NMAP tutorial about gathering information of different servers
how you can extract information about someone’s… NMAP tutorial about gathering information of different servers Hello, I hope everyone is well. You must have read my previous tutorial and article about how you can extract information about

how you can extract information about someone’s…
NMAP tutorial about gathering information of different servers
Hello, I hope everyone is well. You must have read my previous tutorial and article about how you can extract information about someone’s server from the network. Now we will go into a little more detail. And i will define what are the most important things in In Networks.
In this article we will see how we can extract server information and how we can detect hidden paths through which we can collect server information.
Before all these things keep one thing in mind none of my article is leading to harming anyone. Attacking someone’s personal property is a legal offense. Your state should take strict action against it. As a result of the attack, you can also pay a fine for heavy damages. The EU policy is very strict.
Before scanning Target , we will do this very carefully and also understand that if we start investigating on any server, there can be many kinds of problems, for example, firewalls. Or any mechanism that rejects your sent request.
The largest firewall used at the government level is called FortiGate FortiWiFi 40F Series Datasheet This firewall has many features. Most people use IBM’s firewall. Ping request sent by should be blocked.
Let’s examine some things and see what’s wrong with them.
We had a server, we ran a test on that server, and as a result, we found out how many more divisions were on that server. Any DNS is available and they can see DNS up.
In order not to mind this we will send a PING request which will inform us if something exists on this server or if that IP address has expired.
ping www.yourtesget.com
In this image you can see the request I sent is telling about an IP address that is live and is also giving a link to the server where the Paki website is also hosted.

Now we’re going to split this information into two parts. The first part is to scan that IP address and see what’s on it.
In the second part we will do this by looking at the subdomain we found which is a server route and finally we will use a network mapping tool to see how many other things are installed on that route. Which will give us a lot of information and that information will be very helpful for us
PING bicodev.com (198.54.114.247) 56(84) bytes of data.
64 bytes from server62-1.web-hosting.com (198.54.114.247): icmp_seq=1 ttl=47 time=1006 ms
64 bytes from server62-1.web-hosting.com (198.54.114.247): icmp_seq=2 ttl=47 time=532 ms
64 bytes from server62-1.web-hosting.com (198.54.114.247): icmp_seq=3 ttl=47 time=352 ms
64 bytes from server62-1.web-hosting.com (198.54.114.247): icmp_seq=4 ttl=47 time=421 ms
64 bytes from server62-1.web-hosting.com (198.54.114.247): icmp_seq=5 ttl=47 time=324 ms
64 bytes from server62-1.web-hosting.com (198.54.114.247): icmp_seq=6 ttl=47 time=323 ms
64 bytes from server62-1.web-hosting.com (198.54.114.247): icmp_seq=7 ttl=47 time=630 ms
^C
--- bicodev.com ping statistics ---
8 packets transmitted, 7 received, 12.5% packet loss, time 7009ms
rtt min/avg/max/mdev = 323.194/512.705/1006.338/227.894 ms, pipe 2When we scanned the IP address through the network mapping tool, we found that there was an Already server active, so we took full advantage of that, but the information was still lacking. The thing was told that which servers are there, which are safe and which are unsafe.
nmap -A -T4 www.server.com
in the result of the scan we understand that the server is based on Red HAT enterprise Linux Service Info: Host: server62.web-hosting.com; OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:6 and this is one of the important information that we collect once you have the information about the server you can do more aggressive Scan.
53/tcp open domain ISC BIND 9.8.2rc1 (RedHat Enterprise Linux 6)
| dns-nsid:
|_ bind.version: 9.8.2rc1-RedHat-9.8.2-0.68.rc1.el6.11.tuxcare.els6
80/tcp open http Captcha Server
|_http-server-header: Captcha Server
|_http-title: 403 Forbidden
| fingerprint-strings:
| DNSStatusRequestTCP, DNSVersionBindReqTCP, RPCCheck, RTSPRequest, X11Probe:
| HTTP/1.1 400 Bad request
| Content-length: 90
| Cache-Control: no-cache
| Connection: close
| Content-Type: text/html
| <html><body><h1>400 Bad request</h1>
| Your browser sent an invalid request.
| </body></html>
| FourOhFourRequest, GetRequest, HTTPOptions:
| HTTP/1.1 403 Forbidden
| content-length: 93
| cache-control: no-cache
| content-type: text/html
| connection: close
| <html><body><h1>403 Forbidden</h1>
| Request forbidden by administrative rules.
|_ </body></html>
110/tcp open tcpwrappedThe First command shown above can be used to find out about all the servers on the network that are running issues. Let’s see another similar command are. Which will inform you about how many subdomains are on this server and how many ports are active inclouting.
nmap 17.253.144.10/21 -sV -Pn -p 21 — script ftp-anon