Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Correct Cisco PIX fingerprints to use OS rather than service fingerprint #170

Merged
merged 1 commit into from
Aug 21, 2018

Conversation

jhart-r7
Copy link
Contributor

The original code from which these recog fingerprints were derived expects Cisco PIX fingerprints to be for OS rather than service, which aligns with what is done in CPE. Why these were done with service looks like to be an oversight.

Copy link
Contributor

@tsellers-r7 tsellers-r7 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes look good. That being said the FP where a PIX munges the banners are suspect. IIRC, it routes the traffic through the firewall (as opposed to proxying the service) which means the target IP has a PIX in front of it, but isn't a PIX itself. https://blogs.it.ox.ac.uk/networks/2009/11/26/cisco-firewall-smtp-fixup-considered-harmful/comment-page-1/

@jhart-r7 jhart-r7 merged commit c35811b into rapid7:master Aug 21, 2018
@jhart-r7 jhart-r7 deleted the issue/pix branch October 10, 2018 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants