Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Nmap Development: Re: Nmap Redundancy and Script Question

Re: Nmap Redundancy and Script Question

From: Fyodor <fyodor_at_insecure.org>
Date: Thu, 29 Nov 2007 14:01:06 -0800

On Wed, Nov 28, 2007 at 09:45:04PM -0600, Alan Jones wrote:
>
>
> Then the inside "\mswin32\" there are the following directories
> (excluding files):

Hi Alan. Thanks for the report. It turns out that the NSIS "File"
directive has an annoying (but at least documented) side effect when
you specify /r option. I have tested and checked in a fix to Nmap.nsi
which should resolve this for the next release.

> Also inside the \nmap\scripts\ directory is a directory called .svn with
> the following files/directories and stuff in the directories.

I have also checked in a fix for this.

> Also in the 4.23RC3 release notes it was mentioned that promiscuous.nse
> was in the "demo category" for now. In looking at the NSE Usage
> http://insecure.org/nmap/nse/nse-usage.html I did not see a demo
> category listed.
>
> When I checked the script itself it was said it was in the discovery
> category. What am I missing?

I guess discovery is a good category for it, since that is not done by
default. I just didn't want to make it a default script this close to
the stable release. I've updated the CHANGELOG.

We really need to revisit the NSE category names (though any major
changes would be after the stable release).

> What is the easiest way if you want to run "all" scripts?
>
> I see an option -sC equivalent to --script=safe,intrusive. Is there a
> -sA for all scripts or do you just do -script <directory>?

Script <directory> sounds like a good idea. I think we should make a
convenience option for this as well (e.g. -sC all).

Cheers,
Fyodor

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org
Received on Nov 29 2007

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]