Server : Apache/2.4.18 (Ubuntu) System : Linux canvaswebdesign 3.13.0-71-generic #114-Ubuntu SMP Tue Dec 1 02:34:22 UTC 2015 x86_64 User : oppastar ( 1041) PHP Version : 7.0.33-0ubuntu0.16.04.15 Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority, Directory : /usr/share/nmap/scripts/ |
Upload File : |
local nmap = require "nmap" local shortport = require "shortport" local string = require "string" description = [[ Checks if an SSH server supports the obsolete and less secure SSH Protocol Version 1. ]] author = "Brandon Enright" license = "Same as Nmap--See https://nmap.org/book/man-legal.html" categories = {"default", "safe"} --- -- @output -- PORT STATE SERVICE -- 22/tcp open ssh -- |_sshv1: Server supports SSHv1 -- -- @xmloutput -- true portrule = shortport.port_or_service(22, "ssh") action = function(host, port) local socket = nmap.new_socket() local result; local status = true; socket:connect(host, port) status, result = socket:receive_lines(1); if (not status) then socket:close() return end if (result == "TIMEOUT") then socket:close() return end if not string.match(result, "^SSH%-.+\n$") then socket:close() return end socket:send("SSH-1.5-NmapNSE_1.0\n") -- should be able to consume at least 13 bytes -- key length is a 4 byte integer -- padding is between 1 and 8 bytes -- type is one byte -- key is at least several bytes status, result = socket:receive_bytes(13); if (not status) then socket:close() return end if (result == "TIMEOUT") then socket:close() return end if not string.match(result, "^....[\0]+\002") then socket:close() return end socket:close(); return true, "Server supports SSHv1" end