Re: Automated Nmap Scans / Front End



You can get a *nix box and cron the script..

Perl is a good scripting language that I use and prefer for this type of scanning..

To get ALL the machines on a subnet you get send a broadcast ping to the network
and dump the arp tables off of the routers.. That will give you all the hosts that are talking
we do that here for discovery on top of the method that you are using...

Joe

tom jones wrote:
Hello,
I am responsible for monitoring hundreds of machines
over thousands of
external IP addresses. I currently run nmap manually
once a week and import
the results into Excel to compare them with the
previous week to find hosts
that are new and also take note of those that have
been taken off the
Internet. I am looking for a web front end, batch
process, or similar that
would meet the following requirements.

-Input file of external IP ranges I am responsible for
-Have the tool scan all ranges to determine responding
IPs
-Compare results to previous week and note exceptions
-Scheduling capability to have this take place weekly

>From a quick search, I found these two tools that I
might try out if I have
time. I have not heard of them before and have not
had a chance to read up
on their capabilities:

http://sourceforge.net/projects/gwmos/
http://sourceforge.net/projects/cancerbero/

I am also interested to hear thoughts on the best way
to do host discovery.
Many of our firewalls will block ICMP requests which
is fast and not
complete. Scanning for every TCP and UDP port can
take days. I'm looking
for a good middle ground that would be fairly complete
but not take an
excessive amount of time. I currently scan for about
15 common TCP ports
which takes about half of a day.

I have the ability to run these on either a Windows XP
machine or a web
server (php, etc.).

Thanks in advance.






____________________________________________________________________________________
Don't pick lemons.
See all the new 2007 cars at Yahoo! Autos.
http://autos.yahoo.com/new_cars.html

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • RE: RE: Informing Companies about security vulnerabilities...
    ... Where did you see scanning? ... etc on the vulnerable web apps I use for class." ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • RE: The legal / illegal line?
    ... scanning without authorisation is illegal. ... as far as I am aware scanning for open ports is not illegal. ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • RE: Password cracker tool
    ... Subject: Password cracker tool ... sender does not accept liability for any errors or omissions in the ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • RE: Informing Companies about security vulnerabilities...
    ... If one or more of his students hacked any of the sites that he used to ... If I show you the exact steps on how to hack www.xyc.com and then ... vulnerable web apps I use for class. ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • RE: Informing Companies about security vulnerabilities...
    ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ... Click the link to buy it, try it or download Hailstorm for FREE. ...
    (Pen-Test)