rexec-brute.nse returns false positives #1090

Closed
zjtmcozs opened this Issue Dec 20, 2017 · 2 comments

Comments

Projects
None yet
3 participants
@zjtmcozs

zjtmcozs commented Dec 20, 2017

The rexec-brute.nse script reports username:password combinations as "valid credentials" even though the response from the server is "rexecd: Login incorrect".

After looking at the source of the script it looks like it reports every tried user:pass combination as valid as long as the server sends a response. (https://svn.nmap.org/nmap/scripts/rexec-brute.nse)

@E3V3A

This comment has been minimized.

Show comment
Hide comment
@E3V3A

E3V3A Dec 29, 2017

The local link to rexec-brute.nse.
Do you know how to fix it? Then submit a PR.

E3V3A commented Dec 29, 2017

The local link to rexec-brute.nse.
Do you know how to fix it? Then submit a PR.

@egypt

This comment has been minimized.

Show comment
Hide comment
@egypt

egypt Jan 13, 2018

Ran into this today. Modified the script to print the response and it looks like the server is sending "Authentication failed for user GUEST." which obviously isn't a successful execution.

egypt commented Jan 13, 2018

Ran into this today. Modified the script to print the response and it looks like the server is sending "Authentication failed for user GUEST." which obviously isn't a successful execution.

@nmap-bot nmap-bot closed this in 59f819f Jan 22, 2018

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment