Find Network Vulnerabilities with Nmap Scripts [Tutorial]

Поделиться
HTML-код
  • Опубликовано: 3 дек 2024

Комментарии • 209

  • @cracc_baby
    @cracc_baby 2 месяца назад +3

    ofc a lot has changed in 5 years, but this video is still highly discoverable and helpful with nmap 7.94
    worth mentioning, nmap users now must include "vulscan/vulscan.nse" and/or "nmap-vulners/vulners.nse" after the --script. not just "vulscan" anymore, or youll get an error for empty directory

  • @earl_the_great
    @earl_the_great 5 лет назад +26

    I love this channel so much. I learned a lot of things, especially writing your own script. That was amazing.

    • @NullByteWHT
      @NullByteWHT  5 лет назад +4

      I'm glad it's helpful! Thanks for watching

  • @JeanS1989
    @JeanS1989 5 лет назад +23

    Kody, you and your team need a tv program. I Love what you do and I’m sure I ain’t the only one.

    • @roberthorn6707
      @roberthorn6707 5 лет назад +4

      Man Kody scares the shit outta me!! lol I mean like i wouldn't wanna piss him off! But they do produce some pretty amazing content! I'm training to become a PenTester now and between this channel and Cybrary I'll be penetrating people's networks in no time!

    • @NullByteWHT
      @NullByteWHT  5 лет назад +2

      @@roberthorn6707 Hahaha thank you

    • @JeanS1989
      @JeanS1989 5 лет назад

      @@roberthorn6707 lols right! I don't think anyone wants to land on his blacklist. That has to be a pretty scary spot to be in.

    • @JeanS1989
      @JeanS1989 5 лет назад

      @@NullByteWHT Kody, If you ever do a meet & greet somewhere let me know I'm very interested, sounds like a lot of fun.

    • @netbin
      @netbin 5 лет назад

      Jean Suriel what is tv program

  • @RiktigMusik
    @RiktigMusik 5 лет назад +14

    Give this guy a like, he is taking the time to share the knowledge to even the beginners and he has great tips! One of my favorites.. Thank you 🙏, you are appreciated!

    • @NullByteWHT
      @NullByteWHT  5 лет назад +2

      Thank you!

    • @RiktigMusik
      @RiktigMusik 5 лет назад +2

      Null Byte No Thank YOU! Your taking the time to do what many hackers/pentesters etc and pass on your skill.. Most of the people have the attitude of I”learned it myself, and so should you” But some people need a push.. And u are that push for me, you made me go buy a raspberry and WiFi adapters, first time I clips influenced me like this so keep doing what ur doing..Do you provide any online courses that i can take and pay for like live sessions, that would be so dope.. You are appreciated 🙏 .

  • @seamuscampbell5948
    @seamuscampbell5948 5 лет назад +11

    Top man just love your tutorials - thank you very much for all the effort you put in to publishing these.

  • @dennisask3960
    @dennisask3960 5 лет назад +15

    Your content is just amazing. By far one of the best security channels I have ever seen. Love the cat images in the background ;) perfect reference to deep learning if you ask me.

  • @taiquangong9912
    @taiquangong9912 5 лет назад +3

    Stumbled upon this site and love the content it helped me tremendously.

  • @francescopresta9570
    @francescopresta9570 5 лет назад +7

    Very useful, Kody and Tokyoneon number one!

  • @mr_mr
    @mr_mr 5 лет назад +4

    So good as usual. Thanks Kody. Been learning so much from you.

  • @poms3559
    @poms3559 5 лет назад +58

    If we take all the content on this channel and compare it to other content out there we gonna find that this content here is not available out there, thats why this channel worth more than 1m$,
    Oops I said that last time, by updating my packages, its worth now 1. 000000*10 b$

    • @NullByteWHT
      @NullByteWHT  5 лет назад +16

      I really enjoy making these for all of you, I'm glad you think so highly of them!

    • @Aryan-uu1mv
      @Aryan-uu1mv 5 лет назад

      How can I create phishing page

    • @Aryan-uu1mv
      @Aryan-uu1mv 5 лет назад

      Please guide me

    • @Aryan-uu1mv
      @Aryan-uu1mv 5 лет назад

      Steps to do this needed

    • @Sapientiaa
      @Sapientiaa 4 года назад +1

      @@NullByteWHT NSE: failed to initialize the script engine:
      /usr/local/bin/../share/nmap/nse_main.lua:264: vulscan:7: unexpected symbol near '

  • @zardashtjaza1343
    @zardashtjaza1343 4 года назад +1

    congratulations 500k dude hope keep going

  • @EpicLPer
    @EpicLPer 5 лет назад +14

    I'd love to scan my whole network at once for vulnerabilities since I have so many things connected here... But how would I do that instead?

    • @mcbazzauk
      @mcbazzauk 5 лет назад +1

      Look into deploying Tenable Nessus Home. It's an excellent vulnerability scanner that is free for home use.

    • @ashleybishton742
      @ashleybishton742 4 года назад

      Just run the same scan but do the whole range of IPS in the network. Thats how u scan your whole network.

  • @ryaagard8459
    @ryaagard8459 5 лет назад +10

    No dislikes damn! Btw keep up these tutorials they are awesome!

  • @barresoft
    @barresoft 5 лет назад +3

    Que buenos videos! que buena terminación! seguí así maestro! gracias por enseñarnos!!!!!!!!

  • @Tekionemission
    @Tekionemission Год назад

    (4:17) Like the vulscan and the nmap-vulners script. Thank you for sharing. One thing I am not clear about, it looks like you would have to pull the script down from Github and this is not out of the box script from Nmap?

    • @Tekionemission
      @Tekionemission Год назад

      Ignore - I went to your site and got my answer; a great write up by the way.

  • @TOn-fx2gr
    @TOn-fx2gr 5 лет назад +2

    Pls how to interact with router by using python i want to write a code that do similar to reaver it send wps pin and receive output to see if the pin was correct . What module i have to use i heard of piramiko and scapy and heard that i have to logine to router by ssh but we need hostname to do that . Pls if you can do a video about it or tell me where i can find a answer . Thank you

  • @enriqueperez339
    @enriqueperez339 5 лет назад +1

    Exactly what directory would you clone the git repository?

  • @nullpx9548
    @nullpx9548 2 года назад

    thanks sir,,,, i'm from indonesia very like your channel

  • @AbdulKalam-yi6ve
    @AbdulKalam-yi6ve 5 лет назад +6

    i watch all your videos really helpful 💖🔥 #nullbyte fan

  • @akvartz
    @akvartz 5 лет назад +25

    @NullByte
    Great content, and i'm lovin' extra energy in recent videos.
    But could you please blink, at least once

    • @NullByteWHT
      @NullByteWHT  5 лет назад +25

      You can have more energy or more blinking but not both

    • @Nelcj_99
      @Nelcj_99 5 лет назад +7

      @@NullByteWHT I rlly don't know which comment is better XD

  • @sarikapayili2624
    @sarikapayili2624 5 лет назад

    Thank you bro this video helps me so much.....
    Great tutorial man...

    • @NullByteWHT
      @NullByteWHT  5 лет назад

      Thanks Sarika Payili! We really do put in a lot of hard work.

  • @mocheford
    @mocheford 5 лет назад +2

    I always like the video before hitting play. Never regret it.

    • @mr_mr
      @mr_mr 5 лет назад +1

      mocheford agreed. If you take the time to make a comprehensive video and make it available for free, it deserves likes.

    • @NullByteWHT
      @NullByteWHT  5 лет назад

      Thank both of you, we don't make much from this so it's the community I do it for.

    • @mr_mr
      @mr_mr 5 лет назад +1

      @@NullByteWHT What else do you guys do? How can people support you? Do you teach?

    • @NullByteWHT
      @NullByteWHT  5 лет назад +1

      @@mr_mr wht doesn't want a patreon, so we're looking for other ways

  • @MrTyrant258
    @MrTyrant258 5 лет назад +5

    Is Nmap a noisy tool to use? From what I’ve heard, it’s easy to detect with a firewall or an IDS on the network.

    • @ashleybishton742
      @ashleybishton742 4 года назад +3

      U can work round that with -Pn or use -D and for decoy to spoof an IP you type in. So they don't really know its you if you don't want them to know that you scanned them.

  • @BamBam-gs7eb
    @BamBam-gs7eb 4 года назад

    Thanks Kody, excellent as always. Would be great to get an overview of how you got into hacking/InfoSec, experience and how you recommend getting into the industry.

    • @NullByteWHT
      @NullByteWHT  4 года назад

      Good idea BamBam, I've added it to the list of video ideas.

  • @cde-lf7iu
    @cde-lf7iu 4 года назад

    Always the best content... Great work mate !

  • @prive_ik_ben_wie_ik_ben
    @prive_ik_ben_wie_ik_ben 5 лет назад +5

    make a vid on pupy and how to bind the payload. thx again!

  • @soundspoon
    @soundspoon 5 лет назад +1

    awesome content man!!

  • @fanuelalmaw7848
    @fanuelalmaw7848 5 лет назад

    Amazing videos make me to try my kali linux machin and dig more things you make what i need to teach like this

  • @Xxmeca421xX
    @Xxmeca421xX 5 лет назад

    Did you lightly paint your laptop? How did you get the tint over your stickers, I like it.

  • @mgtidus
    @mgtidus 4 года назад

    Thanks Kody, your videos are very helpful as always ! Absolutely no regrets for subscribing at all. ;D

  • @MalibuSea
    @MalibuSea 5 лет назад

    Hello, I get this following error:
    failed to initialize the script engine
    'vulscan' did not match a category, filename or directory stack traceback.

  • @anubhabchowdhury9296
    @anubhabchowdhury9296 4 года назад

    Amazing content bro...

  • @thesuhu
    @thesuhu 4 года назад +1

    His eyes never blinking

  • @Jon-da-bad
    @Jon-da-bad 5 лет назад +1

    Great video bro thank you

  • @grissgray
    @grissgray 5 лет назад +2

    keep up the good work

  • @oceanic_lost_8156
    @oceanic_lost_8156 Год назад

    @Null Byte i have to find a Linux Kernel vulnerability on a machine however when i run the code i am unable to find the correct one, they are listed there but not the kernel one, any chance you can help

  • @v380riMz
    @v380riMz 5 лет назад

    Do you have much experience in the pentesting field?

  • @ArthurRWhite
    @ArthurRWhite 5 лет назад

    We appreciate it bro please keep helping us tnx

  • @7V999
    @7V999 3 года назад

    Thank You Kody Real 👽

  • @yusuususwwwdpppdeew6780
    @yusuususwwwdpppdeew6780 5 лет назад +6

    How do u come up with this it’s amazing

  • @TeluguBusinessChannel
    @TeluguBusinessChannel 5 лет назад +1

    Love you.... Thank you... Respect you...

  • @VNMHCKR
    @VNMHCKR 5 лет назад +5

    Hey man! Could you do a video on metasploit? I’m a beginner and would like to learn from you, since you are so clear. Thx!

    • @NullByteWHT
      @NullByteWHT  5 лет назад +3

      Yes, we can do that

    • @VNMHCKR
      @VNMHCKR 5 лет назад +1

      Null Byte omfg thanks dude!!!

  • @selvador_x5211
    @selvador_x5211 Год назад +1

    Thnks ❤ work

  • @alejandrotaudil3689
    @alejandrotaudil3689 4 года назад

    Thanks for the info!

  • @qxch7222
    @qxch7222 3 года назад +1

    If you get a error:
    Try to list the scripts like this_ sudo nmap --script nmap-vulners/,vulns/ -sV [host]
    hope it helped

  • @cy_wareye7395
    @cy_wareye7395 5 лет назад

    I will test it today

  • @lionheart-mm1334
    @lionheart-mm1334 Год назад

    Can you use nmap to perform authenticated scans?

  • @MajorBuzzKill
    @MajorBuzzKill 5 лет назад

    Which version of Kali do you use?

  • @eranthagunawardena2638
    @eranthagunawardena2638 4 года назад

    When I execute git clone getting an error : bash: git: command not found... Failed to search for file: cannot update read-only report. Please help

  • @tejasmandre666
    @tejasmandre666 5 лет назад

    Pretty awesome ! 👍

  • @forjafuny
    @forjafuny 5 лет назад

    Please friend can u help .i install kali linux in my laptot and whene i want to back to windows 7 i cant .there is any solution god bless u

  • @peacetvafrica957
    @peacetvafrica957 10 месяцев назад +1

    Can you proove you are human your eyes are not blinking

  • @LearnMoreAboutHacking
    @LearnMoreAboutHacking 5 лет назад +1

    nice video bro

  • @fernandoreverse601
    @fernandoreverse601 5 лет назад

    i can use this to found host to create vpn connection? with for example: http injector?

  • @agnieszkalis3568
    @agnieszkalis3568 3 года назад

    Is there any way to discover available linux kernel network vulnerabilities ?

  • @PaulBiyabiya
    @PaulBiyabiya Год назад

    Can we use that mnap script for bug bounty?

  • @Napert
    @Napert 5 лет назад

    Quick question about cracking wifi hashes : can an attacker be thinking that it got the right password if the target clients use wrong password when the handshake was captured?
    An attacker launches deauth attack and listens for handshakes and in the time the attacker listens someone tries to connect to target wifi using wrong password then the attacker gets the handshake and tries to decrypt it and will the final password be the correct one or the invalid used by the someone who tried to connect while an attacker was listening?
    Im sorry for my english

    • @Slepsy
      @Slepsy 5 лет назад

      Yes after deauth is finished there is a possibility that someone is typing password right at that time and that u will catch wrong password he typed instead of other devices automaticly connecting back, tho the chances for that are almost close to 0

  • @buzkings4975
    @buzkings4975 5 лет назад

    Hello, how can i get firewall name and version, tried wawoof, but its giving a wrong name. any other way?

  • @yahyakord7229
    @yahyakord7229 3 года назад

    Grat videos thanks ... Try to blink more !

  • @kangaroux0
    @kangaroux0 5 лет назад +1

    This channel is fucking fantastic I love you

  • @anisiobiarinze8041
    @anisiobiarinze8041 2 года назад

    How can u get a laptop, I need to start learning programming 🥺

  • @badguyrob
    @badguyrob 5 лет назад

    How come I can run this command on my IP and get results, but I do not get any results with another computer on my network?

  • @mynameiszoro
    @mynameiszoro 5 лет назад +1

    awesome video, Keep it up :)

  • @blamepotato8014
    @blamepotato8014 3 года назад

    Thank you so much!

  • @Kvicken223
    @Kvicken223 Год назад

    Very intresting video, im quite late. But doesn't this leave alot of footprints?

  • @tajammul.shaheen
    @tajammul.shaheen 2 года назад

    can we do this for websites as well?

  • @carloscontreras-rq3ms
    @carloscontreras-rq3ms 5 лет назад +3

    Kody my boy much love big fan.luv ur vids

  • @kunalradia6166
    @kunalradia6166 4 года назад

    Hi. I need help. Whenever I am trying to do a Vulnerabilities scan or Service scan. I am receiving following error
    AllProbes::compileFallbacks: Unknown fallback specified in Probe DNSVersionBindReqTCP: 'DNSVersionBindReq' .
    Could you please help out solving this error or anyone can give any clue for the same?

    • @NullByteWHT
      @NullByteWHT  4 года назад

      Sorry I have no experience with that you should contact the devs.

  • @charithadissanayake3304
    @charithadissanayake3304 3 года назад +1

    Gold!

  • @OzoneX4
    @OzoneX4 5 лет назад +1

    Which company do you work for?

    • @NullByteWHT
      @NullByteWHT  5 лет назад +2

      My friends and I produce videos independently, right now we manage Null Byte's channel

  • @bingovalue
    @bingovalue 4 года назад

    how do i fix ‘all 1000 ports scanned are filtered’ ?

  • @unknown-mu2wl
    @unknown-mu2wl 5 лет назад

    Kody how i use 2 wifi adapters in bridge mode to use in a evil twin / honeypot without virtual machine?

  • @xlu125
    @xlu125 5 лет назад

    Hi, do you use Kali inside VM on your computer?

  • @rahulgaikwad9860
    @rahulgaikwad9860 3 года назад

    Bro my nmap is giving error..
    So how to solve that error?
    Can you help me??

  • @morningstar5716
    @morningstar5716 5 лет назад +1

    u are best hacker ... bro u must be OSCP ?

  • @shinrawat4152
    @shinrawat4152 4 года назад

    Actually I want to ask one question that will this scan create a log file on target

  • @iantomlinson2254
    @iantomlinson2254 5 лет назад

    Is it possible to use these scripts on a android device using the turmux app?

  • @garytan3531
    @garytan3531 5 лет назад

    Hi, i hope anyone can help me with this. when i execute "nmap --script vulscan,nmap-vulners -sV " everything was clean and i remember that the server was installed some apache 2.2 , so do i have to connect in the same network or i can do a vulscan on the public IP?

    • @vamsikrishna9737
      @vamsikrishna9737 5 лет назад

      Be in the same network and don't perform on public ip's until you have permission to do so

    • @garytan3531
      @garytan3531 5 лет назад

      @@vamsikrishna9737 yeah i have permission as i would like to use nmap vulscan to check for the vulnerability. but it doesnt show at all. appreciate any help?

    • @vamsikrishna9737
      @vamsikrishna9737 5 лет назад

      @@garytan3531 if the commands you run are executing without any errors then I think the vunlerablity is patched or they are updated so you are not getting anything other way is to try Nessus or openvas

    • @garytan3531
      @garytan3531 5 лет назад

      @@vamsikrishna9737 I used trial version nessus on the internal network and scan with bunch of vulnerabilities but when I use another computer not within the network to nmap vulscan no vulnerability.

  • @순뚜부-d9q
    @순뚜부-d9q 5 лет назад +1

    good job

  • @akashdesai1739
    @akashdesai1739 3 года назад

    NSE: failed to initialize the script engine:
    /usr/bin/../share/nmap/nse_main.lua:821: directory '/usr/bin/../share/nmap/scripts/vulscan' found, but will not match without '/'
    stack traceback:
    [C]: in function 'error'
    /usr/bin/../share/nmap/nse_main.lua:821: in local 'get_chosen_scripts'
    /usr/bin/../share/nmap/nse_main.lua:1312: in main chunk
    [C]: in ?
    QUITTING!

  • @thatniqqakevin644
    @thatniqqakevin644 4 месяца назад

    Hey bro, how are you doing? I’m having some trouble with assignment. I was wondering if you could reach out and we could get in contact and you could help me please

  • @razubial6981
    @razubial6981 2 года назад

    Good video

  • @erazorosero1490
    @erazorosero1490 2 года назад

    NullByte another diferents vulscan ? please tell me

  • @RedHulk64
    @RedHulk64 5 лет назад +1

    can you do a video on bettercap 2 ??

    • @weedaq
      @weedaq 5 лет назад

      Yeah that would be amazing. Thanks

  • @Pokeeeee
    @Pokeeeee 5 лет назад

    Does anyone know the intro music?

  • @stephenpeterwandera9176
    @stephenpeterwandera9176 5 лет назад

    At the point you run the script with nmap, should you also include techniques to hide from IDSs? Like decoys, bits and zombies to name a few

  • @joselaurel4050
    @joselaurel4050 5 лет назад

    how to avoid arp detection of wireshark pls reply

  • @PONCHO19809
    @PONCHO19809 2 года назад

    Hola cuando lo ejecuto el reporte sale diferente ... no sale la puntuación ni la url del cve
    alguien que me pueda orientar por favor

  • @yeshua4590
    @yeshua4590 5 лет назад

    Will you do a review on the ALFA AC1900 adapter doing a wpa2 pw crack on kali linux, You're the best

    • @jacobcyr4879
      @jacobcyr4879 3 года назад

      i got one what a terrible setup hey haha

  • @muhammadshoaibmarwat285
    @muhammadshoaibmarwat285 5 лет назад +1

    great trick

  • @Marienkarpfen
    @Marienkarpfen 5 лет назад +2

    looking at your videos impressions you lately get a lot of attention. Make sure you secure your videos to reupload to vimeo or something.

    • @godfather7339
      @godfather7339 3 года назад

      LBRY is good too, its like RUclips, but decentralized, so complete content freedom.

  • @paulmorrey733
    @paulmorrey733 5 лет назад +1

    Thanks

  • @jitesharora3773
    @jitesharora3773 5 лет назад +1

    PLEASE MAKE A VIDEO ON SQL INJECTION ATTACK

  • @advaithmadhukar2609
    @advaithmadhukar2609 5 лет назад

    please make a video about click jacking

  • @Atomicflee
    @Atomicflee 7 месяцев назад

    Thus script doesn't work anymore
    After the python and kali updates

  • @kranthibendalam4757
    @kranthibendalam4757 3 года назад

    I like this video

  • @oddball8809
    @oddball8809 Год назад +1

    why doesnt he blink 😨

  • @matthewwood587016
    @matthewwood587016 5 лет назад +1

    Does not work anymore

  • @unknown-mu2wl
    @unknown-mu2wl 5 лет назад

    Make a video with this theme please buddy

  • @play_sports_and_read_books
    @play_sports_and_read_books 4 года назад

    Why do they recommend kali linux always, can't i do such stuff on ubuntu?

    • @NullByteWHT
      @NullByteWHT  4 года назад +1

      It already has a lot of required tools and drivers preinstalled.

    • @play_sports_and_read_books
      @play_sports_and_read_books 4 года назад

      Null Byte so that means that other versions of linux all can do the job but you have to install lots of tools first.
      Thannks :)