<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-394</id>
	<title>Nabble - Nmap - Hackers</title>
	<updated>2009-09-28T04:18:30Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Nmap---Hackers-f394.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap---Hackers-f394.html" />
	<subtitle type="html">Moderated list for announcements, patches, and light discussion regarding the Nmap Security Scanner and related projects. - comments provided by seclists.org</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-25644042</id>
	<title>Diagramming networks</title>
	<published>2009-09-28T04:18:30Z</published>
	<updated>2009-09-28T04:18:30Z</updated>
	<author>
		<name>oliverm</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;Is there any addon for NMAP that will allow me to export network diagrams as visio files or some other file type that i can then use to edit and tidy the diagrams up &amp;nbsp;?
&lt;br&gt;&lt;br&gt;Olly</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Diagramming-networks-tp25644042p25644042.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25510603</id>
	<title>Nmap -sC -oG file.xml</title>
	<published>2009-09-18T08:21:13Z</published>
	<updated>2009-09-18T08:21:13Z</updated>
	<author>
		<name>lowtone</name>
	</author>
	<content type="html">I am unable to get the output from script scan in the grep format. I use -oX and try the powershell parser still no script scan data. Would love to get this in -oG any way to do that?</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap--sC--oG-file.xml-tp25510603p25510603.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25367721</id>
	<title>How to scan a secure network</title>
	<published>2009-09-09T08:43:05Z</published>
	<updated>2009-09-09T08:43:05Z</updated>
	<author>
		<name>RedWind</name>
	</author>
	<content type="html">I have tried scaning a network for computer but the network is very secure and blocks a lot of scans is there a way to scan these without being pucked up on</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/How-to-scan-a-secure-network-tp25367721p25367721.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24521069</id>
	<title>Nmap 5.00 Released!</title>
	<published>2009-07-16T10:03:52Z</published>
	<updated>2009-07-16T10:03:52Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">Hello everyone. &amp;nbsp;I'm delighted to announce the release of Nmap 5.00!
&lt;br&gt;This is the first major release since 4.50 in 2007, and includes about
&lt;br&gt;600 significant changes since then! &amp;nbsp;We consider this the most
&lt;br&gt;important Nmap release since 1997, and we recommend that all current
&lt;br&gt;users upgrade.
&lt;br&gt;&lt;br&gt;There are too many changes to list them all in this email, so here are
&lt;br&gt;the top 5 improvements in Nmap 5:
&lt;br&gt;&lt;br&gt;1) The new Ncat tool aims to be your Swiss Army Knife for data
&lt;br&gt;&amp;nbsp; &amp;nbsp;transfer, redirection, and debugging. We released a whole users'
&lt;br&gt;&amp;nbsp; &amp;nbsp;guide (&lt;a href=&quot;http://nmap.org/ncat/guide/index.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/ncat/guide/index.html&lt;/a&gt;) detailing security
&lt;br&gt;&amp;nbsp; &amp;nbsp;testing and network administration tasks it made easy with Ncat.
&lt;br&gt;&amp;nbsp; &amp;nbsp;Details: &lt;a href=&quot;http://nmap.org/5/#changes-ncat&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/5/#changes-ncat&lt;/a&gt;&lt;br&gt;&lt;br&gt;2) The addition of the Ndiff scan comparison tool completes Nmap's
&lt;br&gt;&amp;nbsp; &amp;nbsp;growth into a whole suite of applications which work together to
&lt;br&gt;&amp;nbsp; &amp;nbsp;serve network administrators and security practitioners. Ndiff
&lt;br&gt;&amp;nbsp; &amp;nbsp;makes it easy to automatically scan your network daily and report
&lt;br&gt;&amp;nbsp; &amp;nbsp;on any changes (systems coming up or going down or changes to the
&lt;br&gt;&amp;nbsp; &amp;nbsp;software services they are running). The other two tools now
&lt;br&gt;&amp;nbsp; &amp;nbsp;packaged with Nmap itself are Ncat and the much improved Zenmap GUI
&lt;br&gt;&amp;nbsp; &amp;nbsp;and results viewer. &amp;nbsp;Details: &lt;a href=&quot;http://nmap.org/5/#changes-ndiff&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/5/#changes-ndiff&lt;/a&gt;&lt;br&gt;&lt;br&gt;3) Nmap performance has improved dramatically. We spent last summer
&lt;br&gt;&amp;nbsp; &amp;nbsp;scanning much of the Internet and merging that data with internal
&lt;br&gt;&amp;nbsp; &amp;nbsp;enterprise scan logs to determine the most commonly open
&lt;br&gt;&amp;nbsp; &amp;nbsp;ports. This allows Nmap to scan fewer ports by default while
&lt;br&gt;&amp;nbsp; &amp;nbsp;finding more open ports. We also added a fixed-rate scan engine so
&lt;br&gt;&amp;nbsp; &amp;nbsp;you can bypass Nmap's congestion control algorithms and scan at
&lt;br&gt;&amp;nbsp; &amp;nbsp;exactly the rate (packets per second) you specify. &amp;nbsp;Details:
&lt;br&gt;&amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://nmap.org/5/#changes-performance&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/5/#changes-performance&lt;/a&gt;&lt;br&gt;&lt;br&gt;4) We released Nmap Network Scanning, the official Nmap guide to
&lt;br&gt;&amp;nbsp; &amp;nbsp;network discovery and security scanning. From explaining port
&lt;br&gt;&amp;nbsp; &amp;nbsp;scanning basics for novices to detailing low-level packet crafting
&lt;br&gt;&amp;nbsp; &amp;nbsp;methods used by advanced hackers, this book suits all levels of
&lt;br&gt;&amp;nbsp; &amp;nbsp;security and networking professionals. A 42-page reference guide
&lt;br&gt;&amp;nbsp; &amp;nbsp;documents every Nmap feature and option, while the rest of the book
&lt;br&gt;&amp;nbsp; &amp;nbsp;demonstrates how to apply those features to quickly solve
&lt;br&gt;&amp;nbsp; &amp;nbsp;real-world tasks. More than half the book is available in the free
&lt;br&gt;&amp;nbsp; &amp;nbsp;online edition at &lt;a href=&quot;http://nmap.org/book/toc.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/toc.html&lt;/a&gt;. &amp;nbsp;Details:
&lt;br&gt;&amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://nmap.org/5/#changes-book&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/5/#changes-book&lt;/a&gt;&lt;br&gt;&lt;br&gt;5) The Nmap Scripting Engine (NSE) is one of Nmap's most powerful and
&lt;br&gt;&amp;nbsp; &amp;nbsp;flexible features. It allows users to write (and share) simple
&lt;br&gt;&amp;nbsp; &amp;nbsp;scripts to automate a wide variety of networking tasks. Those
&lt;br&gt;&amp;nbsp; &amp;nbsp;scripts are then executed in parallel with the speed and efficiency
&lt;br&gt;&amp;nbsp; &amp;nbsp;you expect from Nmap. All existing scripts have been improved, and
&lt;br&gt;&amp;nbsp; &amp;nbsp;32 new ones added. New scripts include a whole bunch of
&lt;br&gt;&amp;nbsp; &amp;nbsp;MSRPC/NetBIOS attacks, queries, and vulnerability probes; open
&lt;br&gt;&amp;nbsp; &amp;nbsp;proxy detection; whois and AS number lookup queries; brute force
&lt;br&gt;&amp;nbsp; &amp;nbsp;attack scripts against the SNMP and POP3 protocols; and many
&lt;br&gt;&amp;nbsp; &amp;nbsp;more. All NSE scripts and modules are described in the new NSE
&lt;br&gt;&amp;nbsp; &amp;nbsp;documentation portal. &amp;nbsp;Details: &lt;a href=&quot;http://nmap.org/5/#changes-nse&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/5/#changes-nse&lt;/a&gt;&lt;br&gt;&lt;br&gt;To learn about even more changes, see the full release notes here:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/5/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/5/&lt;/a&gt;&lt;br&gt;&lt;br&gt;The Nmap 5.00 source code and Linux, Mac, and Windows packages are
&lt;br&gt;available for download at the usual place:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/download.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/download.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Go give it a try! &amp;nbsp;And if you find any bugs, let us know on nmap-dev
&lt;br&gt;(&lt;a href=&quot;http://nmap.org/book/man-bugs.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/man-bugs.html&lt;/a&gt;).
&lt;br&gt;&lt;br&gt;As an open source project, we don't have a marketing budget. &amp;nbsp;So
&lt;br&gt;please help spread the word about the new release! &amp;nbsp;I encounter many
&lt;br&gt;folks at security conferences who have been using Nmap for more than a
&lt;br&gt;decade but just as a simple port scanner and never learned about the
&lt;br&gt;newer features. &amp;nbsp;So this is our chance to spread the word about NSE,
&lt;br&gt;Ncat, Ndiff, Zenmap, and all the other great things Nmap has to offer!
&lt;br&gt;&lt;br&gt;Enjoy the new release!
&lt;br&gt;-Fyodor
&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap-5.00-Released%21-tp24521069p24521069.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24517094</id>
	<title>Re: nmap OS detection</title>
	<published>2009-07-16T07:06:24Z</published>
	<updated>2009-07-16T07:06:24Z</updated>
	<author>
		<name>PPPP</name>
	</author>
	<content type="html">What version are you using? &amp;nbsp;
&lt;br&gt;&lt;br&gt;I'm using 4.76 and it seems to work fairly well in a Windows environment.
&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;nandkishorejk wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message&quot;&gt;i am trying to run nmap scan in Windows environment for os detection...
&lt;br&gt;but i am getting the error message as &amp;quot;Too many fingerprints match this host to give specific OS details&amp;quot;
&lt;br&gt;Please suggest how can i overcome this problem
&lt;br&gt;&lt;br&gt;it would be very helpful if someone specifies a model example that i can use on command line to solve my problem,
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nmap-OS-detection-tp24500591p24517094.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24500591</id>
	<title>nmap OS detection</title>
	<published>2009-07-15T08:41:59Z</published>
	<updated>2009-07-15T08:41:59Z</updated>
	<author>
		<name>nandkishorejk</name>
	</author>
	<content type="html">i am trying to run nmap scan in Windows environment for os detection...
&lt;br&gt;but i am getting the error message as &amp;quot;Too many fingerprints match this host to give specific OS details&amp;quot;
&lt;br&gt;Please suggest how can i overcome this problem
&lt;br&gt;&lt;br&gt;it would be very helpful if someone specifies a model example that i can use on command line to solve my problem,
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nmap-OS-detection-tp24500591p24500591.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24227456</id>
	<title>Nmap news: stable release candidate 4.90RC1, SoC team, and new translations</title>
	<published>2009-06-26T14:04:44Z</published>
	<updated>2009-06-26T14:04:44Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">Hi Folks. &amp;nbsp;I'm pleased to announce some exciting Nmap news:
&lt;br&gt;&lt;br&gt;[=================Nmap 4.90RC1==================]
&lt;br&gt;&lt;br&gt;It has been nearly 10 months (and 11 dev releases) since 4.76, the
&lt;br&gt;last stable Nmap release. &amp;nbsp;And we've made many dramatic changes, so it
&lt;br&gt;is time for a new stable version! &amp;nbsp;I've posted a release
&lt;br&gt;candidate--4.90RC1--on the Nmap download page:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/download.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/download.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Please test it out, and let us know if you find any problems (bug
&lt;br&gt;reporting instructions: &lt;a href=&quot;http://nmap.org/book/man-bugs.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/man-bugs.html&lt;/a&gt;). &amp;nbsp;If this
&lt;br&gt;gets some good testing and no show-stopper bugs are discovered, we
&lt;br&gt;hope to do the major release next week.
&lt;br&gt;&lt;br&gt;Changes are too numerous to list here, but you can find them at
&lt;br&gt;&lt;a href=&quot;http://nmap.org/changelog.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/changelog.html&lt;/a&gt;. &amp;nbsp;There are more than 100 significant
&lt;br&gt;changes in the five releases since the last one I sent to this list
&lt;br&gt;(4.85BETA6).
&lt;br&gt;&lt;br&gt;[=================Summer of Code==================]
&lt;br&gt;&lt;br&gt;I'm pleased to introduce the 2009 Nmap/Google Summer of Code team! &amp;nbsp;We
&lt;br&gt;have six students working hard on a network authentication cracker
&lt;br&gt;(ncrack), a raw packet prober (nping), the Nmap Scripting Engine, and
&lt;br&gt;more:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://seclists.org/nmap-dev/2009/q2/0317.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2009/q2/0317.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;You can follow their progress on the nmap-dev mailing list, where they
&lt;br&gt;post updates every Monday night:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://seclists.org/#nmap-dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/#nmap-dev&lt;/a&gt;&lt;br&gt;&lt;br&gt;[=================Twitter==================]
&lt;br&gt;&lt;br&gt;We've been posting news tidbits (only 1 or 2 a week) to Twitter. &amp;nbsp;You
&lt;br&gt;can follow us at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://twitter.com/nmap/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/nmap/&lt;/a&gt;&lt;br&gt;&lt;br&gt;[=================Translation News==================]
&lt;br&gt;&lt;br&gt;Open Source Press has just released their German translation of Nmap
&lt;br&gt;Network Scanning. I worked closely with Dinu Gherman, who did the
&lt;br&gt;actual translating, and Dr. Markus Wirtz, who runs things there and
&lt;br&gt;took a great interest in the book. It is currently featured on their
&lt;br&gt;front page at &lt;a href=&quot;https://www.opensourcepress.de/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.opensourcepress.de/&lt;/a&gt;&amp;nbsp;and the detail page for
&lt;br&gt;Nmap Netzwerke Scannen, Analysieren und Absichern is at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;https://www.opensourcepress.de/index.php?26&amp;backPID=178&amp;tt_products=270&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.opensourcepress.de/index.php?26&amp;backPID=178&amp;tt_products=270&lt;/a&gt;&lt;br&gt;&lt;br&gt;Open Source Press also contributed their German translation of the
&lt;br&gt;Nmap Reference Guide so we could post it free online:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/man/de/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/man/de/&lt;/a&gt;&lt;br&gt;&lt;br&gt;I'm also happy to announce another new Nmap Reference Guide
&lt;br&gt;translation: Indonesian by Tedi Heriyanto. Here it is:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/man/id/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/man/id/&lt;/a&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;We now have the Nmap Reference Guide in 16 languages! You can see
&lt;br&gt;them all here:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/docs.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/docs.html&lt;/a&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;While 16 languages is great, we're always looking for new
&lt;br&gt;translations! If you speak a language other than those 16 (or think
&lt;br&gt;an existing translation needs to be updated/improved) and would like
&lt;br&gt;to help, let me know! Here are the translation instructions:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/xlate-faq.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/xlate-faq.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;We're also always on the lookout for translators for the Zenmap
&lt;br&gt;frontend. This is a substantially easier job than translating the
&lt;br&gt;whole reference guide. And so far, we only have translations to
&lt;br&gt;German, French, Hungarian, and Brazilian Portuguese. If you'd like to
&lt;br&gt;add your native language, see:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/zenmap-lang.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/zenmap-lang.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Official Brazilian Portuguese and Korean translations of the whole
&lt;br&gt;Nmap Network Scanning book are on the way. &amp;nbsp;The English version
&lt;br&gt;continues to be a best-seller, and I'm pleased to see some great
&lt;br&gt;reviews:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/#reviews&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/#reviews&lt;/a&gt;&lt;br&gt;&lt;br&gt;[=================FIN==================]
&lt;br&gt;&lt;br&gt;That is all for now. &amp;nbsp;Happy hacking!
&lt;br&gt;&lt;br&gt;-Fyodor
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap-news%3A-stable-release-candidate-4.90RC1%2C-SoC-team%2C-and-new-translations-tp24227456p24227456.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24032203</id>
	<title>nmap killt internet-connection</title>
	<published>2009-06-15T03:25:54Z</published>
	<updated>2009-06-15T03:25:54Z</updated>
	<author>
		<name>sshot</name>
	</author>
	<content type="html">Hi@all!
&lt;br&gt;&lt;br&gt;I use nmap on my computer which runs sygate personal firewall.
&lt;br&gt;When I scan a target nmap delivers results but when the scan is finished
&lt;br&gt;my Internet-Connection is not available, I can not even access Lan-Resources.
&lt;br&gt;When I do a ping to any host the dos-box answers: Hardware-Error.
&lt;br&gt;When I deactivate the Sygate-Wall, everything works ok.
&lt;br&gt;Any Idea what this is?
&lt;br&gt;&lt;br&gt;Greetings from Germay
&lt;br&gt;&lt;br&gt;Tobi</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nmap-killt-internet-connection-tp24032203p24032203.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23175835</id>
	<title>Need a hacker</title>
	<published>2009-04-22T13:06:12Z</published>
	<updated>2009-04-22T13:06:12Z</updated>
	<author>
		<name>Gandolfini</name>
	</author>
	<content type="html">&lt;br&gt;Can a hacker please send me a pm</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Need-a-hacker-tp23175835p23175835.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23175511</id>
	<title>How to crack the news sistem</title>
	<published>2009-04-22T08:02:49Z</published>
	<updated>2009-04-22T08:02:49Z</updated>
	<author>
		<name>babemb</name>
	</author>
	<content type="html">Hi to everybody, i'd like to now if enyone ever tried to crack a news sistem. My specific interest is to find a way to recive and view videoclips from the APTN network, wich is one of the most important international video provider for broadcasters like CNN, BBC and so on. 
&lt;br&gt;This kind of providers use satellite connection to redistribute videos all over the word and national televisions can use them to creaet news. The problem is that when we watch the tv this images have been cutted and mixet on the discretion of each channel and we loose the capacity of a personal interpretation.
&lt;br&gt;This is the reason why I'd like to find a way to watch original clips without spending the enormous amount of money that a regular subscription to APTN requires, and that joust a great broadcasting network can effort.
&lt;br&gt;Please help me if you can.
&lt;br&gt;&lt;br&gt;Babemb</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/How-to-crack-the-news-sistem-tp23175511p23175511.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22821106</id>
	<title>Nmap 4.85BETA6 now avail w/Conficker detection</title>
	<published>2009-03-31T17:04:29Z</published>
	<updated>2009-03-31T17:04:29Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">Hi Folks! &amp;nbsp;In case you missed all the news reports yesterday, a couple
&lt;br&gt;great researchers from the Honeynet Project (Tillmann Werner and Felix
&lt;br&gt;Leder) and Dan Kaminsky came up with a way to remotely detect the
&lt;br&gt;Conficker worm which has infected millions of machines worldwide.
&lt;br&gt;Some say 15,000,000 machines infected, but that might just be
&lt;br&gt;exaggerated AV-company BS for all I know. &amp;nbsp;But there are clearly
&lt;br&gt;millions of infections, and this massive botnet is scheduled for a new
&lt;br&gt;update cycle starting tomorrow. &amp;nbsp;Will this cause Internet doom? &amp;nbsp;No,
&lt;br&gt;but the bad guys might fix the mechanism that lets us remotely detect
&lt;br&gt;'em. &amp;nbsp;Or they might engage in other mischief with their botnet.
&lt;br&gt;That's why we did the emergency releases--so you can scan for and
&lt;br&gt;remove them early! &amp;nbsp;During the process, I had to infect one of my
&lt;br&gt;systems with Conficker for testing, and Nmap even got booted from
&lt;br&gt;Dreamhost's &amp;quot;unlimited bandwidth&amp;quot; hosting because the downloads were
&lt;br&gt;taking too much bandwidth. &amp;nbsp;They said:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;quot;Sadly your file nmap-4.85BETA5-setup.exe, and a few similar, were
&lt;br&gt;&amp;nbsp; &amp;nbsp;getting so many downloads on your machine, iceman, that it
&lt;br&gt;&amp;nbsp; &amp;nbsp;saturated out the 100mbit connection on it, and cause everyone
&lt;br&gt;&amp;nbsp; &amp;nbsp;else's sites to go down.&amp;quot;
&lt;br&gt;&lt;br&gt;Dreamhost blocked further downloads, but we quickly switched to using
&lt;br&gt;our colocation provider and also got some mirroring help from Brandon
&lt;br&gt;Enright at UCSD! &amp;nbsp;So UCSD is hosting 4.85BETA6. &amp;nbsp;Of course I'd like to
&lt;br&gt;thank Ron Bowes who wrote the detection code (it is an update to his
&lt;br&gt;existing smb-check-vulns SMB script). &amp;nbsp;David Fifield was a huge help
&lt;br&gt;too.
&lt;br&gt;&lt;br&gt;An example Conficker scan command is:
&lt;br&gt;&lt;br&gt;nmap -PN -T4 -p139,445 -n -v --script=smb-check-vulns --script-args safe=1 [targetnets]
&lt;br&gt;&lt;br&gt;A clean machine should report at the bottom: &amp;quot;Conficker: Likely
&lt;br&gt;Clean&amp;quot;, while likely infected machines report &amp;quot;Conflicker: Likely
&lt;br&gt;INFECTED&amp;quot;. &amp;nbsp;For more details and updates, see our announcement here:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://insecure.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://insecure.org/&lt;/a&gt;&lt;br&gt;&lt;br&gt;And of course to download Nmap 4.85BETA6, see:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/download.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/download.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Of course we have some other nice improvements besides Conficker
&lt;br&gt;detection. &amp;nbsp;Here are the changes since BETA4:
&lt;br&gt;&lt;br&gt;Nmap 4.85BETA6 [2009-03-31]
&lt;br&gt;&lt;br&gt;o Fixed some bugs with the Conficker detection script
&lt;br&gt;&amp;nbsp;(smb-check-vulns) [Ron]:
&lt;br&gt;&amp;nbsp;o SMB response timeout raised to 20s from 5s to compensate for
&lt;br&gt;&amp;nbsp; &amp;nbsp;slow/overloaded systems and networks.
&lt;br&gt;&amp;nbsp;o MSRPC now only signs messages if OpenSSL is available (avoids an
&lt;br&gt;&amp;nbsp; &amp;nbsp;error).
&lt;br&gt;&amp;nbsp;o Better error checking for MS08-067 patch
&lt;br&gt;&amp;nbsp;o Fixed forgotten endian-modifier (caused problems on big-endian
&lt;br&gt;&amp;nbsp; &amp;nbsp;systems such as Solaris on SPARC).
&lt;br&gt;&lt;br&gt;o Host status messages (up/down) are now uniform between ping scanning
&lt;br&gt;&amp;nbsp; and port scanning and include more information. They used to vary
&lt;br&gt;&amp;nbsp; slightly, but now all look like
&lt;br&gt;&amp;nbsp; &amp;nbsp; Host &amp;nbsp;is up (Xs latency).
&lt;br&gt;&amp;nbsp; &amp;nbsp; Host &amp;nbsp;is down.
&lt;br&gt;&amp;nbsp; The new latency information is Nmap's estimate of the round trip
&lt;br&gt;&amp;nbsp; time. In addition, the reason for a host being up is now printed for
&lt;br&gt;&amp;nbsp; port scans just as for ping scans, with the --reason option. [David]
&lt;br&gt;&lt;br&gt;o Version detection now has a generic match line for SSLv3 servers,
&lt;br&gt;&amp;nbsp; which matches more servers than the already-existing set of specific
&lt;br&gt;&amp;nbsp; match lines. The match line found 13% more SSL servers in a test.
&lt;br&gt;&amp;nbsp; Note that Nmap will not be able to do SSL scan-through against a
&lt;br&gt;&amp;nbsp; small fraction of these servers, those that are SSLv3-only or
&lt;br&gt;&amp;nbsp; TLSv1-only, because that ability is not yet built into Nsock. There
&lt;br&gt;&amp;nbsp; is also a new version detection probe that works against SSLv2-only
&lt;br&gt;&amp;nbsp; servers. These have shown themselves to be very rare, so that probe
&lt;br&gt;&amp;nbsp; is not sent by default. Kristof Boeynaems provided the patch and did
&lt;br&gt;&amp;nbsp; the testing.
&lt;br&gt;&lt;br&gt;o [Zenmap] A typo that led to a crash if the ndiff subprocess
&lt;br&gt;&amp;nbsp; terminated with an error was fixed. [David] The message was
&lt;br&gt;&amp;nbsp; &amp;nbsp; File &amp;quot;zenmapGUI\DiffCompare.pyo&amp;quot;, line 331, in check_ndiff_process
&lt;br&gt;&amp;nbsp; UnboundLocalError: local variable 'error_test' referenced before assignment
&lt;br&gt;&lt;br&gt;o [Zenmap] A crash was fixed:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; File &amp;quot;zenmapGUI\SearchGUI.pyo&amp;quot;, line 582, in operator_changed
&lt;br&gt;&amp;nbsp; &amp;nbsp; KeyError: &amp;quot;Syst\xc3\xa8me d'Exploitation&amp;quot;
&lt;br&gt;&amp;nbsp; The text could be different, because the error was caused by
&lt;br&gt;&amp;nbsp; translating a string that was also being used as an index into an
&lt;br&gt;&amp;nbsp; internal data structure. The string will be untranslated until that
&lt;br&gt;&amp;nbsp; part of the code can be rewritten. [David]
&lt;br&gt;&lt;br&gt;o [Zenmap] A bug was fixed that caused a crash when doing a keyword:
&lt;br&gt;&amp;nbsp; or target: search over hosts that had a MAC address. [David] 
&lt;br&gt;&amp;nbsp; The crash output was
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; File &amp;quot;zenmapCore\SearchResult.pyo&amp;quot;, line 86, in match_keyword
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; File &amp;quot;zenmapCore\SearchResult.pyo&amp;quot;, line 183, in match_target
&lt;br&gt;&amp;nbsp; &amp;nbsp; TypeError: argument of type 'NoneType' is not iterable
&lt;br&gt;&lt;br&gt;o Fixed a bug which prevented all comma-separated --script arguments
&lt;br&gt;&amp;nbsp; from being shown in Nmap normal and XML output files where they show
&lt;br&gt;&amp;nbsp; the original Nmap command. [David]
&lt;br&gt;&lt;br&gt;o Fixed ping scanner's runtime statistics system so that instead of
&lt;br&gt;&amp;nbsp; saying &amp;quot;0 undergoing Ping Scan&amp;quot; it gives the actual number of hosts in
&lt;br&gt;&amp;nbsp; the group (e.g. 4096). [David]
&lt;br&gt;&lt;br&gt;o [Zenmap] A crash was fixed in displaying the &amp;quot;Error creating the
&lt;br&gt;&amp;nbsp; per-user configuration directory&amp;quot; dialog:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; File &amp;quot;zenmap&amp;quot;, line 104, in 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; File &amp;quot;zenmapGUI\App.pyo&amp;quot;, line 129, in run
&lt;br&gt;&amp;nbsp; &amp;nbsp; UnicodeDecodeError: 'utf8' codec can't decode bytes in position 43-45:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; invalid data
&lt;br&gt;&amp;nbsp; The crash would only happen to users with paths containing
&lt;br&gt;&amp;nbsp; multibyte characters in a non-UTF-8 locale, who also had some error
&lt;br&gt;&amp;nbsp; preventing the creation of the directory. [David]
&lt;br&gt;&lt;br&gt;Nmap 4.85BETA5 [2009-03-30]
&lt;br&gt;&lt;br&gt;o Ron (in just a few hours of furious coding) added remote detection
&lt;br&gt;&amp;nbsp; of the Conficker worm to smb-check-vulns. It is based on new
&lt;br&gt;&amp;nbsp; research by Tillmann Werner and Felix Leder. &amp;nbsp;You can scan your
&lt;br&gt;&amp;nbsp; network for Conficker with a command like: nmap -PN -T4 -p139,445 -n
&lt;br&gt;&amp;nbsp; -v --script=smb-check-vulns --script-args safe=1 [targetnetworks]
&lt;br&gt;&lt;br&gt;o Ndiff now includes service (version detection) and OS detection
&lt;br&gt;&amp;nbsp; differences. [David]
&lt;br&gt;&lt;br&gt;o [Ncat] The --exec and --sh-exec options now work in UDP mode like
&lt;br&gt;&amp;nbsp; they do in TCP mode: the server handles multiple concurrent clients
&lt;br&gt;&amp;nbsp; and doesn't have to be restarted after each one. Marius Sturm
&lt;br&gt;&amp;nbsp; provided the patch.
&lt;br&gt;&lt;br&gt;o [Ncat] The -v option (used alone) no longer floods the screen with
&lt;br&gt;&amp;nbsp; debugging messages. With just -v, we now only print the most
&lt;br&gt;&amp;nbsp; important status messages such as &amp;quot;Connected to ...&amp;quot;, a startup
&lt;br&gt;&amp;nbsp; banner, and error messages. &amp;nbsp;At -vv, minor debugging messages are
&lt;br&gt;&amp;nbsp; enabled, such as what command is being executed by --sh-exec. &amp;nbsp;With
&lt;br&gt;&amp;nbsp; -vvv you get detailed debugging messages. [David]
&lt;br&gt;&lt;br&gt;o [Ncat] Chat mode now lets other participants know when someone
&lt;br&gt;&amp;nbsp; connects or disconnects, and it also broadcasts a current list of
&lt;br&gt;&amp;nbsp; participants at such times. [David]
&lt;br&gt;&lt;br&gt;o [Ncat] Fixed a socket handling bug which could occur when you
&lt;br&gt;&amp;nbsp; redirect Ncat stdin, such as &amp;quot;ncat -l --chat &amp;lt; /dev/null&amp;quot;. &amp;nbsp;The next
&lt;br&gt;&amp;nbsp; user to connect would end up with file descriptor 0 (which is
&lt;br&gt;&amp;nbsp; normally stdin) and thus confuse Ncat. [David]
&lt;br&gt;&lt;br&gt;o [Zenmap] The &amp;quot;Scan Output&amp;quot; expanders in the diff window now behave
&lt;br&gt;&amp;nbsp; more naturally. Some strange behavior on Windows was noted by Jah.
&lt;br&gt;&amp;nbsp; [David]
&lt;br&gt;&lt;br&gt;o The following OS detection tests are no longer included in OS
&lt;br&gt;&amp;nbsp; fingerprints: U1.RUL, U1.TOS, IE.DLI, IE.SI, and IE.TOSI. URL, DLI,
&lt;br&gt;&amp;nbsp; and SI were found not be helpful in distinguishing operating systems
&lt;br&gt;&amp;nbsp; because they didn't vary. TOS and TOSI were disabled in 4.85BETA1
&lt;br&gt;&amp;nbsp; but now they are not included in prints at all. [David]
&lt;br&gt;&lt;br&gt;o The compile-time Nmap ASCII dragon is now more ferocious thanks to
&lt;br&gt;&amp;nbsp; better teeth alignment. [David]
&lt;br&gt;&lt;br&gt;o Version 4.85BETA4 had a bug in the implementation of the new SEQ.CI
&lt;br&gt;&amp;nbsp; test that could cause a closed-port IP ID to be written into the
&lt;br&gt;&amp;nbsp; array for the SEQ.TI test and cause erroneous results. The bug was
&lt;br&gt;&amp;nbsp; found and fixed by Guillaume Prigent.
&lt;br&gt;&lt;br&gt;o Nbase has grown routines for calculating Adler32 and CRC32C
&lt;br&gt;&amp;nbsp; checksums. This is needed for future SCTP support. [Daniel
&lt;br&gt;&amp;nbsp; Roethlisberger]
&lt;br&gt;&lt;br&gt;o [Zenmap] Zenmap no longer shows an error message when running Nmap
&lt;br&gt;&amp;nbsp; with options that cause a zero-length XML file to be produced (like
&lt;br&gt;&amp;nbsp; --iflist). [David]
&lt;br&gt;&lt;br&gt;o Fixed an off-by-one error in printableSize() which could cause Nmap
&lt;br&gt;&amp;nbsp; to crash while reporting NSE results. Also, NmapOutputTable's memory
&lt;br&gt;&amp;nbsp; allocation strategy was improved to conserve memory. [Brandon,
&lt;br&gt;&amp;nbsp; Patrick]
&lt;br&gt;&lt;br&gt;o [Zenmap] We now give the --force option to setup.py for installation
&lt;br&gt;&amp;nbsp; to ensure that it replaces all files. [David]
&lt;br&gt;&lt;br&gt;o Nmap's --packet-trace, --version-trace, and --script-trace now use
&lt;br&gt;&amp;nbsp; an Nsock trace level of 2 rather than 5. &amp;nbsp;This removes some
&lt;br&gt;&amp;nbsp; superfluous lines which can flood the screen. [David]
&lt;br&gt;&lt;br&gt;o [Zenmap] Fixed a crash which could occur when loading the help URL
&lt;br&gt;&amp;nbsp; &amp;nbsp;if the path contains multibyte characters. [David]
&lt;br&gt;&lt;br&gt;o [Ncat] The version number is now matched to the Nmap release it came
&lt;br&gt;&amp;nbsp; with rather than always being 0.2. [David]
&lt;br&gt;&lt;br&gt;o Fixed a strtok issue between load_exclude and
&lt;br&gt;&amp;nbsp; TargetGroup::parse_expr that caused only the first exclude on
&lt;br&gt;&amp;nbsp; a line to be loaded as well as an invalid read into free()'d
&lt;br&gt;&amp;nbsp; memory in load_exclude(). [Brandon, David]
&lt;br&gt;&lt;br&gt;o NSE's garbage collection system (for cleaning up sockets from
&lt;br&gt;&amp;nbsp; completed threads, etc.) has been improved. [Patrick]
&lt;br&gt;&lt;br&gt;&lt;br&gt;Enjoy the new release and disenfect those systems!
&lt;br&gt;-Fyodor
&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap-4.85BETA6-now-avail-w-Conficker-detection-tp22821106p22821106.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22750030</id>
	<title>Nmap News: 4.84BETA4 release, Nmap book news, Summer of Code, Twitter, etc.</title>
	<published>2009-03-27T14:01:00Z</published>
	<updated>2009-03-27T14:01:00Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">Hello everyone. &amp;nbsp;We've seen 848 messages on nmap-dev this year, but
&lt;br&gt;this is my first post to nmap-hackers. &amp;nbsp;So I have a lot of exciting
&lt;br&gt;Nmap news to fit into this one email!
&lt;br&gt;&lt;br&gt;[=================Nmap 4.85BETA4==================]
&lt;br&gt;&lt;br&gt;While the last release I posted to this list was 4.76 in September of
&lt;br&gt;last year, we've had four beta releases since then with hundreds of
&lt;br&gt;important and dramatic changes. &amp;nbsp;I'm pretty happy with the latest
&lt;br&gt;4.85BETA4 release, but more testing and feedback would help. &amp;nbsp;Please
&lt;br&gt;give it a try and report any issues or suggestions to
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22750030&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nmap-dev@...&lt;/a&gt; as described at
&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/man-bugs.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/man-bugs.html&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;4.85BETA4 (compared to 4.76) includes our new Ncat and Ndiff tools, a
&lt;br&gt;ton of new NSE scripts for superior network discovery, more than 5,000
&lt;br&gt;version detection signatures and nearly 2,000 OS fingerprints,
&lt;br&gt;improved scan performance, and much more! &amp;nbsp;You can read about all the
&lt;br&gt;changes at &lt;a href=&quot;http://nmap.org/changelog.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/changelog.html&lt;/a&gt;. &amp;nbsp;Be sure to read all the
&lt;br&gt;way down to 4.85BETA1, as that includes some of the most dramatic
&lt;br&gt;changes.
&lt;br&gt;&lt;br&gt;Download Nmap 4.85BETA4 from: &lt;a href=&quot;http://nmap.org/download.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/download.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;[===============Summer of Code 2009===============]
&lt;br&gt;&lt;br&gt;The Nmap project has been accepted to participate for our fifth year
&lt;br&gt;of the Google Summer of Code! &amp;nbsp;This phenomenal program sponsors
&lt;br&gt;college and graduate students to spend the summer working on open
&lt;br&gt;source software. &amp;nbsp;Many of Nmap's coolest features started out as SoC
&lt;br&gt;projects, including:
&lt;br&gt;&lt;br&gt;Zenmap GUI - &lt;a href=&quot;http://nmap.org/zenmap/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/zenmap/&lt;/a&gt;&lt;br&gt;Nmap Scripting Engine (NSE) - &lt;a href=&quot;http://nmap.org/book/nse.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/nse.html&lt;/a&gt;&lt;br&gt;Ncat - &lt;a href=&quot;http://nmap.org/ncat/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/ncat/&lt;/a&gt;&lt;br&gt;Ndiff - &lt;a href=&quot;http://nmap.org/ndiff/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/ndiff/&lt;/a&gt;&lt;br&gt;2nd Generation OS Detection - &lt;a href=&quot;http://nmap.org/book/osdetect.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/osdetect.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;We hope to work on even more great projects this summer! &amp;nbsp;But the key
&lt;br&gt;to successful projects is recruiting talented and motivated
&lt;br&gt;participants. &amp;nbsp;If anyone here on nmap-hackers is an eligible college
&lt;br&gt;or graduate student with time for full time open source development
&lt;br&gt;work this summer, I urge you to apply! &amp;nbsp;Or if you have eligible
&lt;br&gt;friends or relatives who might benefit from the program, please let
&lt;br&gt;them know about it!
&lt;br&gt;&lt;br&gt;Applications are due next Friday (April 3) by Noon PDT (19:00 UTC).
&lt;br&gt;More information:
&lt;br&gt;&lt;br&gt;Nmap SoC ideas and application instructions: &lt;a href=&quot;http://nmap.org/soc/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/soc/&lt;/a&gt;&lt;br&gt;Google's SoC 2009 information page: &lt;a href=&quot;http://socghop.appspot.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://socghop.appspot.com/&lt;/a&gt;&lt;br&gt;Details on Nmap's Previous SoC Successes: 
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://google-opensource.blogspot.com/2008/11/nmaps-fourth-gsoc-success-stories-and.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://google-opensource.blogspot.com/2008/11/nmaps-fourth-gsoc-success-stories-and.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Even if you aren't eligible or interested in participating as a
&lt;br&gt;student, you can always join the nmap-dev list and help out. &amp;nbsp;That is
&lt;br&gt;where SoC work (and the rest of Nmap development) is coordinated. &amp;nbsp;So
&lt;br&gt;you can discuss ideas, review code patches, try experimental releases,
&lt;br&gt;etc. &amp;nbsp;See &lt;a href=&quot;http://seclists.org/#nmap-dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/#nmap-dev&lt;/a&gt;&amp;nbsp;for archives, or click &amp;quot;about
&lt;br&gt;list&amp;quot; there for a signup form.
&lt;br&gt;&lt;br&gt;[==============Nmap Network Scanning==============]
&lt;br&gt;&lt;br&gt;I'm delighted to report that the Nmap book release was a huge success!
&lt;br&gt;Nmap Network Scanning was even the top selling computer book on Amazon
&lt;br&gt;for a while. &amp;nbsp;I was so excited I took a screen shot:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/img/nns-top-seller-942x1024.png&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/img/nns-top-seller-942x1024.png&lt;/a&gt;&lt;br&gt;&lt;br&gt;It is great to see a book on network scanning up ahead of more
&lt;br&gt;mainstream topics such as digital photography and blogging, even if
&lt;br&gt;only for a day or two.
&lt;br&gt;&lt;br&gt;A down side of the unexpectedly high sales was that NNS went out of
&lt;br&gt;stock on Amazon for a couple weeks. &amp;nbsp;Fortunately it is now back in
&lt;br&gt;stock for immediate shipment:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.amazon.com/dp/0979958717?tag=secbks-20&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.amazon.com/dp/0979958717?tag=secbks-20&lt;/a&gt;&lt;br&gt;&lt;br&gt;Although it is hard in the U.S. to beat Amazon's $32.97 price (which
&lt;br&gt;includes free shipping), I've added some other purchasing options
&lt;br&gt;here:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/#purchase&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/#purchase&lt;/a&gt;&lt;br&gt;&lt;br&gt;I was also gratified to see so many positive reviews of NNS from the
&lt;br&gt;likes of TaoSecurity, Information Week, About.Com, Slashdot, ITWire,
&lt;br&gt;etc. &amp;nbsp;I posted more than a dozen of them to:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/#reviews&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/#reviews&lt;/a&gt;&lt;br&gt;&lt;br&gt;One goal is to make Nmap more accessible by translating the book to
&lt;br&gt;many languages. &amp;nbsp;Contracts have already been signed for German,
&lt;br&gt;Korean, and Brazilian Portuguese editions. &amp;nbsp;But if you have contacts
&lt;br&gt;with publishers in other languages who might be interested, I'd love
&lt;br&gt;to hear from you! &amp;nbsp;Details on the pending translations are available
&lt;br&gt;here:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/#reviews&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/#reviews&lt;/a&gt;&lt;br&gt;&lt;br&gt;Don't forget that more than half the book chapters are already free
&lt;br&gt;online at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/toc.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/toc.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;[================Nmap News Briefs================]
&lt;br&gt;&lt;br&gt;o Nmap won the LinuxQuestions.Org Network Security App of the Year
&lt;br&gt;&amp;nbsp; Award--for the sixth year in a row! &amp;nbsp;See
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2009/q1/0395.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2009/q1/0395.html&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;o Nmap was spotted in its 8th movie (Khottabych). &amp;nbsp;Find them all at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://nmap.org/movies.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/movies.html&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;o The Nmap Project now has a Twitter account! &amp;nbsp;Don't expect more than
&lt;br&gt;&amp;nbsp; a handful of tweets each month, but you can follow us at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://twitter.com/nmap/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/nmap/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;That is all for now, but stay tuned because we have a lot of exciting
&lt;br&gt;plans for 2009!
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Fyodor
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap-News%3A-4.84BETA4-release%2C-Nmap-book-news%2C-Summer-of-Code%2C-Twitter%2C-etc.-tp22750030p22750030.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22598964</id>
	<title>New Hackers Forum h4ckanything.freeforums.org</title>
	<published>2009-03-19T05:16:03Z</published>
	<updated>2009-03-19T05:16:03Z</updated>
	<author>
		<name>emz015</name>
	</author>
	<content type="html">we have a lot of hacking things at our forum like.... the things are listed below...
&lt;br&gt;: For sale .. Fresh ccv, and FULLZ ( paypal login and ebay + email acess ), Bank logins and Tranfer availabler ( only for sale ), western union Transfer Availble ( with debit &amp; credit card ), tranfer from CC ( fullz ) to paypal, Dumps , track 1 &amp; 2.. intrested peoples IM me now ............ contact blackhat.hackers@ymail.com for deal
&lt;br&gt;&lt;br&gt;: western union transfer is available in ... I will show the proof first &amp;nbsp;&lt;a href=&quot;http://h4ckanything.freeforums.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://h4ckanything.freeforums.org/&lt;/a&gt;&amp;nbsp;............ contact blackhat.hackers@ymail.com for deal
&lt;br&gt;&lt;br&gt;: Free credit cards @ &lt;a href=&quot;http://hackanything.freeforums.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://hackanything.freeforums.org/&lt;/a&gt;&amp;nbsp;............ contact &lt;a href=&quot;http://h4ckanything.freeforums.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://h4ckanything.freeforums.org/&lt;/a&gt;&amp;nbsp;for deal
&lt;br&gt;&lt;br&gt;BUY,Exchange, SELL your liberty reserve ,alertpay, altergold, moneybookers amount in &lt;a href=&quot;http://h4ckanything.freeforums.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://h4ckanything.freeforums.org/&lt;/a&gt;............ contact blackhat.hackers@ymail.com for deal
&lt;br&gt;&lt;br&gt;: Learn hacking from best hacking forum on net
&lt;br&gt;&lt;a href=&quot;http://h4ckanything.freeforums.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://h4ckanything.freeforums.org/&lt;/a&gt;&amp;nbsp;............ contact blackhat.hackers@ymail.com for deal
&lt;br&gt;&lt;br&gt;: Bank transfers available on &amp;nbsp;&lt;a href=&quot;http://h4ckanything.freeforums.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://h4ckanything.freeforums.org/&lt;/a&gt;&amp;nbsp;............ contact blackhat.hackers@ymail.com for deal
&lt;br&gt;&lt;br&gt;: CVV : USA = $3 . UK = $5 .. FULLZ &amp;nbsp;USA = $10 .. UK =$ 15 . ASIA = $20 ............ contact blackhat.hackers@ymail.com for deal
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/New-Hackers-Forum-h4ckanything.freeforums.org-tp22598964p22598964.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-20913026</id>
	<title>Nmap Network Scanning Book Released!</title>
	<published>2008-12-09T03:07:59Z</published>
	<updated>2008-12-09T03:07:59Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">Nmap Hackers:
&lt;br&gt;&lt;br&gt;After promising you a book on Nmap for years, I'm delighted to finally
&lt;br&gt;announce the release of Nmap Network Scanning! &amp;nbsp;It contains everything
&lt;br&gt;I've learned about network scanning from more than a decade of Nmap
&lt;br&gt;development, plus some bad jokes and (over Time Warner's written
&lt;br&gt;objections) pictures of Trinity hacking the Matrix :). &amp;nbsp;Here is the
&lt;br&gt;abstract:
&lt;br&gt;&lt;br&gt;&amp;nbsp; Nmap Network Scanning is the official guide to the Nmap Security
&lt;br&gt;&amp;nbsp; Scanner, a free and open source utility used by millions of people
&lt;br&gt;&amp;nbsp; for network discovery, administration, and security auditing. From
&lt;br&gt;&amp;nbsp; explaining port scanning basics for novices to detailing low-level
&lt;br&gt;&amp;nbsp; packet crafting methods used by advanced hackers, this book by
&lt;br&gt;&amp;nbsp; Nmap's original author suits all levels of security and networking
&lt;br&gt;&amp;nbsp; professionals. The reference guide documents every Nmap feature and
&lt;br&gt;&amp;nbsp; option, while the remainder demonstrates how to apply them to
&lt;br&gt;&amp;nbsp; quickly solve real-world tasks. Examples and diagrams show actual
&lt;br&gt;&amp;nbsp; communication on the wire. Topics include subverting firewalls and
&lt;br&gt;&amp;nbsp; intrusion detection systems, optimizing Nmap performance, and
&lt;br&gt;&amp;nbsp; automating common networking tasks with the Nmap Scripting Engine.
&lt;br&gt;&lt;br&gt;The planned release date was January 1, but Amazon beat the deadline
&lt;br&gt;and is now shipping in time for Christmas! &amp;nbsp;Imagine your loved one's
&lt;br&gt;surprise when she (or he) finds nearly 500 pages of port scanning
&lt;br&gt;bliss in her stocking!
&lt;br&gt;&lt;br&gt;You can find reviews, sample chapters, and a detailed summary at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Or you can pick the book up at Amazon for $33.71:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.amazon.com/dp/0979958717?tag=secbks-20&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.amazon.com/dp/0979958717?tag=secbks-20&lt;/a&gt;&lt;br&gt;&lt;br&gt;It is available on the International Amazon sites too, as well as
&lt;br&gt;other online retailers. &amp;nbsp;Your local book store probably doesn't have
&lt;br&gt;it yet, but can likely order it for you.
&lt;br&gt;&lt;br&gt;About half of the content is available free online at
&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/toc.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/toc.html&lt;/a&gt;&amp;nbsp;. &amp;nbsp;Chapters exclusive to the print
&lt;br&gt;edition include &amp;quot;Detecting and Subverting Firewalls and Intrusion
&lt;br&gt;Detection Systems&amp;quot;, &amp;quot;Optimizing Nmap Performance&amp;quot;, &amp;quot;Port Scanning
&lt;br&gt;Techniques and Algorithms&amp;quot;, &amp;quot;Host Discovery (Ping Scanning)&amp;quot;, and
&lt;br&gt;more.
&lt;br&gt;&lt;br&gt;If you enjoy the book, please help spread the word! &amp;nbsp;While my previous
&lt;br&gt;books were published by Addison-Wesley and Syngress, this one was
&lt;br&gt;self-published. &amp;nbsp;While that allowed me to post half the book online
&lt;br&gt;before it was even released, it also means I lose the marketing budget
&lt;br&gt;and clout of a major publisher. &amp;nbsp;So if you like the book, please post
&lt;br&gt;a review to your blog/site/Amazon or tell your friends about it!
&lt;br&gt;&lt;br&gt;Apparently there was some pent-up demand for the book, as it is
&lt;br&gt;currently the 11th best-selling computer book on Amazon. &amp;nbsp;Maybe it
&lt;br&gt;will be even higher by the time you read this:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.amazon.com/gp/bestsellers/books/5/ref=pd_zg_hrsr_b_1_2&amp;tag=secbks-20&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.amazon.com/gp/bestsellers/books/5/ref=pd_zg_hrsr_b_1_2&amp;tag=secbks-20&lt;/a&gt;&lt;br&gt;&lt;br&gt;I'd like to thank the many people who helped make this book possible
&lt;br&gt;by reviewing drafts, contributing stories, brainstorming ideas, etc.
&lt;br&gt;In particular, I'd like to thank David Fifield, Raven Alder, Matt
&lt;br&gt;Baxter, Saurabh Bhasin, Mark Brewis, Ellen Colombo, Patrick Donnelly,
&lt;br&gt;Brandon Enright, Brian Hatch, Loren Heal, Lee &amp;quot;MadHat&amp;quot; Heath, Dan
&lt;br&gt;Henage, Tor Houghton, Doug Hoyte, Marius Huse Jacobsen, Kris
&lt;br&gt;Katterjohn, Eric Krosnes, Vlad Alexa Mancini, Michael Naef, Bill
&lt;br&gt;Pollock, David Pybus, Tyler Reguly, Chuck Sterling, Anders Thulin,
&lt;br&gt;Bennett Todd, Diman Todorov, and Catherine Tornabene!
&lt;br&gt;&lt;br&gt;And most importantly, I want to wish you all happy holidays!
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Fyodor
&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap-Network-Scanning-Book-Released%21-tp20913026p20913026.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-19636353</id>
	<title>Nmap News: 4.76 release, Defcon presentation online, Is port scanning legal?</title>
	<published>2008-09-23T13:11:16Z</published>
	<updated>2008-09-23T13:11:16Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">Hi everyone. &amp;nbsp;I'm happy to report that the Nmap 4.75 release (with
&lt;br&gt;port frequencies, Zenmap topology, etc.) was a big success. &amp;nbsp;But such
&lt;br&gt;large exposure inevitably leads to bug discovery, so we've
&lt;br&gt;released version 4.76 with about a dozen small fixes and stability
&lt;br&gt;improvements. &amp;nbsp;If 4.75 is working great for you, there is probably no
&lt;br&gt;need to upgrade. &amp;nbsp;But if you encountered problems, or if you are the
&lt;br&gt;type who waits a couple weeks for stabilization before trying a big
&lt;br&gt;new release, now is your chance to upgrade to 4.76. &amp;nbsp;It's available at
&lt;br&gt;the normal location:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/download.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/download.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;And you can read about the changes here:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/changelog.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/changelog.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Speaking of the big 4.75 changes, I presented many of them at Defcon
&lt;br&gt;and Black Hat last month in Las Vegas, including details behind my
&lt;br&gt;Worldscan project (scanning tens of millions of hosts all over the
&lt;br&gt;Internet) and some of the ways smart folks can use this empirical data
&lt;br&gt;to make your scans more effective.
&lt;br&gt;&lt;br&gt;But I know that some of you couldn't make it to Defcon this year, and
&lt;br&gt;even many who came were turned away from my talk because the room was
&lt;br&gt;full :(. &amp;nbsp;So now that 4.75 is out and includes most of the new
&lt;br&gt;features I demonstrate in the presentation, I've posted the audio,
&lt;br&gt;video, and slides online (along with a previous presentation at
&lt;br&gt;ShmooCon) at my new presentations page:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://insecure.org/presentations/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://insecure.org/presentations/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Note a few of the new features discussed (particularly Ncat and Ndiff)
&lt;br&gt;didn't make it into 4.75, but they are available now in our SVN
&lt;br&gt;repository:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/install.html#inst-svn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/install.html#inst-svn&lt;/a&gt;&lt;br&gt;&lt;br&gt;The third thing I wanted to mention is that I've freed Ch1 of my
&lt;br&gt;upcoming (in late October) Nmap book. &amp;nbsp;I actually put this online a
&lt;br&gt;while back, but forgot to link to it or tell anyone :). &amp;nbsp;The title is
&lt;br&gt;&amp;quot;Getting Started with Nmap&amp;quot;, which sounds too basic for a group of
&lt;br&gt;nmap-hackers. &amp;nbsp;But there are several sections you might find
&lt;br&gt;interesting:
&lt;br&gt;&lt;br&gt;&amp;quot;Legal issues&amp;quot; discusses whether unauthorized port scanning is a crime
&lt;br&gt;and also how to mitigate the risk of crashing target
&lt;br&gt;computers/networks:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/legal-issues.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/legal-issues.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;quot;The History and Future of Nmap&amp;quot; discusses where we've been and where
&lt;br&gt;we're going:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/history-future.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/history-future.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Sometimes the best way to understand something is to see it in action.
&lt;br&gt;The &amp;quot;Nmap Overview and Demonstration&amp;quot; section includes examples of
&lt;br&gt;Nmap used in (mostly) fictional yet typical circumstances. &amp;nbsp;The Nmap
&lt;br&gt;experts here probably won't learn much from this section, but it is
&lt;br&gt;good for getting newbies excited about Nmap and to understand the
&lt;br&gt;basics:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/nmap-overview-and-demos.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/nmap-overview-and-demos.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Enjoy all the new content!
&lt;br&gt;-Fyodor
&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap-News%3A-4.76-release%2C-Defcon-presentation-online%2C-Is-port-scanning-legal--tp19636353p19636353.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-19381645</id>
	<title>Nmap 4.75 released</title>
	<published>2008-09-08T14:14:31Z</published>
	<updated>2008-09-08T14:14:31Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">Hi Everyone. &amp;nbsp;I'm delighted to report the release of Nmap 4.75, which
&lt;br&gt;has almost 100 significant improvements since 4.68. &amp;nbsp;Some which I'm
&lt;br&gt;most excited about are:
&lt;br&gt;&lt;br&gt;o While Nmap stands for &amp;quot;Network Mapper&amp;quot;, it hasn't been able to
&lt;br&gt;&amp;nbsp; actually draw you a map of the network--until now! &amp;nbsp;Visit
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://nmap.org/book/zenmap-topology.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/zenmap-topology.html&lt;/a&gt;&amp;nbsp;for details and pretty
&lt;br&gt;&amp;nbsp; pictures of Zenmap's new Scan Topology system.
&lt;br&gt;&lt;br&gt;o I spent much of this summer scanning tens of millions of IPs on the
&lt;br&gt;&amp;nbsp; Internet (plus collecting data contributed by some enterprises) to
&lt;br&gt;&amp;nbsp; determine the most commonly open ports. &amp;nbsp;Nmap now uses that
&lt;br&gt;&amp;nbsp; empirical data to scan more effectively.
&lt;br&gt;&lt;br&gt;And there is much more, from hundreds of new OS detection fingerprints
&lt;br&gt;to many new Nmap Scripting Engine scripts and libraries. &amp;nbsp;I had no
&lt;br&gt;idea how many people still used Windows 2000 until 4.68 came out
&lt;br&gt;broken on that platform and I was flooded with email! &amp;nbsp;That is fixed
&lt;br&gt;now. &amp;nbsp;And its just one of many bug fixes and performance improvements
&lt;br&gt;in this release. &amp;nbsp;Remember that we had 7 Google SoC students working
&lt;br&gt;full-time this summer, and this release includes some of their best
&lt;br&gt;work.
&lt;br&gt;&lt;br&gt;You can obtain Nmap 4.75 from the normal location:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/download.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/download.html&lt;/a&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;Please give it a try! And if you encounter any problems, report them
&lt;br&gt;to nmap-dev as described at &lt;a href=&quot;http://nmap.org/book/man-bugs.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/man-bugs.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Here is the detailed list of important 4.75 changes from
&lt;br&gt;&lt;a href=&quot;http://nmap.org/changelog.html:&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/changelog.html:&lt;/a&gt;&lt;br&gt;&lt;br&gt;o [Zenmap] Added a new Scan Topology system. The idea is that if we
&lt;br&gt;&amp;nbsp; are going to call Nmap the &amp;quot;Network Mapper&amp;quot;, it should at least be
&lt;br&gt;&amp;nbsp; able to draw you a map of the network! &amp;nbsp;And that is what this new
&lt;br&gt;&amp;nbsp; system does. It was achieved by integrating the RadialNet Nmap
&lt;br&gt;&amp;nbsp; visualization tool (&lt;a href=&quot;http://www.dca.ufrn.br/~joaomedeiros/radialnet&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dca.ufrn.br/~joaomedeiros/radialnet&lt;/a&gt;),
&lt;br&gt;&amp;nbsp; into Zenmap. Joao Medeiros has been developing RadialNet for more
&lt;br&gt;&amp;nbsp; than a year. For details, complete with some of the most beautiful
&lt;br&gt;&amp;nbsp; Zenmap screen shots ever, visit
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://nmap.org/book/zenmap-topology.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/zenmap-topology.html&lt;/a&gt;. The integration work was
&lt;br&gt;&amp;nbsp; done by SoC student Vladimir Mitrovic and his mentor David Fifield.
&lt;br&gt;&lt;br&gt;o [Zenmap] Another exciting new Zenmap feature is Scan Aggregation.
&lt;br&gt;&amp;nbsp; This allows you to visualize and analyze the results of multiple
&lt;br&gt;&amp;nbsp; scans at once, as if they were from one Nmap execution. So you might
&lt;br&gt;&amp;nbsp; scan one network, analyze the results a bit, then scan some of the
&lt;br&gt;&amp;nbsp; machines more intensely or add a completely new subnet to the
&lt;br&gt;&amp;nbsp; scan. The new results are seamlessly added to the old, as described
&lt;br&gt;&amp;nbsp; at &lt;a href=&quot;http://nmap.org/book/zenmap-scanning.html#aggregation&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/zenmap-scanning.html#aggregation&lt;/a&gt;. [David,
&lt;br&gt;&amp;nbsp; Vladimir]
&lt;br&gt;&lt;br&gt;o Expanded nmap-services to include information on how frequently each
&lt;br&gt;&amp;nbsp; port number is found open. &amp;nbsp;The results were generated by scanning
&lt;br&gt;&amp;nbsp; tens of millions of IPs on the Internet this Summer, and augmented
&lt;br&gt;&amp;nbsp; with internal network data contributed by some large
&lt;br&gt;&amp;nbsp; organizations. [Fyodor]
&lt;br&gt;&lt;br&gt;o Nmap now scans the most common 1,000 ports by default in either
&lt;br&gt;&amp;nbsp; protocol (UDP scan is still optional). &amp;nbsp;This is a decrease from
&lt;br&gt;&amp;nbsp; 1,715 TCP ports and 1,488 UDP ports in Nmap 4.68. &amp;nbsp;So Nmap is faster
&lt;br&gt;&amp;nbsp; by default and, since the port selection is better thanks to the
&lt;br&gt;&amp;nbsp; port frequency data, it often finds more open ports as
&lt;br&gt;&amp;nbsp; well. [Fyodor]
&lt;br&gt;&lt;br&gt;o Nmap fast scan (-F) now scans the top 100 ports by default in either
&lt;br&gt;&amp;nbsp; protocol. &amp;nbsp;This is a decrease from 1,276 (TCP) and 1,017 (UDP) in
&lt;br&gt;&amp;nbsp; Nmap 4.68. Port scanning time with -F is generally an order of
&lt;br&gt;&amp;nbsp; magnitude faster than before, making -F worthy of its &amp;quot;fast scan&amp;quot;
&lt;br&gt;&amp;nbsp; moniker. [Fyodor]
&lt;br&gt;&lt;br&gt;o The --top-ports option lets you specify the number of ports you wish
&lt;br&gt;&amp;nbsp; to scan in each protocol, and will pick the most popular ports for
&lt;br&gt;&amp;nbsp; you based on the new frequency data. &amp;nbsp;For both TCP and UDP, the top
&lt;br&gt;&amp;nbsp; 10 ports gets you roughly half of the open ports. &amp;nbsp;The top 1,000
&lt;br&gt;&amp;nbsp; (out of 65,536 possible) finds roughly 93% of the open TCP ports and
&lt;br&gt;&amp;nbsp; more than 95% of the open UDP ports. [Fyodor, Doug Hoyte]
&lt;br&gt;&lt;br&gt;o David integrated all of your OS detection fingerprint and correction
&lt;br&gt;&amp;nbsp; submissions from March 11 until mid-July. &amp;nbsp;In the process we reached
&lt;br&gt;&amp;nbsp; the 1500-signature milestone for the 2nd generation OS detection
&lt;br&gt;&amp;nbsp; system. We can now detect the newest iPhones, Linux 2.6.25, OS X
&lt;br&gt;&amp;nbsp; Darwin 9.2.2, Windows Vista SP1, and even the Nintendo Wii. Nmap now
&lt;br&gt;&amp;nbsp; has 1,503 signatures, vs. 1,320 in 4.68. Integration is now faster
&lt;br&gt;&amp;nbsp; and more pleasant thanks to the new OSassist application developed
&lt;br&gt;&amp;nbsp; by Nmap SoC student Michael Pattrick. See
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0089.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0089.html&lt;/a&gt;&amp;nbsp;and
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0139.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0139.html&lt;/a&gt;&amp;nbsp;for more details.
&lt;br&gt;&lt;br&gt;o Nmap now works with Windows 2000 again, after being broken by our
&lt;br&gt;&amp;nbsp; IPv6 support improvements in version 4.65. A couple new dependencies
&lt;br&gt;&amp;nbsp; are required to run on Win2K, as described at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://nmap.org/book/inst-windows.html#inst-win2k&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/inst-windows.html#inst-win2k&lt;/a&gt;&amp;nbsp;.
&lt;br&gt;&lt;br&gt;o [Zenmap] Added a context-sensitive help system to the Profile
&lt;br&gt;&amp;nbsp; Editor. &amp;nbsp;You can now mouse-over options to learn more about what
&lt;br&gt;&amp;nbsp; they are used for and their proper argument syntax. [Jurand Nogiec]
&lt;br&gt;&lt;br&gt;o When Nmap finds a probe during ping scan which elicits a response,
&lt;br&gt;&amp;nbsp; it now saves that information for the port scan and later phases.
&lt;br&gt;&amp;nbsp; It can then &amp;quot;ping&amp;quot; the host with that probe as necessary to collect
&lt;br&gt;&amp;nbsp; timing information even if the host is not responding to the normal
&lt;br&gt;&amp;nbsp; port scan packets. Previously, Nmap's port scan timing pings could
&lt;br&gt;&amp;nbsp; only use information gathered during that port scan itself. &amp;nbsp;A
&lt;br&gt;&amp;nbsp; number of other &amp;quot;port scan ping&amp;quot; system improvements were made at
&lt;br&gt;&amp;nbsp; the same time to improve performance against firewalled hosts. For
&lt;br&gt;&amp;nbsp; full details, see &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0647.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0647.html&lt;/a&gt;&lt;br&gt;&amp;nbsp; [David, Michael, Fyodor]
&lt;br&gt;&lt;br&gt;o --traceroute now uses the timing ping probe saved from host
&lt;br&gt;&amp;nbsp; discovery and port scanning instead of finding its own probe. The
&lt;br&gt;&amp;nbsp; timing ping probe is always the best probe Nmap knows about for
&lt;br&gt;&amp;nbsp; eliciting a response from a target. This will have the most effect
&lt;br&gt;&amp;nbsp; on traceroute after a ping scan, where traceroute would sometimes
&lt;br&gt;&amp;nbsp; pick an ineffective probe and traceroute would fail even though the
&lt;br&gt;&amp;nbsp; target was up. [David]
&lt;br&gt;&lt;br&gt;o Added dns-safe-recursion-port and dns-safe-recursion-txid
&lt;br&gt;&amp;nbsp; (non-default NSE scripts) which use the 3rd party dns-oarc.net
&lt;br&gt;&amp;nbsp; lookup to test the source port and transaction ID randomness of
&lt;br&gt;&amp;nbsp; discovered DNS servers (assuming they allow recursion at all).
&lt;br&gt;&amp;nbsp; These scripts, which test for the &amp;quot;Kaminsky&amp;quot; DNS bugs, were
&lt;br&gt;&amp;nbsp; contributed by Brandon Enright.
&lt;br&gt;&lt;br&gt;o Added whois.nse, which queries the Regional Internet Registries
&lt;br&gt;&amp;nbsp; (RIRs) to determine who the target IP addresses are assigned
&lt;br&gt;&amp;nbsp; to. [Jah]
&lt;br&gt;&lt;br&gt;o [Zenmap] Overhauled the default list of scan profiles based on
&lt;br&gt;&amp;nbsp; nmap-dev discussion. &amp;nbsp;Users now have a much more diverse and useful
&lt;br&gt;&amp;nbsp; set of default profile options. And if they don't like any of those
&lt;br&gt;&amp;nbsp; canned scan commands, they can easily create their own in the
&lt;br&gt;&amp;nbsp; Profile Editor! [David]
&lt;br&gt;&lt;br&gt;o Fyodor made a number of performance tweaks, such as:
&lt;br&gt;&amp;nbsp; o increase host group sizes in many cases, so Nmap will now commonly
&lt;br&gt;&amp;nbsp; &amp;nbsp; scan 64 hosts at a time rather than 30
&lt;br&gt;&amp;nbsp; o align host groups with common network boundaries, such as /24 or
&lt;br&gt;&amp;nbsp; &amp;nbsp;/25
&lt;br&gt;&amp;nbsp; o Increase maximum per-target port-scan ping frequency to one every
&lt;br&gt;&amp;nbsp; &amp;nbsp; 1.25 seconds rather than every five. Port scan pings happen
&lt;br&gt;&amp;nbsp; &amp;nbsp; against heavily firewalled hosts and the like when Nmap is not
&lt;br&gt;&amp;nbsp; &amp;nbsp; receiving enough responses to normal scan to properly calculate
&lt;br&gt;&amp;nbsp; &amp;nbsp; timing variables and detect packet drops.
&lt;br&gt;&lt;br&gt;o Added a new NSE binlib library, which offers bin.pack() and
&lt;br&gt;&amp;nbsp; bin.unpack() functions for dealing with storing values in and
&lt;br&gt;&amp;nbsp; extracting them from binary strings. &amp;nbsp;For details, see
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://nmap.org/book/nse-library.html#nse-binlib&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/nse-library.html#nse-binlib&lt;/a&gt;&amp;nbsp;. [Philip
&lt;br&gt;&amp;nbsp; Pickering]
&lt;br&gt;&lt;br&gt;o Added a new NSE DNS library. See this thread:
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0310.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0310.html&lt;/a&gt;&amp;nbsp;[Philip Pickering]
&lt;br&gt;&lt;br&gt;o Added new NSE libraries for base64 encoding, SNMP, and POP3 mail
&lt;br&gt;&amp;nbsp; operations. &amp;nbsp;They are described at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0233.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0233.html&lt;/a&gt;&amp;nbsp;. [Philip Pickering]
&lt;br&gt;&lt;br&gt;o Added NSE scripts popcapa (retrieves POP3 server capabilities) and
&lt;br&gt;&amp;nbsp; brutePOP3 (brute force POP3 authentication cracker) which make use
&lt;br&gt;&amp;nbsp; of the new POP3 library. [Philip Pickering]
&lt;br&gt;&lt;br&gt;o Added the SNMPcommunitybrute NSE script, which is a brute force
&lt;br&gt;&amp;nbsp; community string cracker. Also modified SNMPsysdescr to use the new
&lt;br&gt;&amp;nbsp; SNMP library. [Philip Pickering]
&lt;br&gt;&lt;br&gt;o Fixed the SMTPcommands script so that it can't return multiple
&lt;br&gt;&amp;nbsp; values (which was causing problems). Thanks to Jah for tracking down
&lt;br&gt;&amp;nbsp; the problem and sending a fix for SMTPcommands. Then Patrick fixed
&lt;br&gt;&amp;nbsp; NSE so it can handle misbehaving scripts like this without causing
&lt;br&gt;&amp;nbsp; mysterious side effects.
&lt;br&gt;&lt;br&gt;o Added a new NSE Unpwdb (username/password database) library for
&lt;br&gt;&amp;nbsp; easily obtaining usernames or passwords from a list. &amp;nbsp;The functions
&lt;br&gt;&amp;nbsp; usernames() and passwords() return a closure which returns a new
&lt;br&gt;&amp;nbsp; list entry with every call, or nil when the list is exhausted. &amp;nbsp;You
&lt;br&gt;&amp;nbsp; can specify your own username and/or password lists via the script
&lt;br&gt;&amp;nbsp; arguments userdb and passdb, respectively. [Kris]
&lt;br&gt;&lt;br&gt;o Nmap's Nsock-utilizing subsystems (DNS, NSE, version detection) have
&lt;br&gt;&amp;nbsp; been updated to support the -S and --ip-options flags. [Kris]
&lt;br&gt;&lt;br&gt;o A new --max-rate option was added, which complements --min-rate. It
&lt;br&gt;&amp;nbsp; allows you to specify the maximum byte rate that Nmap is allowed to
&lt;br&gt;&amp;nbsp; send packets. [David]
&lt;br&gt;&lt;br&gt;o Added --ip-options support for the connect() scan (-sT). [Kris]
&lt;br&gt;&lt;br&gt;o Nsock now supports binding to a local address and setting IPv4
&lt;br&gt;&amp;nbsp; options with nsi_set_localaddr() and nsi_set_ipoptions(),
&lt;br&gt;&amp;nbsp; respectively. [Kris]
&lt;br&gt;&lt;br&gt;o Added IPProto Ping (-PO) support to Traceroute, and fixed support for
&lt;br&gt;&amp;nbsp; IPProto Scan (-sO) and the ICMP Pings (-PE, -PP, -PM) in Traceroute
&lt;br&gt;&amp;nbsp; as well. &amp;nbsp;These could cause Nmap to hang during Traceroute. [Kris]
&lt;br&gt;&lt;br&gt;o [Zenmap] Added a &amp;quot;Cancel&amp;quot; button for cancelling a scan in progress
&lt;br&gt;&amp;nbsp; without losing any Nmap output obtained so far. [Jurand Nogiec]
&lt;br&gt;&lt;br&gt;o Improve the netbios-smb-os-discovery NSE script to improve target
&lt;br&gt;&amp;nbsp; port selection and to also decode the system's timestamp from an SMB
&lt;br&gt;&amp;nbsp; response. [Ron at SkullSecurity]
&lt;br&gt;&lt;br&gt;o Nmap now avoids collapsing large numbers of ports in open|filtered
&lt;br&gt;&amp;nbsp; state (e.g. just printing that 500 ports are in that state rather
&lt;br&gt;&amp;nbsp; than listing them individually) if verbosity or debugging levels are
&lt;br&gt;&amp;nbsp; greater than two. &amp;nbsp;See this thread:
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0312.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0312.html&lt;/a&gt;&amp;nbsp;. [Fyodor]
&lt;br&gt;&lt;br&gt;o The NSE http library now supports chunked encoding. [Sven Klemm]
&lt;br&gt;&lt;br&gt;o The NSE datafiles library now has generic file parsing routines, and
&lt;br&gt;&amp;nbsp; the parsing of the standard nmap data files (e.g. nmap-services,
&lt;br&gt;&amp;nbsp; nmap-protocols, etc.) now uses those generic routines. &amp;nbsp;NSE scripts
&lt;br&gt;&amp;nbsp; and libraries may find them useful for dealing with their own data
&lt;br&gt;&amp;nbsp; files, such as password lists. [Jah]
&lt;br&gt;&lt;br&gt;o Passed the big revision 10,000 milestone in the Nmap project SVN
&lt;br&gt;&amp;nbsp; server: &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0682.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0682.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;o Added some Windows and MinGW compatibility patches submitted by
&lt;br&gt;&amp;nbsp; Gisle Vanem.
&lt;br&gt;&lt;br&gt;o Improved nse_init so that compilation/runtime errors in NSE scripts
&lt;br&gt;&amp;nbsp; no longer cause the script engine to abort. [Patrick]
&lt;br&gt;&lt;br&gt;o Fix a cosmetic bug in --script-trace hex dump output which resulting
&lt;br&gt;&amp;nbsp; in bytes with the highest bit set being prefixed with ffffff. [Sven
&lt;br&gt;&amp;nbsp; Klemm]
&lt;br&gt;&lt;br&gt;o Removed the nselib-bin directory. The last remaining shared NSE
&lt;br&gt;&amp;nbsp; module, bit, has been made static by Patrick. Shared modules were
&lt;br&gt;&amp;nbsp; broken for static builds of Nmap, such as those in the RPMS. We also
&lt;br&gt;&amp;nbsp; had the compilation problems (particularly on OpenBSD) with shared
&lt;br&gt;&amp;nbsp; modules which lead us to make PCRE static a while back. [David]
&lt;br&gt;&lt;br&gt;o Updated rpcinfo NSE script to use the new pack/unpack (binlib)
&lt;br&gt;&amp;nbsp; functions, use the new tab library, include better documentation, and
&lt;br&gt;&amp;nbsp; fix some bugs. [Sven Klemm]
&lt;br&gt;&lt;br&gt;o Add useful details to the error message printed when an NSE script
&lt;br&gt;&amp;nbsp; fails to load (due to syntax error, etc.) [Patrick]
&lt;br&gt;&lt;br&gt;o Fix a bug in the NSE http library which would cause some scripts to
&lt;br&gt;&amp;nbsp; give the error: SCRIPT ENGINE: C:\Program
&lt;br&gt;&amp;nbsp; Files\Nmap\nselib/http.lua:77: attempt to call field 'parse' (a nil
&lt;br&gt;&amp;nbsp; value) [Jah]
&lt;br&gt;&lt;br&gt;o Fixed a Makefile problem (race condition) which could lead to build
&lt;br&gt;&amp;nbsp; failures when launching make in parallel mode (e.g. -j4). [Michal
&lt;br&gt;&amp;nbsp; Januszewski]
&lt;br&gt;&lt;br&gt;o Added new addrow() function to NSE tab library. &amp;nbsp;It allows
&lt;br&gt;&amp;nbsp; developers to add a whole row at once rather than doing a separate
&lt;br&gt;&amp;nbsp; add() call for each column in a row. [Sven Klemm]
&lt;br&gt;&lt;br&gt;o Completion time estimates provided in verbose mode or when you hit a
&lt;br&gt;&amp;nbsp; key during scanning are now more accurate thanks to algorithm
&lt;br&gt;&amp;nbsp; improvements by David.
&lt;br&gt;&lt;br&gt;o Fixed a number of NSE scripts which used print_debug()
&lt;br&gt;&amp;nbsp; incorrectly. See
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0470.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0470.html&lt;/a&gt;. [Sven Klemm].
&lt;br&gt;&lt;br&gt;o [Zenmap] The Ports/Hosts view now provides full version detection
&lt;br&gt;&amp;nbsp; values rather than just a simple summary. [Jurand Nogiec]
&lt;br&gt;&amp;nbsp; 
&lt;br&gt;o [Zenmap] When you edit the command-entry field, then change the
&lt;br&gt;&amp;nbsp; target selection, Nmap no longer blows away your edits in favor of
&lt;br&gt;&amp;nbsp; using your current profile. [Jurand Nogiec]
&lt;br&gt;&lt;br&gt;o Nsock now returns data from UDP packets individually, preserving the
&lt;br&gt;&amp;nbsp; packet boundary, rather than concatenating the data from multiple
&lt;br&gt;&amp;nbsp; packets into a single buffer. &amp;nbsp;This fixes a problem related to our
&lt;br&gt;&amp;nbsp; reverse-DNS system, which can only handle one DNS packet at a time.
&lt;br&gt;&amp;nbsp; Thanks to Tim Adam of ManageSoft for debugging the problem and
&lt;br&gt;&amp;nbsp; sending the patch. &amp;nbsp;Doug Hoyte helped with testing, and it was
&lt;br&gt;&amp;nbsp; applied by Fyodor.
&lt;br&gt;&lt;br&gt;o [Zenmap] Fixed a crash which would occur when you try to compare two
&lt;br&gt;&amp;nbsp; files, either of which has more than one extraports element. [David]
&lt;br&gt;&lt;br&gt;o Added the undocumented (except here) --nogcc option which disables
&lt;br&gt;&amp;nbsp; global/group congestion control algorithms and so each member of a
&lt;br&gt;&amp;nbsp; scan group of machines is treated separately. &amp;nbsp;This is just an
&lt;br&gt;&amp;nbsp; experimental option for now. [Fyodor]
&lt;br&gt;&lt;br&gt;o [Zenmap] The Ports/Hosts display now has different colors for open
&lt;br&gt;&amp;nbsp; and closed ports. [Vladimir]
&lt;br&gt;&lt;br&gt;o Fixed Zenmap so that it displays all Nmap errors. &amp;nbsp;Previously, only
&lt;br&gt;&amp;nbsp; stdout was redirected into the window, and not stderr. &amp;nbsp;Now they are
&lt;br&gt;&amp;nbsp; both redirected. [Vladimir]
&lt;br&gt;&lt;br&gt;o NSE can now be used in combination with ping scan (e.g. &amp;quot;-sP
&lt;br&gt;&amp;nbsp; --script&amp;quot;) so that you can execute host scripts without needing to
&lt;br&gt;&amp;nbsp; perform a port scan. [Kris]
&lt;br&gt;&lt;br&gt;o [NSE] Category names are now case insensitive. [Patrick]
&lt;br&gt;&lt;br&gt;o [NSE] Each thread for a script now gets its own action closure (and
&lt;br&gt;&amp;nbsp; &amp;nbsp;upvalues). See: &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q2/0549.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q2/0549.html&lt;/a&gt;&lt;br&gt;&amp;nbsp; [Patrick]
&lt;br&gt;&lt;br&gt;o [NSE] The script_scan_result structure has been changed to a class,
&lt;br&gt;&amp;nbsp; ScriptResult, which now holds a Script's output in an std::string.
&lt;br&gt;&amp;nbsp; This removes the need to use malloc and free to manage this memory.
&lt;br&gt;&amp;nbsp; A similar change was made to the run_record structure. [Patrick]
&lt;br&gt;&lt;br&gt;o [NSE] Fixed a socket exhaustion deadlock which could prevent a
&lt;br&gt;&amp;nbsp; script scan from ever finishing. Now, rather than limit the total
&lt;br&gt;&amp;nbsp; number of sockets which can be open, we limit the number of scripts
&lt;br&gt;&amp;nbsp; which can have sockets open at once. &amp;nbsp;And once a script has one
&lt;br&gt;&amp;nbsp; socket opened, it is permitted to open as many more as it
&lt;br&gt;&amp;nbsp; needs. [Patrick]
&lt;br&gt;&lt;br&gt;o A hashing library (code from OpenSSL) was added to NSE. &amp;nbsp;hashlib
&lt;br&gt;&amp;nbsp; contains md5 and sha1 routines. [Philip Pickering]
&lt;br&gt;&lt;br&gt;o Fixed host discovery probe matching when looking at the returned TCP
&lt;br&gt;&amp;nbsp; data in an ICMP error message. &amp;nbsp;This could formerly lead to
&lt;br&gt;&amp;nbsp; incorrectly discarded responses and the debugging error message:
&lt;br&gt;&amp;nbsp; &amp;quot;Bogus trynum or sequence number in ICMP error message&amp;quot; [Kris]
&lt;br&gt;&lt;br&gt;o Fixed a segmentation fault in Nsock which occurred when calling
&lt;br&gt;&amp;nbsp; nsock_write() with a data length of -1 (which means the data is a
&lt;br&gt;&amp;nbsp; NUL-terminated string and Nsock should take the length itself) and
&lt;br&gt;&amp;nbsp; the Nsock trace level was at least 2. [Kris]
&lt;br&gt;&lt;br&gt;o The NSE Comm library now defaults to trying to read as many bytes as
&lt;br&gt;&amp;nbsp; are available rather than lines if neither the &amp;quot;bytes&amp;quot; nor &amp;quot;lines&amp;quot;
&lt;br&gt;&amp;nbsp; options are given. &amp;nbsp;Thanks to Brandon for reporting a problem which
&lt;br&gt;&amp;nbsp; he noticed in the dns-test-open-recursion script. [Kris]
&lt;br&gt;&lt;br&gt;o Updated zoneTrans.nse to replace length bytes in returned domain
&lt;br&gt;&amp;nbsp; names to periods itself rather than relying on NSE's old behavior of
&lt;br&gt;&amp;nbsp; replacing non-printable characters with periods. &amp;nbsp;Thanks to Rob
&lt;br&gt;&amp;nbsp; Nicholls for reporting the problem. [Kris]
&lt;br&gt;&lt;br&gt;o Some Zenmap crashes have been fixed: trying to &amp;quot;refresh&amp;quot; the output
&lt;br&gt;&amp;nbsp; of a scan loaded from a file, and trying to re-save a file loaded
&lt;br&gt;&amp;nbsp; from the command line in some circumstances. [David]
&lt;br&gt;&lt;br&gt;o [Zenmap] The file selector now remembers what directory it was last
&lt;br&gt;&amp;nbsp; looking at. [David]
&lt;br&gt;&lt;br&gt;o Added an extra layer of validity checking to received packets
&lt;br&gt;&amp;nbsp; (readip_pcap), just to be extra safe. See
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0644.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0644.html&lt;/a&gt;&amp;nbsp;. [Kris]
&lt;br&gt;&lt;br&gt;o Zenmap defaults to showing files matching both *.xml and *.usr in
&lt;br&gt;&amp;nbsp; the file selector. Previously it only showed those matching *.usr.
&lt;br&gt;&amp;nbsp; The new combined format will be XML and .usr will be deprecated.
&lt;br&gt;&amp;nbsp; See &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0093.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0093.html&lt;/a&gt;&amp;nbsp;.
&lt;br&gt;&lt;br&gt;o Nmap avoids printing the sending rate in bytes per second during a
&lt;br&gt;&amp;nbsp; TCP connect scan. Because the number of bytes per probe is not
&lt;br&gt;&amp;nbsp; known, it used to print current sending rates: 11248.85 packets / s,
&lt;br&gt;&amp;nbsp; 0.00 bytes / s. &amp;nbsp;Now it will print simply print rates like &amp;quot;11248.85
&lt;br&gt;&amp;nbsp; packets / s&amp;quot;. [David]
&lt;br&gt;&lt;br&gt;o [Zenmap] Nmap's installation process now include .desktop files
&lt;br&gt;&amp;nbsp; which install menu items for launching Zenmap as a privileged or
&lt;br&gt;&amp;nbsp; non-privileged process on Linux. This will mainly effect people who
&lt;br&gt;&amp;nbsp; install nmap and Zenmap directly from the source code. [Michael]
&lt;br&gt;&lt;br&gt;o Improved performance of IP protocol scan by fixing a bug related to
&lt;br&gt;&amp;nbsp; timing calculations on ICMP probe responses. &amp;nbsp;See r8754 svn log for
&lt;br&gt;&amp;nbsp; full details. [David]
&lt;br&gt;&lt;br&gt;o Nmap --reason output no longer falsely reports a localhost-response
&lt;br&gt;&amp;nbsp; during -PN scans. See
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0188.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0188.html&lt;/a&gt;. [Michael]
&lt;br&gt;&lt;br&gt;o [Zenmap] The higwidgets Python package has moved so it is now a
&lt;br&gt;&amp;nbsp; subpackage of zenmapGUI. This avoids naming conflicts with Umit,
&lt;br&gt;&amp;nbsp; which uses a slightly different version of higwidgets. [David]
&lt;br&gt;&lt;br&gt;o A bug that could cause some host discovery probes to be incorrectly
&lt;br&gt;&amp;nbsp; interpreted as drops was fixed. This occurred only when the IP
&lt;br&gt;&amp;nbsp; protocol ping (-PO) option was combined with other ping
&lt;br&gt;&amp;nbsp; types. [David]
&lt;br&gt;&lt;br&gt;o A new scanflags attribute has been added to XML output, which lists
&lt;br&gt;&amp;nbsp; all user specified --scanflags for the scan. nmap.dtd has been
&lt;br&gt;&amp;nbsp; modified to account for this. [Michael]
&lt;br&gt;&lt;br&gt;o The loading of the nmap-services file has been made much
&lt;br&gt;&amp;nbsp; faster--roughly 9 times faster in common cases. &amp;nbsp;This is important
&lt;br&gt;&amp;nbsp; for the new (much larger) frequency augmented nmap-services
&lt;br&gt;&amp;nbsp; file. [David]
&lt;br&gt;&lt;br&gt;o Added a script (ASN.nse) which uses Team Cymru's DNS interface to
&lt;br&gt;&amp;nbsp; determine the routing AS numbers of scanned IP addresses. &amp;nbsp;They even
&lt;br&gt;&amp;nbsp; set up a special domain just for Nmap queries. &amp;nbsp;The script is still
&lt;br&gt;&amp;nbsp; experimental and non-default. [Jah, Michael]
&lt;br&gt;&lt;br&gt;o [Zenmap] Clicking &amp;quot;Cancel&amp;quot; in a file chooser in the diff interface
&lt;br&gt;&amp;nbsp; no longer causes a crash. [David]
&lt;br&gt;&lt;br&gt;o The shtool build helper script has been updated to version 2.0.8. An
&lt;br&gt;&amp;nbsp; older version of shutil caused installation to fail when the locale
&lt;br&gt;&amp;nbsp; was set to et_EE. Thanks to Michal Januszewski for the bug
&lt;br&gt;&amp;nbsp; report. [David]
&lt;br&gt;&lt;br&gt;o [Zenmap] Removed services.dmp and os_dmp.dmp and all the files that
&lt;br&gt;&amp;nbsp; referred to them. They are not needed with the new search
&lt;br&gt;&amp;nbsp; interface. Also removed an unused search progress bar. &amp;nbsp;And some
&lt;br&gt;&amp;nbsp; broken fingerprint submission code. &amp;nbsp;Yay for de-bloating! [David]
&lt;br&gt;&lt;br&gt;o [Zenmap] Added &amp;quot;%F&amp;quot; to the Exec link in the new Zenmap desktop
&lt;br&gt;&amp;nbsp; file. We expect (hope) that this will allow dragging and dropping
&lt;br&gt;&amp;nbsp; XML files onto the icon. [David]
&lt;br&gt;&lt;br&gt;o [Zenmap] The -o[XGASN] options can now be specified, just as you can
&lt;br&gt;&amp;nbsp; at the console. [Vladimir]
&lt;br&gt;&lt;br&gt;o [Zenmap] You can now shrink the scan window below its default
&lt;br&gt;&amp;nbsp; size thanks to NmapOutputViewer code enhancements. [David]
&lt;br&gt;&lt;br&gt;o [Zenmap] Removed optional use of the Psyco Python optimizer since
&lt;br&gt;&amp;nbsp; Zenmap is not the kind of CPU-bound application which benefits from
&lt;br&gt;&amp;nbsp; Psyco.
&lt;br&gt;&lt;br&gt;o [Zenmap] You can now select more than one host in the &amp;quot;Ports /
&lt;br&gt;&amp;nbsp; Hosts&amp;quot; view by control-clicking them in the column at left.
&lt;br&gt;&lt;br&gt;o [Zenmap] The profile editor now offers the --traceroute option.
&lt;br&gt;&lt;br&gt;o Zenmap now uses Unicode objects pervasively when dealing with Nmap
&lt;br&gt;&amp;nbsp; text output, though the only internationalized text Nmap currently
&lt;br&gt;&amp;nbsp; outputs is the user's time zone. [David]
&lt;br&gt;&lt;br&gt;o Unprintable characters in NSE script output (which really shouldn't
&lt;br&gt;&amp;nbsp; happen anyway) are now printed like \xHH, where HH is the
&lt;br&gt;&amp;nbsp; hexadecimal representation of the character. See
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0180.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0180.html&lt;/a&gt;&amp;nbsp;. [Patrick]
&lt;br&gt;&lt;br&gt;o Nmap sometimes sent packets with incorrect IP checksums,
&lt;br&gt;&amp;nbsp; particularly when sending the UDP probes in OS detection. This has
&lt;br&gt;&amp;nbsp; been fixed. Thanks to Gisle Vanem for reporting and investigating the
&lt;br&gt;&amp;nbsp; bug. [David]
&lt;br&gt;&lt;br&gt;o Fixed the --without-liblua configure option so that it works
&lt;br&gt;&amp;nbsp; again. [David]
&lt;br&gt;&lt;br&gt;o In the interest of forward compatibility, the xmloutputversion
&lt;br&gt;&amp;nbsp; attribute in Nmap XML output is no longer constrained to be a
&lt;br&gt;&amp;nbsp; certain string (&amp;quot;1.02&amp;quot;). The xmloutputversion should be taken as
&lt;br&gt;&amp;nbsp; merely advisory by authors of parsers.
&lt;br&gt;&lt;br&gt;o Zenmap no longer leaves any temporary files lying around. [David]
&lt;br&gt;&lt;br&gt;o Nmap only prints an uptime guess in verbose mode now, because in
&lt;br&gt;&amp;nbsp; some situations it can be very inaccurate. See the discussion at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q3/0392.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q3/0392.html&lt;/a&gt;. [David]
&lt;br&gt;&lt;br&gt;Enjoy the release!
&lt;br&gt;-Fyodor
&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap-4.75-released-tp19381645p19381645.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-19297995</id>
	<title>New to nmap...</title>
	<published>2008-09-03T13:57:14Z</published>
	<updated>2008-09-03T13:57:14Z</updated>
	<author>
		<name>eastbay80</name>
	</author>
	<content type="html">Hello all,
&lt;br&gt;&lt;br&gt;I just discovered nmap and have been trying to get a better grasp of nmap. &amp;nbsp;To be more specific, I am have been looking for specific information but can't seem to find it. &amp;nbsp;Bet yet, maybe if i explain my situation to get clearer responses..
&lt;br&gt;&lt;br&gt;I currently live in a complex which offers inet (meraki.net w/ 5 gb usage per month). &amp;nbsp;I do a lot of p2p, so you can imagine that i kill about 5 gigs per day. &amp;nbsp;I was able to surpass 5 gb per month by chaning computer name and changing macid when they ban me from the inet.
&lt;br&gt;&lt;br&gt;However, it is firewalled, so when i upload, i am limited...so my question is
&lt;br&gt;&lt;br&gt;1. will nmap do anything for me?
&lt;br&gt;2. if so, can someone link me to a forum or pm me a set of step by step direction in order to use open ports?
&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;-eastbay80</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/New-to-nmap...-tp19297995p19297995.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-19009897</id>
	<title>remote desktop trojan</title>
	<published>2008-08-16T01:57:36Z</published>
	<updated>2008-08-16T01:57:36Z</updated>
	<author>
		<name>anitha2324</name>
	</author>
	<content type="html">Hi all ,
&lt;br&gt;&lt;br&gt;I want to know about the windows remote desktop trojan ( remote machine is windows 2003 server ) is there any remote desktop trojan tool which allows
&lt;br&gt;me to remotely access the desktop of remote machine
&lt;br&gt;&lt;br&gt;am new bie in this field</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/remote-desktop-trojan-tp19009897p19009897.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18768817</id>
	<title>Nmap 4.68 release</title>
	<published>2008-07-31T23:06:28Z</published>
	<updated>2008-07-31T23:06:28Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">Hi All. &amp;nbsp;I'm happy to report that there have been several stable Nmap
&lt;br&gt;releases since I mailed you about Nmap 4.60 in March. &amp;nbsp;The latest
&lt;br&gt;version is 4.68, and I think you'll like it (unless you still use
&lt;br&gt;Win2K, which can be problematic due to IPv6 issues that we hope to
&lt;br&gt;resolve in the next release). &amp;nbsp;Before I give you the full list of 125
&lt;br&gt;improvements, I'll start with a few highlights:
&lt;br&gt;&lt;br&gt;o Added a new --min-rate option that allows specifying a minimum rate
&lt;br&gt;&amp;nbsp; at which to send packets. This allows you to override Nmap's
&lt;br&gt;&amp;nbsp; congestion control algorithms and request that Nmap try to keep at
&lt;br&gt;&amp;nbsp; least the rate you specify. &amp;nbsp;The rate is given in packets per
&lt;br&gt;&amp;nbsp; second. Read more in the Nmap man page
&lt;br&gt;&amp;nbsp; (&lt;a href=&quot;http://nmap.org/book/man-performance.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/man-performance.html&lt;/a&gt;). &amp;nbsp;If you use the latest
&lt;br&gt;&amp;nbsp; version in the Nmap subversion repository, you'll also get a
&lt;br&gt;&amp;nbsp; --max-rate option which lets you
&lt;br&gt;&amp;nbsp; limit Nmap's packet rate (and thus bandwidth used).
&lt;br&gt;&lt;br&gt;o Mac OS X binary packages for Zenmap+Nmap are now available, as I
&lt;br&gt;&amp;nbsp; mentioned in the previous mail.
&lt;br&gt;&lt;br&gt;o The Windows version of Nmap now supports OpenSSL just as the UNIX
&lt;br&gt;&amp;nbsp; versions have for years. &amp;nbsp;Both the .zip and executable installer
&lt;br&gt;&amp;nbsp; binary packages we ship from the Nmap download page now include
&lt;br&gt;&amp;nbsp; OpenSSL.
&lt;br&gt;&lt;br&gt;o We now compile in IPv6 support on Windows. &amp;nbsp;In order to use this,
&lt;br&gt;&amp;nbsp; you need to have IPv6 set up. &amp;nbsp;It is installed by default on Vista,
&lt;br&gt;&amp;nbsp; but must be downloaded from Microsoft for XP. &amp;nbsp;See
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://www.microsoft.com/technet/network/ipv6/ipv6faq.mspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.microsoft.com/technet/network/ipv6/ipv6faq.mspx&lt;/a&gt;&amp;nbsp;. &amp;nbsp;This
&lt;br&gt;&amp;nbsp; feature causes Nmap to no longer work on Windows 2000, but we hope to
&lt;br&gt;&amp;nbsp; fix that in the next release.
&lt;br&gt;&lt;br&gt;o Tons of new version detection signatures and OS detection
&lt;br&gt;&amp;nbsp; fingerprints have been added. &amp;nbsp;Version 4.68 has reached more than
&lt;br&gt;&amp;nbsp; 5,000 version detection signatures, and the latest subversion
&lt;br&gt;&amp;nbsp; version of Nmap has more than 1,500 2nd generation OS detection
&lt;br&gt;&amp;nbsp; fingerprints. &amp;nbsp;We were only able to do this because so many of you
&lt;br&gt;&amp;nbsp; submit updates and corrections when Nmap guesses wrong or provides a
&lt;br&gt;&amp;nbsp; fingerprint and URL for submission on our site. &amp;nbsp;Please keep those
&lt;br&gt;&amp;nbsp; submissions coming! &amp;nbsp;We receive far more fingerprint submissions
&lt;br&gt;&amp;nbsp; than correction notices -- please do remember to submit a correction
&lt;br&gt;&amp;nbsp; when Nmap guesses wrong, as described at &lt;a href=&quot;http://nmap.org/submit/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/submit/&lt;/a&gt;&amp;nbsp;.
&lt;br&gt;&lt;br&gt;o Nmap now supports 64-bit versions of Windows.
&lt;br&gt;&lt;br&gt;o We added advanced search functionality (and dozens of other
&lt;br&gt;&amp;nbsp; improvements) to the Zenamp GUI. &amp;nbsp;You can now locate previous scans
&lt;br&gt;&amp;nbsp; using criteria such as which ports were open, keywords in the target
&lt;br&gt;&amp;nbsp; names, OS detection results. etc. &amp;nbsp;Try it out with Ctrl-F or
&lt;br&gt;&amp;nbsp; &amp;quot;Tools-&amp;gt;Search Scan Results&amp;quot;
&lt;br&gt;&lt;br&gt;o Fixed an integer overflow which prevented a target specification of
&lt;br&gt;&amp;nbsp; &amp;quot;*.*.*.*&amp;quot; from working. &amp;nbsp;Support for the CIDR /0 is now also
&lt;br&gt;&amp;nbsp; available for those times you wish to scan the entire
&lt;br&gt;&amp;nbsp; Internet.
&lt;br&gt;&lt;br&gt;o Made many performance enhancements, and also fixed many errors which
&lt;br&gt;&amp;nbsp; could lead to crashes in Nmap or Zenmap. &amp;nbsp;See the big list below for
&lt;br&gt;&amp;nbsp; details.
&lt;br&gt;&lt;br&gt;You can obtain Nmap 4.68 from the normal location:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/download.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/download.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Please give it a try! &amp;nbsp;And if you encounter any problems, report them
&lt;br&gt;to nmap-dev as described at &lt;a href=&quot;http://nmap.org/book/man-bugs.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/man-bugs.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;I've included the detailed list of changes between 4.60 and 4.68
&lt;br&gt;below. &amp;nbsp;Or you can read it at &lt;a href=&quot;http://nmap.org/changelog.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/changelog.html&lt;/a&gt;&amp;nbsp;. &amp;nbsp;The
&lt;br&gt;URL version also includes the post-4.68 changes which you get if you
&lt;br&gt;use the svn version.
&lt;br&gt;&lt;br&gt;Nmap 4.68 [2008-6-28]
&lt;br&gt;&lt;br&gt;o Doug integrated all of your version detection submissions and
&lt;br&gt;&amp;nbsp; corrections for the year up to May 31. &amp;nbsp;There were more than 1,000
&lt;br&gt;&amp;nbsp; new submissions and 18 corrections. &amp;nbsp;Please keep them coming! &amp;nbsp;And
&lt;br&gt;&amp;nbsp; don't forget that corrections are very important, so do submit them
&lt;br&gt;&amp;nbsp; if you ever catch Nmap making a version detection or OS detection
&lt;br&gt;&amp;nbsp; mistake. &amp;nbsp;The version detection DB has grown to 5,054 signatures
&lt;br&gt;&amp;nbsp; representing 486 service protocols. &amp;nbsp;Protocols span the gamut from
&lt;br&gt;&amp;nbsp; abc, acap, access-remote-pc, activefax, and activemq, to zebedee,
&lt;br&gt;&amp;nbsp; zebra, zenimaging, and zenworks. &amp;nbsp;The most popular protocols are
&lt;br&gt;&amp;nbsp; http (1,672 signatures), telnet (519), ftp (459), smtp (344), and
&lt;br&gt;&amp;nbsp; pop3 (201).
&lt;br&gt;&lt;br&gt;o Nmap compilation on Windows is now done with Visual C++ Express 2008
&lt;br&gt;&amp;nbsp; rather than 2005. &amp;nbsp;Windows compilation instructions have been
&lt;br&gt;&amp;nbsp; updated at &lt;a href=&quot;http://nmap.org/book/inst-windows.html#inst-win-source&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/inst-windows.html#inst-win-source&lt;/a&gt;&amp;nbsp;.
&lt;br&gt;&amp;nbsp; [Kris]
&lt;br&gt;&lt;br&gt;o The Nmap Windows self-installer now automatically installs the MS
&lt;br&gt;&amp;nbsp; Visual C++ 2008 runtime components if they aren't already installed
&lt;br&gt;&amp;nbsp; on a system. &amp;nbsp;These are some reasonably small DLLs that are
&lt;br&gt;&amp;nbsp; generally necessary for applications compiled with Visual C++ (with
&lt;br&gt;&amp;nbsp; dynamic linking). &amp;nbsp;Many or most systems already have these installed
&lt;br&gt;&amp;nbsp; from other software packages. &amp;nbsp;The lack of these components led to
&lt;br&gt;&amp;nbsp; the error message &amp;quot;The Application failed to initialize properly
&lt;br&gt;&amp;nbsp; (0xc0150002).&amp;quot; with Nmap 4.65. &amp;nbsp;A related change is that Nmap on
&lt;br&gt;&amp;nbsp; Windows is now compiled with /MD rather than /MT so that it
&lt;br&gt;&amp;nbsp; consistently uses these runtime libraries. &amp;nbsp;The patch was created by
&lt;br&gt;&amp;nbsp; Rob Nicholls.
&lt;br&gt;&lt;br&gt;o Added advanced search functionality to Zenmap so that you can locate
&lt;br&gt;&amp;nbsp; previous scans using criteria such as which ports were open,
&lt;br&gt;&amp;nbsp; keywords
&lt;br&gt;&amp;nbsp; in the target names, OS detection results. etc. &amp;nbsp;Try it out with
&lt;br&gt;&amp;nbsp; Ctrl-F or &amp;quot;Tools-&amp;gt;Search Scan Results&amp;quot;. [Vladimir]
&lt;br&gt;&lt;br&gt;o Nmap's special WinPcap installer now handles 64-bit Windows machines
&lt;br&gt;&amp;nbsp; by installing the proper 64-bit npf.sys. [Rob Nicholls]
&lt;br&gt;&lt;br&gt;o Added a new NSE Comm (common communication) library for common
&lt;br&gt;&amp;nbsp; network discovery tasks such as banner-grabbing (get_banner()) and
&lt;br&gt;&amp;nbsp; making a quick exchange of data (exchange()). &amp;nbsp;16 scripts were
&lt;br&gt;&amp;nbsp; updated to use this library. [Kris]
&lt;br&gt;&lt;br&gt;o The Nmap Scripting Engine now supports mutexes for gracefully
&lt;br&gt;&amp;nbsp; handling concurrency issues. &amp;nbsp;Mutexes are documented at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://nmap.org/book/nse-api.html#nse-mutex&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/nse-api.html#nse-mutex&lt;/a&gt;&amp;nbsp;. [Patrick]
&lt;br&gt;&lt;br&gt;o Added a UDP SNMPv3 probe to version detection, along with 9 vendor
&lt;br&gt;&amp;nbsp; match lines. The patch was from Tom Sellers, who contributed other
&lt;br&gt;&amp;nbsp; probes and match lines to this release as well.
&lt;br&gt;&lt;br&gt;o Added a new timing_level() function to NSE which reports the Nmap
&lt;br&gt;&amp;nbsp; timing level from 0 to 5, as set by the Nmap -T option. &amp;nbsp;The default
&lt;br&gt;&amp;nbsp; is 3. [Thomas Buchanan]
&lt;br&gt;&lt;br&gt;o Update the HTTP library to use the new timing_level functionality to
&lt;br&gt;&amp;nbsp; set connection and response timeouts. An error preventing the new
&lt;br&gt;&amp;nbsp; timing_level feature from working was also fixed. &amp;nbsp;[Jah]
&lt;br&gt;&lt;br&gt;o Optimized the doAnyOutstandingProbes() function to make Nmap a bit
&lt;br&gt;&amp;nbsp; faster and more efficient. &amp;nbsp;This makes a particularly big difference
&lt;br&gt;&amp;nbsp; in cases where --min-rate is being used to specify a very high
&lt;br&gt;&amp;nbsp; packet sending rate. [David]
&lt;br&gt;&lt;br&gt;o Fixed an integer overflow which prevented a target specification of
&lt;br&gt;&amp;nbsp; &amp;quot;*.*.*.*&amp;quot; from working. &amp;nbsp;Support for the CIDR /0 is now also
&lt;br&gt;&amp;nbsp; available for those times you wish to scan the entire
&lt;br&gt;&amp;nbsp; Internet. [Kris]
&lt;br&gt;&lt;br&gt;o The robots.nse script has been improved to print output more
&lt;br&gt;&amp;nbsp; compactly and limit the number of entries of large robots.txt files
&lt;br&gt;&amp;nbsp; based on Nmap verbosity and debugging levels. [Eddie Bell]
&lt;br&gt;&lt;br&gt;o The Nmap NSE scripts have been re-categorized in a more logical
&lt;br&gt;&amp;nbsp; fashion. &amp;nbsp;The new categories are described at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://nmap.org/book/nse-usage.html#nse-categories&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/nse-usage.html#nse-categories&lt;/a&gt;&amp;nbsp;. [Kris]
&lt;br&gt;&lt;br&gt;o Improve AIX support by linking against -lodm and -lcfg on that
&lt;br&gt;&amp;nbsp; platform. [David]
&lt;br&gt;&lt;br&gt;o Updated showHTMLTitle NSE script to follow one HTTP redirect if
&lt;br&gt;&amp;nbsp; necessary as long as it is on the same server. [Jah]
&lt;br&gt;&lt;br&gt;o Michael Pattrick and David created a new OSassist application which
&lt;br&gt;&amp;nbsp; streamlines the OS fingerprint submission integration process and
&lt;br&gt;&amp;nbsp; prevents certain previously common errors. &amp;nbsp;OSassist isn't part of
&lt;br&gt;&amp;nbsp; Nmap, but the system was used to integrate some submissions for this
&lt;br&gt;&amp;nbsp; release. &amp;nbsp;13 fingerprints were added during OSassist testing, and
&lt;br&gt;&amp;nbsp; some existing fingerprints were improved as well. &amp;nbsp;Expect many more
&lt;br&gt;&amp;nbsp; fingerprints coming soon.
&lt;br&gt;&lt;br&gt;o Improved the mapping from dnet device names (like eth0) and WinPcap
&lt;br&gt;&amp;nbsp; names (like \Device\NPF_{28700713...}). &amp;nbsp;You can see this mapping
&lt;br&gt;&amp;nbsp; with --iflist, and the change should make Nmap more likely to work
&lt;br&gt;&amp;nbsp; on Windows machines with unusual networking configurations. [David]
&lt;br&gt;&lt;br&gt;o Service fingerprints in XML output are no longer be truncated to
&lt;br&gt;&amp;nbsp; 2kb. &amp;nbsp;[Michael]
&lt;br&gt;&lt;br&gt;o Some laptops report the IP Family as NULL for disabled WiFi cards.
&lt;br&gt;&amp;nbsp; This could lead to a crash with the &amp;quot;sin-&amp;gt;sin_family == AF_INET6&amp;quot;
&lt;br&gt;&amp;nbsp; assertion failure. &amp;nbsp;Nmap no longer quits when this is
&lt;br&gt;&amp;nbsp; encountered. [Michael]
&lt;br&gt;&lt;br&gt;o On systems without the GNU getopt_long_only() function, Nmap has its
&lt;br&gt;&amp;nbsp; own replacement. &amp;nbsp;That replacement used to call the system's
&lt;br&gt;&amp;nbsp; getopt() function if it exists. &amp;nbsp;But the AIX and Solaris getopt()
&lt;br&gt;&amp;nbsp; functions proved insufficient/buggy, so Nmap now always calls its
&lt;br&gt;&amp;nbsp; own internal getopt() now from its getopt_long_only()
&lt;br&gt;&amp;nbsp; replacement. [David]
&lt;br&gt;&lt;br&gt;o Integrated several service match lines from Tom Sellers.
&lt;br&gt;&lt;br&gt;o An error was fixed where Zenmap would crash when trying to load from
&lt;br&gt;&amp;nbsp; the recent scans database a file containing non-ASCII
&lt;br&gt;&amp;nbsp; characters. The error looked like
&lt;br&gt;&amp;nbsp; &amp;nbsp; pysqlite2.dbapi2.OperationalError: Could not decode to UTF-8
&lt;br&gt;&amp;nbsp; column
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 'nmap_xml_output' with text
&lt;br&gt;&amp;nbsp; &amp;nbsp; '&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;iso-8859-1&amp;quot;?&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;lt;nmaprun profile=&amp;quot;nmap -T Aggressive -n -v %s&amp;quot; scanner=&amp;quot;nmap&amp;quot;
&lt;br&gt;&amp;nbsp; hint=&amp;quot;&amp;quot;
&lt;br&gt;&amp;nbsp; The error would be seen when such a scan was found in using the
&lt;br&gt;&amp;nbsp; search interface. [David]
&lt;br&gt;&lt;br&gt;o Fix a Zenmap crash which occurred when local.getpreferredencoding()
&lt;br&gt;&amp;nbsp; returns &amp;quot;None&amp;quot;. &amp;nbsp;Similarly, deal with the case when a &amp;quot;X-MAC-KOREAN&amp;quot;
&lt;br&gt;&amp;nbsp; is returned by this function. &amp;nbsp;Both problems were found with the
&lt;br&gt;&amp;nbsp; Zenmap crash reporter. [David]
&lt;br&gt;&lt;br&gt;o A whole bunch of internal Zenmap cleanup was done by David to make
&lt;br&gt;&amp;nbsp; the code more logical and remove dead code.
