Re: Service identification

Robert Rich <[email protected]>
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
I say go for it.  Nmap's approach is fairly effective, but we won't know 
if it could be better without someone putting in the effort to try it a 
different way.  As part of Nessus, whatever you put together will 
certainly get its share of use.

 From my admittedly user-centric perspective, i'd toss out a few pennies 
of thought.

- nmaps service database is probably nearly as valuable as the code 
itself...might be a good idea to see if any of the information contained 
therein is usable in an alternate approach and start off with a fairly 
big database

- my biggest beef with the nmap service output is that it is just a 
single string...i like the vendor/product/release/misc (patch level, 
whatever)...it's not always easy to categorize products, but being able 
to roll up stuff by vendor or whatever is nice

- one of the things that helps nmap's database grow is the fingerprint 
output when a service has not been successfully identified... some 
ability for end users to upload a copy of the fingerprint with a 
positive ID of the service would ensure the list stays up to date

Were you planning on building it in nasl or C?



Michel Arboi wrote:

>Lionel CONS <[email protected]> writes:
>
>  
>
>>Why not using the results of "nmap -sV"?
>>    
>>
>
>For many reasons. The main one being that I don't believe in the
>technique used by nmap -sV. This does not mean that we will never use
>the output of nmap (I planned to rewrite the plugin as a NASL "trusted
>plugin"), anyway we will always have out own code.
>
>
>  
>
>>It's a pity to duplicate the code finding network services...
>>    
>>
>
>The code is not duplicated, it is different.
>_______________________________________________
>Nessus-devel mailing list
>[email protected]
>http://mail.nessus.org/mailman/listinfo/nessus-devel
>  
>

_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.