1
0
mirror of https://github.com/nmap/nmap.git synced 2026-01-26 08:09:07 +00:00

o Renamed irc-zombie.nse to auth-spoof and improved its description

and output a bit. [Fyodor]
This commit is contained in:
fyodor
2008-11-06 21:58:29 +00:00
parent cfb9678a60
commit c73dfd173a
2 changed files with 9 additions and 4 deletions

30
scripts/auth-spoof.nse Normal file
View File

@@ -0,0 +1,30 @@
description = [[
Checks for an identd (auth) server which is spoofing its replies.
Tests whether an identd (auth) server responds with an answer before
we even send the query. This sort of identd spoofing can be a sign of
malware infection though it can also be used for legitimate privacy
reasons.
]]
author = "Diman Todorov <diman.todorov@gmail.com>"
license = "Same as Nmap--See http://nmap.org/book/man-legal.html"
categories = {"malware"}
require "comm"
require "shortport"
portrule = shortport.port_or_service(113, "auth")
action = function(host, port)
local status, owner = comm.get_banner(host, port, {lines=1})
if not status then
return
end
return "Spoofed reply: " .. owner
end