Re: Can you send the Nmap Project some scan data?
Robin Wood <[email protected]> Wed, 12 Jun 2019 17:14:28 +0100
| Newsgroups | gmane.comp.security.nmap.devel |
|---|---|
| Message-ID | <CALmccy6JW5G5X+NndR5uoNkvFweF-N3J8N9Xtzx1fSQ3t9+UUA@mail.gmail.com> |
--===============2498407597307378431== Content-Type: multipart/alternative; boundary="0000000000000620e3058b22b6c5" --0000000000000620e3058b22b6c5 Content-Type: text/plain; charset="UTF-8" Ok. I've not got many but I'll go over what I've got and send it over. Robin On Wed, 12 Jun 2019, 16:59 Daniel Miller, <[email protected]> wrote: > Robin, > > Thanks for asking. Any way that you are comfortable would be fine. I > assume most people would prefer to email directly, as it is a more private > way of sharing potentially sensitive data. > > Dan > > On Tue, Jun 11, 2019 at 1:56 AM Robin Wood <[email protected]> wrote: > >> How do you want them submitted? GitHub issues, mailed to the list or to >> you directly? >> >> Robin >> >> On Tue, 9 Oct 2018, 19:22 Daniel Miller, <[email protected]> wrote: >> >>> Nmap community members and developers, >>> >>> The Nmap Project is in need of current port scans in order to update the >>> open-port frequency data that Nmap uses to determine which ports to scan. >>> This data is used every time a user scans the default 1000 ports, and it is >>> based on scan data that is over 10 years old. A lot has changed in that >>> time, and Nmap's port data is no longer up-to-date. >>> >>> We are already doing scans of the public Internet for this purpose. What >>> we desperately need is port scans of *internal* networks, behind the >>> firewalls and NAT, from as many different sources as possible. Ideal data >>> would be all-port scans (-p 1-65535), but everything is helpful, especially >>> scans that include more than the current default 1000 ports or that include >>> UDP or SCTP port scan results. >>> >>> In order to make sharing scans safer and easier, I've attached a couple >>> of scripts that can be used to strip the output files of any identifying >>> information, including service and OS fingerprinting results, hostnames, IP >>> addresses, and traceroute data. Our preference is for XML output files, >>> which can be processed with nmap-sanitize.py. If you have gnmap scan output >>> instead, gnmap-convert.pl will convert it into a stripped-down XML >>> format. >>> >>> I really appreciate any help you can provide in this regard. Accurate >>> port frequency data will result in faster and more complete scan results >>> for everyone. >>> >>> Dan >>> >>> _______________________________________________ >>> Sent through the dev mailing list >>> https://nmap.org/mailman/listinfo/dev >>> Archived at http://seclists.org/nmap-dev/ >> >> --0000000000000620e3058b22b6c5 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">Ok. I've not got many but I'll go over what I'= ;ve got and send it over.<div dir=3D"auto"><br></div><div dir=3D"auto">Robi= n</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail= _attr">On Wed, 12 Jun 2019, 16:59 Daniel Miller, <<a href=3D"mailto:dmil= [email protected]">[email protected]</a>> wrote:<br></div><blockquote class=3D= "gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding= -left:1ex"><div dir=3D"ltr"><div>Robin,</div><div><br></div><div>Thanks for= asking. Any way that you are comfortable would be fine. I assume most peop= le would prefer to email directly, as it is a more private way of sharing p= otentially sensitive data.</div><div><br></div><div>Dan<br></div></div><br>= <div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Ju= n 11, 2019 at 1:56 AM Robin Wood <<a href=3D"mailto:[email protected]"= target=3D"_blank" rel=3D"noreferrer">[email protected]</a>> wrote:<br= ></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;= border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"auto">= How do you want them submitted? GitHub issues, mailed to the list or to you= directly?<div dir=3D"auto"><br></div><div dir=3D"auto">Robin</div></div><b= r><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, = 9 Oct 2018, 19:22 Daniel Miller, <<a href=3D"mailto:[email protected]" ta= rget=3D"_blank" rel=3D"noreferrer">[email protected]</a>> wrote:<br></div= ><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border= -left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div>Nm= ap community members and developers,</div><div><br></div><div><div>The Nmap= Project is in need of current port scans in order to=20 update the open-port frequency data that Nmap uses to determine which=20 ports to scan. This data is used every time a user scans the default=20 1000 ports, and it is based on scan data that is over 10 years old. A=20 lot has changed in that time, and Nmap's port data is no longer=20 up-to-date.</div><div><br></div><div>We are already doing scans of the=20 public Internet for this purpose. What we desperately need is port scans of *internal* networks, behind the firewalls and NAT, from as many=20 different sources as possible. Ideal data would be all-port scans (-p=20 1-65535), but everything is helpful, especially scans that include more=20 than the current default 1000 ports or that include UDP or SCTP port=20 scan results.<br></div><div><br></div><div>In order to make sharing=20 scans safer and easier, I've attached a couple of scripts that can be= =20 used to strip the output files of any identifying information, including service and OS fingerprinting results, hostnames, IP addresses, and=20 traceroute data. Our preference is for XML output files, which can be=20 processed with nmap-sanitize.py. If you have gnmap scan output instead, <a = href=3D"http://gnmap-convert.pl" rel=3D"noreferrer noreferrer" target=3D"_b= lank">gnmap-convert.pl</a> will convert it into a stripped-down XML format.= </div><div><br></div><div>I really appreciate any help you can provide in this regard. Accurate=20 port frequency data will result in faster and more complete scan results for everyone.</div><div><br></div><div>Dan<div class=3D"m_1582431819382787= 776gmail-m_3301304262682359378m_5574318596741730689gmail-adL"><br></div></d= iv></div></div> _______________________________________________<br> Sent through the dev mailing list<br> <a href=3D"https://nmap.org/mailman/listinfo/dev" rel=3D"noreferrer norefer= rer noreferrer" target=3D"_blank">https://nmap.org/mailman/listinfo/dev</a>= <br> Archived at <a href=3D"http://seclists.org/nmap-dev/" rel=3D"noreferrer nor= eferrer noreferrer" target=3D"_blank">http://seclists.org/nmap-dev/</a></bl= ockquote></div> </blockquote></div> </blockquote></div> --0000000000000620e3058b22b6c5-- --===============2498407597307378431== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Sent through the dev mailing list https://nmap.org/mailman/listinfo/dev Archived at http://seclists.org/nmap-dev/ --===============2498407597307378431==--