Nmap Development mailing list archives

Re: New script names


From: Fyodor <fyodor () insecure org>
Date: Thu, 6 Nov 2008 23:10:47 -0800

On Fri, Nov 07, 2008 at 08:16:36AM +0100, Dirk Loss wrote:
Fyodor wrote:
So for now I've changed the name to 'auth-spoof' and the description
to:
"Tests whether an identd (auth) server responds with an answer before
we even send the query.

IMHO 'auth-spoof' is a pretty generic name that could be used for 
'authentication spoofing' as well (e.g. 'SNMP HMAC Authentication 
Spoofing' [1] or 'RPC Authentication Spoofing' [2]).

So I suggest to name the script 'identd-spoof' instead, which would make 
it clearer to me that port 113 is tested.

Hi Dirk.  To be honest, identd-spoof was my first thought as well.
But Nmap reports port 113 as "auth", so I figure we might as well be
consistent.  We could potentially change nmap-services too, but my
suggestion of changing 'named' to 'dns' in that file didn't really get
a warm reception.  So I don't know that there is a lot of support for
chnging auth to ident or identd.

Cheers,
-F


_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org


Current thread: