1
00:00:06,480 --> 00:00:07,313
- [Instructor] In this segment,

2
00:00:07,313 --> 00:00:09,390
we're gonna take a closer look at ZenMap,

3
00:00:09,390 --> 00:00:13,080
which is the official Nmap
Graphical User Interface or GUI.

4
00:00:13,080 --> 00:00:15,390
First released in 2007,

5
00:00:15,390 --> 00:00:17,760
Nmap continues to be
one of the most popular

6
00:00:17,760 --> 00:00:20,310
and beloved security tools.

7
00:00:20,310 --> 00:00:22,590
The Nmap, which stands for Network Mapper,

8
00:00:22,590 --> 00:00:24,660
is a free and open-source utility

9
00:00:24,660 --> 00:00:27,270
for network discovery
and security auditing.

10
00:00:27,270 --> 00:00:30,750
Nmap uses raw IP packets
in very novel ways

11
00:00:30,750 --> 00:00:33,660
to determine what hosts are
available on the network,

12
00:00:33,660 --> 00:00:35,850
what services those hosts are offering,

13
00:00:35,850 --> 00:00:38,100
what operating systems they're running,

14
00:00:38,100 --> 00:00:40,800
what type of packet filters
and firewalls are in use,

15
00:00:40,800 --> 00:00:43,590
and dozens of other characteristics.

16
00:00:43,590 --> 00:00:46,350
Now, the Nmap Suite
includes an advanced GUI

17
00:00:46,350 --> 00:00:48,450
and results viewer known as ZenMap.

18
00:00:48,450 --> 00:00:50,370
That's what you're looking at right now.

19
00:00:50,370 --> 00:00:53,943
ZenMap is a multi-platform
Linux, Windows, Mac,

20
00:00:53,943 --> 00:00:58,943
OSX, BSD, et cetera, free
and open-source application

21
00:00:59,010 --> 00:01:02,610
which aims to make Nmap
easy for beginners to use

22
00:01:02,610 --> 00:01:04,440
while providing advanced features

23
00:01:04,440 --> 00:01:06,933
for experienced Nmap users.

24
00:01:08,400 --> 00:01:12,630
Now, I took the liberty of
setting up a pre-configured scan

25
00:01:12,630 --> 00:01:15,780
of my local network so that
we could look at the results.

26
00:01:15,780 --> 00:01:16,980
And we started with the target.

27
00:01:16,980 --> 00:01:18,720
I had to say what the target was gonna be.

28
00:01:18,720 --> 00:01:22,110
I said 192, 168, 0.1 through 254.

29
00:01:22,110 --> 00:01:23,670
That's my local network.

30
00:01:23,670 --> 00:01:26,190
I had to choose the profile for the scan,

31
00:01:26,190 --> 00:01:29,010
and there's a number of different
profiles to choose from,

32
00:01:29,010 --> 00:01:32,820
from intense scan to
intense scan, all TCP ports,

33
00:01:32,820 --> 00:01:34,800
a quick scan, a regular scan,

34
00:01:34,800 --> 00:01:37,620
even a slow comprehensive
scan that, hopefully,

35
00:01:37,620 --> 00:01:39,690
will, you know, fly underneath the radar

36
00:01:39,690 --> 00:01:41,253
and not be detected.

37
00:01:42,480 --> 00:01:44,670
So looking here in the body,

38
00:01:44,670 --> 00:01:46,350
I'm gonna scroll back up to the top.

39
00:01:46,350 --> 00:01:50,370
You can see that Nmap
looked at the entire range

40
00:01:50,370 --> 00:01:54,843
to try to find hosts that
were alive and responding.

41
00:01:55,770 --> 00:01:59,343
And eventually, it did
find a number of hosts

42
00:01:59,343 --> 00:02:02,257
that you can see over here
on the left-hand side,

43
00:02:02,257 --> 00:02:07,257
.1, .2, 118, 163, 171, 191, 195, and 197.

44
00:02:09,450 --> 00:02:12,360
Now, I can organize
those hosts in this panel

45
00:02:12,360 --> 00:02:17,360
either by operating
system or by IP address.

46
00:02:17,700 --> 00:02:19,950
If I wanna just get this quick visual of,

47
00:02:19,950 --> 00:02:21,840
okay, what are those hosts,

48
00:02:21,840 --> 00:02:23,400
I'm gonna come over to the fourth tab

49
00:02:23,400 --> 00:02:25,170
and look at host details.

50
00:02:25,170 --> 00:02:29,130
I'm gonna find out what the
host is, what it's IP address,

51
00:02:29,130 --> 00:02:33,540
the number of open ports, it's
uptime, and it's last boot.

52
00:02:33,540 --> 00:02:36,153
So I can see here, I've
got a Linux device,

53
00:02:37,530 --> 00:02:42,360
I've got a VxWorks, looks
like an Apple Mac device,

54
00:02:42,360 --> 00:02:45,090
one that couldn't be identified,

55
00:02:45,090 --> 00:02:50,090
Windows server 2008, a Windows
10, another Apple device,

56
00:02:50,250 --> 00:02:53,610
and a device that looks like
it's going to be probably

57
00:02:53,610 --> 00:02:54,690
a printer 'cause it's running

58
00:02:54,690 --> 00:02:58,713
the HP iLO 4 remote management interface.

59
00:02:59,820 --> 00:03:03,600
So quick and dirty information
on each one of the hosts.

60
00:03:03,600 --> 00:03:06,420
If I'm interested in what ports are open,

61
00:03:06,420 --> 00:03:09,690
well, I can do a quick
look through each one

62
00:03:09,690 --> 00:03:12,060
of my hosts here on the left-hand side

63
00:03:12,060 --> 00:03:14,850
and find out what the ports,
the protocol, the state,

64
00:03:14,850 --> 00:03:17,643
the service, and the version is.

65
00:03:18,630 --> 00:03:20,580
Maybe I don't wanna look
through each one of my hosts,

66
00:03:20,580 --> 00:03:23,580
I'm just looking for a particular service,

67
00:03:23,580 --> 00:03:26,070
so I'm gonna click on the
services tab in the panel,

68
00:03:26,070 --> 00:03:29,280
and maybe I wanna know if any
of the devices I just scanned

69
00:03:29,280 --> 00:03:30,450
are running FTP.

70
00:03:30,450 --> 00:03:31,710
Well, there we go.

71
00:03:31,710 --> 00:03:33,480
What if they're running HTTP?

72
00:03:33,480 --> 00:03:36,480
Well, now I've got a list
of who's running HTTP,

73
00:03:36,480 --> 00:03:39,960
the port, again, protocol,
the current state,

74
00:03:39,960 --> 00:03:41,610
and the version.

75
00:03:41,610 --> 00:03:44,430
So a lot of really good
information, you know,

76
00:03:44,430 --> 00:03:48,450
that I can quickly use for
both inventory purposes

77
00:03:48,450 --> 00:03:51,390
as well as to begin enumerating details

78
00:03:51,390 --> 00:03:53,610
about each one of these hosts.

79
00:03:53,610 --> 00:03:56,050
I can also look a little topology

80
00:03:57,720 --> 00:04:02,700
so I can see the relationship
of those devices to my scan.

81
00:04:02,700 --> 00:04:04,950
I can see if the host
was not port scanned,

82
00:04:04,950 --> 00:04:07,110
a host with fewer than three open ports,

83
00:04:07,110 --> 00:04:10,830
host with three to six
ports, more than six ports.

84
00:04:10,830 --> 00:04:12,870
I can see the trace route connections,

85
00:04:12,870 --> 00:04:16,530
and then, by the various icons,
I can learn more information

86
00:04:16,530 --> 00:04:19,623
so I can start mapping
out my network as well.

87
00:04:20,970 --> 00:04:24,210
Now, one of the really
nice things about ZENworks

88
00:04:24,210 --> 00:04:27,780
is that I can go and I could
save the scans if I want.

89
00:04:27,780 --> 00:04:30,810
So frequently used scans
can be saved as profiles

90
00:04:30,810 --> 00:04:33,363
to make them easy to run repeatedly.

91
00:04:35,400 --> 00:04:37,890
Scan results can be
saved and viewed later.

92
00:04:37,890 --> 00:04:40,710
I can save, take those saved scan results

93
00:04:40,710 --> 00:04:43,260
and compare them with another
one to see how they differ.

94
00:04:43,260 --> 00:04:45,120
And the results of the recent scans

95
00:04:45,120 --> 00:04:48,063
are all stored in a searchable database.

96
00:04:50,580 --> 00:04:53,130
You definitely should
get to know this program,

97
00:04:53,130 --> 00:04:54,300
this is ZenMap,

98
00:04:54,300 --> 00:04:58,650
as well as the classic
command line Nmap executable.

99
00:04:58,650 --> 00:05:00,030
Lots of help available too.

100
00:05:00,030 --> 00:05:01,680
If you go up to the help screen,

101
00:05:01,680 --> 00:05:04,170
it's going to tell you that,

102
00:05:04,170 --> 00:05:07,080
lemme bring it over so
you can actually see it,

103
00:05:07,080 --> 00:05:09,090
there we go, it's gonna tell you

104
00:05:09,090 --> 00:05:12,240
that you can get more documentation

105
00:05:12,240 --> 00:05:14,490
at the Nmap documentation directory

106
00:05:14,490 --> 00:05:16,830
or at the ZenMap webpage itself,

107
00:05:16,830 --> 00:05:19,950
but a lot of really good help

108
00:05:19,950 --> 00:05:24,240
and documentation available
to you to learn, you know,

109
00:05:24,240 --> 00:05:26,280
what can be a very simple program

110
00:05:26,280 --> 00:05:29,343
or an extraordinarily complex program.

111
00:05:30,300 --> 00:05:34,680
Before we wrap up, just a bit
of trivia for you about Nmap,

112
00:05:34,680 --> 00:05:38,580
that Nmap has actually
been featured in 12 movies

113
00:05:38,580 --> 00:05:41,917
including "Matrix Reloaded," "Die Hard 4,"

114
00:05:41,917 --> 00:05:46,590
"Girl with the Dragon Tattoo"
and "The Bourne Ultimatum."

115
00:05:46,590 --> 00:05:49,743
And that, my friends, is
a closer look at ZenMap.
