mirror of
https://github.com/nmap/nmap.git
synced 2026-08-04 06:40:48 +00:00
NSE re-categorization
* Merge the "backdoor" category into "malware" * Add "auth" for authentication credential determination * Rename "vulnerability" to "vuln" * Place 12 scripts into their correct categories
This commit is contained in:
parent
30d60b97ed
commit
ac5138b975
15 changed files with 120 additions and 93 deletions
|
|
@ -1893,18 +1893,26 @@ way.</para>
|
|||
</para>
|
||||
|
||||
<para>
|
||||
<emphasis>Malware-detection</emphasis> (categories
|
||||
<literal>malware</literal> and <literal>backdoor</literal>)- Both attackers
|
||||
<emphasis>Malware-detection</emphasis> (category <literal>malware</literal>)—Both attackers
|
||||
and worms often leave backdoors—be it in form of SMTP-servers listening on
|
||||
uncommon ports mostly used by spammers for mail relay, or in form of an
|
||||
FTP-server giving crackers access to critical data. A few lines of Lua code
|
||||
can help to identify those loopholes easily.
|
||||
</para>
|
||||
|
||||
<para>
|
||||
<emphasis>Vulnerability Detection</emphasis> (category
|
||||
<literal>vulnerability</literal>)- NSE's capacity in detecting risks ranges
|
||||
from checking for default passwords on Apache distributions to testing
|
||||
whether a SMTP-server supports relaying mail from arbitrary domains.
|
||||
<literal>vuln</literal>)—NSE's capacity in detecting risks ranges
|
||||
from testing whether an SMTP server supports relaying mail from arbitrary
|
||||
domains to testing whether an HTTP server is vulnerable to directory
|
||||
traversal attacks.
|
||||
</para>
|
||||
|
||||
<para>
|
||||
<emphasis>Determination of Authentication Credentials</emphasis> (category
|
||||
<literal>auth</literal>)—NSE can be used for determining authentication
|
||||
credentials on the target's services, with a common method being brute-force
|
||||
attack.
|
||||
</para>
|
||||
|
||||
<para>
|
||||
|
|
@ -1918,7 +1926,7 @@ way.</para>
|
|||
available NFS/SMB/RPC shares, the number of channels of an irc-network or
|
||||
currently logged on users.
|
||||
</para>
|
||||
|
||||
|
||||
<para>
|
||||
To reflect those different uses and to simplify the choice of which
|
||||
scripts to run, each script contains a field associating it with one or more
|
||||
|
|
|
|||
|
|
@ -185,9 +185,9 @@ Nmap finished: 1 IP address (1 host up) scanned in 0.907 seconds
|
|||
Currently defined categories are <literal>safe</literal>,
|
||||
<literal>intrusive</literal>, <literal>malware</literal>,
|
||||
<literal>version</literal>, <literal>discovery</literal>,
|
||||
<literal>vulnerability</literal> and <literal>default</literal>.
|
||||
Categories are not case sensitive. The following list
|
||||
describes each category.</para>
|
||||
<literal>vuln</literal>, <literal>auth</literal> and
|
||||
<literal>default</literal>. Categories are not case
|
||||
sensitive. The following list describes each category.</para>
|
||||
|
||||
<variablelist>
|
||||
<varlistentry>
|
||||
|
|
@ -213,11 +213,12 @@ Nmap finished: 1 IP address (1 host up) scanned in 0.907 seconds
|
|||
<option>intrusive</option>
|
||||
</term>
|
||||
<listitem>
|
||||
<para>These are not intended to
|
||||
crash or damage anything, but are more likely to leave
|
||||
suspicious logs or otherwise arouse sysadmin ire. Scripts
|
||||
which attempt to login to services with default passwords
|
||||
fall into this class.</para>
|
||||
<para>These are scripts that cannot be classified in the
|
||||
"safe" category because the risks are too high that they
|
||||
will crash the target system, use up significant resources
|
||||
on the target host (such as bandwidth or CPU time), or
|
||||
otherwise be perceived as malicious by the target's
|
||||
system administrators.</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
|
|
@ -259,10 +260,21 @@ Nmap finished: 1 IP address (1 host up) scanned in 0.907 seconds
|
|||
|
||||
<varlistentry>
|
||||
<term>
|
||||
<option>vulnerability</option>
|
||||
<option>vuln</option>
|
||||
</term>
|
||||
<listitem>
|
||||
<para>These scripts check for a specific vulnerability and report results only if it is found.</para>
|
||||
<para>These scripts check for specific known vulnerabilities and
|
||||
generally only report results if it is found.</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>
|
||||
<option>auth</option>
|
||||
</term>
|
||||
<listitem>
|
||||
<para>These scripts try to determine authentication credentials
|
||||
on the target system, often through a brute-force attack.</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
|
|
@ -272,8 +284,9 @@ Nmap finished: 1 IP address (1 host up) scanned in 0.907 seconds
|
|||
</term>
|
||||
<listitem>
|
||||
<para>These scripts are the default set and are run when
|
||||
using <option>-sC</option>. This category can also be
|
||||
specified like any other with <option>--script</option>.
|
||||
using <option>-sC</option>, <option>-A</option> or <option>--script</option>
|
||||
without any arguments. This category can also be specified
|
||||
explicitly like any other using <option>--script</option>.
|
||||
Don't be fooled into thinking that just because these scripts
|
||||
are run by default that they are all completely unobtrusive:
|
||||
these scripts should not be run against target networks without
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue