1
0
mirror of https://github.com/nmap/nmap.git synced 2025-12-22 07:29:01 +00:00
Commit Graph

466 Commits

Author SHA1 Message Date
fyodor
c993172b87 Cyrus POP3 v2.3.12 through v2.3.13 have an extra space before the hostname. - signature update by Matt Selsky 2009-11-30 22:53:40 +00:00
fyodor
f0d8b0b702 Improve a couple Polycom SoundStation sip match lines - patch by Matt Selsky 2009-11-30 06:10:37 +00:00
david
a4c2e4fc9b Add a UDP SIPOptions service probe. 2009-11-26 01:52:13 +00:00
david
7f21296ec2 Adjust the Citrix MetaFrame (icabrowser) match line. The final two bytes
were part of an IP address (\xc0\xa8 = 192.168) and could vary in
different environments.
2009-11-25 20:40:48 +00:00
david
d1d910f13e Add a Citrix MetaFrame (icabrowser) service probe from Thomas Buchanan. 2009-11-24 17:28:21 +00:00
fyodor
8c6093581f Applied a patch from Matt Selsky which improves Oracle TNS Listener signature 2009-11-18 08:59:08 +00:00
tomsellers
3432ae3ad5 Updated DB2 port ranges to be broader in order to improve detection of the database instances that typically live in the 50000-50025 and 60000-60025 range. [Tom] 2009-11-11 13:45:57 +00:00
fyodor
1b767b9cbc Add Oracle Enterprise Manager Agent version detection signature (and added it to the ports list). Patch by Matt Selsky 2009-10-10 00:27:14 +00:00
david
c7fccb4d0c Implement the proposed changes from docs/device-types.txt to being the
device types in nmap-os-db and nmap-service-probes in line with that
document.
2009-08-28 23:52:41 +00:00
david
ceb10ffe29 Add an extra blank line to nmap-service-probes for uniformity. 2009-08-27 20:43:09 +00:00
david
f6d8d8b290 Add an HP Printer Job Language version probe from Brandon Enright. It is
inactive at the moment because its ports 9100-9107 are in the default
Exclude list. (In fact, they are the default exclude list.) Users will
have to comment out the Exclude line to test these.
2009-08-27 20:37:15 +00:00
david
f6463017db Add a service probe for DNS-based service discovery (DNS-SD). See
http://seclists.org/nmap-dev/2009/q3/0610.html.
2009-08-18 19:00:59 +00:00
david
fae45d2c3c Remove the last byte from the end of the xdmcp version probe. According
to the XDMCP specification at
http://cgit.freedesktop.org/xorg/doc/xorg-docs/plain/hardcopy/XDMCP/xdmcp.PS.gz,
it's just a junk trailer following the zero-length array of
authentication names, and that "no padding of any sort will occur within
the packets." It still correctly identifies an xdm running locally in my
testing.

The specification also says "Packets that have too little or too much
data should be ignored," but that must not be taken seiously because the
X server that comes with Mac OS X sends several junk null bytes at the
end of its XDMCP queries.
2009-08-14 16:56:05 +00:00
fyodor
a678608afd add probe for Apache JServ Protocol (AJP) and a match line for Apache Jserv 1.3 from Tom Sellers 2009-07-07 06:42:03 +00:00
fyodor
97f3bb4502 added Traffic Spicer ICAP signature by Tom Sellers 2009-07-07 06:38:49 +00:00
bmenrigh
f20150351e Added and improved Famatech Radmin service matches/softmatch to better
support various 3.X releases.  Also added a match for Radmin when the
source IP is ACL'd.  Thanks to Tom Sellers for the hard work and
providing a patch!
2009-06-12 22:01:31 +00:00
bmenrigh
0c937eec65 Updated the slow ser2net match that we had with the original
fingerprint submission.  The service was telnet and so the protocol
has been changed to telnet and ser2net has been put into the product
field.
2009-06-09 20:09:09 +00:00
bmenrigh
635f464a7c I updated our 5 slowest match lines with slightly more efficient
matching strategies.  It is really great that we have so few match
lines that really need any performance attention.  As long as a match
has an anchor (though ^ seems better than $ with PRCE) it should be
fast enough.  We also want to avoid things like
"m|^whatever.*something.*" but we got rid of all of those in a
previous review.

The only "bad" match we have now is:

match ser2net m|\r\nser2net port \d+ device (/dev/[-\w_]+) ...snip...

I think this match should be commented out so that we can get a better
submission.  With a big release coming up so soon though I don't want
to remove any useful features.  I've left a comment about it's
performance and maybe myself, Doug, or somebody else will think about
the match more at a later date.
2009-06-09 00:00:51 +00:00
david
753679d84c Enhance the ncat-chat service match line so it works with IPv6 addresses
(ncat --chat -l -6).
2009-05-26 21:49:36 +00:00
david
7184ce9646 Add an nmap-service-probes match for ncat --chat. 2009-05-26 21:39:46 +00:00
fyodor
a420fe3d4f o Improved the Oracle DB version detection signatures. [Tom Sellers] 2009-05-14 04:32:50 +00:00
bmenrigh
3164ea7a20 I ran into a case where Hummingbird Exceed X11 reported slightly
different bytes in a few X11 fields.  I've made the match more
generic.  I have a feeling that the X11 fields might contain useful
information that we could include in i// but I don't know enough about
X11 to do that myself.
2009-04-14 22:06:31 +00:00
bmenrigh
ae9def6d85 Handled all of our stray uses of .*\r\n.* and variations like .*\n.*\n
by collapsing them to a single .* and making sure that the DOTALL
(PCRE s modifier) is set on the match.  This should dramatically cut
down on cases where MATCHLIMIT is returned.  See
http://seclists.org/nmap-dev/2009/q2/0086.html for a discussion.  I
chose to only use .* in this patch even though .*? will be faster in
some cases.  I felt the speed benefit of .*? did not outweigh the
relative obscurity of lazy quantifiers.  I have some ideas on how
audit matches for performance and some ideas on optimizations that can
be done.  .*? and friends will have wait.
2009-04-07 21:51:36 +00:00
bmenrigh
c01e0c56e3 Added match by Tom Sellers for Service Pack 3 of Microsoft SQL Server 2005. 2009-04-03 00:15:38 +00:00
david
8fef386595 Add a new generic match line for SSLv3-only servers to
nmap-service-probes. This replaces an incomplete set of specific match
lines, though a few of those have been retained where they might give
information on the OS or SSL implementation. There is also a new probe
that works against SSLv2-only servers. The patch is from Kristof
Boeynaems.
2009-03-31 16:14:14 +00:00
fyodor
c2fc8af1ba Add the MochiWeb Erlang HTTP library 2009-03-10 05:53:57 +00:00
fyodor
83b83ee36c comment out idps signature for now, since Brandon and Tom are still figuring out the best way to do this 2009-02-27 04:40:21 +00:00
fyodor
9a5ce9bfcc A few version detection sigs contributed by Tom Sellers 2009-02-27 04:35:30 +00:00
doug
190f7ff6c4 Oops. Should have used a different character from =. # might
be OK but I usually don't use cause I was scared of interference
from comment character #.

Ended up using %
2009-02-26 01:50:56 +00:00
doug
994317f13d Fix for assertion failure problem. Thanks to Brandon and David for finding this. 2009-02-26 01:45:02 +00:00
david
209601b44a Device type canonicalization. Put some videoconferencing system is "webcam",
not "telecom-misc". Put some temperature sensors in "specialized".
2009-02-25 23:34:37 +00:00
doug
85f4cb66e2 Fixed issue with RPM Print Manager match line 2009-02-25 01:44:41 +00:00
david
1273142341 FIx a typo in nmap-service-probes, adjust some categorizations in nmap-os-db. 2009-02-21 00:34:33 +00:00
david
1ca5e5b637 Canonicalize a device type in nmap-service-probes: "media-device" ->
"media device".
2009-02-20 19:36:49 +00:00
doug
531e2b7c22 MSSQL updates from Tom Sellers 2009-02-20 01:33:55 +00:00
doug
e13283b01e Finished nmapsubmit-svfp-020309.mbx 2009-02-19 22:17:24 +00:00
doug
e087884f2c Another batch of misc from nmapsubmit-svfp-020309.mbx (almost done) 2009-02-18 23:57:43 +00:00
doug
7b862ddd1e Another batch of misc from nmapsubmit-svfp-020309.mbx (hah - gopher) 2009-02-16 22:27:30 +00:00
doug
91129a3830 Lots more misc services from nmapsubmit-svfp-020309.mbx 2009-02-15 03:00:02 +00:00
doug
bae386daa4 * Lots of misc fingerprints from nmapsubmit-svfp-020309.mbx
* Update to socks5 probe. Big thanks to Brandon for letting me test his machines!
2009-02-14 21:31:36 +00:00
doug
7d6ead8b39 Last of the HTTP fingerprints from nmapsubmit-svfp-020309.mbx. 710 out of 1746 remaining FPs 2009-02-12 21:13:29 +00:00
doug
e47bff465c Some more http from nmapsubmit-svfp-020309.mbx 2009-02-11 22:32:47 +00:00
doug
0ccb796e34 * Another batch of HTTP from nmapsubmit-svfp-020309.mbx (almost 2/3 done the HTTP ones now)
* Found and deleted/fixed a few garbage http match lines
2009-02-10 18:03:08 +00:00
doug
bc378dc626 * Another batch of HTTP from nmapsubmit-svfp-020309.mbx
* Moved lighttpd match lines from HTTPOptions to GetRequest (HTTPOptions falls back to GetRequest).
2009-02-10 06:45:32 +00:00
doug
06f5b7e8db Next batch of HTTP fingerprints from nmapsubmit-svfp-020309.mbx 2009-02-08 20:30:41 +00:00
doug
8d75390c9b First batch of http/http-proxy submissions from nmapsubmit-svfp-020309.mbx 2009-02-07 03:35:31 +00:00
doug
1491180c50 IRC, SIP and jabber from nmapsubmit-svfp-020309.mbx 2009-02-06 03:41:17 +00:00
doug
e73920016e * Remaining telnet submissions from nmapsubmit-svfp-020309.mbx
* Normalized cable modem match lines to be "broadband router" not "router"
2009-02-06 02:35:18 +00:00
doug
cedc80699d About 2/3 of the telnet match lines from nmapsubmit-svfp-020309.mbx 2009-02-05 22:53:27 +00:00
doug
7a1470fde5 * SQL submissions from nmapsubmit-svfp-020309.mbx
* Refined PostgreSQL and MySQL match lines
2009-02-05 03:04:35 +00:00