Nmap Development mailing list archives

Re: smbv2-dos.nse


From: Kris Katterjohn <katterjohn () gmail com>
Date: Sat, 12 Sep 2009 11:14:30 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 09/12/2009 10:19 AM, Ron wrote:
I added it to the 'dos' category, which I don't think should be implied by 'all'.

I think it should be, since it's called "all".  Just because so far "all"
hasn't contained stuff like dos and exploit scripts doesn't mean it shouldn't
live up to its name now.

Correct me if I'm wrong, but couldn't you do "all and not dos" or something
similiar for this effect?

If the concern is for users accidently running evil dos and exploit scripts
when they specify "all", then I'm not sure what to say.  If they're going to
blindly run "all" scripts without knowing what they do, then they're just in
for trouble anyway.

We shouldn't butcher a category like "all", when its name describes it
perfectly in 3 letters.  All is all.

However if you're concerned with the fact that "all" isn't "relatively safe"
anymore, so you can't type just 3 letters, I think the boolean rule above will
suffice (or we could theoretically create yet another category to work around
this, but I don't like that very much).

Sorry if I've sounded stern; I've just wanted to get all of this out
beforehand in case this discussion takes off :)

Ron


Cheers,
Kris Katterjohn

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iQIcBAEBAgAGBQJKq8jmAAoJEEQxgFs5kUfuyrsQAK0JyIvDAmGjq32hdl1PONbF
0HZiwZW5qsQztcYMilMghg5136QYNNeOdI3qtP5z7Tr+LUZRV8P/9drSPPRUUsfP
lrWQz5VU7atLE1sxE8vjBmm+4e2XUgYB/SJA4c9CEL6Mqa/PhWVPVIskOXPR9QsN
tQKEuFrSYoTjWW7KDxC+9dply+rBNu1ZLVUQD9ZZP01eHciyePWnzAUTc4DaNo0d
dKr/t/UJjeYXtf9T6KI/LF46sARKo7qJtC7UnWd3S+7Dm49KDpxXnjdtpGnUhhIq
Us37CNCWrSJPFghyQKLbA2ZcGoq1DurJrneehY4MyLHTb3SPUbOZXH8VCM+Quxtu
ba63yItX5otzhOPa9Ixt4zZ/XWWdVI5skvuhTPeffVKp4wI+RQnjG81lZHS8EzgA
xF78RPA7Zo00VROLHFd85kQ0xb8JrTy53/zj84OGideOdMGFVJ7/lUY3hhVQOBoy
BE6biHeh+QEtSJY0SPtH3w+d35ZCFT4nthRCyoQ8Kk79xV0ZR0HHD0EHDOLPG2tB
hm2wZDyPToGiOVu1LNJM2xRSwA9rg9UDUaV/daAQTpl3VrW2ZWLf0J7HqXYxpVkA
x52LsqNwLA1jT57lywHpWDPr8tUGy41sVvDsOf3vFyj81j5p+c4L2LajJ4UhNEzd
G9U9nvIjP8pNGXC8Chgb
=MWql
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org


Current thread: