mirror of
https://github.com/nmap/nmap.git
synced 2026-08-27 03:48:14 +00:00
o [NSE] Added script dns-nsid by John Bond, that retrieves name server ID and
version information. o [NSE] Applied patch to DNS library by John Bond that adds support for the CHAOS class and NSID requests.
This commit is contained in:
parent
0fad67e9e1
commit
c579d844ba
4 changed files with 119 additions and 10 deletions
69
scripts/dns-nsid.nse
Normal file
69
scripts/dns-nsid.nse
Normal file
|
|
@ -0,0 +1,69 @@
|
|||
description = [[
|
||||
Ateemps to get more information from a server by requesting the server nsid[1],
|
||||
and asking for id.server[2] and version.bind. This script dose the same as the
|
||||
following two dig commands:
|
||||
- dig CH TXT bind.version @target
|
||||
- dig +nsid CH TXT id.server @target
|
||||
|
||||
[1]http://www.ietf.org/rfc/rfc5001.txt
|
||||
[2]http://www.ietf.org/rfc/rfc4892.txt
|
||||
]]
|
||||
|
||||
---
|
||||
-- @usage
|
||||
-- nmap -sSU -p 53 --script dns-nsid <target>
|
||||
--
|
||||
-- @output
|
||||
-- 53/udp open domain udp-response
|
||||
-- | dns-nsid:
|
||||
-- | NSID dns.example.com (646E732E6578616D706C652E636F6D)
|
||||
-- | id.server: dns.example.com
|
||||
-- |_ bind.version: 9.7.3-P3
|
||||
---
|
||||
|
||||
author = "John Bond"
|
||||
license = "Simplified (2-clause) BSD license--See http://nmap.org/svn/docs/licenses/BSD-simplified"
|
||||
|
||||
categories = {"discovery", "default"}
|
||||
|
||||
require "stdnse"
|
||||
require "shortport"
|
||||
require "dns"
|
||||
|
||||
portrule = shortport.port_or_service(53, "domain", {"tcp", "udp"})
|
||||
|
||||
local function rr_filter(pktRR, label)
|
||||
for _, rec in ipairs(pktRR, label) do
|
||||
if ( rec[label] and 0 < #rec.data ) then
|
||||
if ( dns.types.OPT == rec.dtype ) then
|
||||
local pos, _, len = bin.unpack(">SS", rec.data)
|
||||
if ( len ~= #rec.data - pos + 1 ) then
|
||||
return false, "Failed to decode NSID"
|
||||
end
|
||||
return true, select(2, bin.unpack("A" .. len, rec.data, pos))
|
||||
else
|
||||
return true, select(2, bin.unpack("p", rec.data))
|
||||
end
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
action = function(host, port)
|
||||
local result = {}
|
||||
local status, resp = dns.query("id.server", {host = host.ip, dtype='TXT', class=dns.CLASS.CH, retAll=true, retPkt=true, nsid=true, dnssec=true})
|
||||
if ( status ) then
|
||||
local status, nsid = rr_filter(resp.add,'OPT')
|
||||
if ( status ) then
|
||||
table.insert(result, ("NSID: %s (%s)"):format(nsid, stdnse.tohex(nsid)))
|
||||
end
|
||||
local status, id_server = rr_filter(resp.answers,'TXT')
|
||||
if ( status ) then
|
||||
table.insert(result, ("id.server: %s"):format(id_server))
|
||||
end
|
||||
end
|
||||
local status, bind_version = dns.query("version.bind", {host = host.ip, dtype='TXT', class=dns.CLASS.CH})
|
||||
if ( status ) then
|
||||
table.insert(result, ("bind.version: %s"):format(bind_version))
|
||||
end
|
||||
return stdnse.format_output(true, result)
|
||||
end
|
||||
|
|
@ -55,6 +55,7 @@ Entry { filename = "dns-brute.nse", categories = { "discovery", "intrusive", } }
|
|||
Entry { filename = "dns-cache-snoop.nse", categories = { "discovery", "intrusive", } }
|
||||
Entry { filename = "dns-fuzz.nse", categories = { "fuzzer", "intrusive", } }
|
||||
Entry { filename = "dns-nsec-enum.nse", categories = { "discovery", "intrusive", } }
|
||||
Entry { filename = "dns-nsid.nse", categories = { "default", "discovery", } }
|
||||
Entry { filename = "dns-random-srcport.nse", categories = { "external", "intrusive", } }
|
||||
Entry { filename = "dns-random-txid.nse", categories = { "external", "intrusive", } }
|
||||
Entry { filename = "dns-recursion.nse", categories = { "default", "safe", } }
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue