Thread: nmap list scan

    nmap list scan

    Hello everyone, sorry to post this here but I couldn't find any nmap-only forums.

    I need to scan an entire internal network for hostnames, no need to know if they're up, after some research I found that nmap list scan (sL) that only does a reverse DNS lookup would be the "softest" aproach, rather than just ping shooting everything. My question is how stealthy is in fact this type of scan? It does send packets, so would this kind of traffic raise some IDS flags up coming from a single machine, or because it's not even a "scan" per se no one bats an eye?

    I think that would very much depend on how your IDS is configured. I'd suggest running the scan in a lab with wireshark and analyse the packets which are sent/received. Then you can make a judgement on how that may effect your IDS.
    If it smells like a duck, walks like a duck and quacks like a duck; then it probably is a duck.

    Great idea, thank you, nothing better than to see it with my own eyes.

    nmap -sP will scan from to but i want to scan the network from to
    what is the command for that

    in cidr it's nmap -sn but you can also use ranges like 10.10.0-255.0-255

    about the first post, -sL option sends reverse DNS requests for the ip's in list and then simply lists your targets, no other packets are sent, if you also specify -n flag then it won't send any packet. just keep in mind there's no scan at all when using this option it just lists your targets.
    Last edited by jnpa; 2015-02-12 at 20:12.

    regarding NMAP i have a query
    how to scan a windows machine who's printing and sharing is not enable
    plz reply with syntax.... thanks in advance

