Nmap Development mailing list archives

Re: Bug report:brute.lua and oracle-brute NSE script


From: David Fifield <david () bamsoftware com>
Date: Mon, 21 Mar 2011 16:13:23 -0700

On Sat, Mar 19, 2011 at 09:30:43AM +0100, Patrik Karlsson wrote:

On Mar 12, 2011, at 17:22 , Tod Beardsley wrote:

Thanks for checking into this Patrik.

Have you tuned the file-max value on your Debian server according to the
suggestions here?
http://download.oracle.com/docs/html/B15521_01/toc.htm

Yup:
root@dbsrv:~# cat /proc/sys/fs/file-max
65536

I've not been able to reproduce this against my test environment running
in VirtualBox (against which I do most testing).

Just to be perfectly clear, my target is Oracle 10g Express Edition
(XE), running on Ubuntu 9.10 (aka 2.6.31-20-generic #57-Ubuntu SMP Mon
Feb 8 09:05:19 UTC 2010 i686 GNU/Linux), running locally on VMWware
Workstation, and I'm connecting over the usual vmnet interface.

I'm mailing you off-list with results from the debug testing, so as to
avoid spamming the list with attachments.

-todb

I've worked with Tod off-list to solve this problem.
It turned out to be on application level and occurred due to connection exhaustion.
I've fixed this for the Oracle brute script and will probably do a more generic fix, allowing the brute library to 
detect this kind of problem, in the future.
The changes are commited as r22666.

Thanks, Patrik.

David Fifield
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: