Nmap Development mailing list archives

Re: More Service Detection Notes (Skype)


From: Fyodor <fyodor () insecure org>
Date: Thu, 27 Jul 2006 17:37:37 -0700

On Wed, Jul 26, 2006 at 12:25:58AM -0700, doug () hcsw org wrote:
What do you think about an addition to the nmap-service-probes
format that requires multiple match lines having to be triggered
in order to report a result? Specifically, do you (or anyone else) see
anything wrong with the following:

That does look like a clever mechanism.  But I'm concerned about
adding too much complexity to the system.  Maybe it would be best to
let the upcoming scripting system deal with service detection for
these especially tough cases.

Probe TCP GetRequest q|GET / HTTP/1.0\r\n\r\n|
...
match &skype2 m|^HTTP/1\.0 404 Not Found\r\n\r\n$| p/Skype v2/

Has anyone discovered any URLs which don't give 404 errors?  What sort
of URLs are seen when you sniff a skype connection?

Cheers,
-F


_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev


Current thread: