nmap -sS -sC -A -Pn -p- --min-rate 5000 192.168.229.138 Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times will be slower. Starting Nmap 7.91 ( https://nmap.org ) at 2022-07-01 04:45 EDT Nmap scan report for 192.168.229.138 Host is up (0.00035s latency). Not shown: 65523 closed ports PORT STATE SERVICE VERSION 80/tcp open http Apache httpd 2.4.23 ((Win32) OpenSSL/1.0.2j PHP/5.4.45) |_http-server-header: Apache/2.4.23 (Win32) OpenSSL/1.0.2j PHP/5.4.45 |_http-title: phpStudy \xE6\x8E\xA2\xE9\x92\x88 2014 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 445/tcp open microsoft-ds Windows 7 Professional 7601 Service Pack 1 microsoft-ds (workgroup: GOD) 1025/tcp open msrpc Microsoft Windows RPC 1026/tcp open msrpc Microsoft Windows RPC 1027/tcp open msrpc Microsoft Windows RPC 1028/tcp open msrpc Microsoft Windows RPC 1029/tcp open msrpc Microsoft Windows RPC 1030/tcp open msrpc Microsoft Windows RPC 3306/tcp open mysql MySQL (unauthorized) 3389/tcp open tcpwrapped | ssl-cert: Subject: commonName=stu1.god.org | Not valid before: 2022-06-29T05:13:38 |_Not valid after: 2022-12-29T05:13:38 |_ssl-date: 2022-07-01T08:46:49+00:00; -2s from scanner time. MAC Address: 00:0C:29:58:D7:1A (VMware) Device type: general purpose Running: Microsoft Windows 7|2008|8.1 OS CPE: cpe:/o:microsoft:windows_7::- cpe:/o:microsoft:windows_7::sp1 cpe:/o:microsoft:windows_server_2008::sp1 cpe:/o:microsoft:windows_server_2008:r2 cpe:/o:microsoft:windows_8 cpe:/o:microsoft:windows_8.1 OS details: Microsoft Windows 7 SP0 - SP1, Windows Server 2008 SP1, Windows Server 2008 R2, Windows 8, or Windows 8.1 Update 1 Network Distance: 1 hop Service Info: Host: STU1; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results: |_clock-skew: mean: -2h00m01s, deviation: 3h59m59s, median: -2s |_nbstat: NetBIOS name: STU1, NetBIOS user: <unknown>, NetBIOS MAC: 00:0c:29:58:d7:1a (VMware) | smb-os-discovery: | OS: Windows 7 Professional 7601 Service Pack 1 (Windows 7 Professional 6.1) | OS CPE: cpe:/o:microsoft:windows_7::sp1:professional | Computer name: stu1 | NetBIOS computer name: STU1\x00 | Domain name: god.org | Forest name: god.org | FQDN: stu1.god.org |_ System time: 2022-07-01T16:46:35+08:00 | smb-security-mode: | account_used: <blank> | authentication_level: user | challenge_response: supported |_ message_signing: disabled (dangerous, but default) | smb2-security-mode: | 2.02: |_ Message signing enabled but not required | smb2-time: | date: 2022-07-01T08:46:35 |_ start_date: 2022-07-01T08:35:44
TRACEROUTE HOP RTT ADDRESS 1 0.35 ms 192.168.229.138
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 90.94 seconds
net view # 查看局域网内其他主机名 net config Workstation # 查看计算机名、全名、用户名、系统版本、工作站、域、登录域 net user # 查看本机用户列表 net user /domain # 查看域用户 net localgroup administrators # 查看本地管理员组(通常会有域用户) net view /domain # 查看有几个域 net user 用户名 /domain # 获取指定域用户的信息 net group /domain # 查看域里面的工作组,查看把用户分了多少组(只能在域控上操作) net time /domain #判断主域,主域服务器一般做时间服务器 net group 组名 /domain # 查看域中某工作组 net group "domain admins" /domain # 查看域管理员的名字 net group "domain computers" /domain # 查看域中的其他主机名 net group "domain controllers" /domain # 查看域控制器主机名(可能有多台) ipconfig /all #查询本机IP段,所在域等