Nmap Development mailing list archives

Re: Using Samba code?


From: Ron <ron () skullsecurity net>
Date: Sun, 28 Sep 2008 00:43:56 -0500

Fyodor wrote:
On Sat, Sep 27, 2008 at 11:28:44PM -0500, Ron wrote:

I think 'svn up' is very easy and effective.  That's what I do every
morning.  It gets you all the new scripts, and you don't even need to
rebuild Nmap unless there was an important code change (I almost
always do just to be on the safe side since it only takes a couple
minutes).
Yeah, I've been doing the same thing since I started writing scripts,
but that's not quite what I was talking about (read on)

Of course this doesn't help so much for (hypothetical) 3rd party
script repositories.  An NSE script could be written which contacts
other repositories and downloads the latest scripts.  There are also
the nmap-exp branches, such as Sven's, where developers can host their
latest scripts before they are merged.

We have OpenSSL to help verify that the scripts were not compromised
during download, but that doesn't stop a rogue repository operator
from including a trojan script.  Which would be dangerous, since NSE
scripts are not sandboxed.  So you certainly need to be very careful
about what scripts you run.
I was thinking more along the lines of a "script feed", where a user can
subscribe to their favourite script repositories and automatically
update their scripts from various sources.

Sort of like the idea of Nessus feeds, where if I don't want to be bound
by Nessus's agreement, I can subscribe to other feeds like OpenVAS.

Maybe it's as simple as a shellscript that can read a config file and
point to different download locations. *shrug* just thinking out loud. :)


Cheers,
-F

Ron

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org


Current thread: