Host discovery is the process of looking for hosts on a network. This is useful if you gained access to a machine on a private network, and you want to see which other machines are on the network and start to gather a picture of what the network looks like. You can also treat the entire internet as the network and look for certain types of hosts or just look for any hosts at all. Ping sweeps and port scanning are common techniques of identifying hosts. A common tool used for this purpose is nmap. In this chapter, we will cover basic port scanning with a TCP connect scan and banner grabbing, which are two of the most common use cases for nmap. We will also cover raw socket connections that can be used to manually interact and explore a server's ports.
Enumeration is a similar idea, but refers to actively examining a specific machine to determine...