使用 awk 处理 nmap 扫描结果,求出存活主机IP

在使用 nmap 扫描时,得到如下结果:
结果1:
Interesting ports on 172.22.43.23:
PORT   STATE SERVICE
22/tcp open  ssh

Interesting ports on 172.22.43.24:
PORT   STATE SERVICE
22/tcp open  ssh

Interesting ports on 172.22.43.25:
PORT   STATE SERVICE
22/tcp open  ssh

Interesting ports on 172.22.43.250:
PORT   STATE    SERVICE
22/tcp filtered ssh

Interesting ports on 172.22.43.251:
PORT   STATE SERVICE
22/tcp open  ssh

Nmap run completed -- 256 IP addresses (17 hosts up) scanned in 2.375 seconds

要求:如果 扫描 22 端口为 open 则打印 所扫IP地址 (如:172.22.43.251 的 22/tcp 为 open 则打印 这个 IP )

扫描结果2:
Interesting ports on 172.22.43.251:
PORT     STATE  SERVICE
5911/tcp closed unknown
5912/tcp closed unknown
5913/tcp closed unknown
5914/tcp closed unknown
5915/tcp closed unknown
5916/tcp closed unknown
5917/tcp closed unknown
5918/tcp closed unknown
5919/tcp closed unknown
5920/tcp closed unknown

Interesting ports on 172.22.43.252:
PORT     STATE  SERVICE
5911/tcp closed unknown
5912/tcp closed unknown
5913/tcp closed unknown
5914/tcp closed unknown
5915/tcp closed unknown
5916/tcp closed unknown
5917/tcp closed unknown
5918/tcp closed unknown
5919/tcp closed unknown
5920/tcp closed unknown

Interesting ports on 172.22.43.254:
PORT     STATE  SERVICE
5911/tcp closed unknown
5912/tcp open unknown
5913/tcp closed unknown
5914/tcp closed unknown
5915/tcp closed unknown
5916/tcp closed unknown
5917/tcp closed unknown
5918/tcp closed unknown
5919/tcp closed unknown
5920/tcp closed unknown

Nmap run completed -- 256 IP addresses (17 hosts up) scanned in 3.446 seconds

我在扫描 5911-5920 这10个端口时只要有一个端口为open,就打印这个IP地址 (如:172.22.43.254 的 5912/tcp 端口为 open的,就打印 172.22.43.254 这个IP)

不清楚这个 awk 应怎么写,求助 !



 

问题1:

awk 'BEGIN{RS="Interesting ports on";FS="\n";OFS="\n"}{for(j=1;j<=NF;j++){if($j~/open/){print $1;break}}}' data.txt

同意适合问题2

[ 本帖最后由 sunbw001 于 2009-11-24 10:11 编辑 ]



 

第一个
awk -v RS="\n\n" '{if($9=="open") print $4}'

第二个
awk -v RS="\n\n" '{for (i=9;i<=NF;i+=3) if($i=="open") print $4}'



 

awk 'BEGIN {ip="";state="closed"} /Interesting ports on/ {ip=$4} $2=="open" {state="open"} NF==0{if(state=="open") print ip;ip="";state="closed"}'



 

1.   awk '/^Interesting/{sub(/:$/,"",$NF);ip=$NF}$1~/^22/&&$2=="open"{print ip}'
2.   awk '/^Interesting/{T=0;sub(/:$/,"",$NF);ip=$NF}!T&&$2=="open"{print ip;T=1}'
__________________________________
http://ywlscpl.cublog.cn
天上浮云似白衣,斯须改变如苍狗



 

1:
nawk -v RS="\n\n" '$8 ~ /22/ && $9 ~ /open/{sub(/:/,"",$4);print $4}'

2:
nawk -v RS="\n\n" '/ open /{sub(/:/,"",$4);print $4}'



 

楼主要扫ssh 和 vnc services?
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值