nbtscan是一个可以扫描WINDOWS网络NetBIOS信息的小工具,体积小巧,只能用于局域网,可以显示IP,主机名,用户名称和MAC地址等等。通过nbtscan可以获取PC端真实IP地址和MAC地址,如果有”传奇木马”在做怪,可以找到装有木马的PC的IP/和MAC地址。
软件功能
1、获取电脑的真实IP地址和mac地址。
2、当局域网内有电脑感染病毒木马时,nbtscan能快速找到感染木马的电脑。
3、查看局域网内其他用户的信息。
软件特点
1、体积小巧,安装便捷。
2、界面清爽,操作简单。
3、功能全面。
使用说明
1、将压缩包中的nbtscan.exe和cygwin1.dll解压缩放到c:下,比如:C:WindowsSystem32。
2、在命令提示符中输入:C: btscan -r 192.168.1.1/256(这里需要根据用户实际网段输入)。
3、通过查询IP--MAC对应表,查出“000d870d585f”的病毒主机的IP地址。
使用帮助
输入命令
nbtscan.exe -v
Usage:
nbtscan [-v] [-d] [-e] [-l] [-t timeout] [-b bandwidth] [-r] [-q] [-s separator] [-m retransmits] (-f filename)|()
-v verbose output. Print all names received
from each host
-d dump packets. Print whole packet contents.
-e Format output in /etc/hosts format.
-l Format output in lmhosts format.
Cannot be used with -v, -s or -h options.
-t timeout wait timeout milliseconds for response.
Default 1000.
-b bandwidth Output throttling. Slow down output
so that it uses no more that bandwidth bps.
Useful on slow links, so that ougoing queries
don‘t get dropped.
-r use local port 137 for scans. Win95 boxes
respond to this only.
You need to be root to use this option on Unix.
-q Suppress banners and error messages,
-s separator Script-friendly output. Don’t print
column and record headers, separate fields with separator.
-h Print human-readable names for services.
Can only be used with -v option.
-m retransmits Number of retransmits. Default 0.
-f filename Take IP addresses to scan from file filename.
-f - makes nbtscan take IP addresses from stdin.
what to scan. Can either be single IP
like 192.168.1.1 or
range of addresses in one of two forms:
xxx.xxx.xxx.xxx/xx or xxx.xxx.xxx.xxx-xxx.
Examples:
nbtscan -r 192.168.1.0/24
Scans the whole C-class network.
nbtscan 192.168.1.25-137
Scans a range from 192.168.1.25 to 192.168.1.137
nbtscan -v -s : 192.168.1.0/24
Scans C-class network. Prints results in script-friendly
format using colon as field separator.
Produces output like that:
192.168.0.1:NT_SERVER:00U
192.168.0.1:MY_DOMAIN:00G
192.168.0.1:ADMINISTRATOR:03U
192.168.0.2:OTHER_BOX:00U
。。。
nbtscan -f iplist
Scans IP addresses specified in file iplist.