Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Nmap Development: Zone Transfer Results

Zone Transfer Results

From: Rob Nicholls <robert_at_everythingeverything.co.uk>
Date: Mon, 28 Jul 2008 12:29:43 +0100

I was testing out SVN 9146 and spotted that the zone-transfer script is
displaying the results in a slightly strange way, different to the behaviour
seen with 4.68. I hope it still makes sense after some obfuscation,
basically the full stops are incorrectly displayed if they're part of a
string (IP addresses appear to be unaffected):

SVN:
| zone-transfer:
| xxxxxx\2co\2uk\0 SOA ns1\15yyyyyy\3net\0
server\15zzzzzz\-64net\0
| xxxxxx\2co\2uk\0 MX xxxxxx\2co\2uk\0
| xxxxxx\2co\2uk\0 NS ns1\15yyyyyy\3net\0
| xxxxxx\2co\2uk\0 NS ns2\-64yyyyyy\3net\0
| xxxxxx\2co\2uk\0 A aa.bb.cc.dd
| ftp\-64xxxxxx\2co\2uk\0 CNAME
| localhost\-64xxxxxx\2co\2uk\0 A 127.0.0.1
| mail\-64xxxxxx\2co\2uk\0 CNAME
| www\-64xxxxxx\2co\2uk\0 CNAME
|_ xxxxxx\2co\2uk\0 SOA ns1\15yyyyyy\3net\0
server\15zzzzzz\-64net\0

4.68:
| zone-transfer:
| xxxxxx.co.uk. SOA ns1.yyyyyy.net. server.zzzzzz.net.
| xxxxxx.co.uk. MX xxxxxx.co.uk.
| xxxxxx.co.uk. NS ns1.yyyyyy.net.
| xxxxxx.co.uk. NS ns2.yyyyyy.net.
| xxxxxx.co.uk. A aa.bb.cc.dd
| ftp.xxxxxx.co.uk. CNAME
| localhost.xxxxxx.co.uk. A 127.0.0.1
| mail.xxxxxx.co.uk. CNAME
| www.xxxxxx.co.uk. CNAME
|_ xxxxxx.co.uk. SOA ns1.yyyyyy.net. server.zzzzzz.net.

It looks like the script itself has barely changed since January, so I
presume something else internally has changed. Does anyone know what's at
fault?

Rob

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org
Received on Jul 28 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]