MYTHOSAI

Tool tutorials / PRACTICAL GUIDE

Check specific ports and service versions with Nmap

Separate basic reachability, version probing and a real application test.

Before you start

An authorised lab host, Nmap and a small approved port list.

Ask a narrow question

If an SSH service should exist on one server, you do not need to scan every address and port first. Define the target and expected service, then test only the relevant path. A version probe sends application-level traffic and deserves more care than a simple listener check.

Check reachability

bash
nmap -sT -n -p 22,443 192.168.50.10

Replace the lab address with your authorised target. If host discovery fails but you have confirmed that this one host is reachable and in scope, you can skip discovery for that target:

bash
nmap -sT -Pn -n -p 22,443 192.168.50.10

The -Pn option does not bypass a firewall. It tells Nmap to attempt the scan without first deciding the host is up through normal discovery.

Add a controlled version query

When the host and service can tolerate it:

bash
nmap -sT -sV --version-light -n -p 22,443 192.168.50.10

Version-light uses a reduced probe intensity. It still interacts with services and can be inconclusive. Avoid fragile equipment or an unreviewed production scope.

Save a useful record

bash
nmap -sT -n -p 22,443 -oA lab-port-check 192.168.50.10

This writes several output formats using the given basename. Store them privately because inventories and version information can be sensitive. Use a new basename or move prior output before another test to avoid confusing runs.

Interpret without overclaiming

A product banner can be hidden, misleading or reflect a distribution package with backported fixes. Do not declare a specific vulnerability from a version string alone. Check the vendor's advisory and the installed package or product build.

Verify the actual service

Use an SSH login or HTTPS request through the intended route. A TCP connection proves less than a successful authenticated application action. Conversely, an application failure can be caused by certificate or account settings even when the port is open.

Common mistakes

The name assigned to a port by Nmap is not identical to a confirmed product version. Local scanning and external scanning see different paths. Scanning all ports with multiple detection features makes results harder to interpret and may disturb services. Keep the smallest scan that answers your operational question.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.