Nmap Development mailing list archives

Re: [NSE] errors: path-mtu, dns-cache-snoop, and firewalk


From: Kris Katterjohn <katterjohn () gmail com>
Date: Wed, 10 Nov 2010 19:33:08 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 11/02/2010 02:54 PM, Kris Katterjohn wrote:
On 10/18/2010 08:05 PM, Ron wrote:
I didn't really collect much information, I was hoping there'd be an obvious cause. What I *can* tell you is that it 
didn't fail for every host, just for one or a couple. 
<snip>
Thanks.  Sorry, I've been busy and I forgot about this.

If possible, can you find the smallest scan (hosts and ports) which still
causes this problem and send me the output with debugging and script/packet
tracing turned on (off-list with altered addresses if you want)?  I can search
through the output if you can't narrow it down much, but it would just be
helpful if you can find a single host and port which can still cause this, if
the problem can even occur that way.

I'll try to examine this as soon as I can after I receive it and get back to
you (and the list) with something.


Last week Ron and I were discussing this and he sent me all kinds of data I
wanted to examine.  However, I'm having a hard time seeing any reason why
these failures are occurring (maybe it's a weird Linux fluke since he said
he's tested on Linux distros?  But then I would presume this would occur for
more hosts for more people).  I'll still look into it further when I have time.

In r21016 I've changed it so that raw IP send failures in NSE don't cause
scripts to bail with a backtrace.  This was actually the original design but
was changed in r20267, which was why the error Ron saw was so prominent
(path-mtu is designed to recognize send failures and just drop an MTU level
and try again).

Cheers,
Kris Katterjohn

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBAgAGBQJM20fTAAoJEEQxgFs5kUfu8cAP/0LJzmi2ih6yOCFxlJBhNDLZ
uPdQiVmtbdAvog8tD8+XwYiFgNQU/QzLPso3dVAymBhui1VALYnpHWKad4v13iR+
0yZk2xVAEOgqOzG3wH/D6PPqTV+7DW3X6oB2QPGPpm/uJs4PFWB8CaA3q8lH+POa
H4NpYE31VrinuTXFFfBneTq/cC5JuHWDUFfOHUymTUm1ApsZjfws9j9WqS1gG2FG
ARFiBPKAbln4vNLiEQ+KuLVlWe9BmxMED6326kVErrjDWG7c6JU2WX0bUNc2p9so
B/0r6XLNmy5VOOHkrPutTSc9G5HKno9teL7X2p/HVJAZ5lAMfhUlA7lIwsrHkXFx
thKpmkGpfpqESmj3noPsXos7qq2Tr4d1yHBo/S3YYiEcxTzj2H8FVSVUwfKUSsVK
KOKqciCpjKQtDvtlWxmS8M/DygL4fMe+nuM9pZcSj9Fcwr4y+veT36rm/Dc0UU7T
8HWfTAOhlzjuYiKkdEcZIfgcE3GTfIx8iJDfe5XdhFoLe7tD67M6trbSd1BpknFl
XJSyKLK5/B6bGnEeU9rIKiqeFlEZfWzOU/jLJ0aXfG6/GWkqDsaxF/G5OmGkne0y
aqoHRzCfzODh8h2lHsJIquLpjYMHAcxW5U5ec9j1k8PsNQ+2TDpTEMg7mZsXT0nX
VV/CYsUhZVcjdlqaQNwC
=bfhO
-----END PGP SIGNATURE-----
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: