room ~ Nmap - Network Scanner
Nmap - Network Scanner
Port scanning, scan types, NSE scripts, firewall evasion, and practical techniques
1/7
lessons
Nmap Introduction & Ports
What is Nmap?
- Nmap (Network Mapper) = most important reconnaissance tool in pentesting
- Discovers hosts, open ports, running services, OS versions
- First step in EVERY pentest: what's listening?
What is a Port?
- Port = door to a service. Har service ek port pe listen karti hai
- Total ports: 65535 (1-65535)
- Well-known: 0-1023 | Registered: 1024-49151 | Dynamic: 49152-65535
Must-Know Ports
| Port | Service | Notes |
|---|---|---|
| 21 | FTP | File transfer, check anonymous login |
| 22 | SSH | Secure shell, brute force target |
| 23 | Telnet | Insecure, cleartext credentials |
| 25 | SMTP | Email, can verify users |
| 53 | DNS | Domain info, zone transfers |
| 80 | HTTP | Web server |
| 110 | POP3 | Email retrieval |
| 111 | RPCbind | NFS enumeration |
| 135 | MSRPC | Windows RPC |
| 139/445 | SMB | Windows file sharing, common exploits |
| 443 | HTTPS | Encrypted web |
| 3306 | MySQL | Database |
| 3389 | RDP | Remote Desktop |
| 5985 | WinRM | Windows Remote Management |
| 6667 | IRC | Chat, some backdoors use this |
| 8080 | HTTP-Alt | Alternative web/proxy |
How Connections Work
Your PC (random port 49534) ←→ Server (fixed port 443)
- Server listens on fixed port
- Client uses random high port
- Connection = IP:port ↔ IP:port pair