1
0
mirror of https://github.com/nmap/nmap.git synced 2025-12-20 22:49:01 +00:00
Commit Graph

491 Commits

Author SHA1 Message Date
tomsellers
44b7f59523 Add match line for IneoQuest Video Diagnostic device/software HTTP server 2013-03-09 20:56:32 +00:00
tomsellers
9cfdb23f75 Adjustment to Cisco ASA match line to make it match a broader range of versions when scanning the port 80 redirect to https 2013-03-06 03:14:32 +00:00
dmiller
76307e992b Add payload, probe, and matchline for svrloc
Service Location Protocol version 2 specified by RFC 2608. Partially
implemented by srvloc.lua library. Probe checks for
service:service-agent, which should be implemented by all Service Agents
(servers). Match line only matches version 2, since I don't have any
other versions to test. Expect we will get more service fingerprints to
clarify.
2013-03-04 19:06:53 +00:00
tomsellers
5a54ce293b Correct a copy error in a recently added match line at 5931 2013-03-02 14:24:48 +00:00
tomsellers
9b98997c94 Added match line for the SmartPortal on CheckPoint GAiA platform firewalls. Known to work against R75.4x versions.
Changed two existing match lines to softmatches as they were triggering against messages instructing the client to change protocols to SSL.  This was preventing nmap from checking the service on SSL as it though a match was found.  See http://seclists.org/nmap-dev/2013/q1/280
2013-03-02 01:07:53 +00:00
david
2318ff2e70 Remove a too-generic service fingerprint for which we need more data.
It was listed as "Microsoft UPnP", but was also matching a trivial
golang web server.
2013-02-01 20:45:12 +00:00
david
76e68ed6a1 More specific match for TeamSpeak TCPQuery and ServerQuery.
http://seclists.org/nmap-dev/2012/q4/490
2012-12-23 01:13:47 +00:00
david
7dfb56a74a Revert r30053, debian_kfreebsd in service CPE.
Most of these matches are likely to be Linux, not FreeBSD.
2012-11-28 03:47:36 +00:00
david
15b8cdc62d All 11 service corrections. 2012-10-30 04:29:52 +00:00
david
f2b0dc2748 Last 40 service submissions. 2012-10-30 04:29:50 +00:00
david
c52a82356f 100 service submissions. 2012-10-30 04:29:48 +00:00
david
ffd13c0f60 100 service submissions. 2012-10-30 02:37:37 +00:00
david
bd3b79d832 100 service submissions. 2012-10-29 23:52:56 +00:00
david
d1bb2839af 100 service submissions. 2012-10-29 21:33:39 +00:00
david
451cc7184e 100 service submissions. 2012-10-29 19:56:48 +00:00
david
47982a960e 100 service submissions. 2012-10-29 17:58:50 +00:00
david
c0cf25dabd 100 service submissions.
Finally out of the http wasteland.
2012-10-29 03:17:10 +00:00
david
b4dc4f009e 100 service submissions. 2012-10-28 23:36:46 +00:00
david
090cef5b34 100 service submissions. 2012-10-27 18:41:50 +00:00
david
cd9be39e3a 100 service submissions. 2012-10-27 16:34:38 +00:00
david
6739558788 100 service submissions, mostly http. 2012-10-27 05:41:34 +00:00
david
91d40ba8ee Service submissions up through gopher. 2012-10-25 20:25:35 +00:00
david
5fcc3bebd7 Ubuntu-specific Debian-liks service match.
Told to me by Henri; if we see "ubuntu" in the version, we can be more
specific in the CPE, and in particular we know it's not Debian
GNU/kFreeBSD.
2012-10-22 04:27:39 +00:00
david
17766fd7f0 100 service submissions. 2012-10-16 00:39:02 +00:00
david
1fce24f3a3 Add cpe:/o:debian:debian_kfreebsd to most Debian match lines.
Debian can also run on the FreeBSD kernel. I changed o/Linux/ to o/Unix/
and added the debian_kfreebsd CPE to most match lines that mentioned
Debian. I excepted a few that said explicitly "Debian GNU/Linux".
2012-10-15 16:57:14 +00:00
david
719f026891 sv-tidy. 2012-10-14 00:31:14 +00:00
david
4d0c36b88c Add some missing CPE versions where v// was present. 2012-10-13 23:45:06 +00:00
david
3e8cd823ab More nmap-service-probes CPE from Dillon Graham.
http://seclists.org/nmap-dev/2012/q4/92
2012-10-13 23:45:03 +00:00
david
cd90838c2e Change CPE from cpe:/o:linux:kernel to cpe:/o:linux:linux_kernel.
This reflects a deprecation in the official CPE dictionary, which seems
to have happened on 2012-03-08.

  <cpe-item deprecation_date="2012-03-08T20:00:15.120Z" deprecated_by="cpe:/o:linux:linux_kernel:2.6.0" deprecated="true" name="cpe:/o:linux:kernel:2.6.0">
    <title xml:lang="en-US">Linux Kernel 2.6.0</title>
    <meta:item-metadata modification-date="2012-03-08T20:00:15.120Z" status="DRAFT" deprecated-by-nvd-id="35565" nvd-id="91585" />
  </cpe-item>
2012-10-11 06:46:28 +00:00
david
8e0ed1e83e nmap-service-probes CPE for nginx, activesync, antivirus.
http://seclists.org/nmap-dev/2012/q4/57
2012-10-10 17:00:07 +00:00
dmiller
7751a61e82 Fix broken service matches
Discussion: http://seclists.org/nmap-dev/2012/q3/929

Similar situation to http://seclists.org/nmap-dev/2009/q2/75

Fixed by changing .*\n.* to .* (since s modifier was in place)
2012-09-20 19:21:34 +00:00
david
c5d3bf247b Add CPE for Minix services. 2012-08-28 14:30:20 +00:00
david
7fc0f3ee6d Add new matchlines for Sybase Backup. 2012-08-01 17:00:14 +00:00
david
913bbd60a3 sv-tidy. 2012-07-17 18:33:40 +00:00
david
2202781cba Resolve some language i// and cpe:// mismatches. 2012-07-17 18:33:39 +00:00
david
9002e84ff4 Move various product names from i// to p// templates.
Generally, when we know the specific name of a web server, for example,
running on an embedded system, we prefer to list the server itself in
p// and v//, and the hardware in i//, like so:

match m|| p/thttpd/ v/$1/ i/Foobar 2000 ADSL router http config/

But it's very common that match lines instead look like this:

match m|| p/Foobar 2000 ADSL router http config/ i/thttpd $1/

This commit fixes many of these, with assistance from sv-tidy.
2012-07-17 18:33:37 +00:00
david
db594ed246 Fix the few instances of a capture being used in unrelated templates. 2012-07-17 16:19:19 +00:00
david
4f84ae1f13 Reorder character classes so they don't look like ranges.
sv-tidy complains:
8487: can't parse m regex (bad character range): |^HTTP/1\.0 405 Method Not Allowed\r\nServer: Membase Server ([\w-.]+)\r\nPragma:|
8488: can't parse m regex (bad character range): |^HTTP/1\.0 405 Method Not Allowed\r\nServer: Couchbase Server ([\w-.]+)\r\nPragma:|
2012-07-17 15:54:01 +00:00
tomsellers
c87a6b4b0a A change to matchline for Atmail IMAP4 server to make it more flexible when dealing with different capabilities configurations. 2012-07-09 02:05:06 +00:00
tomsellers
22ae4ae108 Added couchbase matchline that does not require a database name. This is useful when the service response is so large that the database info is pushed outside the capture buffer. This was added *after* the matchline that captures the dbname if it is present.
Also added space and a ':' to the database name capture character set to allow for when the database is on a windows server.
2012-07-04 17:09:21 +00:00
tomsellers
17fe702314 Service detection for Couchbase and Membase NoSQL server's web based administrative portal. By default this is on 8091 but can occur on any port. 2012-07-04 14:57:27 +00:00
tomsellers
1c1b257c62 Version detection matchline updates:
Barracuda HTTP filter    - adjustment to match more versions

GlobalScape CuteFTP sshd - additional match line
Cisco ASA WebVPN         - additional match line
VMware View              - additional match line

Bomgar Remote Access     - new product detection
Sybase SQLAnywhere httpd - new product detection, version string
2012-07-03 03:47:41 +00:00
tomsellers
2a8f2f4f0d Update Microsoft Exchange detection string for pop3 and imap to indiciate that the current match string also matches Exchange 2010. 2012-07-02 23:58:41 +00:00
david
6a0771f3b7 Add Metasploit remote API probe and matchline. 2012-06-29 23:21:52 +00:00
david
531dd2348c I'm guessing the dot in the kumo-server match should match '\n'. 2012-06-29 16:35:40 +00:00
david
f1b7b54da2 Get rid of useless trailing .* in matchline. 2012-06-29 16:35:38 +00:00
david
65c4f0f6d7 Capitalization of pcAnywhere. 2012-06-15 16:33:47 +00:00
david
250520ed17 Add CPE for pcanywheredata. 2012-06-15 16:22:24 +00:00
david
afdedbbcbc Oracle OVM Manager is called Oracle VM Manager now. 2012-06-12 14:41:53 +00:00
david
755b3fc959 Put RomPager in p//, not in i//. 2012-05-29 04:48:54 +00:00