patrik
4de3601473
o [NSE] Added script db2-discover into the default category [Patrik Karlsson]
2011-07-10 08:04:52 +00:00
patrik
1feb1bd582
o [NSE] Split script db2-discover into two scripts, adding a new
...
broadcast-db2-discover script. This script attempts to discover DB2
database servers through broadcast requests. [Patrik Karlsson]
2011-07-10 08:01:26 +00:00
paulino
52b7dbac5e
Updates script.db to include http-google-malware:
2011-07-08 23:45:49 +00:00
djalal
7b0b7c3370
Added the ftp-vsftpd-backdoor entry to the script.db file.
2011-07-05 09:19:59 +00:00
paulino
82a68e02db
Adds http-default-accounts - It tests for access with default credentials in a variety of web applications and devices.
...
It works similar to http-enum, we detect applications by matching known paths and launching a login routine using default credentials when found.
This script depends on a fingerprint file containing the target's information: name, category, location paths, default credentials and login routine.
2011-07-01 21:43:34 +00:00
djalal
1c3d400822
o [NSE] Added ftp-vuln-cve2010-4221 script which checks if the ProFTPD
...
server is vulnerable to the Telnet IAC stack overflow CVE-2010-4221
[Djalal].
2011-06-30 22:21:25 +00:00
fyodor
9a2b80c34d
Remove ip-geolocation-quova -- it include an API key which apparently required agreeing to the Quova terms of service to obtain ( http://developer.quova.com/apps/tos ). And those seem to pretty clearly ban this sort of use. So we can only use this script if we get permission from Quova (best option), or we make it so that user is required to pass a key as nsearg
2011-06-29 03:34:47 +00:00
paulino
651197768b
Adds http-barracuda-dir-traversal -
...
Attempts to retrieve the configuration settings from the MySQL database
dump on a Barracuda Networks Spam & Virus Firewall device using the
directory traversal vulnerability in the "locale" parameter of
"/cgi-mod/view_help.cgi" or "/cgi-bin/view_help.cgi".
The web administration interface runs on port 8000 by default.
Barracuda Networks Spam & Virus Firewall <= 4.1.1.021 Remote Configuration Retrieval
Original exploit by ShadowHatesYou <Shadow@SquatThis.net >
For more information, see:
http://seclists.org/fulldisclosure/2010/Oct/119
http://www.exploit-db.com/exploits/15130/
2011-06-28 23:43:34 +00:00
patrik
55da9dc683
added the creds-summary.nse script [Patrik]
2011-06-27 21:21:15 +00:00
paulino
4f60960b29
Adds http-majordomo2-dir-traversal to the repository. This script exploits a directory traversal vulnerability existing in Majordomo2 to retrieve remote files.
2011-06-27 20:22:25 +00:00
djalal
49774ecf10
o [NSE] Added smtp-vuln-cve2010-4344 script that will check and exploit
...
two vulnerabilities in the Exim SMTP Server:
o CVE-2010-4344: A heap overflow vulnerability.
o CVE-2010-4345: A privileges escalation vulnerability.
2011-06-24 15:37:53 +00:00
gorjan
21ece8d864
Update script database for the ip-geolocation scripts
2011-06-20 12:56:34 +00:00
patrik
5558837091
o [NSE] Added two new scripts broadcast-netbios-master-browser and smb-mbenum:
...
- broadcast-netbios-master-browser attempts to discover master browsers in
the broadcast domain
- smb-mbenum lists servers registered with the master browser
[Patrik]
2011-06-19 18:47:19 +00:00
patrik
0a3bf95897
o [NSE] Added a MySQL audit script and a rulebase that supports auditing a
...
subset of the MySQL CIS 1.0.2 Benchmark. [Patrik]
2011-06-17 06:12:01 +00:00
patrik
cf873707cd
o [NSE] Added minimal Service Location Protocol (SLP) library and the script
...
broadcast-novell-locate that detects servers running eDirectory. [Patrik]
2011-06-15 06:23:30 +00:00
fyodor
9f04bd554b
regen the script.db (there was no entry for mac-geolocation)
2011-06-08 06:06:07 +00:00
patrik
873cf47611
o [NSE] Added the Netware Core Protocol (NCP) library and the scripts
...
ncp-serverinfo and ncp-enum-users. [Patrik]
2011-05-28 09:01:31 +00:00
patrik
8b78ccf469
o [NSE] Added ldap-novell-getpass, a script that provides support for
...
retrieving Universal Passwords in plain-text from Novell eDirectory.
[Patrik]
2011-05-28 08:48:26 +00:00
paulino
1e0e438b09
Added http-cakephp-version.nse - NSE script for fingerprinting versions of CakePHP applications.
2011-05-20 09:25:22 +00:00
djalal
edda382a77
Add the smtp-vuln-cve2011-1720 script to the script.db file.
2011-05-19 18:31:34 +00:00
fyodor
20e03044bf
Reran nmap --script-updatedb to catch new categories of smtp-check-vulns script
2011-05-17 17:43:35 +00:00
djalal
c1ba251135
o [NSE] Added smtp-check-vulns, which currently checks for the Postfix
...
SMTP server Cyrus SASL authentication memory corruption (CVE-2011-1720).
