Chuyển đến nội dung chính

Lesson 14: Reconnaissance and Scanning — Nmap, Amass, Nuclei

Passive/Active recon toolkit, advanced port scanning, vulnerability scanning with Nuclei templates.

🔒 DevSecOps — Lesson 14 Lesson 14: Reconnaissance and Scanning — Nmap, Amass, Nuclei__HTMLTAG_55___

Performance Testing & Pentest: Enterprise Standard Process 2026

Part 3: Pentest Foundations — Process and Methodology

xdev.asia

1. Reconnaissance — Overview

Reconnaissance Pipeline:

Target → Passive Recon → Active Recon → Scan → Report
          │                │               │
          ├── OSINT        ├── Port scan   ├── Vuln scan
          ├── DNS enum     ├── Service ID  ├── Nuclei
          ├── Subdomain    ├── Web crawl   └── Custom
          ├── Cert trans   └── Dir brute
          └── Shodan/Censys

Tools by Phase:
  Passive: Amass, subfinder, theHarvester, Shodan, crt.sh
  Active:  Nmap, masscan, httpx, ffuf, gobuster
  Vuln:    Nuclei, nikto, OWASP ZAP, Burp Suite

2. Subdomain Enumeration

# --- Amass — comprehensive subdomain discovery ---

# Passive enumeration (no direct connection to target)
amass enum -passive -d example.com -o amass_passive.txt

# Active enumeration (includes DNS brute-force)
amass enum -active -d example.com -brute -w /usr/share/wordlists/dns.txt \
  -o amass_active.txt

# Amass with config file
cat > amass_config.ini << 'EOF'
[scope]
[scope.domains]
domain = example.com

[data_sources]
[data_sources.Shodan]
[data_sources.Shodan.account1]
apikey = YOUR_SHODAN_KEY

[data_sources.SecurityTrails]
[data_sources.SecurityTrails.account1]
apikey = YOUR_ST_KEY

[data_sources.VirusTotal]
[data_sources.VirusTotal.account1]
apikey = YOUR_VT_KEY
EOF

amass enum -active -d example.com -config amass_config.ini -o amass_full.txt

# --- subfinder — fast passive subdomain discovery ---
subfinder -d example.com -all -recursive -o subfinder.txt

# --- Combine and deduplicate ---
cat amass_passive.txt subfinder.txt | sort -u > all_subdomains.txt
echo "[+] Total unique subdomains: $(wc -l < all_subdomains.txt)"

# --- Check which subdomains are alive ---
cat all_subdomains.txt | httpx -silent -status-code -title \
  -o alive_subdomains.txt

# --- Certificate Transparency ---
curl -s "https://crt.sh/?q=%.example.com&output=json" | \
  jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u > crt_subs.txt

3. Nmap — Advanced Port Scanning

# --- Host Discovery ---

# Ping sweep — find alive hosts
nmap -sn 10.0.0.0/24 -oG ping_sweep.gnmap
grep "Up" ping_sweep.gnmap | awk '{print $2}' > alive_hosts.txt

# ARP scan (local network only)
nmap -sn -PR 10.0.0.0/24

# --- Port Scanning Techniques ---

# SYN scan (default, stealthy, requires root)
sudo nmap -sS -p- --min-rate 5000 -T4 10.0.0.1 -oA syn_scan

# TCP Connect scan (no root required)
nmap -sT -p 80,443,8080,3306,5432,6379,27017 10.0.0.1

# UDP scan (slow but important)
sudo nmap -sU --top-ports 50 10.0.0.1

# Version detection
nmap -sV --version-intensity 5 -p 22,80,443,3306 10.0.0.1

# OS detection
sudo nmap -O --osscan-guess 10.0.0.1

# --- NSE Scripts ---

# Default scripts
nmap -sC -sV -p 80,443 example.com

# Specific vulnerability scripts
nmap --script vuln -p 80,443 example.com

# HTTP enumeration
nmap --script http-enum,http-headers,http-methods -p 80,443 example.com

# SSL/TLS analysis
nmap --script ssl-enum-ciphers,ssl-cert -p 443 example.com

# SMB enumeration (Windows)
nmap --script smb-enum-shares,smb-vuln-ms17-010 -p 445 10.0.0.1

# --- Comprehensive scan command ---
sudo nmap -sS -sV -sC -O -p- \
  --min-rate 10000 \
  --script "default,vuln,discovery" \
  -oA full_scan \
  10.0.0.1
Nmap Output Formats:
  -oN  normal output (human-readable)
  -oG  grepable output (for scripting)
  -oX  XML output (for tools like searchsploit)
  -oA  all formats at once

Port States:
  open          Service accepting connections
  closed        Accessible but no service listening
  filtered      Firewall blocking — can't determine
  unfiltered    Accessible but open/closed unknown
  open|filtered Can't determine if open or filtered

4. Masscan — High-speed Port Scanner

# Masscan — scan entire internet in 6 minutes (don't do this!)
# Fast scan of large networks
sudo masscan 10.0.0.0/16 -p 80,443,8080,8443 \
  --rate 10000 \
  --output-format json \
  --output-filename masscan_results.json

# Combine with Nmap for accuracy
# Step 1: Fast port discovery with masscan
sudo masscan 10.0.0.0/24 -p 1-65535 --rate 10000 \
  -oG masscan_ports.gnmap

# Step 2: Extract open ports
grep "open" masscan_ports.gnmap | \
  awk '{print $4}' | cut -d/ -f1 | sort -un | \
  tr '\n' ',' > open_ports.txt

# Step 3: Detailed scan with Nmap on discovered ports
nmap -sV -sC -p $(cat open_ports.txt) 10.0.0.0/24 -oA detailed_scan

5. Nuclei — Template-based Vulnerability Scanner

# --- Installation ---
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest

# Update templates
nuclei -update-templates

# --- Basic scanning ---

# Scan single target
nuclei -u https://example.com -o nuclei_results.txt

# Scan with severity filter
nuclei -u https://example.com \
  -severity critical,high \
  -stats \
  -o nuclei_critical.txt

# Scan multiple targets
nuclei -l alive_subdomains.txt \
  -severity critical,high,medium \
  -c 50 \
  -rate-limit 150 \
  -o nuclei_all.txt

# --- Template categories ---

# CVE scanning
nuclei -u https://example.com -t cves/ -severity critical

# Exposure scanning (sensitive files, misconfigs)
nuclei -u https://example.com -t exposures/

# Technology detection
nuclei -u https://example.com -t technologies/

# Misconfiguration scanning
nuclei -u https://example.com -t misconfiguration/

# Default credentials
nuclei -u https://example.com -t default-logins/

# Specific tags
nuclei -u https://example.com -tags sqli,xss,ssrf,lfi
# --- Custom Nuclei Template ---
# custom-templates/api-key-exposure.yaml

id: api-key-in-js

info:
  name: API Key Exposure in JavaScript Files
  author: xdev-pentester
  severity: high
  description: Detects API keys exposed in JavaScript files
  tags: exposure,apikey,javascript

http:
  - method: GET
    path:
      - "{{BaseURL}}/js/app.js"
      - "{{BaseURL}}/static/js/main.js"
      - "{{BaseURL}}/assets/js/config.js"

    matchers-condition: or
    matchers:
      - type: regex
        regex:
          - "(?i)(api[_-]?key|apikey|api_secret)['\"]?\\s*[:=]\\s*['\"][a-zA-Z0-9]{20,}"
          - "(?i)(aws_access_key_id)['\"]?\\s*[:=]\\s*['\"]AKIA[A-Z0-9]{16}"
          - "(?i)(firebase|supabase).*['\"][a-zA-Z0-9]{30,}['\"]"
        part: body

    extractors:
      - type: regex
        regex:
          - "(?i)(api[_-]?key|apikey)['\"]?\\s*[:=]\\s*['\"][^'\"]{20,}['\"]"
        part: body
# custom-templates/auth-bypass.yaml

id: auth-bypass-path-traversal

info:
  name: Authentication Bypass via Path Traversal
  author: xdev-pentester
  severity: critical
  tags: auth-bypass,critical

http:
  - method: GET
    path:
      - "{{BaseURL}}/admin"
      - "{{BaseURL}}//admin"
      - "{{BaseURL}}/./admin"
      - "{{BaseURL}}/admin;/"
      - "{{BaseURL}}/admin/..;/"
      - "{{BaseURL}}/%2f/admin"
      - "{{BaseURL}}/admin%20/"
      - "{{BaseURL}}/admin%09/"

    matchers-condition: and
    matchers:
      - type: status
        status:
          - 200

      - type: word
        words:
          - "dashboard"
          - "admin panel"
          - "management"
        condition: or
        part: body

6. Recon Automation Pipeline

#!/bin/bash
# recon-pipeline.sh — Automated reconnaissance

TARGET=$1
OUTPUT_DIR="./recon/$TARGET"
mkdir -p "$OUTPUT_DIR"/{subdomains,ports,vulns}

echo "[*] Starting recon for $TARGET"

# Phase 1: Subdomain Enumeration
echo "[+] Phase 1: Subdomain enumeration..."
subfinder -d "$TARGET" -all -silent > "$OUTPUT_DIR/subdomains/subfinder.txt"
amass enum -passive -d "$TARGET" -o "$OUTPUT_DIR/subdomains/amass.txt" 2>/dev/null

# Combine and deduplicate
cat "$OUTPUT_DIR"/subdomains/*.txt | sort -u > "$OUTPUT_DIR/subdomains/all.txt"
echo "    Found $(wc -l < "$OUTPUT_DIR/subdomains/all.txt") unique subdomains"

# Phase 2: Alive check
echo "[+] Phase 2: Checking alive hosts..."
cat "$OUTPUT_DIR/subdomains/all.txt" | \
  httpx -silent -status-code -title -tech-detect \
  -o "$OUTPUT_DIR/subdomains/alive.txt"

# Phase 3: Port scanning
echo "[+] Phase 3: Port scanning..."
cat "$OUTPUT_DIR/subdomains/alive.txt" | awk '{print $1}' | \
  while read -r url; do
    host=$(echo "$url" | sed 's|https\?://||' | cut -d/ -f1)
    nmap -sV --top-ports 1000 -T4 "$host" \
      -oN "$OUTPUT_DIR/ports/${host}.txt" 2>/dev/null
  done

# Phase 4: Vulnerability scanning
echo "[+] Phase 4: Nuclei vulnerability scan..."
cat "$OUTPUT_DIR/subdomains/alive.txt" | awk '{print $1}' | \
  nuclei -severity critical,high,medium \
  -c 30 -rate-limit 100 \
  -o "$OUTPUT_DIR/vulns/nuclei.txt"

# Summary
echo ""
echo "========== RECON SUMMARY =========="
echo "Subdomains found: $(wc -l < "$OUTPUT_DIR/subdomains/all.txt")"
echo "Alive hosts:      $(wc -l < "$OUTPUT_DIR/subdomains/alive.txt")"
echo "Vulnerabilities:  $(wc -l < "$OUTPUT_DIR/vulns/nuclei.txt")"
echo "Results saved to: $OUTPUT_DIR"

7. Summary

  • Amass + subfinder: Subdomain enumeration (passive + active)
  • Nmap: Port scanning, service detection, NSE scripts
  • Masscan: High-speed scanning for large networks, combining Nmap
  • Nuclei: Template-based vulnerability scanning, custom templates
  • Automation: Pipeline combines all tools for effective recon

The next lesson will practice Web Application Testing with Burp Suite and OWASP ZAP.