l% B5 b% h- p& A1 C1 y: x) B8 u7 M- v$ A
PORT STATE SERVICE& b7 W" u* a2 t4 g2 U, ~6 [
Z* t; y3 J. Q
135/tcp open msrpc $ h o8 l8 b1 h# {8 {. P2 `) [) {4 y; }1 m: ~+ u' q: a8 M
139/tcp open netbios-ssn# }3 i5 `8 I1 [# P7 K3 j g& o$ U
2 M" S! ~( {1 Z2 {) O$ `
445/tcp open microsoft-ds 2 M: r- m/ z6 ]/ h0 K5 t6 o1 Z0 J5 T' C: v6 y. B, d! V
1025/tcp open NFS-or-IIS& T* }; X1 j) D; F
$ F1 ?$ E* m1 L7 S2 p( C" z1026/tcp open LSA-or-nterm E; h! }- A, a# m% ^3 M4 a9 j/ ]" O( [' U% Q5 q; @
3372/tcp open msdtc# Q5 R3 z# D+ m, @9 F
* w* s6 f; ~0 }' S/ A" J7 V
3389/tcp open ms-term-serv $ D( ^& q ~' ]4 u$ N# l* A/ \# Q5 B5 Y. l( b* C% a
MAC Address: 08:00:277:2E:79 (Cadmus Computer Systems)- y( g4 _) S; r8 i' T% J0 X: U, h0 i
& D- Z7 N- x! Z, E2 ?5 A
Host script results: 7 U9 ~ I) z$ n Y: Y& ]1 X {' b* R8 T! y! X
| smb-enum-shares:1 |; d, Z9 W2 G- T; R- n0 W
0 H; C) X1 x. J0 J1 y| ADMIN$ 5 x$ w' T+ v- { 5 n5 E! s' u. s3 R; \7 N1 W| Anonymous access: <none>: D% { X9 Y0 E( i) @- Z6 i