New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

rexec-brute.nse returns false positives #1090

Closed
zjtmcozs opened this Issue Dec 20, 2017 · 2 comments

Comments

Projects
None yet
3 participants
@zjtmcozs

zjtmcozs commented Dec 20, 2017

The rexec-brute.nse script reports username:password combinations as "valid credentials" even though the response from the server is "rexecd: Login incorrect".

After looking at the source of the script it looks like it reports every tried user:pass combination as valid as long as the server sends a response. (https://svn.nmap.org/nmap/scripts/rexec-brute.nse)

@E3V3A

This comment has been minimized.

E3V3A commented Dec 29, 2017

The local link to rexec-brute.nse.
Do you know how to fix it? Then submit a PR.

@egypt

This comment has been minimized.

egypt commented Jan 13, 2018

Ran into this today. Modified the script to print the response and it looks like the server is sending "Authentication failed for user GUEST." which obviously isn't a successful execution.

@nmap-bot nmap-bot closed this in 59f819f Jan 22, 2018

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment