Thursday, March 28, 2024

Nmap 7.70 Released With Better OS Detection, 9 new NSE scripts and Much More

Nmap first release of 2018, “Nmap 7.70” includes hundreds of new OS and service fingerprints, improved version of the Npcap windows library, service detection and 9 NSE scripts.

Nmap (“Network Mapper”) is one of the best free and open source utility for network scanning and security auditing.

Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime.

Nmap 7.70 Packages available for Linux, Windows, and Mac. To download the Nmap. It is a flexible, powerful and portable tool supported, including Linux, Microsoft Windows, FreeBSD, OpenBSD, Solaris, IRIX, Mac OS X, HP-UX, NetBSD, Sun OS, Amiga, and more.

Changes with Nmap 7.70

Npcap Windows

A lot of improvements with packet capturing library and the Nmap 7.70 includes the recent version of Npcap version 0.93.

OS fingerprint

The new version of Nmap includes 298 fingerprints, so now in total Nmap holds 5,652 fingerprints. Also now it detects detect 1224 protocols and 33 of IPv6 OS fingerprint submissions.

Also Read How to perform Information Gathering in Kali using NMAP – A Detailed Explanation

9 New NSE scripts

deluge-rpc-brute: Performs Brute force attacks against BitTorrent RPC services by using the zlib library.

hostmap-crtsh: Lists subdomains by querying Google Certificate Transparency logs.

http-bigip-cookie: Decodes unencrypted F5 BIG-IP cookies.

http-jsonp-detection: Detects JSONP endpoints in web servers.

http-trane-info: Get’s information from Trane Tracer SC controllers.

nbd-info: Employees nbd.lua to query Network Block Devices.

RSA-vuln-Roca: Checks RSA key for Coppersmith Attack,

smb-enum-services: Lists services running on remote Windows machine.

tls-alpn: Checks TLS for Application layers.

Nmap was designed to rapidly scan large networks, but works fine against single hosts. In addition to the classic command-line Nmap executable, the Nmap suite includes an advanced GUI and results in the viewer (Zenmap), a flexible data transfer, redirection, and debugging tool (Ncat), a utility for comparing scan results (Ndiff), and a packet generation and response analysis tool (Nping).

Website

Latest articles

2 Chrome Zero-Days Exploited at Pwn2Own 2024: Patch Now

Google has announced a crucial update to its Chrome browser, addressing several vulnerabilities, including...

The Moon Malware Hacked 6,000 ASUS Routers in 72hours to Use for Proxy

Black Lotus Labs discovered a multi-year campaign by TheMoon malware targeting vulnerable routers and...

Hackers Actively Exploiting Ray AI Framework Flaw to Hack Thousands of Servers

A critical vulnerability in Ray, an open-source AI framework that is widely utilized across...

Chinese Hackers Attacking Southeast Asian Nations With Malware Packages

Cybersecurity researchers at Unit 42 have uncovered a sophisticated cyberespionage campaign orchestrated by two...

CISA Warns of Hackers Exploiting Microsoft SharePoint Server Vulnerability

Cybersecurity and Infrastructure Security Agency (CISA) has warned about a critical vulnerability in Microsoft...

Microsoft Expands Edge Bounty Program to Include WebView2!

Microsoft announced that Microsoft Edge WebView2 eligibility and specific out-of-scope information are now included...

Beware of Free Android VPN Apps that Turn Your Device into Proxies

Cybersecurity experts have uncovered a cluster of Android VPN applications that covertly transform user...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Mitigating Vulnerability Types & 0-day Threats

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

Related Articles