Thursday, June 25, 2015

nmap: scanning for conficker


nmap -p139,445 --script p2p-conficker,smb-os-discovery,smb-check-vulns --script-args=smbuser=*****,smbpass=*****,checkconficker=1,safe=1 -T4 192.168.1.100-254

Bad results look like this


Nmap scan report for 192.168.1.253
Host is up (0.00018s latency).
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
MAC Address: 70:71:BC:0E:00:92 (Pegatron)

Host script results:
| smb-check-vulns:
|   MS08-067: CHECK DISABLED (add '--script-args=unsafe=1' to run)
|   Conficker: Likely INFECTED (by Conficker.C or lower)
|   regsvc DoS: CHECK DISABLED (add '--script-args=unsafe=1' to run)
|   SMBv2 DoS (CVE-2009-3103): CHECK DISABLED (add '--script-args=unsafe=1' to run)
|   MS06-025: CHECK DISABLED (add '--script-args=unsafe=1' to run)
|_  MS07-029: CHECK DISABLED (add '--script-args=unsafe=1' to run)
| smb-os-discovery:
|   OS: Windows XP (Windows 2000 LAN Manager)
|   OS CPE: cpe:/o:microsoft:windows_xp::-
|   Computer name: E10
|   NetBIOS computer name: E10
|   Workgroup: *********
|_  System time: 2015-06-26T02:06:02-07:00

No comments:

Post a Comment