Re: Can you send the Nmap Project some scan data?

Robin Wood <[email protected]> Wed, 12 Jun 2019 17:14:28 +0100
Newsgroups gmane.comp.security.nmap.devel
Message-ID <CALmccy6JW5G5X+NndR5uoNkvFweF-N3J8N9Xtzx1fSQ3t9+UUA@mail.gmail.com>
--===============2498407597307378431==
Content-Type: multipart/alternative; boundary="0000000000000620e3058b22b6c5"

--0000000000000620e3058b22b6c5
Content-Type: text/plain; charset="UTF-8"

Ok. I've not got many but I'll go over what I've got and send it over.

Robin

On Wed, 12 Jun 2019, 16:59 Daniel Miller, <[email protected]> wrote:

> Robin,
>
> Thanks for asking. Any way that you are comfortable would be fine. I
> assume most people would prefer to email directly, as it is a more private
> way of sharing potentially sensitive data.
>
> Dan
>
> On Tue, Jun 11, 2019 at 1:56 AM Robin Wood <[email protected]> wrote:
>
>> How do you want them submitted? GitHub issues, mailed to the list or to
>> you directly?
>>
>> Robin
>>
>> On Tue, 9 Oct 2018, 19:22 Daniel Miller, <[email protected]> wrote:
>>
>>> Nmap community members and developers,
>>>
>>> The Nmap Project is in need of current port scans in order to update the
>>> open-port frequency data that Nmap uses to determine which ports to scan.
>>> This data is used every time a user scans the default 1000 ports, and it is
>>> based on scan data that is over 10 years old. A lot has changed in that
>>> time, and Nmap's port data is no longer up-to-date.
>>>
>>> We are already doing scans of the public Internet for this purpose. What
>>> we desperately need is port scans of *internal* networks, behind the
>>> firewalls and NAT, from as many different sources as possible. Ideal data
>>> would be all-port scans (-p 1-65535), but everything is helpful, especially
>>> scans that include more than the current default 1000 ports or that include
>>> UDP or SCTP port scan results.
>>>
>>> In order to make sharing scans safer and easier, I've attached a couple
>>> of scripts that can be used to strip the output files of any identifying
>>> information, including service and OS fingerprinting results, hostnames, IP
>>> addresses, and traceroute data. Our preference is for XML output files,
>>> which can be processed with nmap-sanitize.py. If you have gnmap scan output
>>> instead, gnmap-convert.pl will convert it into a stripped-down XML
>>> format.
>>>
>>> I really appreciate any help you can provide in this regard. Accurate
>>> port frequency data will result in faster and more complete scan results
>>> for everyone.
>>>
>>> Dan
>>>
>>> _______________________________________________
>>> Sent through the dev mailing list
>>> https://nmap.org/mailman/listinfo/dev
>>> Archived at http://seclists.org/nmap-dev/
>>
>>

--0000000000000620e3058b22b6c5
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">Ok. I&#39;ve not got many but I&#39;ll go over what I&#39=
;ve got and send it over.<div dir=3D"auto"><br></div><div dir=3D"auto">Robi=
n</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail=
_attr">On Wed, 12 Jun 2019, 16:59 Daniel Miller, &lt;<a href=3D"mailto:dmil=
[email protected]">[email protected]</a>&gt; wrote:<br></div><blockquote class=3D=
"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding=
-left:1ex"><div dir=3D"ltr"><div>Robin,</div><div><br></div><div>Thanks for=
 asking. Any way that you are comfortable would be fine. I assume most peop=
le would prefer to email directly, as it is a more private way of sharing p=
otentially sensitive data.</div><div><br></div><div>Dan<br></div></div><br>=
<div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Ju=
n 11, 2019 at 1:56 AM Robin Wood &lt;<a href=3D"mailto:[email protected]"=
 target=3D"_blank" rel=3D"noreferrer">[email protected]</a>&gt; wrote:<br=
></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;=
border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"auto">=
How do you want them submitted? GitHub issues, mailed to the list or to you=
 directly?<div dir=3D"auto"><br></div><div dir=3D"auto">Robin</div></div><b=
r><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, =
9 Oct 2018, 19:22 Daniel Miller, &lt;<a href=3D"mailto:[email protected]" ta=
rget=3D"_blank" rel=3D"noreferrer">[email protected]</a>&gt; wrote:<br></div=
><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border=
-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div>Nm=
ap community members and developers,</div><div><br></div><div><div>The Nmap=
 Project is in need of current port scans in order to=20
update the open-port frequency data that Nmap uses to determine which=20
ports to scan. This data is used every time a user scans the default=20
1000 ports, and it is based on scan data that is over 10 years old. A=20
lot has changed in that time, and Nmap&#39;s port data is no longer=20
up-to-date.</div><div><br></div><div>We are already doing scans of the=20
public Internet for this purpose. What we desperately need is port scans
 of *internal* networks, behind the firewalls and NAT, from as many=20
different sources as possible. Ideal data would be all-port scans (-p=20
1-65535), but everything is helpful, especially scans that include more=20
than the current default 1000 ports or that include UDP or SCTP port=20
scan results.<br></div><div><br></div><div>In order to make sharing=20
scans safer and easier, I&#39;ve attached a couple of scripts that can be=
=20
used to strip the output files of any identifying information, including
 service and OS fingerprinting results, hostnames, IP addresses, and=20
traceroute data. Our preference is for XML output files, which can be=20
processed with nmap-sanitize.py. If you have gnmap scan output instead, <a =
href=3D"http://gnmap-convert.pl" rel=3D"noreferrer noreferrer" target=3D"_b=
lank">gnmap-convert.pl</a> will convert it into a stripped-down XML format.=
</div><div><br></div><div>I
 really appreciate any help you can provide in this regard. Accurate=20
port frequency data will result in faster and more complete scan results
 for everyone.</div><div><br></div><div>Dan<div class=3D"m_1582431819382787=
776gmail-m_3301304262682359378m_5574318596741730689gmail-adL"><br></div></d=
iv></div></div>
_______________________________________________<br>
Sent through the dev mailing list<br>
<a href=3D"https://nmap.org/mailman/listinfo/dev" rel=3D"noreferrer norefer=
rer noreferrer" target=3D"_blank">https://nmap.org/mailman/listinfo/dev</a>=
<br>
Archived at <a href=3D"http://seclists.org/nmap-dev/" rel=3D"noreferrer nor=
eferrer noreferrer" target=3D"_blank">http://seclists.org/nmap-dev/</a></bl=
ockquote></div>
</blockquote></div>
</blockquote></div>

--0000000000000620e3058b22b6c5--

--===============2498407597307378431==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/
--===============2498407597307378431==--