Updated nmap parsing, store notes for last boot and os matches

git-svn-id: file:///home/svn/framework3/trunk@8494 4d416f70-5f16-0410-b530-b9f4589650da
unstable
HD Moore 2010-02-14 19:07:15 +00:00
parent 2460037fdd
commit 2539a6fc09
2 changed files with 34 additions and 1 deletions

View File

@ -1123,7 +1123,7 @@ class DBManager
data[:state] = (h["status"] == "up") ? Msf::HostState::Alive : Msf::HostState::Dead data[:state] = (h["status"] == "up") ? Msf::HostState::Alive : Msf::HostState::Dead
# XXX: There can be multiple matches, but we only see the *last* right now # XXX: There can be multiple matches, but we only see the *last* right now
if (h["os_accuracy"] and h["os_accuracy"].to_i > 75) if (h["os_accuracy"] and h["os_accuracy"].to_i > 95)
data[:os_name] = h["os_vendor"] data[:os_name] = h["os_vendor"]
data[:os_sp] = h["os_version"] data[:os_sp] = h["os_version"]
end end
@ -1151,6 +1151,35 @@ class DBManager
report_host(data) report_host(data)
if( data[:os_name] )
note = {
:host => addr,
:type => 'host.os.nmap_fingerprint',
:data => {
:os_vendor => h["os_vendor"],
:os_family => h["os_family"],
:os_version => h["os_version"],
:os_accuracy => h["os_accuracy"]
}
}
if(h["os_match"])
note[:data][:os_match] = h['os_match']
end
report_note(note)
end
if (h["last_boot"])
report_note(
:host => addr,
:type => 'host.last_boot',
:data => {
:time => h["last_boot"]
}
)
end
# Put all the ports, regardless of state, into the db. # Put all the ports, regardless of state, into the db.
h["ports"].each { |p| h["ports"].each { |p|
extra = "" extra = ""

View File

@ -64,6 +64,10 @@ class NmapXMLStreamParser
@host["os_family"] = attributes["osfamily"] @host["os_family"] = attributes["osfamily"]
@host["os_version"] = attributes["osgen"] @host["os_version"] = attributes["osgen"]
@host["os_accuracy"] = attributes["accuracy"] @host["os_accuracy"] = attributes["accuracy"]
when "osmatch"
if(attributes["accuracy"].to_i == 100)
@host["os_match"] = attributes["name"]
end
when "uptime" when "uptime"
@host["last_boot"] = attributes["lastboot"] @host["last_boot"] = attributes["lastboot"]
when "hostname" when "hostname"