diff --git a/CHANGELOG b/CHANGELOG index d859d0bff..7e9207ed5 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -19,6 +19,9 @@ o Whenever Nmap sends packets with the SYN bit set (except for OS all hosts set at least this option. Thanks to Juergen Schmidt (ju(a)heisec.de) for the suggestion. +o Applied a patch for a Windows "interface reading bug" from Doug + Hoyte. + o Minor changes to recognize DragonFly BSD in configure scripts. Thanks to Joerg Sonnenberger (joerg(a)britannica.bec.de) for sending the patch. @@ -873,7 +876,7 @@ o The XML nmaprun element now has a startstr attribute which gives the o Fixed a memory leak that would generally consume several hundred bytes per down host scanned. While the effect for most scans is negligible, it was overwhelming when Scott Carlson - (Scott.Carlson(a)schwab.com) tried to scan 24 million IPs + (Scott.Carlson(a)schwab.com) tried to scan 16.8 million IPs (10.0.0.0/8). Thanks to him for reporting the problem. Also thanks to Valgrind ( http://valgrind.kde.org ) for making it easy to debug. diff --git a/docs/nmap.1 b/docs/nmap.1 index 95e157868..42d8ab509 100644 --- a/docs/nmap.1 +++ b/docs/nmap.1 @@ -2,7 +2,7 @@ .\" It was generated using the DocBook XSL Stylesheets (version 1.69.1). .\" Instead of manually editing it, you probably should edit the DocBook XML .\" source for it and then use the DocBook XSL Stylesheets to regenerate it. -.TH "NMAP" "1" "01/31/2006" "" "Nmap Reference Guide" +.TH "NMAP" "1" "02/09/2006" "" "Nmap Reference Guide" .\" disable hyphenation .nh .\" disable justification (adjust text to left margin only) diff --git a/nmap-os-fingerprints b/nmap-os-fingerprints index 308f994fb..a012dcf52 100644 --- a/nmap-os-fingerprints +++ b/nmap-os-fingerprints @@ -4015,18 +4015,6 @@ T6(DF=N%W=400|800|C00|1000%ACK=S%Flags=AR%Ops=) T7(DF=N%W=400|800|C00|1000%ACK=S++%Flags=AR%Ops=) PU(DF=N%TOS=C0%IPLEN=38%RIPTL=148%RID=E%RIPCK=E%UCK=E%ULEN=134%DAT=E) -Fingerprint Cisco 3600 router running IOS 12.2(6c) -Class Cisco | IOS | 12.X | router -TSeq(Class=TR%gcd=<6%IPID=Z%TS=U) -T1(DF=N%W=1020%ACK=S++%Flags=AS%Ops=ME) -T2(Resp=Y%DF=N%W=0%ACK=S%Flags=AR%Ops=) -T3(Resp=Y%DF=N%W=1020%ACK=S++%Flags=AS%Ops=M) -T4(DF=N%W=0%ACK=O%Flags=R%Ops=) -T5(DF=N%W=0%ACK=S++%Flags=AR%Ops=) -T6(DF=N%W=0%ACK=O%Flags=R%Ops=) -T7(DF=N%W=0%ACK=S%Flags=AR%Ops=) -PU(DF=N%TOS=0%IPLEN=38%RIPTL=148%RID=E%RIPCK=E%UCK=E%ULEN=134%DAT=E) - # Cisco 3660, IOS 12.0(6r)T Fingerprint Cisco 3660 running IOS 12.0(6r)T Class Cisco | IOS | 12.X | router @@ -4079,18 +4067,6 @@ T6(DF=N%W=0%ACK=O%Flags=R%Ops=) T7(DF=N%W=0%ACK=S%Flags=AR%Ops=) PU(Resp=N) -Fingerprint Cisco 5200 router running IOS v12.0(15) -Class Cisco | IOS | 12.X | router -TSeq(Class=TR%gcd=<6%IPID=Z%TS=U) -T1(DF=N%W=1020%ACK=S++%Flags=AS%Ops=M) -T2(Resp=Y%DF=N%W=0%ACK=S%Flags=AR%Ops=) -T3(Resp=Y%DF=N%W=1020%ACK=S++%Flags=AS%Ops=M) -T4(DF=N%W=0%ACK=O%Flags=R%Ops=) -T5(DF=N%W=0%ACK=S++%Flags=AR%Ops=) -T6(DF=N%W=0%ACK=O%Flags=R%Ops=) -T7(DF=N%W=0%ACK=S%Flags=AR%Ops=) -PU(DF=N%TOS=0%IPLEN=38%RIPTL=148%RID=E%RIPCK=E%UCK=E%ULEN=134%DAT=E) - Fingerprint Cisco 7200 router running IOS 12.1(14)E6 Class Cisco | IOS | 12.X | router TSeq(Class=TR%gcd=<6%IPID=Z%TS=U) @@ -4330,6 +4306,22 @@ T6(DF=N%W=0%ACK=O%Flags=R%Ops=) T7(DF=N%W=0%ACK=S%Flags=AR%Ops=) PU(DF=N%TOS=20|C0%IPLEN=38%RIPTL=148%RID=E%RIPCK=E%UCK=E%ULEN=134%DAT=E) +# Cisco WS-C4006 +# Cisco 7120-4T1 ISO 12.2 +# CISCO 2950C +# Cisco 3600 +Fingerprint Cisco router running IOS 12.2 +Class Cisco | IOS | 12.X | router +TSeq(Class=TR%gcd=<6%IPID=Z%TS=U) +T1(DF=N%W=1020%ACK=S++%Flags=AS%Ops=ME) +T2(Resp=Y%DF=N%W=0%ACK=S%Flags=AR%Ops=) +T3(Resp=Y%DF=N%W=1020%ACK=S++%Flags=AS%Ops=M) +T4(DF=N%W=0%ACK=O%Flags=R%Ops=) +T5(DF=N%W=0%ACK=S++%Flags=AR%Ops=) +T6(DF=N%W=0%ACK=O%Flags=R%Ops=) +T7(DF=N%W=0%ACK=S%Flags=AR%Ops=) +PU(DF=N%TOS=0%IPLEN=38%RIPTL=148%RID=E%RIPCK=E%UCK=E%ULEN=134%DAT=E) + # Cisco 2621 running IOS 12.2.8T # Cisco SOHO 77 running IOS 12.2(8)T Fingerprint Cisco router running IOS 12.2(8)T @@ -4378,6 +4370,20 @@ T6(DF=N%W=0%ACK=O%Flags=R%Ops=) T7(DF=N%W=0%ACK=S%Flags=AR%Ops=) PU(DF=N%TOS=0|C0%IPLEN=38%RIPTL=148%RID=E%RIPCK=E%UCK=E%ULEN=134%DAT=E) +# Cisco 5200 router IOS v12.0(15) +# Cisco 2924C +Fingerprint Cisco router running IOS v12.0(15) +Class Cisco | IOS | 12.X | router +TSeq(Class=TR%gcd=<6%IPID=Z%TS=U) +T1(DF=N%W=1020%ACK=S++%Flags=AS%Ops=M) +T2(Resp=Y%DF=N%W=0%ACK=S%Flags=AR%Ops=) +T3(Resp=Y%DF=N%W=1020%ACK=S++%Flags=AS%Ops=M) +T4(DF=N%W=0%ACK=O%Flags=R%Ops=) +T5(DF=N%W=0%ACK=S++%Flags=AR%Ops=) +T6(DF=N%W=0%ACK=O%Flags=R%Ops=) +T7(DF=N%W=0%ACK=S%Flags=AR%Ops=) +PU(DF=N%TOS=0%IPLEN=38%RIPTL=148%RID=E%RIPCK=E%UCK=E%ULEN=134%DAT=E) + # IOS (tm) SOHO91 Software (SOHO91-K9OY6-M), Version 12.3(2)XC, EARLY DEPLOYMENT RELEASE SOFTWARE (fc1) (Cisco SOHO 91 Secure router) Fingerprint Cisco SOHO 91 secure router running IOS 12.3 Class Cisco | IOS | 12.X | router diff --git a/nmap_dns.cc b/nmap_dns.cc index baf640294..f44df40ac 100644 --- a/nmap_dns.cc +++ b/nmap_dns.cc @@ -861,6 +861,63 @@ void close_dns_servers() { } +#ifdef WIN32 +void win32_read_registry(char *controlset) { + HKEY hKey; + HKEY hKey2; + char keybasebuf[2048]; + char buf[2048], keyname[2048], *p; + DWORD sz, i; + + snprintf(keybasebuf, sizeof(keybasebuf), "SYSTEM\\%s\\Services\\Tcpip\\Parameters", controlset); + if (RegOpenKeyEx(HKEY_LOCAL_MACHINE, keybasebuf, + 0, KEY_READ, &hKey) != ERROR_SUCCESS) + fatal("Error opening registry to read DNS servers. Try using --system-dns or specify valid servers with --dns-servers"); + + sz = sizeof(buf); + if (RegQueryValueEx(hKey, "NameServer", NULL, NULL, (LPBYTE) buf, (LPDWORD) &sz) == ERROR_SUCCESS) + add_dns_server(buf); + + sz = sizeof(buf); + if (RegQueryValueEx(hKey, "DhcpNameServer", NULL, NULL, (LPBYTE) buf, (LPDWORD) &sz) == ERROR_SUCCESS) + add_dns_server(buf); + + RegCloseKey(hKey); + + snprintf(keybasebuf, sizeof(keybasebuf), "SYSTEM\\%s\\Services\\Tcpip\\Parameters\\Interfaces", controlset); + if (RegOpenKeyEx(HKEY_LOCAL_MACHINE, keybasebuf, + 0, KEY_ENUMERATE_SUB_KEYS, &hKey) == ERROR_SUCCESS) { + + sz = sizeof(buf); + for (i=0; RegEnumKeyEx(hKey, i, buf, &sz, NULL, NULL, NULL, NULL) != ERROR_NO_MORE_ITEMS; i++) { + + snprintf(keyname, sizeof(keyname), "SYSTEM\\%s\\Services\\Tcpip\\Parameters\\Interfaces\\%s", controlset, buf); + + if (RegOpenKeyEx(HKEY_LOCAL_MACHINE, keyname, + 0, KEY_READ, &hKey2) == ERROR_SUCCESS) { + + sz = sizeof(buf); + if (RegQueryValueEx(hKey2, "DhcpNameServer", NULL, NULL, (LPBYTE) buf, (LPDWORD) &sz) == ERROR_SUCCESS) + add_dns_server(buf); + + sz = sizeof(buf); + if (RegQueryValueEx(hKey2, "NameServer", NULL, NULL, (LPBYTE) buf, (LPDWORD) &sz) == ERROR_SUCCESS) + add_dns_server(buf); + + RegCloseKey(hKey2); + } + + sz = sizeof(buf); + } + + RegCloseKey(hKey); + + } + +} +#endif + + // Parses /etc/resolv.conf (unix) or the registry (win32) and adds // all the nameservers found via the add_dns_server() function. @@ -894,62 +951,11 @@ void parse_resolvdotconf() { fclose(fp); #else - - HKEY hKey; - HKEY hKey2; - char buf[2048], keyname[2048], *p; - long sz, i; - - if (RegOpenKeyEx(HKEY_LOCAL_MACHINE, - "SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters", - 0, KEY_READ, &hKey) != ERROR_SUCCESS) - fatal("Error opening registry to read DNS servers. Try using --system-dns or specify valid servers with --dns-servers"); - - sz = sizeof(buf); - if (RegQueryValueEx(hKey, "NameServer", NULL, NULL, (LPBYTE) buf, (LPDWORD) &sz) == ERROR_SUCCESS) - add_dns_server(buf); - - sz = sizeof(buf); - if (RegQueryValueEx(hKey, "DhcpNameServer", NULL, NULL, (LPBYTE) buf, (LPDWORD) &sz) == ERROR_SUCCESS) - add_dns_server(buf); - - RegCloseKey(hKey); - - if (RegOpenKeyEx(HKEY_LOCAL_MACHINE, - "SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Interfaces", - 0, KEY_READ, &hKey) == ERROR_SUCCESS) { - - for (i=0; sz = sizeof(buf) && RegEnumKeyEx(hKey, i, buf, (LPDWORD) &sz, NULL, NULL, NULL, NULL) != ERROR_NO_MORE_ITEMS; i++) { - - snprintf(keyname, sizeof(keyname), "SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Interfaces\\%s", buf); - - if (RegOpenKeyEx(HKEY_LOCAL_MACHINE, - keyname, - 0, KEY_READ, &hKey2) == ERROR_SUCCESS) { - - sz = sizeof(buf); - if (RegQueryValueEx(hKey2, "DhcpNameServer", NULL, NULL, (LPBYTE) buf, (LPDWORD) &sz) == ERROR_SUCCESS) - add_dns_server(buf); - - sz = sizeof(buf); - if (RegQueryValueEx(hKey2, "NameServer", NULL, NULL, (LPBYTE) buf, (LPDWORD) &sz) == ERROR_SUCCESS) - add_dns_server(buf); - - RegCloseKey(hKey2); - } - - } - - RegCloseKey(hKey); - - } - + win32_read_registry("CurrentControlSet"); #endif - } - void parse_etchosts(char *fname) { FILE *fp; char buf[2048], hname[256], ipaddrstr[16], *tp;