Nmap Development mailing list archives

Re: Unbounded memory use in drda-info


From: Fyodor <fyodor () insecure org>
Date: Sun, 8 May 2011 12:22:36 -0700

On Wed, May 04, 2011 at 05:13:20PM -0700, David Fifield wrote:
drda-info uses up all my memory when I run this command:

      nmap --script=drda-info localhost -p 50000 -d2

against this server:

      ncat -lk -v 50000 --sh-exec "echo foo"

Good catch, I can reproduce it.  My Nmap process grew to more than a
gigabyte in seconds (then I quit with ^C).  At least drda-info is not
in default category.  I'll add this to Nmap TODO now.

Cheers,
Fyodor
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: