PaulDotCom mailing list archives

Looking for web app signatures for Nmap


From: Ron <ron () skullsecurity net>
Date: Wed, 3 Nov 2010 15:58:09 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hey all,

I'm trying to build a fingerprint database of common web applications for Nmap (anything from database frontends to 
security tools, routers, embedded devices, blog software, whatever you can think of). The problem is, I don't have 
access to a whole lot of stuff, and 'my friend bob' hasn't had all that much luck scanning the Internet to find random 
stuff. 

I wrote a blog about it here:
http://www.skullsecurity.org/blog/2010/a-call-to-arms-web-app-fingerprints-needed

And you can take a peek at what I already have here:
http://nmap.org/svn/nselib/data/http-fingerprints.lua

The current set of fingerprints isn't using any of the really interesting features yet, like pattern matching, 
capturing versions, etc. 

I'm hoping to spread the word and find people bored at work who can find fingerprints for the applications/management 
interfaces/etc that they use. Or, people who are kind enough to send me the .html from them, that's good too. 

So, please spread the word! 

Ron
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.16 (GNU/Linux)

iEYEARECAAYFAkzRzOUACgkQ2t2zxlt4g/T4MwCgzEM5vc5g0Qe3LvBS3ceOIIze
6DAAn3Xmh5/AEMvc99WvEMT0FmNf8xi+
=VIfO
-----END PGP SIGNATURE-----
_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com


Current thread: