Find Network Vulnerabilities with Nmap Scripts [Tutorial]

Поділитися
Вставка
  • Опубліковано 3 січ 2025

КОМЕНТАРІ • 210

  • @cracc_baby
    @cracc_baby 3 місяці тому +3

    ofc a lot has changed in 5 years, but this video is still highly discoverable and helpful with nmap 7.94
    worth mentioning, nmap users now must include "vulscan/vulscan.nse" and/or "nmap-vulners/vulners.nse" after the --script. not just "vulscan" anymore, or youll get an error for empty directory

  • @earl_the_great
    @earl_the_great 5 років тому +26

    I love this channel so much. I learned a lot of things, especially writing your own script. That was amazing.

    • @NullByteWHT
      @NullByteWHT  5 років тому +4

      I'm glad it's helpful! Thanks for watching

  • @JeanS1989
    @JeanS1989 6 років тому +23

    Kody, you and your team need a tv program. I Love what you do and I’m sure I ain’t the only one.

    • @roberthorn6707
      @roberthorn6707 6 років тому +4

      Man Kody scares the shit outta me!! lol I mean like i wouldn't wanna piss him off! But they do produce some pretty amazing content! I'm training to become a PenTester now and between this channel and Cybrary I'll be penetrating people's networks in no time!

    • @NullByteWHT
      @NullByteWHT  6 років тому +2

      @@roberthorn6707 Hahaha thank you

    • @JeanS1989
      @JeanS1989 6 років тому

      @@roberthorn6707 lols right! I don't think anyone wants to land on his blacklist. That has to be a pretty scary spot to be in.

    • @JeanS1989
      @JeanS1989 6 років тому

      @@NullByteWHT Kody, If you ever do a meet & greet somewhere let me know I'm very interested, sounds like a lot of fun.

    • @netbin
      @netbin 6 років тому

      Jean Suriel what is tv program

  • @RiktigMusik
    @RiktigMusik 6 років тому +14

    Give this guy a like, he is taking the time to share the knowledge to even the beginners and he has great tips! One of my favorites.. Thank you 🙏, you are appreciated!

    • @NullByteWHT
      @NullByteWHT  6 років тому +2

      Thank you!

    • @RiktigMusik
      @RiktigMusik 6 років тому +2

      Null Byte No Thank YOU! Your taking the time to do what many hackers/pentesters etc and pass on your skill.. Most of the people have the attitude of I”learned it myself, and so should you” But some people need a push.. And u are that push for me, you made me go buy a raspberry and WiFi adapters, first time I clips influenced me like this so keep doing what ur doing..Do you provide any online courses that i can take and pay for like live sessions, that would be so dope.. You are appreciated 🙏 .

  • @seamuscampbell5948
    @seamuscampbell5948 6 років тому +11

    Top man just love your tutorials - thank you very much for all the effort you put in to publishing these.

  • @dennisask3960
    @dennisask3960 6 років тому +15

    Your content is just amazing. By far one of the best security channels I have ever seen. Love the cat images in the background ;) perfect reference to deep learning if you ask me.

  • @taiquangong9912
    @taiquangong9912 6 років тому +3

    Stumbled upon this site and love the content it helped me tremendously.

  • @francescopresta9570
    @francescopresta9570 6 років тому +7

    Very useful, Kody and Tokyoneon number one!

  • @zardashtjaza1343
    @zardashtjaza1343 4 роки тому +1

    congratulations 500k dude hope keep going

  • @mr_mr
    @mr_mr 6 років тому +4

    So good as usual. Thanks Kody. Been learning so much from you.

  • @poms3559
    @poms3559 6 років тому +58

    If we take all the content on this channel and compare it to other content out there we gonna find that this content here is not available out there, thats why this channel worth more than 1m$,
    Oops I said that last time, by updating my packages, its worth now 1. 000000*10 b$

    • @NullByteWHT
      @NullByteWHT  6 років тому +16

      I really enjoy making these for all of you, I'm glad you think so highly of them!

    • @Aryan-uu1mv
      @Aryan-uu1mv 6 років тому

      How can I create phishing page

    • @Aryan-uu1mv
      @Aryan-uu1mv 6 років тому

      Please guide me

    • @Aryan-uu1mv
      @Aryan-uu1mv 6 років тому

      Steps to do this needed

    • @Sapientiaa
      @Sapientiaa 4 роки тому +1

      @@NullByteWHT NSE: failed to initialize the script engine:
      /usr/local/bin/../share/nmap/nse_main.lua:264: vulscan:7: unexpected symbol near '

  • @EpicLPer
    @EpicLPer 6 років тому +14

    I'd love to scan my whole network at once for vulnerabilities since I have so many things connected here... But how would I do that instead?

    • @mcbazzauk
      @mcbazzauk 6 років тому +1

      Look into deploying Tenable Nessus Home. It's an excellent vulnerability scanner that is free for home use.

    • @ashleybishton742
      @ashleybishton742 4 роки тому

      Just run the same scan but do the whole range of IPS in the network. Thats how u scan your whole network.

  • @ryaagard8459
    @ryaagard8459 6 років тому +10

    No dislikes damn! Btw keep up these tutorials they are awesome!

  • @AbdulKalam-yi6ve
    @AbdulKalam-yi6ve 6 років тому +6

    i watch all your videos really helpful 💖🔥 #nullbyte fan

  • @barresoft
    @barresoft 6 років тому +3

    Que buenos videos! que buena terminación! seguí así maestro! gracias por enseñarnos!!!!!!!!

  • @sarikapayili2624
    @sarikapayili2624 5 років тому

    Thank you bro this video helps me so much.....
    Great tutorial man...

    • @NullByteWHT
      @NullByteWHT  5 років тому

      Thanks Sarika Payili! We really do put in a lot of hard work.

  • @enriqueperez339
    @enriqueperez339 5 років тому +1

    Exactly what directory would you clone the git repository?

  • @Tekionemission
    @Tekionemission Рік тому

    (4:17) Like the vulscan and the nmap-vulners script. Thank you for sharing. One thing I am not clear about, it looks like you would have to pull the script down from Github and this is not out of the box script from Nmap?

    • @Tekionemission
      @Tekionemission Рік тому

      Ignore - I went to your site and got my answer; a great write up by the way.

  • @MrTyrant258
    @MrTyrant258 5 років тому +5

    Is Nmap a noisy tool to use? From what I’ve heard, it’s easy to detect with a firewall or an IDS on the network.

    • @ashleybishton742
      @ashleybishton742 4 роки тому +3

      U can work round that with -Pn or use -D and for decoy to spoof an IP you type in. So they don't really know its you if you don't want them to know that you scanned them.

  • @prive_ik_ben_wie_ik_ben
    @prive_ik_ben_wie_ik_ben 6 років тому +5

    make a vid on pupy and how to bind the payload. thx again!

  • @cde-lf7iu
    @cde-lf7iu 4 роки тому

    Always the best content... Great work mate !

  • @Xxmeca421xX
    @Xxmeca421xX 5 років тому

    Did you lightly paint your laptop? How did you get the tint over your stickers, I like it.

  • @nullpx9548
    @nullpx9548 2 роки тому

    thanks sir,,,, i'm from indonesia very like your channel

  • @soundspoon
    @soundspoon 6 років тому +1

    awesome content man!!

  • @mocheford
    @mocheford 6 років тому +2

    I always like the video before hitting play. Never regret it.

    • @mr_mr
      @mr_mr 6 років тому +1

      mocheford agreed. If you take the time to make a comprehensive video and make it available for free, it deserves likes.

    • @NullByteWHT
      @NullByteWHT  6 років тому

      Thank both of you, we don't make much from this so it's the community I do it for.

    • @mr_mr
      @mr_mr 6 років тому +1

      @@NullByteWHT What else do you guys do? How can people support you? Do you teach?

    • @NullByteWHT
      @NullByteWHT  6 років тому +1

      @@mr_mr wht doesn't want a patreon, so we're looking for other ways

  • @TOn-fx2gr
    @TOn-fx2gr 6 років тому +2

    Pls how to interact with router by using python i want to write a code that do similar to reaver it send wps pin and receive output to see if the pin was correct . What module i have to use i heard of piramiko and scapy and heard that i have to logine to router by ssh but we need hostname to do that . Pls if you can do a video about it or tell me where i can find a answer . Thank you

  • @v380riMz
    @v380riMz 6 років тому

    Do you have much experience in the pentesting field?

  • @akvartz
    @akvartz 6 років тому +25

    @NullByte
    Great content, and i'm lovin' extra energy in recent videos.
    But could you please blink, at least once

    • @NullByteWHT
      @NullByteWHT  6 років тому +25

      You can have more energy or more blinking but not both

    • @Nelcj_99
      @Nelcj_99 6 років тому +7

      @@NullByteWHT I rlly don't know which comment is better XD

  • @BamBam-gs7eb
    @BamBam-gs7eb 5 років тому

    Thanks Kody, excellent as always. Would be great to get an overview of how you got into hacking/InfoSec, experience and how you recommend getting into the industry.

    • @NullByteWHT
      @NullByteWHT  5 років тому

      Good idea BamBam, I've added it to the list of video ideas.

  • @yusuususwwwdpppdeew6780
    @yusuususwwwdpppdeew6780 6 років тому +6

    How do u come up with this it’s amazing

  • @fanuelalmaw7848
    @fanuelalmaw7848 5 років тому

    Amazing videos make me to try my kali linux machin and dig more things you make what i need to teach like this

  • @oceanic_lost_8156
    @oceanic_lost_8156 Рік тому

    @Null Byte i have to find a Linux Kernel vulnerability on a machine however when i run the code i am unable to find the correct one, they are listed there but not the kernel one, any chance you can help

  • @anisiobiarinze8041
    @anisiobiarinze8041 2 роки тому

    How can u get a laptop, I need to start learning programming 🥺

  • @mgtidus
    @mgtidus 4 роки тому

    Thanks Kody, your videos are very helpful as always ! Absolutely no regrets for subscribing at all. ;D

  • @VNMHCKR
    @VNMHCKR 6 років тому +5

    Hey man! Could you do a video on metasploit? I’m a beginner and would like to learn from you, since you are so clear. Thx!

    • @NullByteWHT
      @NullByteWHT  6 років тому +3

      Yes, we can do that

    • @VNMHCKR
      @VNMHCKR 6 років тому +1

      Null Byte omfg thanks dude!!!

  • @lionheart-mm1334
    @lionheart-mm1334 Рік тому

    Can you use nmap to perform authenticated scans?

  • @anubhabchowdhury9296
    @anubhabchowdhury9296 4 роки тому

    Amazing content bro...

  • @Jon-da-bad
    @Jon-da-bad 6 років тому +1

    Great video bro thank you

  • @qxch7222
    @qxch7222 3 роки тому +1

    If you get a error:
    Try to list the scripts like this_ sudo nmap --script nmap-vulners/,vulns/ -sV [host]
    hope it helped

  • @MajorBuzzKill
    @MajorBuzzKill 6 років тому

    Which version of Kali do you use?

  • @PaulBiyabiya
    @PaulBiyabiya Рік тому

    Can we use that mnap script for bug bounty?

  • @thesuhu
    @thesuhu 4 роки тому +1

    His eyes never blinking

  • @telugubusinesschannel
    @telugubusinesschannel 6 років тому +1

    Love you.... Thank you... Respect you...

  • @MalibuSea
    @MalibuSea 5 років тому

    Hello, I get this following error:
    failed to initialize the script engine
    'vulscan' did not match a category, filename or directory stack traceback.

  • @Napert
    @Napert 6 років тому

    Quick question about cracking wifi hashes : can an attacker be thinking that it got the right password if the target clients use wrong password when the handshake was captured?
    An attacker launches deauth attack and listens for handshakes and in the time the attacker listens someone tries to connect to target wifi using wrong password then the attacker gets the handshake and tries to decrypt it and will the final password be the correct one or the invalid used by the someone who tried to connect while an attacker was listening?
    Im sorry for my english

    • @Slepsy
      @Slepsy 6 років тому

      Yes after deauth is finished there is a possibility that someone is typing password right at that time and that u will catch wrong password he typed instead of other devices automaticly connecting back, tho the chances for that are almost close to 0

  • @erazorosero1490
    @erazorosero1490 2 роки тому

    NullByte another diferents vulscan ? please tell me

  • @grissgray
    @grissgray 6 років тому +2

    keep up the good work

  • @Kvicken223
    @Kvicken223 2 роки тому

    Very intresting video, im quite late. But doesn't this leave alot of footprints?

  • @fernandoreverse601
    @fernandoreverse601 6 років тому

    i can use this to found host to create vpn connection? with for example: http injector?

  • @ArthurRWhite
    @ArthurRWhite 5 років тому

    We appreciate it bro please keep helping us tnx

  • @RedHulk64
    @RedHulk64 6 років тому +1

    can you do a video on bettercap 2 ??

    • @weedaq
      @weedaq 6 років тому

      Yeah that would be amazing. Thanks

  • @tajammul.shaheen
    @tajammul.shaheen 2 роки тому

    can we do this for websites as well?

  • @agnieszkalis3568
    @agnieszkalis3568 3 роки тому

    Is there any way to discover available linux kernel network vulnerabilities ?

  • @OzoneX4
    @OzoneX4 6 років тому +1

    Which company do you work for?

    • @NullByteWHT
      @NullByteWHT  6 років тому +2

      My friends and I produce videos independently, right now we manage Null Byte's channel

  • @shinrawat4152
    @shinrawat4152 4 роки тому

    Actually I want to ask one question that will this scan create a log file on target

  • @xlu125
    @xlu125 5 років тому

    Hi, do you use Kali inside VM on your computer?

  • @mynameiszoro
    @mynameiszoro 6 років тому +1

    awesome video, Keep it up :)

  • @kangaroux0
    @kangaroux0 6 років тому +1

    This channel is fucking fantastic I love you

  • @yeshua4590
    @yeshua4590 6 років тому

    Will you do a review on the ALFA AC1900 adapter doing a wpa2 pw crack on kali linux, You're the best

    • @jacobcyr4879
      @jacobcyr4879 3 роки тому

      i got one what a terrible setup hey haha

  • @peacetvafrica957
    @peacetvafrica957 11 місяців тому +1

    Can you proove you are human your eyes are not blinking

  • @7V999
    @7V999 3 роки тому

    Thank You Kody Real 👽

  • @forjafuny
    @forjafuny 6 років тому

    Please friend can u help .i install kali linux in my laptot and whene i want to back to windows 7 i cant .there is any solution god bless u

  • @iantomlinson2254
    @iantomlinson2254 5 років тому

    Is it possible to use these scripts on a android device using the turmux app?

  • @buzkings4975
    @buzkings4975 5 років тому

    Hello, how can i get firewall name and version, tried wawoof, but its giving a wrong name. any other way?

  • @eranthagunawardena2638
    @eranthagunawardena2638 4 роки тому

    When I execute git clone getting an error : bash: git: command not found... Failed to search for file: cannot update read-only report. Please help

  • @carloscontreras-rq3ms
    @carloscontreras-rq3ms 6 років тому +3

    Kody my boy much love big fan.luv ur vids

  • @badguyrob
    @badguyrob 5 років тому

    How come I can run this command on my IP and get results, but I do not get any results with another computer on my network?

  • @alejandrotaudil3689
    @alejandrotaudil3689 5 років тому

    Thanks for the info!

  • @thatniqqakevin644
    @thatniqqakevin644 5 місяців тому

    Hey bro, how are you doing? I’m having some trouble with assignment. I was wondering if you could reach out and we could get in contact and you could help me please

  • @stephenpeterwandera9176
    @stephenpeterwandera9176 5 років тому

    At the point you run the script with nmap, should you also include techniques to hide from IDSs? Like decoys, bits and zombies to name a few

  • @unknown-mu2wl
    @unknown-mu2wl 6 років тому

    Kody how i use 2 wifi adapters in bridge mode to use in a evil twin / honeypot without virtual machine?

  • @yahyakord7229
    @yahyakord7229 3 роки тому

    Grat videos thanks ... Try to blink more !

  • @garytan3531
    @garytan3531 5 років тому

    Hi, i hope anyone can help me with this. when i execute "nmap --script vulscan,nmap-vulners -sV " everything was clean and i remember that the server was installed some apache 2.2 , so do i have to connect in the same network or i can do a vulscan on the public IP?

    • @vamsikrishna9737
      @vamsikrishna9737 5 років тому

      Be in the same network and don't perform on public ip's until you have permission to do so

    • @garytan3531
      @garytan3531 5 років тому

      @@vamsikrishna9737 yeah i have permission as i would like to use nmap vulscan to check for the vulnerability. but it doesnt show at all. appreciate any help?

    • @vamsikrishna9737
      @vamsikrishna9737 5 років тому

      @@garytan3531 if the commands you run are executing without any errors then I think the vunlerablity is patched or they are updated so you are not getting anything other way is to try Nessus or openvas

    • @garytan3531
      @garytan3531 5 років тому

      @@vamsikrishna9737 I used trial version nessus on the internal network and scan with bunch of vulnerabilities but when I use another computer not within the network to nmap vulscan no vulnerability.

  • @PONCHO19809
    @PONCHO19809 2 роки тому

    Hola cuando lo ejecuto el reporte sale diferente ... no sale la puntuación ni la url del cve
    alguien que me pueda orientar por favor

  • @jitesharora3773
    @jitesharora3773 6 років тому +1

    PLEASE MAKE A VIDEO ON SQL INJECTION ATTACK

  • @advaithmadhukar2609
    @advaithmadhukar2609 6 років тому

    please make a video about click jacking

  • @tejasmandre666
    @tejasmandre666 6 років тому

    Pretty awesome ! 👍

  • @joselaurel4050
    @joselaurel4050 5 років тому

    how to avoid arp detection of wireshark pls reply

  • @kunalradia6166
    @kunalradia6166 4 роки тому

    Hi. I need help. Whenever I am trying to do a Vulnerabilities scan or Service scan. I am receiving following error
    AllProbes::compileFallbacks: Unknown fallback specified in Probe DNSVersionBindReqTCP: 'DNSVersionBindReq' .
    Could you please help out solving this error or anyone can give any clue for the same?

    • @NullByteWHT
      @NullByteWHT  4 роки тому

      Sorry I have no experience with that you should contact the devs.

  • @Pokeeeee
    @Pokeeeee 5 років тому

    Does anyone know the intro music?

  • @morningstar5716
    @morningstar5716 6 років тому +1

    u are best hacker ... bro u must be OSCP ?

  • @selvador_x5211
    @selvador_x5211 Рік тому +1

    Thnks ❤ work

  • @cy_wareye7395
    @cy_wareye7395 5 років тому

    I will test it today

  • @bingovalue
    @bingovalue 4 роки тому

    how do i fix ‘all 1000 ports scanned are filtered’ ?

  • @mohammadsaad2336
    @mohammadsaad2336 6 років тому

    Which books you guys refer.
    Can you please tell us

  • @rahulgaikwad9860
    @rahulgaikwad9860 3 роки тому

    Bro my nmap is giving error..
    So how to solve that error?
    Can you help me??

  • @akashdesai1739
    @akashdesai1739 3 роки тому

    NSE: failed to initialize the script engine:
    /usr/bin/../share/nmap/nse_main.lua:821: directory '/usr/bin/../share/nmap/scripts/vulscan' found, but will not match without '/'
    stack traceback:
    [C]: in function 'error'
    /usr/bin/../share/nmap/nse_main.lua:821: in local 'get_chosen_scripts'
    /usr/bin/../share/nmap/nse_main.lua:1312: in main chunk
    [C]: in ?
    QUITTING!

  • @unknown-mu2wl
    @unknown-mu2wl 6 років тому

    Make a video with this theme please buddy

  • @Marienkarpfen
    @Marienkarpfen 6 років тому +2

    looking at your videos impressions you lately get a lot of attention. Make sure you secure your videos to reupload to vimeo or something.

    • @godfather7339
      @godfather7339 4 роки тому

      LBRY is good too, its like UA-cam, but decentralized, so complete content freedom.

  • @LearnMoreAboutHacking
    @LearnMoreAboutHacking 6 років тому +1

    nice video bro

  • @blamepotato8014
    @blamepotato8014 3 роки тому

    Thank you so much!

  • @krzysztofjuszczak906
    @krzysztofjuszczak906 5 років тому

    Why is hour blurred?

  • @spetsnazrussia2446
    @spetsnazrussia2446 5 років тому

    How to make a CVE ?

  • @lucky_fellow_yo
    @lucky_fellow_yo 6 років тому

    I need Ur help bro !!! Can u guide me plzz ... I want to contact u personally !!!

    • @snipsnap9995
      @snipsnap9995 6 років тому

      Lol, why would he do that? I'm sure every single one of us would like to be taught by him personally, but that's just not how the world works...

    • @securitypoint8280
      @securitypoint8280 5 років тому

      Check this ua-cam.com/video/1XAssdnTQSo/v-deo.html

  • @Atomicflee
    @Atomicflee 8 місяців тому

    Thus script doesn't work anymore
    After the python and kali updates

  • @play_sports_and_read_books
    @play_sports_and_read_books 4 роки тому

    Why do they recommend kali linux always, can't i do such stuff on ubuntu?

    • @NullByteWHT
      @NullByteWHT  4 роки тому +1

      It already has a lot of required tools and drivers preinstalled.

    • @play_sports_and_read_books
      @play_sports_and_read_books 4 роки тому

      Null Byte so that means that other versions of linux all can do the job but you have to install lots of tools first.
      Thannks :)

  • @matthewwood587016
    @matthewwood587016 5 років тому +1

    Does not work anymore

  • @oddball8809
    @oddball8809 Рік тому +1

    why doesnt he blink 😨

  • @jerryjohn2655
    @jerryjohn2655 5 років тому

    You didn't said where to exactly cope that script

  • @순뚜부-d9q
    @순뚜부-d9q 6 років тому +1

    good job