Nmap Development mailing list archives

Re: POC Payloader dat


From: Jay Fink <jay.fink () gmail com>
Date: Wed, 9 Dec 2009 08:01:03 -0500

So I don't like the label, I am going to push that back to the loader
(somehow :) - so the new format would be more like unicornscan but
less the payload group:
/* PROTOCOL  USABLE_DESTINATION_PORTS_LIST  SOURCE_PORT PAYLOAD */
/* radius */
udp 1604,1645,1812  -1 {
"\x1e\x00\x01\x30\x02\xfd\xa8\xe3\x00\x00\x00\x00\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00";
};

What with holidays, new gig and all haven't had much time to look at
this but unicornscan uses a mix of lex and c to parse these out - not
very striaghtforward to me - so I might look at how nmap loads
services etc. for guidance instead.

thx,
 j
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: