Nmap Development mailing list archives

Re: [NSE script] SSH weak hostkey


From: Arturo 'Buanzo' Busleiman <buanzo () buanzo com ar>
Date: Mon, 08 Sep 2008 18:59:04 -0300

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Fyodor wrote:
Hi Sven.  Sounds like a great script, but unfortunately 8MB is too
large to ship with Nmap by default.  Though people could download and

I've just finished this first test, anyone care to implement it into the NSE script?

http://tools.buanzo.org/sshvulnkey/$type/$key

where $type = 'dsa1024' | 'rsa2048'
and $key = last 20 chars of a key, like '0011223344aabbccddee'

The php script returns '0' or '1'.

Anyone care to test it?

- --
Arturo "Buanzo" Busleiman
Independent Linux and Security Consultant - SANS - OISSG - OWASP
http://www.buanzo.com.ar/pro/eng.html
Mailing List Archives at http://archiver.mailfighter.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFIxaAoAlpOsGhXcE0RCp6gAJ46fqMCcwaTkjtOK6QorDlfQd9UIgCcCcnS
zeUxtvnjl7rzSZcm0vltAZU=
=SEtu
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org


Current thread: