Resultados de escaneo diferentes con Nmap

1

Mi amigo y yo tenemos acceso a un entorno privado, y usamos Nmap para escanear un dominio y un www.

Obtengo el siguiente resultado:

======================================================================
                          INCORRECT SCANNING
======================================================================

nmap -sS -v www.site.com.br

Starting Nmap 7.31 ( https://nmap.org ) at 2017-01-02 13:45 EST
Initiating Ping Scan at 13:45
Scanning www.site.com.br (173.x.x.20) [4 ports]
Completed Ping Scan at 13:45, 0.20s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 13:45
Completed Parallel DNS resolution of 1 host. at 13:45, 0.45s elapsed
Initiating SYN Stealth Scan at 13:45
Scanning www.site.com.br (173.x.x.20) [1000 ports]
Discovered open port 22/tcp on 173.x.x.20
Discovered open port 53/tcp on 173.x.x.20
Discovered open port 21/tcp on 173.x.x.20
Discovered open port 554/tcp on 173.x.x.20
Discovered open port 111/tcp on 173.x.x.20
Discovered open port 80/tcp on 173.x.x.20
Discovered open port 7070/tcp on 173.x.x.20
Completed SYN Stealth Scan at 13:45, 6.73s elapsed (1000 total ports)
Nmap scan report for www.site.com.br (173.x.x.20)
Host is up (0.17s latency).
rDNS record for 173.x.x.20: 14.5d.2d.static.xlhost.com
Not shown: 990 closed ports
PORT     STATE    SERVICE
19/tcp   filtered chargen
21/tcp   open     ftp
22/tcp   open     ssh
25/tcp   filtered smtp
53/tcp   open     domain
80/tcp   open     http
111/tcp  open     rpcbind
554/tcp  open     rtsp
5555/tcp filtered freeciv
7070/tcp open     realserver

Read data files from: /usr/bin/../share/nmap
Nmap done: 1 IP address (1 host up) scanned in 7.72 seconds
Raw packets sent: 1034 (45.472KB) | Rcvd: 1022 (40.896KB)

Pero mi amigo recibe esto:

======================================================================
                          CORRECT SCANNING
======================================================================

nmap -sS -v www.site.com.br

Starting Nmap 7.31 ( https://nmap.org ) at 2017-01-02 15:26 BRT
Initiating Ping Scan at 15:26
Scanning www.site.com.br (173.x.x.20) [4 ports]
Completed Ping Scan at 15:26, 0.21s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 15:26
Completed Parallel DNS resolution of 1 host. at 15:26, 0.01s elapsed
Initiating SYN Stealth Scan at 15:26
Scanning www.site.com.br (173.x.x.20) [1000 ports]
Discovered open port 80/tcp on 173.x.x.20
Discovered open port 111/tcp on 173.x.x.20
Discovered open port 22/tcp on 173.x.x.20
Discovered open port 21/tcp on 173.x.x.20
Discovered open port 53/tcp on 173.x.x.20
Completed SYN Stealth Scan at 15:26, 6.58s elapsed (1000 total ports)
Nmap scan report for www.site.com.br (173.x.x.20)
Host is up (0.17s latency).
rDNS record for 173.x.x.20: 14.x.x.x.x.com
Not shown: 991 closed ports
PORT     STATE    SERVICE
21/tcp   open     ftp
22/tcp   open     ssh
25/tcp   filtered smtp
53/tcp   open     domain
80/tcp   open     http
111/tcp  open     rpcbind
139/tcp  filtered netbios-ssn
445/tcp  filtered microsoft-ds
2301/tcp filtered compaqdiag

Mis resultados no tienen sentido, y el suyo es correcto. ¿Por qué obtenemos resultados diferentes y cómo puedo solucionarlo?

    
pregunta MHenrique12 03.01.2017 - 20:05
fuente

2 respuestas

2

Centrémonos solo en los datos relevantes: el puerto 554 y 7070 se abre en su escaneo.

Hay 1 hora y 19 minutos (13:45 EST = 16:45 BRT) de diferencia entre los escaneos, así que quizás cuando escaneó el objetivo, tenía un RealServer en ejecución (puertos 554 y 7070), y cuando su amigo Lo escaneó, no tenía el RealServer en funcionamiento.

    
respondido por el yzT 03.01.2017 - 20:38
fuente
2

Probablemente reglas de firewall basadas en el país. He comprobado este rDNS record for 173.x.x.20: 14.5d.2d.static.xlhost.com , y desde mi país solo han abierto estos puertos:

21/tcp  open     ftp
22/tcp  open     ssh
53/tcp  open     domain
80/tcp  open     http
111/tcp open     rpcbind
    
respondido por el Mirsad 03.01.2017 - 21:19
fuente

Lea otras preguntas en las etiquetas