Recon

$ nmap -p- --min-rate=1000 -Pn -v 192.168.170.175
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-08-24 14:54 CDT
Initiating Parallel DNS resolution of 1 host. at 14:54
Completed Parallel DNS resolution of 1 host. at 14:54, 0.03s elapsed
Initiating Connect Scan at 14:54
Scanning 192.168.170.175 [65535 ports]
Discovered open port 53/tcp on 192.168.170.175
Discovered open port 3389/tcp on 192.168.170.175
Discovered open port 445/tcp on 192.168.170.175
Discovered open port 135/tcp on 192.168.170.175
Discovered open port 139/tcp on 192.168.170.175
Discovered open port 9389/tcp on 192.168.170.175
Discovered open port 464/tcp on 192.168.170.175
Connect Scan Timing: About 23.32% done; ETC: 14:57 (0:01:42 remaining)
Discovered open port 49667/tcp on 192.168.170.175
Discovered open port 389/tcp on 192.168.170.175
Discovered open port 3269/tcp on 192.168.170.175
Discovered open port 3268/tcp on 192.168.170.175
Connect Scan Timing: About 46.57% done; ETC: 14:57 (0:01:10 remaining)
Discovered open port 49666/tcp on 192.168.170.175
Discovered open port 636/tcp on 192.168.170.175
Discovered open port 49739/tcp on 192.168.170.175
Discovered open port 49670/tcp on 192.168.170.175
Discovered open port 49671/tcp on 192.168.170.175
Discovered open port 49704/tcp on 192.168.170.175
Connect Scan Timing: About 73.92% done; ETC: 14:56 (0:00:32 remaining)
Discovered open port 5985/tcp on 192.168.170.175
Discovered open port 593/tcp on 192.168.170.175
Discovered open port 88/tcp on 192.168.170.175
Completed Connect Scan at 14:56, 121.53s elapsed (65535 total ports)
Nmap scan report for 192.168.170.175
Host is up (0.053s latency).
Not shown: 65515 filtered tcp ports (no-response)
PORT      STATE SERVICE
53/tcp    open  domain
88/tcp    open  kerberos-sec
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds
464/tcp   open  kpasswd5
593/tcp   open  http-rpc-epmap
636/tcp   open  ldapssl
3268/tcp  open  globalcatLDAP
3269/tcp  open  globalcatLDAPssl
3389/tcp  open  ms-wbt-server
5985/tcp  open  wsman
9389/tcp  open  adws
49666/tcp open  unknown
49667/tcp open  unknown
49670/tcp open  unknown
49671/tcp open  unknown
49704/tcp open  unknown
49739/tcp open  unknown

Read data files from: /usr/bin/../share/nmap
Nmap done: 1 IP address (1 host up) scanned in 121.62 seconds

Last updated