Script ssl-cert-intaddr

Script types: portrule
Categories: vuln, discovery, safe

Script Summary

Reports any private (RFC1918) IPv4 addresses found in the various fields of an SSL service's certificate. These will only be reported if the target address itself is not private. Nmap v7.30 or later is required.

See also:

Script Arguments


See the documentation for the tls library.

smbdomain, smbhash, smbnoguest, smbpassword, smbtype, smbusername

See the documentation for the smbauth library.


See the documentation for the smtp library.

randomseed, smbbasic, smbport, smbsign

See the documentation for the smb library.

mssql.domain, mssql.instance-all, mssql.instance-name, mssql.instance-port, mssql.password, mssql.protocol, mssql.scanned-ports-only, mssql.timeout, mssql.username

See the documentation for the mssql library.

Example Usage

nmap -p 443 --script ssl-cert-intaddr <target>

Script Output

443/tcp open  https
| ssl-cert-intaddr:
|   Subject commonName:
|   Subject organizationName:
|   Issuer emailAddress:
|   X509v3 Subject Alternative Name:



  • Steve Benson

License: Same as Nmap--See