Security Basics mailing list archives

Re: powerbook with nmap superpowers


From: Geoffrey J Gowey <gjgowey () gmail com>
Date: Thu, 16 Jul 2009 13:27:37 -0700

Not to knock ubuntu (I'm really not trying to start a distro flame war), but they do a lot of weird things to their binaries (and I don't mean that in a good way). The differences won't be noticeable to a normal user, but can bite a developer. I'll suggest one thing to try my hunch: install vmware on it and load another distro (slackware, rhel, CentOS, fedora, etc) then try again.

Sent from my iPhone

On Jul 15, 2009, at 8:14 PM, Jonathan Gallant <blackdog.tasha () gmail com> wrote:

I have a curious problem (feature?) in which my powerbook appears to
have superpowers.
I have a home network with 3 computers, a Windows box running XP home
with a few shares, an Ubuntu Laptop (8.10) and a Mac Powerbook running
10.5.6. I compiled nmap 4.90RC1 on the ubuntu box and installed the
4.90RC1 dmg on the powerbook. I run the following command on both
machines but get different results:
nmap -d -p445 --script=smb-enum-shares XPHOMEBOX

on the powerbook I get:
NSE: SMB: Extended login as \guest failed, but was given guest access
(username may be wrong, or system may only allow guest)
NSE: SMB: Extended login as \<blank> succeeded
Host script results:
|  smb-enum-shares:
|  Anonymous shares:
|     IPC$
|  Restricted shares:
|     Share 1
|     print$
|     Share 2
|_   Share 3

On the ubuntu machine I get:
NSE: SMB: Extended login as \<blank> succeeded
Host script results:
|  smb-enum-shares:
|  ERROR: Couldn't enum all shares, checking for common ones
(NT_STATUS_ACCESS_DENIED)
|  Anonymous shares:
|     IPC$
|  Restricted shares:
|_    PRINT$


So as you can see, the ubuntu machine does not get me nearly as much
info, as I can't see the restricted shares names. In fact Ubuntu gives
an access denied error, and no "Guest access" like I do with the
powerbook. I ran several other tests, including the built nmap 4.76
from ubuntu, which didn't run the smb scripts at all, and I tried
ubuntu version 9, and 8.04. I tried many other smb scripts all with
the result that the powerbook gave me lots of info, but the ubuntu
machine gave me almost nothing.
Any thoughts as to why this might be?

cheers,

J

--- ---------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
--- ---------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: