>большое спасибо за ответ.
да собственно не за что, самому стало интересно.... после полдкрутки парочки параметров и использования последней версии nmap получил
nmap -O -P0 172.16.0.1
Starting nmap 3.93 ( http://www.insecure.org/nmap/ ) at 2005-10-11 16:08 YEKST
Warning: OS detection will be MUCH less reliable because we did not find at least 1 open and 1 closed TCP port
Interesting ports on 172.16.0.1:
(The 1666 ports scanned but not shown below are in state: filtered)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
MAC Address: 00:0C:29:F1:66:66
Device type: general purpose
Running (JUST GUESSING) : FreeBSD 5.X (96%), Linux 2.4.X (90%), OpenBSD 3.X (90%), Apple Mac OS 8.X (89%), Novell NetWare 3.X|4.X|5.X (87%), Sun Solaris 2.X|7 (86%), IBM AIX 5.X (86%)
Aggressive OS guesses: FreeBSD 5.3-STABLE (96%), FreeBSD 5.2.1 (SPARC) (92%), FreeBSD 5.2 - 5.4 (92%), FreeBSD 5.3-RELEASE (90%), Linux 2.4.23-grsec w/o timestamps (90%), OpenBSD 3.2 (x86) (90%), FreeBSD 5.4-RELEASE (89%), Apple Mac OS 8.1 (89%), Linux 2.4.27 with grsec (88%), FreeBSD 5.3 (87%)
No exact OS matches for host (test conditions non-ideal).
Nmap finished: 1 IP address (1 host up) scanned in 31.737 seconds
|