Nmap Development mailing list archives

Re: "Strange connect error" when using -sV


From: monzy merza <monzymerza () gmail com>
Date: Thu, 2 Feb 2006 23:29:41 -0700

some more info on this.

did a few more runs with nmap 4. turns out that if i use -T2 i don't
see the problem. recreated the problem with -T3, -T4.

the ip in the example below and the ones in other tests belong to
cisco 6509 switches. i am told by the admins that those switches are
running cat os 7.6.9. and ssh is indeed enabled on them.

on the paranoia set to T2 nmap 4 reports that it is unable to identify
the version and outputs the fingerprint. (i'll submit the fingerprint
once i ensure that i have accurate verion info for all of them, since
there are multiple 6509's here ).

also, on some of the tests i don't get the message"
Got nsock WRITE error #32 (Broken pipe)
"

i just get the "
Strange connect error from 192.168.3.12 (32): Operation now in progress
nmap: nsock_core.c:273: handle_connect_result: Assertion `0' failed.
Aborted
"

thats all i have for now... i'll keep digging.

monzy

On 2/2/06, monzy merza <monzymerza () gmail com> wrote:
hello All,

i installed nmap 4 from source. ran a scan:

[root@d root]# nmap -sV -T5 -p 22 192.168.3.0/24

Starting Nmap 4.00 ( http://www.insecure.org/nmap/ ) at 2006-02-02 18:08 MST
Got nsock WRITE error #32 (Broken pipe)

Got nsock WRITE error #32 (Broken pipe)

Got nsock WRITE error #32 (Broken pipe)

Got nsock WRITE error #32 (Broken pipe)

Got nsock WRITE error #32 (Broken pipe)

Strange connect error from 192.168.3.41 (32): Operation now in progress
nmap: nsock_core.c:273: handle_connect_result: Assertion `0' failed.
Aborted

so i used 3.95 from another machine and got the same error. i used
3.83 from a third machine and got the same error. i ran several tests
the same ip is not repeated in the error (from any version). may be i
just have'nt run enough tests to start seeing the cycle.

i have used nmap to scan the above ip space before, (as late as last
week) and never gotten this message before.

i ran the scans w/o the -sV option and there are no errors.

any thoughts ?

monzy



_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev


Current thread: