From 1538e21724cb20e9914232684f0d948079041f06 Mon Sep 17 00:00:00 2001 From: david Date: Wed, 27 May 2009 18:21:28 +0000 Subject: [PATCH] There is a new default ping probe set: -PE -PS443 -PA80 -PP. In exhaustive testing of 90 different probes, this one emerged as the best four-probe combination, finding 14% more Internet hosts than the previous default, -PE -PA80. The default for nonroot users is -PS80,443, replacing the previous default of -PS80. In addition, ping probes are now sent in order of effectiveness (-PE first) so that less likely probes may not have to be sent. --- CHANGELOG | 8 ++++++++ nmap.cc | 15 +++++++++++---- nmap.h | 20 ++++++++++++++----- scan_engine.cc | 52 +++++++++++++++++++++++++++++--------------------- 4 files changed, 64 insertions(+), 31 deletions(-) diff --git a/CHANGELOG b/CHANGELOG index bcdd2d68b..74ce69d50 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -1,5 +1,13 @@ # Nmap Changelog ($Id$); -*-text-*- +o There is a new default ping probe set: -PE -PS443 -PA80 -PP. In + exhaustive testing of 90 different probes, this one emerged as the + best four-probe combination, finding 14% more Internet hosts than + the previous default, -PE -PA80. The default for nonroot users is + -PS80,443, replacing the previous default of -PS80. In addition, + ping probes are now sent in order of effectiveness (-PE first) so + that less likely probes may not have to be sent. [David/Fyodor] + o [Zenmap] Fixed a crash, introduced in 4.85BETA4, that happened when searching scan results by date. [David] The error message was File "zenmapGUI\SearchGUI.pyo", line 816, in set_date diff --git a/nmap.cc b/nmap.cc index 5804e0c8d..26e4e45e6 100644 --- a/nmap.cc +++ b/nmap.cc @@ -450,10 +450,17 @@ static char *grab_next_host_spec(FILE *inputfd, int argc, char **fakeargv) { void validate_scan_lists(scan_lists &ports, NmapOps &o){ if (o.pingtype == PINGTYPE_UNKNOWN) { - if (o.isr00t && o.pf() == PF_INET) o.pingtype = DEFAULT_PING_TYPES; - else o.pingtype = PINGTYPE_TCP; // if nonr00t or IPv6 - getpts_simple(DEFAULT_TCP_PROBE_PORT_SPEC, SCAN_TCP_PORT, &ports.ack_ping_ports, &ports.ack_ping_count); - assert(ports.ack_ping_count > 0); + if (o.isr00t && o.pf() == PF_INET) { + o.pingtype = DEFAULT_PING_TYPES; + getpts_simple(DEFAULT_PING_ACK_PORT_SPEC, SCAN_TCP_PORT, + &ports.ack_ping_ports, &ports.ack_ping_count); + getpts_simple(DEFAULT_PING_SYN_PORT_SPEC, SCAN_TCP_PORT, + &ports.syn_ping_ports, &ports.syn_ping_count); + } else { + o.pingtype = PINGTYPE_TCP; // if nonr00t or IPv6 + getpts_simple(DEFAULT_PING_CONNECT_PORT_SPEC, SCAN_TCP_PORT, + &ports.syn_ping_ports, &ports.syn_ping_count); + } } if ((o.pingtype & PINGTYPE_TCP) && (!o.isr00t || o.pf() != PF_INET)) { diff --git a/nmap.h b/nmap.h index 78936c82e..912d6fb15 100644 --- a/nmap.h +++ b/nmap.h @@ -266,12 +266,11 @@ void *realloc(); #define MAX_TIMEOUTS MAX_SOCKETS /* How many timed out connection attempts in a row before we decide the host is dead? */ -#define DEFAULT_TCP_PROBE_PORT_SPEC "80" /* The ports TCP probes go to if +#define DEFAULT_TCP_PROBE_PORT_SPEC "80" /* The ports TCP ping probes go to if unspecified by user -- uber hackers change this to 113 */ -#define DEFAULT_UDP_PROBE_PORT_SPEC "31338" /* The port UDP probes (esp. "ping" - probes) go to if unspecified by - user */ +#define DEFAULT_UDP_PROBE_PORT_SPEC "31338" /* The port UDP ping probes go to + if unspecified by user */ #define DEFAULT_PROTO_PROBE_PORT_SPEC "1,2,4" /* The IPProto ping probes to use if unspecified by user */ @@ -341,7 +340,18 @@ void *realloc(); #define PINGTYPE_ARP 1024 #define PINGTYPE_PROTO 2048 -#define DEFAULT_PING_TYPES PINGTYPE_TCP|PINGTYPE_TCP_USE_ACK|PINGTYPE_ICMP_PING +/* Empirically determined optimum combinations of different numbers of probes: + -PE + -PE -PA80 + -PE -PA80 -PS443 + -PE -PA80 -PS443 -PP + -PE -PA80 -PS443 -PP -PU40125 + We use the four-probe combination. */ +#define DEFAULT_PING_TYPES (PINGTYPE_ICMP_PING|PINGTYPE_TCP|PINGTYPE_TCP_USE_ACK|PINGTYPE_TCP_USE_SYN|PINGTYPE_ICMP_TS) +#define DEFAULT_PING_ACK_PORT_SPEC "80" +#define DEFAULT_PING_SYN_PORT_SPEC "443" +/* For nonroot. */ +#define DEFAULT_PING_CONNECT_PORT_SPEC "80,443" /* OS scan */ #define OS_SCAN_DEFAULT 9 diff --git a/scan_engine.cc b/scan_engine.cc index 42d73c385..cb4e528e5 100644 --- a/scan_engine.cc +++ b/scan_engine.cc @@ -1892,28 +1892,10 @@ static int get_next_target_probe(UltraScanInfo *USI, HostScanStats *hss, hss->sent_arp = true; return 0; } else if (USI->ping_scan) { - if (USI->ptech.rawtcpscan) { - pspec->type = PS_TCP; - pspec->proto = IPPROTO_TCP; - if ((o.pingtype & PINGTYPE_TCP_USE_ACK) - && hss->next_ackportpingidx < USI->ports->ack_ping_count) { - pspec->pd.tcp.dport = USI->ports->ack_ping_ports[hss->next_ackportpingidx++]; - pspec->pd.tcp.flags = TH_ACK; - return 0; - } - if ((o.pingtype & PINGTYPE_TCP_USE_SYN) - && hss->next_synportpingidx < USI->ports->syn_ping_count) { - pspec->pd.tcp.dport = USI->ports->syn_ping_ports[hss->next_synportpingidx++]; - pspec->pd.tcp.flags = TH_SYN; - return 0; - } - } - if (USI->ptech.rawudpscan && hss->next_udpportpingidx < USI->ports->udp_ping_count) { - pspec->type = PS_UDP; - pspec->proto = IPPROTO_UDP; - pspec->pd.udp.dport = USI->ports->udp_ping_ports[hss->next_udpportpingidx++]; - return 0; - } + /* This is ordered to try probes of higher effectiveness first: + -PE -PS -PA -PP -PU + -PA is slightly better than -PS when combined with -PE, but give -PS an + edge because it is less likely to be dropped by firewalls. */ if (USI->ptech.rawicmpscan) { pspec->type = PS_ICMP; pspec->proto = IPPROTO_ICMP; @@ -1923,6 +1905,26 @@ static int get_next_target_probe(UltraScanInfo *USI, HostScanStats *hss, pspec->pd.icmp.code = 0; return 0; } + } + if (USI->ptech.rawtcpscan) { + pspec->type = PS_TCP; + pspec->proto = IPPROTO_TCP; + if ((o.pingtype & PINGTYPE_TCP_USE_SYN) + && hss->next_synportpingidx < USI->ports->syn_ping_count) { + pspec->pd.tcp.dport = USI->ports->syn_ping_ports[hss->next_synportpingidx++]; + pspec->pd.tcp.flags = TH_SYN; + return 0; + } + if ((o.pingtype & PINGTYPE_TCP_USE_ACK) + && hss->next_ackportpingidx < USI->ports->ack_ping_count) { + pspec->pd.tcp.dport = USI->ports->ack_ping_ports[hss->next_ackportpingidx++]; + pspec->pd.tcp.flags = TH_ACK; + return 0; + } + } + if (USI->ptech.rawicmpscan) { + pspec->type = PS_ICMP; + pspec->proto = IPPROTO_ICMP; if ((o.pingtype & PINGTYPE_ICMP_MASK) && !hss->sent_icmp_mask) { hss->sent_icmp_mask = true; pspec->pd.icmp.type = ICMP_MASK; @@ -1936,6 +1938,12 @@ static int get_next_target_probe(UltraScanInfo *USI, HostScanStats *hss, return 0; } } + if (USI->ptech.rawudpscan && hss->next_udpportpingidx < USI->ports->udp_ping_count) { + pspec->type = PS_UDP; + pspec->proto = IPPROTO_UDP; + pspec->pd.udp.dport = USI->ports->udp_ping_ports[hss->next_udpportpingidx++]; + return 0; + } if (USI->ptech.rawprotoscan) { pspec->type = PS_PROTO; pspec->proto = USI->ports->proto_ping_ports[hss->next_protoportpingidx++];