Nmap Development mailing list archives

Re: [GSOC]2013 Web scanning specialist


From: Kaiyi Zhang <zky.own.star () gmail com>
Date: Sun, 28 Apr 2013 20:42:09 +0800

Hello David:
        I'm  sorry for replying your email so late. According to your
suggestions ,
I have read the document of NSE and the basic usage of Lua. It's very
useful
for contributing to the nmap script. the scriptes under the nmap are powful.
I tried to read some of  the source code
(http-brute.nse,http-auth.nse,nbstat.nse..).
It makes me excited. I tried to write my script to understand the NSE
better;
the http-server-info.nse is the script i wrote .this script referes to
http-header.nse.
But I add a function of location.
        I know it is starting point of my NSE Journey,there will be more
difficulties.
I believe i can overcome these difficulties. I hope to take part in this
gsoc ,not only imporving
my program technology  but also feeling the sprint of open source.

     To be honest, I have watched the video Mastering the Nmap Scripting
Engine when i first
contact nmap. you made  me a deep impression -capable brilliant.


2013/4/27 David Fifield <david () bamsoftware com>

On Fri, Apr 26, 2013 at 10:43:08PM +0800, Kaiyi Zhang wrote:
Hello everyone,
I'm Kaiyi Zhang,A Computer Science and Engineering studeng from Civil
Auiation University of China.I Headred the GSOC and I'm very
instersted in this, I look through manny projects until i see the "Web
scanning specialist".

I think it's very suitale for me,first I leaned the Infomation
Security Major which focus Security likes Nmap and I'm now focus on
web security.I got the sql injection,XSS,File upload etc. more is
going to learn. Second I hava a good knowledge of web.I can make one
site myself use ,css,javascript(Jquery), sql,php.and a little of jsp..
the most import is I love nmap.I want to contribute to nmap. I know
that is not enough for this porject.this need a google knowledge of
web not only php but also asp jsp and phthon. But I  believe i can get
these.one of my best technology is using the internet for the best
information i want. and i hava enough time to work on this.

I send for this email to see if i'm on the right track.

It sounds like you are on the right track with the skills needed for
the web scanning specialist. Perhaps more important than knowing web
technologies, is to know something about programming Lua. I recommend
that you read the book chapter on NSE, and take a look at some of the
existing web scripts.

http://nmap.org/book/nse.html
http://nmap.org/nsedoc/

David Fifield

Attachment: http-server-info.nse
Description:

_______________________________________________
Sent through the dev mailing list
http://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/

Current thread: