Security Basics mailing list archives

Re: NMAP Scan of My Company's Internal Network: 666, 880 IP addresses in 49 hours


From: "Hasnain Atique" <hatique () hasnains com>
Date: Sat, 6 Nov 2004 00:21:51 +0600 (BDT)

Jack,

I'd be interested to learn how you managed the data from the nmap scan.

Thanks,

-- H


  I just wanted to let the list know my NMAP scanning results for my
company's large privately owned internal network.  I scanned 10 class B
ranges and several class Cs in our internal network.

As part of a plan to perform internal network inventories or my company's
network, I scanned 666,880 IP addresses and found 66,558 active addresses.
 The scan took 49 hours and was performed from a Compaq DL380 running
Redhat Linux 8.0.  This is the NMAP options I used:

nmap -O -T5 -PE --osscan_limit -F -v --max_rtt_timeout 100
--max_parallelism 100 --min_hostgroup 96 -oX /home/security/all_ip.xml -iL
/home/security/ip_addresses.txt

I also customized nmap-services file to only include 270 services.  We
plan to perform this scan on a weekly basis.  Thanks to all who gave me
ideas.

Jack Mogren
Mayo Clinic
Foundation Information Security Office







Current thread: