我尝试使用 扫描我的家庭网络nmap
,进行192.168.0.0/16
netscan。令我惊讶的是,结果显示多个实时设备不仅在 192.168.1.x
(我们所有已知设备所在的位置)而且在192.168.2.x
!
设置:
- Ubuntu 11.10
- 地图 5.21
- 私人网络上的家庭 wifi 连接 (192.168.1.x)
- 无线路由器设置在 192.168.1.1 / 255.255.255.0
- 启用 DHCP
- 仅连接到我们自己的安全 wifi 网络
- 我们所有的设备和计算机都在 192.168.1.x 网络上
- 路由器日志不显示任何 192.168.2.x IP(DHCP 租约和 wifi 日志仅显示我们的设备 IP)
nmap 结果子集:
$ nmap 192.168.2.0/24
Starting Nmap 5.21 ( http://nmap.org ) at 2012-07-05 21:30 CEST
Nmap scan report for 192.168.2.1
Host is up (0.045s latency).
All 1000 scanned ports on 192.168.2.1 are closed
Nmap scan report for 192.168.2.3
Host is up (0.048s latency).
Not shown: 999 closed ports
PORT STATE SERVICE
23/tcp open telnet
Nmap scan report for 192.168.2.69
Host is up (0.045s latency).
Not shown: 993 closed ports
PORT STATE SERVICE
80/tcp open http
111/tcp open rpcbind
139/tcp open netbios-ssn
443/tcp open https
445/tcp open microsoft-ds
631/tcp open ipp
2049/tcp open nfs
Nmap scan report for 192.168.2.77
Host is up (0.067s latency).
Not shown: 999 closed ports
PORT STATE SERVICE
80/tcp open http
Nmap scan report for 192.168.2.78
Host is up (0.044s latency).
Not shown: 999 closed ports
PORT STATE SERVICE
80/tcp open http
Nmap scan report for 192.168.2.80
Host is up (0.012s latency).
Not shown: 841 closed ports, 149 filtered ports
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
23/tcp open telnet
37/tcp open time
80/tcp open http
2000/tcp open cisco-sccp
5003/tcp open filemaker
5004/tcp open unknown
32769/tcp open unknown
32770/tcp open sometimes-rpc3
Nmap scan report for 192.168.2.84
Host is up (0.043s latency).
Not shown: 843 closed ports, 149 filtered ports
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
23/tcp open telnet
37/tcp open time
80/tcp open http
5003/tcp open filemaker
5004/tcp open unknown
32769/tcp open unknown
Nmap scan report for 192.168.2.89
Host is up (0.014s latency).
Not shown: 999 filtered ports
PORT STATE SERVICE
80/tcp open http
Nmap scan report for 192.168.2.90
Host is up (0.063s latency).
Not shown: 993 closed ports
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
23/tcp open telnet
80/tcp open http
111/tcp open rpcbind
6000/tcp open X11
8088/tcp open unknown
...
以下是一些 telnet 响应:
$ telnet 192.168.2.80
Trying 192.168.2.80...
Connected to 192.168.2.80.
Escape character is '^]'.
Linux 2.6.10-mV01-00-54 (localhost.localdomain) (0)
dcm login:
和
$ telnet 192.168.2.90
Trying 192.168.2.90...
Connected to 192.168.2.90.
Escape character is '^]'.
Welcome to Appear TV Embedded Software Environment
dvbs2 login:
看起来像网络设备、数字电视等,但这些都没有连接到我们的路由器!有谁知道这怎么可能?
编辑:nmap --traceroute
在这种情况下不知何故不起作用,但traceroute
确实返回了一些有趣的结果:
$ nmap --traceroute 192.168.2.90
Starting Nmap 5.21 ( http://nmap.org ) at 2012-07-07 14:48 CEST
Warning: Traceroute does not support idle or connect scan, disabling...
Nmap scan report for 192.168.2.90...
$ traceroute 192.168.2.69
traceroute to 192.168.2.69 (192.168.2.69), 30 hops max, 60 byte packets
1 RT-G32 (192.168.1.1) 1.240 ms 1.375 ms 1.589 ms
2 10.17.64.1 (10.17.64.1) 10.396 ms 10.400 ms 10.372 ms
3 192.168.100.13 (192.168.100.13) 14.912 ms 16.572 ms 16.487 ms
4 192.168.2.69 (192.168.2.69) 13.146 ms 13.127 ms 14.658 ms
$ traceroute 192.168.2.90
traceroute to 192.168.2.90 (192.168.2.90), 30 hops max, 60 byte packets
1 RT-G32 (192.168.1.1) 1.466 ms 1.418 ms 1.551 ms
2 10.17.64.1 (10.17.64.1) 11.025 ms 11.005 ms 10.975 ms
3 192.168.100.13 (192.168.100.13) 10.958 ms 15.729 ms 15.715 ms
4 192.168.2.90 (192.168.2.90) 15.640 ms 15.561 ms 15.532 ms
我很困惑我怎么有一个链接10.17.64.1
?RFC1918 中究竟在哪里引用了这个问题?