2011-05-15 15:57:10 +00:00
djalal
31310f43bc
Add the backorifice-brute script entry to the script.db file
2011-05-14 13:12:18 +00:00
patrik
e8c5640dda
o [NSE] Added a SIP library and two new scripts sip-brute.nse and
...
sip-user-enum.nse providing brute and user enumeration support for the SIP
protocol. [Patrik]
2011-05-09 18:00:52 +00:00
djalal
9e60e88eca
o [NSE] Added broadcast-avahi-dos.nse, which tries to detect if the
...
hosts in the local network that are running Avahi are vulnerable to
the NULL UDP packet denial of service (CVE-2011-1002).
2011-05-02 23:38:18 +00:00
david
b1e8d47fee
Put http-auth in "safe" now that it is not in "default".
2011-04-30 19:23:19 +00:00
david
3ae3339cb7
Make the set of script "default and intrusive" empty.
...
These scripts got removed from default:
dhcp-discover
dns-zone-transfer
These scripts got removed from intrusive:
dns-recursion
ftp-bounce
http-open-proxy
socks-open-proxy
Thanks to Toni for noticing these.
2011-04-30 19:21:38 +00:00
david
6920f6b913
Remove credential guessing from http-auth.nse.
...
This was really lame compared to http-brute, only guessing two
username/password combinations. Also we shouldn't be guessing any
passwords in a default script.
2011-04-30 19:21:36 +00:00
henri
7e2a85cab9
Added the http-wp-plugins script by Ange Gutek.
2011-04-29 07:43:41 +00:00
david
fef214063a
Add omp2-brute and omp2-enum-targets from Henri Doreau.
2011-04-20 23:44:16 +00:00
david
5726c875e9
Add backorifice-info.nse.
2011-04-20 07:45:10 +00:00
patrik
bbbccd4e01
o [NSE] Added the afp-ls script that lists files accessible on remote
...
AFP Volumes. [Patrik]
2011-04-05 08:31:34 +00:00
david
067d7d9660
Put targets-sniffer.nse in "broadcast".
2011-04-05 06:12:00 +00:00
david
aa3a9baac8
Add the targets-sniffer script by Nick Nikolaou.
2011-04-05 06:11:59 +00:00
david
d0ea18119c
Add epmd-info script from Toni Ruottu.
2011-04-04 18:28:33 +00:00
david
f522332a89
Add http-affiliate-id.nse, originally from Hani Benhabiles, then patched
...
by Daniel Miller.
2011-03-31 20:32:50 +00:00
david
477bd66fc9
Merge r22369:22777 from /nmap-exp/david/nmap-nsec. This adds the
...
dns-nsec-enum script, originally by John Bond and improved by him and
me.
Changes in dns.lua:
Add dnssec option to dns.query that adds an OPT RR with the DO (DNSSEC
okay) flag set.
Add answer fetcher for NSEC records (unused currently).
Add decoder for NSEC records.
Add rudimentary handling of the additional section in dns.encode.
Add a check that a decoder exists before trying to call it.
Also added a copy of the simplified BSD license that the new script is
under.
2011-03-27 04:24:43 +00:00
david
ae11175ad8
Put ssl-known-key in {"safe", "discovery", "vuln"} (was {"discovery"}).
2011-03-22 19:44:46 +00:00
david
47557a108b
o [NSE] Added ssl-known-key.nse, which checks SSL certificates against a
...
list of certificates with known keys that have been extracted from
firmware files. [Mak Kolybabi]
2011-03-22 19:44:40 +00:00
patrik
4528f52188
Deleted the ms-sql-discover script per the following discussion:
...
http://seclists.org/nmap-dev/2011/q1/725 [Patrik]
2011-03-19 20:09:43 +00:00
fyodor
e896e27e8a
Put rpcinfo in the default category and also improve the NSEDoc documentation for it slightly
2011-03-19 08:06:34 +00:00
david
a3ec901899
Add nping-brute.nse from Toni Ruottu.
2011-03-13 02:02:27 +00:00
david
3fe40dd995
Add dns-brute.nse.
2011-03-05 21:15:58 +00:00
david
987d5f19a4
--script-updatedb.
2011-03-05 21:05:28 +00:00
david
bb4a4203a5
Add ovs-agent-version.nse, a script to detect the ovs-agent service for
...
which existing single probes are ambiguous.
2011-03-02 07:39:31 +00:00
patrik
d6bbc6da8f
o [NSE] Added probe for Apple iPhoto (DPAP) and the dpap-brute script that
...
performs password guessing against a shared iPhoto library. [Patrik]
2011-02-26 16:24:54 +00:00
david
e5717f259a
Add quake3-master-getservers from Toni Ruottu. Move the
...
quake3-master-protocols data file inside of
quake3-master-getservers.nse.
2011-02-22 21:55:23 +00:00
patrik
e50d65755b
* Add a new script snmp-ios-config that pulls the config from a Cisco devices
...
using SNMP and tftp. The script was created by Vikas Singhal.
* Add tftp library, used by the snmp-ios-config script, that acts as a server
and receives the config file from the device. [Patrik]
2011-02-22 09:13:03 +00:00
david
181951a2c6
Move db2-discover out of "discovery" and into "safe", like the other
...
scripts that behave like it does.
2011-01-24 07:22:07 +00:00
fyodor
f037a54cd7
Update Nmap version number to 5.36TEST4 in prep for the next release in a day or two and regenerate relevant files
2011-01-20 10:29:18 +00:00