Menu

#1 Output Module bug with dual mode scan

0.4.7-2
open
nobody
4
2008-01-24
2008-01-24
No

When scanning TCP and UDP at the same time, the report module that displays to the screen will only show one Open per port per machine. Ie, if I scan an IP and both TCP and UDP 53 are open, it will only display the 1st protocol scanned as Open.

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
# time us scanme.insecure.org/32:mT,q scanme.insecure.org/32:mU,q -L4 -r10 -E
TCP open ssh[ 22] from 205.217.153.62 ttl 52
TCP closed smtp[ 25] from 205.217.153.62 ttl 52
TCP open domain[ 53] from 205.217.153.62 ttl 52
TCP closed gopher[ 70] from 205.217.153.62 ttl 52
TCP open http[ 80] from 205.217.153.62 ttl 52
TCP closed ident[ 113] from 205.217.153.62 ttl 52

real 0m56.200s
user 0m45.674s
sys 0m0.019s

***Note: tcp port 53 is open, nothing for UDP

=-=-=-=-=-=

# time us scanme.insecure.org/32:mU,q -L4 -r10 -E
UDP open domain[ 53] from 205.217.153.62 ttl 52

real 0m16.815s
user 0m10.918s
sys 0m0.009s

***Note: udp port 53 is actually responding

=-=-=-=-=-=

# time us scanme.insecure.org/32:mU,q scanme.insecure.org/32:mT,a -L7 -r75000 -E -w foo.pcap
TCP open ssh[ 22] from 205.217.153.62 ttl 52
TCP closed smtp[ 25] from 205.217.153.62 ttl 52
UDP open domain[ 53] from 205.217.153.62 ttl 52
TCP closed gopher[ 70] from 205.217.153.62 ttl 52
TCP open http[ 80] from 205.217.153.62 ttl 52
TCP closed ident[ 113] from 205.217.153.62 ttl 52

real 0m17.832s
user 0m0.435s
sys 0m0.592s

***Note: Now that I switched the order to perform the UDP scan first, the UDP port 53 is listed as open, while TCP is not.

=-=-=-=-=-=

# tcpdump -n -X -s0 -r foo.pcap port 53
reading from file foo.pcap, link-type EN10MB (Ethernet)
04:53:21.961845 IP 205.217.153.62.domain > 206.82.208.122.19796: 47760* 1/1/1 A 127.0.0.1 (85)
0x0000: 4500 0071 0000 4000 3411 4097 cdd9 993e E..q..@.4.@....>
0x0010: ce52 d07a 0035 4d54 005d c21c ba90 8580 .R.z.5MT.]......
0x0020: 0001 0001 0001 0001 096c 6f63 616c 686f .........localho
0x0030: 7374 0000 0100 01c0 0c00 0100 0100 0151 st.............Q
0x0040: 8000 047f 0000 01c0 0c00 0200 0100 0151 ...............Q
0x0050: 8000 02c0 0cc0 0c00 1c00 0100 0151 8000 .............Q..
0x0060: 1000 0000 0000 0000 0000 0000 0000 0000 ................
0x0070: 01 .
04:53:21.962323 IP 205.217.153.62.domain > 206.82.208.122.49878: 18295 0/13/1 (272)
0x0000: 4500 012c 0000 4000 3411 3fdc cdd9 993e E..,..@.4.?....>
0x0010: ce52 d07a 0035 c2d6 0118 870c 4777 8080 .R.z.5......Gw..
0x0020: 0001 0000 000d 0001 0236 3203 3135 3303 .........62.153.
0x0030: 3231 3703 3230 3507 696e 2d61 6464 7204 217.205.in-addr.
0x0040: 6172 7061 0000 0c00 0100 0002 0001 0007 arpa............
0x0050: 3b6c 0014 0141 0c52 4f4f 542d 5345 5256 ;l...A.ROOT-SERV
0x0060: 4552 5303 4e45 5400 0000 0200 0100 073b ERS.NET........;
0x0070: 6c00 0401 42c0 3a00 0002 0001 0007 3b6c l...B.:.......;l
0x0080: 0004 0143 c03a 0000 0200 0100 073b 6c00 ...C.:.......;l.
0x0090: 0401 44c0 3a00 0002 0001 0007 3b6c 0004 ..D.:.......;l..
0x00a0: 0145 c03a 0000 0200 0100 073b 6c00 0401 .E.:.......;l...
0x00b0: 46c0 3a00 0002 0001 0007 3b6c 0004 0147 F.:.......;l...G
0x00c0: c03a 0000 0200 0100 073b 6c00 0401 48c0 .:.......;l...H.
0x00d0: 3a00 0002 0001 0007 3b6c 0004 0149 c03a :.......;l...I.:
0x00e0: 0000 0200 0100 073b 6c00 0401 4ac0 3a00 .......;l...J.:.
0x00f0: 0002 0001 0007 3b6c 0004 014b c03a 0000 ......;l...K.:..
0x0100: 0200 0100 073b 6c00 0401 4cc0 3a00 0002 .....;l...L.:...
0x0110: 0001 0007 3b6c 0004 014d c03a c0cf 0001 ....;l...M.:....
0x0120: 0001 0008 8cec 0004 c03a 801e .........:..
04:53:21.962339 IP 205.217.153.62.domain > 206.82.208.122.46350: 10*- 1/1/0 CHAOS TXT "9.3.4" (62)
0x0000: 4500 005a 0000 4000 3411 40ae cdd9 993e E..Z..@.4.@....>
0x0010: ce52 d07a 0035 b50e 0046 9c61 000a 8500 .R.z.5...F.a....
0x0020: 0001 0001 0001 0000 0756 4552 5349 4f4e .........VERSION
0x0030: 0442 494e 4400 0010 0003 c00c 0010 0003 .BIND...........
0x0040: 0000 0000 0006 0539 2e33 2e34 c00c 0002 .......9.3.4....
0x0050: 0003 0000 0000 0002 c00c ..........
04:53:30.759968 IP 205.217.153.62.domain > 206.82.208.122.4744: S 1023296155:1023296155(0) ack 1961547797 win 5792 <mss 1460,sackOK,timestamp 3377673892 378686792,nop,wscale 7>
0x0000: 4500 003c 0000 4000 3406 40d7 cdd9 993e E..<..@.4.@....>
0x0010: ce52 d07a 0035 1288 3cfe 429b 74ea d815 .R.z.5..<.B.t...
0x0020: a012 16a0 e841 0000 0204 05b4 0402 080a .....A..........
0x0030: c953 36a4 1692 4d48 0103 0307 .S6...MH....

***Bug: Both TCP and UDP port 53 did respond, but the output module only listed the 1st protocol batch/match for the host:port combination.

Discussion


Log in to post a comment.