-
Notifications
You must be signed in to change notification settings - Fork 2.7k
Closed
Description
UDP scanning is one of the slowest processes for Nmap, due largely to the fact that most invalid UDP datagrams are ignored by the target service. nmap-payloads remedies this somewhat by defining data payloads that have a high chance of eliciting a response from a target service on a particular port. We also have probes defined in nmap-service-probes that are designed to get a unique response from various software implementations. If we used these probes as data payloads, we could increase the chance of getting a response from various UDP services. Other benefits might result as well.
Brief description of work items necessary to accomplish this:
- Extend functions from
payload.ccto retrieve payloads from theAllProbesclass defined inservice_scan.h - Ensure "duplicate payload" warnings are not produced at normal or verbosity level 1 when they come from this retrieval.
A good solution will also:
- avoid duplicating payload data in memory, perhaps by linking the
struct payloadto theServiceProbeit is related to.
Ideally, we would like to:
- Save any responses to probes from the port scan phase in order to match them in the service scan phase.
- Save any responses to payloads from the port scan phase in order to print them in the service fingerprint if the service scan does not find a match.
- Provide a means such as a
nmap-service-probesdirective to avoid sending a probe in this manner, for the case where a particular probe is found to be unsuitable for this
Metadata
Metadata
Assignees
Labels
No labels