Nmap Development mailing list archives

Re: More Service Detection notes: HTTP, FTP, DNS, etc


From: Fyodor <fyodor () insecure org>
Date: Fri, 19 May 2006 14:35:49 -0700

On Mon, May 08, 2006 at 11:14:08PM -0700, Fyodor wrote:
The next question is what the text string should be.
/0wned/by/Nmap.txt would be amusing for a few hours until I get
flooded by hate mail from admins who don't know what is going on and
think I hacked their server :).  A short non-threatening message like
"/nice/ports" or "/Trinity/was/here" might be OK :).  Though I suppose
a more practical string might be something hard to Google yet unlikely
to exist ("/pear") or inconspicuous (/robot.txt or /robots.text
instead of the real /robots.txt).

Actually, we may want to include some escaped characters as the way
the 404 page returns them may give more details as to the service.

Maybe "GET /nice%20ports%2C/Tri%6Eity.txt%2ebak HTTP/1.0\r\n\r\n"

Cheers,
-F



_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev


Current thread: