PaulDotCom mailing list archives

Scanning for Confiker via nmap


From: jsawyer at ufl.edu (John Sawyer)
Date: Mon, 30 Mar 2009 18:24:03 -0400

Odd. I got it working on a 4.76 install without a problem.

A new Windows version is now available that has the updated files. It  
is 4.85Beta5.

http://nmap.org/dist/nmap-4.85BETA4-setup.exe

-jhs

On Mar 30, 2009, at 5:27 PM, Albert R. Campa wrote:

simply copying those files into appropriate directories didnt work  
for me on windows. threw a run time error and could not be loaded.



__________________________________
Albert R. Campa


2009/3/30 John Sawyer <jsawyer at ufl.edu>
Grab these three files and you should be good to go.

scripts/smb-check-vulns.nse
nselib/msrpc.lua
nselib/smb.lua

-jhs

On Mar 30, 2009, at 2:11 PM, Chris Merkel wrote:

You should be able to just grab the NSE file from SVN - no need to
recompile nmap, right?

- Chris

2009/3/30 John Sawyer <jsawyer at ufl.edu>:
The Conficker check is in the latest SVN version of Nmap. It's in  
the
smb-check-vulns.nse which now checks for Conficker, MS08-067 and a  
regsvc
DoS.

nmap --script smb-check-vulns.nse -p445

For safety's sake, you might want to also run it with --script- 
args=unsafe=1
to prevent possible crashes from the regsvc check. That should not  
turn off
the conficker check.

-jhs

_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20090330/dda37229/attachment.htm 


Current thread: