⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 amap.1

📁 Ubuntu packages of security software。 相当不错的源码
💻 1
字号:
.\" This definition swiped from the nmap(1) page, which in turn was ripped from gcc(1) man page.de Sp.if n .sp.if t .sp 0.4...TH AMAP 1.SH NAMEamap \- a powerful application mapper.SH SYNOPSIS.B amap[Mode] [Options] <target> <port/portrange> [<port> ...].SH DESCRIPTION.I Amap is a scanning tool that allows you to identify the applications that arerunning on a specific port or ports. This is achieved by connecting to theport(s) and sending trigger packets. These trigger packets will typically bean application protocol handshake. Many network daemons will only respond tothe correct handshake (i.e. SSL). Amap then looks up the response in a listand prints out any match it finds. .I Amap supports tcp and udp protocols, regular and SSL-enabled ASCII and binary protocols and a variety of options are at your disposal to control the behaviour of the tool. It can take an nmap machine readable output file as its input file and can log to a file and screen. .PPWhy use our tool? Well, when portscanning a host, you will be presented with alist of open ports. In many cases, the port number tells you whatapplication is running. Port 25 is usually SMTP, port 80 mostly HTTP.However, this is not always the case, and especially when dealing withproprietary protocols running on non-standard ports you will not beable to determine what application is running. With amap, you will be ableto identify that SSL server running on port 3445 and some oracle listener onport 23. Also, it will actually do an SSL connect if you want and thentry to identify the SSL-enabled protocol!.PPPlease also see.I amapcrap -hfor an additional tool for ports who do not give any output..SH MODES.I amapcan be run in three different modes:.TP.B \-A Map applications: send triggers and analyse responses (default). All optionscan be used in this mode..TP.B \-BJust grab banners, do not send triggers. Only a few commandline options areused from the set when run this mode. They are maked below as "(Banner)".TP.B \-PNo banner, application, stuff - be a (full connect) port scanner! Only a fewcommandline options areused from the set when run this mode. They are maked below as "(Portscan)".TP.B \-WThis is the Web Online Update mode. When specifying this option, all otheroptions except -D are ignored, and the application fingerprints and triggersare updated from the thc.org web site..SH OPTIONSOptions can also be seen by typing 'amap -h'. Here follows an explanation ofall options..TP.B HOSTS AND PORTS (all modes).TP.B \-i <file> This makes amap read its hosts and ports from the specified file. The filemust be generated by nmap, using the -oM <file> option of nmap. It doesn'tmatter if you have multiple hosts and mixed tcp and udp ports in the file:amap reads them all..TP.B \<target> and <port/portlist>Target can be an IP address or fully qualified host name. A port can be anynumber between 1 and 65535, ranges (e.g. 1-65535) are also supported.You can specify as many ports on the commandline as you want. Ports are by default TCP (see -u option below)..TP.B GENERAL OPTIONS.TPNone of these are required but some can be quite useful..TPNote that all options can be used in amap's default mode (\-A), the banner grab (\-B) and portscan modes (-\P) support only those options which are marked as such..TP.B \-uPorts specified on commandline are UDP (default is TCP). (Modes: Amap, Banner,Portscan).TP.B \-6Use IPv6, not IPv4.TP.B \-1Only send triggers to a port until 1st identification. Speeeeed!.TP.B \-vVerbose. Usually not used, but gives detailed info on the screen as to whatconnections are made to what ip's/ports. Don't use twice. You will be boredto death with even more stupid uninteresting information. (Modes: Amap,Banner, Portscan).TP.B \-qQuiet. Has got nothing to do with the "-v" option :-) If the -q option is applied, all closed and timed out ports are NOT markedas unidentified, and are not reported at all..TP.B \-dMake a hex dump of all received responses. The default is to only printunrecognised responses..TP.B \-UDo not dump unrecognized responses. (see option above).TP.B \-bPrint ACSII banners (if one is received)..TP.B \-o <file>Log the output of amap to <file>. (Modes: Amap, Banner, Portscan).TP.B \-m <file>Make the log file output (-o option) machine readable (colon seperated).(Modes: Amap, Banner, Portscan).TP.B \-D <file>Triggers and responses are read by default from appdefs.trig andappdefs.resp. By specifying for instance '-D trojans' it will read triggersand responses from trojans.trig and trojans.resp. It can be very usefull ifyou only want to scan for certain applications. Please take a look at theappdefs files to see what the format of these files is (it's pretty simple,you shouldn't have any trouble adding your own triggers and responses, whichyou are encouraged to do, btw)..TP.B SCANNING OPTIONSThese options influence the behaviour of amap when scanning..TP.B \-p <proto>This specifies a single protocol trigger to send. The name of the protocol mustmatch one of the first fields of the lines in the trigger file. Forinstance, '-p SSL' will scan only for SSL enabled port. However, if bychance other protocols are also indentified, they will be printed..TP.B \-SDo NOT NOT look behind an SSL port. Otherwise amap will reconnect later toidentify the service running behind the ssl wrapper..TP.B \-RDo NOT identify RPC service. Otherwise amap will connect many times toidentify the exact rpc service type and version. This can be time consuming..TP.B \-c nOpen 'n' parallel tasks (connections). The default is 32, the maximum 256.(Modes: Amap, Banner, Portscan).TP.B \-C nIf a TCP connect timed out (did not finnish in "-T n" time), how oftenshould be retried the connect? This is by default 3.(Modes: Amap, Banner, Portscan).TP.B \-T nCauses amap to wait upto 'n' seconds for a successful TCP connect. Default is 5 seconds, butthis can be too few sometimes when scanning over a slow link, and too longon a LAN. (Modes: Amap, Banner, Portscan).TP.B \-t nCauses amap to wait upto 'n' seconds for a response. Default is 5 seconds, butthis can be too few sometimes when scanning over a slow link, and too longon a LAN. (Modes: Amap, Banner).TP.B \-HSkip potentially harmful triggers. Some daemons and applications will crashwhen receiving long or unexpected binary input. -H skips triggers marked aspotentially harmful. See appdefs.trig for information on how to mark atrigger as harmful..SH LICENSE AND USER BEWARES.I amap is (C) 2003 by vanHauser and DJ.RevMoon (of THC - www.thc.org).SpThis program is free software; you can redistribute itand/or modify it under the terms of the GNU General PublicLicense as published by the Free Software Foundation;Version 2.  This guarantees your right to use, modify, andredistribute amap under certain conditions..SpSource is provided to this software because we believe usershave a right to know exactly what a program is going to dobefore they run it.  This also allows you to audit thesoftware for security holes..SpSource code also allows you to port amap to new platforms,fix bugs, and add new features.  You are highly encouragedto send your application triggers and responses to us. Please send triggersand responses (either as a tcpdump file or in our own format) toamap-dev@thc.org..SpThis program is distributed in the hope that it will be useful, but.B WITHOUT ANY WARRANTY;without even the implied warranty of.B MERCHANTABILITY or .B FITNESS FOR A PARTICULAR PURPOSE.See the GNUGeneral Public License for more details (it is in the COPYING file ofthe.I amap distribution).  .SpIt should also be noted that amap has been known to crashcertain poorly written applications, TCP/IP stacks, and evenoperating systems..B Amap should never be run against mission critical systems unless you are prepared to suffer downtime.  We acknowledgehere that Amap may crash your systems or networks and wedisclaim all liability for any damage or problems Amap couldcause..SH BUGSThere are bound to be numerous bugs in amap. Please tell us if you find any.Please email to amap-dev@thc.org.

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -