Metasploit mailing list archives

Minor problem db_hosts not showing OS


From: Michel Ferreira <michelf () gmail com>
Date: Tue, 14 Sep 2010 14:07:43 -0300

Hi,

I've been trying to get the OS flavor on the db_hosts but I'm unable
to do so :(
I've followed the steps provided on the MSFU, here's what i'm doing in
detail so you guys can point me where I'm screwing up =)

--- Method 1 ---
msf > db_conect
[-] Note that sqlite is not supported due to numerous issues.
[-] It may work, but don't count on it
[*] Creating a new database file...
[*] Successfully connected to the database
[*] File: /root/.msf3/sqlite3.db
msf > db_hosts

Hosts
=====

address  address6  arch  comm  comments  created_at  info  mac  name
os_flavor  os_lang  os_name  os_sp  purpose  state  updated_at  svcs
vulns  workspace
-------  --------  ----  ----  --------  ----------  ----  ---  ----
---------  -------  -------  -----  -------  -----  ----------  ----
-----  ---------

msf > db_nmap -sV -O 192.168.80.128

Starting Nmap 5.35DC18 ( http://nmap.org ) at 2010-09-14 12:36 BRT
Nmap scan report for 192.168.80.128
Host is up (0.00088s latency).
Not shown: 991 closed ports
PORT     STATE SERVICE      VERSION
21/tcp   open  ftp          Microsoft ftpd
25/tcp   open  smtp         Microsoft ESMTP 6.0.2600.2180
80/tcp   open  http         Microsoft IIS httpd 5.1
135/tcp  open  msrpc        Microsoft Windows RPC
139/tcp  open  netbios-ssn
443/tcp  open  https?
445/tcp  open  microsoft-ds Microsoft Windows XP microsoft-ds
1056/tcp open  msrpc        Microsoft Windows RPC
1433/tcp open  ms-sql-s     Microsoft SQL Server 2005 9.00.1399; RTM
MAC Address: 00:0C:29:53:0C:5A (VMware)
Device type: general purpose
Running: Microsoft Windows XP|2003
OS details: Microsoft Windows XP Professional SP2 or Windows Server 2003
Network Distance: 1 hop
Service Info: Host: admin-mj9s8zclq; OS: Windows

OS and Service detection performed. Please report any incorrect
results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 78.19 seconds


msf > db_hosts -c address,state,os_flavor,os_lang,os_name,os_sp

Hosts
=====

address         os_flavor  os_lang  os_name  os_sp  state
-------         ---------  -------  -------  -----  -----
192.168.80.128                                      alive

msf >

--- Method 2 ---
msf > nmap -sV -O -oX scan.xml 192.168.80.128
[*] exec: nmap -sV -O -oX scan.xml 192.168.80.128


Starting Nmap 5.35DC18 ( http://nmap.org ) at 2010-09-14 12:50 BRT
Nmap scan report for 192.168.80.128
Host is up (0.00063s latency).
Not shown: 991 closed ports
PORT     STATE SERVICE      VERSION
21/tcp   open  ftp          Microsoft ftpd
25/tcp   open  smtp         Microsoft ESMTP 6.0.2600.2180
80/tcp   open  http         Microsoft IIS httpd 5.1
135/tcp  open  msrpc        Microsoft Windows RPC
139/tcp  open  netbios-ssn
443/tcp  open  https?
445/tcp  open  microsoft-ds Microsoft Windows XP microsoft-ds
1056/tcp open  msrpc        Microsoft Windows RPC
1433/tcp open  ms-sql-s     Microsoft SQL Server 2005 9.00.1399; RTM
MAC Address: 00:0C:29:53:0C:5A (VMware)
Device type: general purpose
Running: Microsoft Windows XP|2003
OS details: Microsoft Windows XP Professional SP2 or Windows Server 2003
Network Distance: 1 hop
Service Info: Host: admin-mj9s8zclq; OS: Windows

OS and Service detection performed. Please report any incorrect
results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 53.56 seconds
msf > db_import nmapscan.xml
[*] Importing 'Nmap XML' data
[*] Importing host 192.168.80.128
[*] Successfully imported /home/drak/tmp/svn/msf3-dev/nmapscan.xml
msf > db_hosts -c address,state,os_flavor,os_lang,os_name,os_sp

Hosts
=====

address         os_flavor  os_lang  os_name  os_sp  state
-------         ---------  -------  -------  -----  -----
192.168.80.128                                      alive

msf >

--- Versions
msf > version
Framework: 3.4.2-dev.10130
Console  : 3.4.2-dev.10119
svn r10302 updated today (2010.09.13)

msf > uname -a
[*] exec: uname -a
Linux loki 2.6.32-24-generic #42-Ubuntu SMP Fri Aug 20 14:24:04 UTC
2010 i686 GNU/Linux
---

So, any thoughts ?

Regards,
Michel
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


Current thread: