Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Nmap Development: Re: Nmap Fingerprint Submitter - Broken?

Re: Nmap Fingerprint Submitter - Broken?

From: Fyodor <fyodor_at_insecure.org>
Date: Thu, 20 Dec 2007 19:25:11 -0800

On Sat, Dec 15, 2007 at 09:13:23PM -0000, Rob Nicholls wrote:
>
> I see the fingerprint because I normally run nmap with -vv (NB: the osdetect
> page David mentioned says "Unless you force them by enabling debugging (-d),
> G=N fingerprints aren't printed by Nmap." which is incorrect as I'm not
> using -d);

I've updated the page in SVN to note that -vv does it too.

> try and paste it into the online submitter. Perhaps the JavaScript could
> read the first line to make sure it says "%G=Y" and display a different
> warning instead? That might stop bad submissions from anyone still using

Good idea. Doug has implemented this and it is now live on the site.

> Also, http://insecure.org/nmap/man/man-output.html says for verbosity "Using
> it more than twice has no effect." but that can't be right? Using -vvv will
> add the "DNS resolution of 1 IPs took 0.14s. Mode: Async [#: 3, OK: 0, NX:

Good point, I've changed the document in SVN (not reflected on web site yet).

Cheers,
-F

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org
Received on Dec 20 2007

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos