Thursday, August 25, 2011

Melihat Service yang aktif pada sebuah Server


[root@andik-rock]# nmap -v -sS -O www.detik.com
Starting nmap V. 2.53 by fyodor@insecure.org ( www.insecure.org/nmap/ )
Host www.detik.com (202.158.66.181) appears to be up … good.
Initiating SYN half-open stealth scan against www.detik.com
Interesting ports on www.detik.com (202.158.66.181):
(The 1513 ports scanned but not shown below are in state: filtered)
Port       State       Service
20/tcp     closed      ftp-data
21/tcp     closed      ftp
22/tcp     open        ssh
25/tcp     closed      smtp
80/tcp     open        http
110/tcp    closed      pop-3
443/tcp    closed      https
1417/tcp   closed      timbuktu-srv1
5900/tcp   closed      vnc
5901/tcp   closed      vnc-1
TCP Sequence Prediction: positive increments
Difficulty=3193299 (Good luck!)
Nmap run completed — 1 IP address (1 host up) scanned in 580 seconds
[root@andik-rock]# nmap -v -sS -O www.telkom.co.id
Starting nmap V. 2.53 by fyodor@insecure.org ( www.insecure.org/nmap/ )
Host  (202.134.2.15) appears to be up … good.
Interesting ports on  (202.134.2.15):
(The 1493 ports scanned but not shown below are in state: closed)
Port       State       Service
7/tcp      open        echo
9/tcp      open        discard
13/tcp     open        daytime
19/tcp     open        chargen
37/tcp     open        time
80/tcp     open        http
111/tcp    open        sunrpc
137/tcp    filtered    netbios-ns
138/tcp    filtered    netbios-dgm
139/tcp    filtered    netbios-ssn
199/tcp    open        smux
512/tcp    open        exec
513/tcp    open        login
514/tcp    open        shell
543/tcp    open        klogin
544/tcp    open        kshell
882/tcp    open        unknown
883/tcp    open        unknown
1234/tcp   open        hotline
1352/tcp   open        lotusnotes
1524/tcp   filtered    ingreslock
2041/tcp   filtered    interbase
2401/tcp   open        cvspserver
6000/tcp   filtered    X11
6112/tcp   open        dtspc
12345/tcp  filtered    NetBus
12346/tcp  filtered    NetBus
27665/tcp  filtered    Trinoo_Master
32771/tcp  open        sometimes-rpc5
32773/tcp  open        sometimes-rpc9
TCP Sequence Prediction: random
Difficulty=9999999 (Good luck!)
Nmap run completed — 1 IP address (1 host up) scanned in 284 seconds
[root@andik-rock]#
[root@andik-rock]# nmap -vv -sS -O ibank.klikbca.com
Starting nmap V. 2.53 by fyodor@insecure.org ( www.insecure.org/nmap/ )
Host  (202.158.15.52) appears to be down, skipping it.
Note: Host seems down. If it is really up, but blocking our ping probes, try -P0
Nmap run completed — 1 IP address (0 hosts up) scanned in 43 seconds

root@Maximum:/home/easy2study# nmap -v -sS -O www.google.co.id

Starting Nmap 5.21 ( http://nmap.org ) at 2011-08-25 08:36 WIT
Initiating Ping Scan at 08:36
Scanning www.google.co.id (74.125.235.49) [4 ports]
Completed Ping Scan at 08:36, 0.13s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 08:36
Completed Parallel DNS resolution of 1 host. at 08:36, 0.11s elapsed
Initiating SYN Stealth Scan at 08:36
Scanning www.google.co.id (74.125.235.49) [1000 ports]
Discovered open port 53/tcp on 74.125.235.49
Discovered open port 443/tcp on 74.125.235.49
Discovered open port 80/tcp on 74.125.235.49
Completed SYN Stealth Scan at 08:36, 18.09s elapsed (1000 total ports)
Initiating OS detection (try #1) against www.google.co.id (74.125.235.49)
Retrying OS detection (try #2) against www.google.co.id (74.125.235.49)
Nmap scan report for www.google.co.id (74.125.235.49)
Host is up (0.054s latency).
Hostname www.google.co.id resolves to 5 IPs. Only scanned 74.125.235.49
Not shown: 996 filtered ports
PORT    STATE  SERVICE
53/tcp  open   domain
80/tcp  open   http
113/tcp closed auth
443/tcp open   https
Device type: general purpose|storage-misc|WAP|specialized|switch
Running (JUST GUESSING) : Linux 2.6.X|2.4.X (93%), D-Link embedded (93%), Linksys embedded (93%), Western Digital Linux 2.6.X (88%), Acorp embedded (87%), Google embedded (87%), HP embedded (87%), MontaVista Linux 2.4.X (87%)
Aggressive OS guesses: Linux 2.6.15 - 2.6.23 (embedded) (93%), D-Link DNS-323 NAS device or Linksys WRT300N wireless broadband router (93%), Linux 2.6.18 (ClarkConnect 4.3 Enterprise Edition) (92%), Linux 2.6.15 - 2.6.27 (89%), Linux 2.6.23 (88%), Linux 2.4.21 - 2.4.31 (likely embedded) (88%), Linux 2.6.15 - 2.6.30 (88%), Linux 2.6.9 - 2.6.27 (88%), Western Digital MyBook World Edition 2 NAS device (Linux 2.6.17.14) (88%), Acorp W400G or W422G wireless ADSL modem (MontaVista embedded Linux 2.4.17) (87%)
No exact OS matches for host (test conditions non-ideal).
Uptime guess: 0.474 days (since Wed Aug 24 21:14:36 2011)
TCP Sequence Prediction: Difficulty=203 (Good luck!)
IP ID Sequence Generation: All zeros

Read data files from: /usr/share/nmap
OS detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 29.64 seconds
           Raw packets sent: 3070 (138.588KB) | Rcvd: 37 (2228B)


root@Maximum:/home/easy2study# nmap -v -sS -O www.facebook.com

Starting Nmap 5.21 ( http://nmap.org ) at 2011-08-25 08:31 WIT
Initiating Ping Scan at 08:31
Scanning www.facebook.com (69.171.228.39) [4 ports]
Completed Ping Scan at 08:31, 0.35s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 08:31
Completed Parallel DNS resolution of 1 host. at 08:31, 0.18s elapsed
Initiating SYN Stealth Scan at 08:31
Scanning www.facebook.com (69.171.228.39) [1000 ports]
Discovered open port 80/tcp on 69.171.228.39
Discovered open port 443/tcp on 69.171.228.39
Discovered open port 53/tcp on 69.171.228.39
SYN Stealth Scan Timing: About 13.85% done; ETC: 08:35 (0:03:13 remaining)
SYN Stealth Scan Timing: About 63.62% done; ETC: 08:33 (0:00:35 remaining)
Completed SYN Stealth Scan at 08:33, 100.55s elapsed (1000 total ports)
Initiating OS detection (try #1) against www.facebook.com (69.171.228.39)
Retrying OS detection (try #2) against www.facebook.com (69.171.228.39)
Nmap scan report for www.facebook.com (69.171.228.39)
Host is up (0.14s latency).
rDNS record for 69.171.228.39: www-14-05-prn1.facebook.com
Not shown: 997 filtered ports
PORT    STATE SERVICE
53/tcp  open  domain
80/tcp  open  http
443/tcp open  https
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|printer|media device|WAP|firewall
Running (JUST GUESSING) : Linux 2.6.X|2.4.X (95%), Lexmark embedded (93%), Chumby embedded (90%), FON Linux 2.6.X (90%), RGB Spectrum embedded (90%), Linksys embedded (88%), Xerox embedded (88%), Cisco embedded (87%)
Aggressive OS guesses: Linux 2.6.15 - 2.6.23 (embedded) (95%), Lexmark X4530, X4650, or 4800 wireless printer (93%), Linux 2.6.9 - 2.6.30 (91%), Chumby Internet radio (90%), DD-WRT v24 (Linux 2.6.22) (90%), RGB Spectrum MediaWall 1500 video processor (90%), Linux 2.4.21 - 2.4.31 (likely embedded) (89%), Linux 2.6.15 - 2.6.30 (89%), Linux 2.6.15 - 2.6.27 (89%), Linux 2.6.20 (88%)
No exact OS matches for host (test conditions non-ideal).
Uptime guess: 0.471 days (since Wed Aug 24 21:14:35 2011)
TCP Sequence Prediction: Difficulty=204 (Good luck!)
IP ID Sequence Generation: All zeros

Read data files from: /usr/share/nmap
OS detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 120.91 seconds
           Raw packets sent: 4115 (184.916KB) | Rcvd: 72 (3836B)