&lt;br&gt;&lt;br&gt;o Install icons and pixmaps under /usr/share/zenmap/{icons,pixmaps} so
&lt;br&gt;&amp;nbsp; they don't get mixed in with the files in
&lt;br&gt;&amp;nbsp; /usr/share/{icons,pixmaps}. &amp;nbsp;[Jurand Nogiec]
&lt;br&gt;&lt;br&gt;o Fixed a Zenmap command entry problem where Zenmap would lose a
&lt;br&gt;&amp;nbsp; custom command you had entered into the command entry field if you
&lt;br&gt;&amp;nbsp; changed the target field after entering the custom command. [Jurand
&lt;br&gt;&amp;nbsp; Nogiec]
&lt;br&gt;&lt;br&gt;o The Zenmap crash reporter now includes a stack trace rather than
&lt;br&gt;&amp;nbsp; just the exception name. [David]
&lt;br&gt;&lt;br&gt;o Zenmap now executes the proper Nmap command by honoring the
&lt;br&gt;&amp;nbsp; nmap_command_path variable in zenmap.conf. [Jurand Nogiec]
&lt;br&gt;&lt;br&gt;o Fixed a bug which caused -PN to erroneously bail out for
&lt;br&gt;&amp;nbsp; unprivileged users. &amp;nbsp;Thanks to Jabra (jabra(a)spl0it.org) for the
&lt;br&gt;&amp;nbsp; report. [Kris]
&lt;br&gt;&lt;br&gt;o Fixed several Nmap NSE memory leaks found with Valgrind. [Kris]
&lt;br&gt;&lt;br&gt;o Migrated some stray malloc()/realloc() calls to the Nbase
&lt;br&gt;&amp;nbsp; safe_malloc()/safe_realloc() versions which guard against certain
&lt;br&gt;&amp;nbsp; errors.
&lt;br&gt;&lt;br&gt;o Fixed a bunch of subtle bugs, some of which could have resulted in
&lt;br&gt;&amp;nbsp; a crash, reported by Ilja van Sprundel. [Kris]
&lt;br&gt;&lt;br&gt;o Fixed several byte-order bugs in Traceroute. [Kris]
&lt;br&gt;&lt;br&gt;o Fixed a crash in RateMeter::update() which could lead to an error
&lt;br&gt;&amp;nbsp; saying &amp;quot;diff &amp;gt;= 0.0&amp;quot; assertion failed. &amp;nbsp;I think the problem was
&lt;br&gt;&amp;nbsp; actually caused by SMP machines which didn't sync the clock time
&lt;br&gt;&amp;nbsp; perfectly. &amp;nbsp;This lead to gettimeofday() sometimes reporting that
&lt;br&gt;&amp;nbsp; time decreased by some microseconds. &amp;nbsp;Now Nmap is willing to
&lt;br&gt;&amp;nbsp; tolerate decreases of up to 1 millisecond in this function. [Fyodor]
&lt;br&gt;&lt;br&gt;o Nmap now returns correct values for --iflist in windows even
&lt;br&gt;&amp;nbsp; if interface aliases have been set. Previously it would misreport
&lt;br&gt;&amp;nbsp; the windevices and not list all interfaces. [Michael]
&lt;br&gt;&lt;br&gt;o Nmap no longer crashes with an 'assert' error when its told to
&lt;br&gt;&amp;nbsp; access a disabled WiFi NIC on some laptops. [Michael]
&lt;br&gt;&lt;br&gt;o Upgraded the OpenSSL shipped for Windows to 0.9.8h. [Kris]
&lt;br&gt;&lt;br&gt;o The NSE http library was updated to gracefully handle certain bogus
&lt;br&gt;&amp;nbsp; (non-)http responses. [Jah]
&lt;br&gt;&lt;br&gt;o The zoneTrans.nse script now takes a &amp;quot;domain&amp;quot; script argument to
&lt;br&gt;&amp;nbsp; specify the desired domain name to transfer. &amp;nbsp;You can narrow the
&lt;br&gt;&amp;nbsp; scope down with the form &amp;quot;zoneTrans={domain=xxx}&amp;quot;. [Kris]
&lt;br&gt;&lt;br&gt;o Increase write buffer length for Nmap output on Windows. This should
&lt;br&gt;&amp;nbsp; prevent error messages like: &amp;quot;log_vwrite: vnsprintf failed. &amp;nbsp;Even
&lt;br&gt;&amp;nbsp; after increasing bufferlen to 819200, Vsnprintf returned -1 (logt ==
&lt;br&gt;&amp;nbsp; 1).&amp;quot; &amp;nbsp;Thanks to prozente0 for the report. [Fyodor]
&lt;br&gt;&lt;br&gt;o Fixed the --script-updatedb command, which was claiming to be
&lt;br&gt;&amp;nbsp; &amp;quot;Aborting database update&amp;quot; even when the update was performed
&lt;br&gt;&amp;nbsp; perfectly. &amp;nbsp;See &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q2/0623.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q2/0623.html&lt;/a&gt;&amp;nbsp;.
&lt;br&gt;&amp;nbsp; Thanks to Jah for the report.
&lt;br&gt;&lt;br&gt;Nmap 4.65 [2008-6-1]
&lt;br&gt;&lt;br&gt;o A Mac OS X Nmap/Zenmap installer is now available from the Nmap
&lt;br&gt;&amp;nbsp; download page! &amp;nbsp;It is rather straightforward, but detailed
&lt;br&gt;&amp;nbsp; instructions are available anyway at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://nmap.org/book/inst-macosx.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/inst-macosx.html&lt;/a&gt;&amp;nbsp;. &amp;nbsp;As a universal installer,
&lt;br&gt;&amp;nbsp; it works on both Intel and PPC Macs. It is distributed as a disk
&lt;br&gt;&amp;nbsp; image file (.dmg) containing an mpkg package. &amp;nbsp;The installed Nmap
&lt;br&gt;&amp;nbsp; does include OpenSSL support. &amp;nbsp;It also supports Authorization
&lt;br&gt;&amp;nbsp; Services so that Zenmap can run as root. &amp;nbsp;David created this
&lt;br&gt;&amp;nbsp; installer. &amp;nbsp;He wants to thank Benson Kalahar and Vlad Alexa for
&lt;br&gt;&amp;nbsp; extensive testing of the nine test releases.
&lt;br&gt;&lt;br&gt;o The Windows version of Nmap now supports OpenSSL just as the UNIX
&lt;br&gt;&amp;nbsp; versions have for years. &amp;nbsp;Both the .zip and executable installer
&lt;br&gt;&amp;nbsp; binary packages we ship from the Nmap download page now include
&lt;br&gt;&amp;nbsp; OpenSSL. [Kris, Thomas Buchanan]
&lt;br&gt;&lt;br&gt;o We now compile in IPv6 support on Windows. &amp;nbsp;In order to use this,
&lt;br&gt;&amp;nbsp; you need to have IPv6 set up. &amp;nbsp;It is installed by default on Vista,
&lt;br&gt;&amp;nbsp; but must be downloaded from Microsoft for XP. &amp;nbsp;See
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://www.microsoft.com/technet/network/ipv6/ipv6faq.mspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.microsoft.com/technet/network/ipv6/ipv6faq.mspx&lt;/a&gt;&amp;nbsp;. [Kris]
&lt;br&gt;&lt;br&gt;o Seven Google-sponsored Summer of Code students began working on
&lt;br&gt;&amp;nbsp; exciting Nmap projects full times. &amp;nbsp;The winning students and their
&lt;br&gt;&amp;nbsp; Nmap development projects are described at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q2/0132.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q2/0132.html&lt;/a&gt;&amp;nbsp;.
&lt;br&gt;&lt;br&gt;o Our WinPcap installer now starts the NPF driver running as a
&lt;br&gt;&amp;nbsp; service immediately upon installation and after restarts. You can
&lt;br&gt;&amp;nbsp; disable this with new check-boxes. This behavior is important for
&lt;br&gt;&amp;nbsp; Vista and Windows Server 2008 machines when User Account
&lt;br&gt;&amp;nbsp; Control (UAC) is enabled. [Rob Nicholls]
&lt;br&gt;&lt;br&gt;o Nmap and Nmap-WinPcap silent installation now works. &amp;nbsp;Nmap can
&lt;br&gt;&amp;nbsp; be silently installed with the /S option to the installer.
&lt;br&gt;&amp;nbsp; If you install Nmap from the zip file, you can install just
&lt;br&gt;&amp;nbsp; WinPcap silently with the /S option to that
&lt;br&gt;&amp;nbsp; installer. [Rob Nicholls]
&lt;br&gt;&lt;br&gt;o Our WinPcap installer is now included with the Nmap Win32 zip
&lt;br&gt;&amp;nbsp; file. [Fyodor]
&lt;br&gt;&lt;br&gt;o Numerous miscellaneous improvements were made to our Win32
&lt;br&gt;&amp;nbsp; installer, such as using the &amp;quot;Modern&amp;quot; NSIS UI for WinPcap,
&lt;br&gt;&amp;nbsp; improving the option description labels, and showing a finish
&lt;br&gt;&amp;nbsp; page in all cases. [Rob Nicholls]
&lt;br&gt;&lt;br&gt;o The nmap-dev and nmap-hackers mailing list RSS feeds at seclists.org
&lt;br&gt;&amp;nbsp; now include message excerpts to make it easier to identify
&lt;br&gt;&amp;nbsp; interesting messages and speed the process of reading through the
&lt;br&gt;&amp;nbsp; list. &amp;nbsp;Feeds for all other mailing lists archived at SecLists.Org
&lt;br&gt;&amp;nbsp; have been similarly augmented. &amp;nbsp;For details, see
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q2/0333.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q2/0333.html&lt;/a&gt;&amp;nbsp;. [David]
&lt;br&gt;&lt;br&gt;o A new &amp;quot;default&amp;quot; Nmap Scripting Engine category was added. &amp;nbsp;Only
&lt;br&gt;&amp;nbsp; scripts in this category now run by default (except for &amp;quot;version&amp;quot;
&lt;br&gt;&amp;nbsp; scripts which run when version detection was requested).
&lt;br&gt;&amp;nbsp; Previously, any scripts in the &amp;quot;safe&amp;quot; or &amp;quot;intrusive&amp;quot; categories were
&lt;br&gt;&amp;nbsp; run. &amp;nbsp;21 &amp;nbsp;being recorded properly when scanning certain printers
&lt;br&gt;&amp;nbsp; from
&lt;br&gt;&amp;nbsp; little-endian computers. Updated nmap-os-db to compensate for
&lt;br&gt;&amp;nbsp; signatures that had an incorrect U1.RID value. &amp;nbsp;[Michael]
&lt;br&gt;&lt;br&gt;o Updated to include the latest MAC Address prefixes from the IEEE in
&lt;br&gt;&amp;nbsp; nmap-mac-prefixes [Fyodor]
&lt;br&gt;&lt;br&gt;o Updated the SMTPcommands NSE script to work better against Postfix
&lt;br&gt;&amp;nbsp; and reduce verbosity. [Jason DePriest, Fyodor]
&lt;br&gt;&lt;br&gt;o Reorganized the way ping probes are handled internally. &amp;nbsp;Rather than
&lt;br&gt;&amp;nbsp; being stored in the NmapOps structure, they are now stored within
&lt;br&gt;&amp;nbsp; the individual scan_lists structures. &amp;nbsp;This is a cleaner
&lt;br&gt;&amp;nbsp; organization. [Michael]
&lt;br&gt;&lt;br&gt;o Fix grepable output's &amp;quot;Ignored State&amp;quot; reporting. &amp;nbsp;Only one ignored
&lt;br&gt;&amp;nbsp; state (the one with the highest numbers of ports) is shown. [David]
&lt;br&gt;&lt;br&gt;o Update to Lua version 5.1.3 [Patrick]
&lt;br&gt;&lt;br&gt;o Add NSE stdnse library to include tobinary, tooctal, and tohex
&lt;br&gt;&amp;nbsp; functions. [Patrick]
&lt;br&gt;&lt;br&gt;o Fixed a bug which caused the Zenmap crash reporter to, uh,
&lt;br&gt;&amp;nbsp; crash. [David]
&lt;br&gt;&lt;br&gt;o NSE engine was cleaned up significantly. &amp;nbsp;nse_auxiliar was removed,
&lt;br&gt;&amp;nbsp; and file system manipulation functions were moved from nse_init.cc
&lt;br&gt;&amp;nbsp; into a new nse_fs.cc file. &amp;nbsp;Numerous interfaces between Nmap and Lua
&lt;br&gt;&amp;nbsp; were improved. &amp;nbsp;Most of these functions are now callable directly by
&lt;br&gt;&amp;nbsp; Lua. [Patrick]
&lt;br&gt;&lt;br&gt;o Fixed a bug in the showOwner NSE script which caused it to try UDP
&lt;br&gt;&amp;nbsp; ports instead of just TCP ports. &amp;nbsp;This made it very slow in the
&lt;br&gt;&amp;nbsp; common case where there are many UDP ports in the open|filtered
&lt;br&gt;&amp;nbsp; state. &amp;nbsp;Thanks to Jason DePriest for reporting the problem and Jah
&lt;br&gt;&amp;nbsp; for tracking it down and fixing it.
&lt;br&gt;&lt;br&gt;o Nbase now generates pseudo-random numbers itself rather than using
&lt;br&gt;&amp;nbsp; /dev/urandom on Linux and the terrible rand() function on Windows.
&lt;br&gt;&amp;nbsp; The new system uses ARC4 based on libdnet's
&lt;br&gt;&amp;nbsp; implementation. [Brandon]
&lt;br&gt;&lt;br&gt;o Made a number of updates and improvements to the Zenmap Users' Guide
&lt;br&gt;&amp;nbsp; at &lt;a href=&quot;http://nmap.org/book/zenmap.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/zenmap.html&lt;/a&gt;&amp;nbsp;. [David]
&lt;br&gt;&lt;br&gt;o Fixed the way Zenmap handles command-line entry to prevent your
&lt;br&gt;&amp;nbsp; custom command-line to be overwritten with the current profile's
&lt;br&gt;&amp;nbsp; command just because you edited the target field. [Jurand]
&lt;br&gt;&lt;br&gt;o Nsock was improved to better support reading from non-network
&lt;br&gt;&amp;nbsp; descriptors such as stdin. &amp;nbsp;This is important for the upcoming Ncat
&lt;br&gt;&amp;nbsp; project Mixter is working on. [Mixter]
&lt;br&gt;&lt;br&gt;o A bug was fixed that could cause Zenmap to crash when loading a
&lt;br&gt;&amp;nbsp; results file that had multibyte characters in it. The error looked
&lt;br&gt;&amp;nbsp; like:
&lt;br&gt;&amp;nbsp; Gtk-ERROR **: file gtktextsegment.c: line 196
&lt;br&gt;&amp;nbsp; (_gtk_char_segment_new): assertion failed:
&lt;br&gt;&amp;nbsp; (gtk_text_byte_begins_utf8_char (text))
&lt;br&gt;&amp;nbsp; [David]
&lt;br&gt;&lt;br&gt;o Removed a superfluous test for the existence of the C++ compiler in
&lt;br&gt;&amp;nbsp; the configure script. The test was not robust when configured with
&lt;br&gt;&amp;nbsp; CXX=&amp;quot;ccache g++&amp;quot;. Thanks to Rainer Müller for the report.
&lt;br&gt;&lt;br&gt;o Optimized cached DNS lookups so they are equally efficient when
&lt;br&gt;&amp;nbsp; running on big-endian or little-endian systems. [Michael]
&lt;br&gt;&lt;br&gt;o Fixed the nmap_command_path Zenmap configuration variable so that it
&lt;br&gt;&amp;nbsp; is actually used to start the specified Nmap executable
&lt;br&gt;&amp;nbsp; path. [Jurand Nogiec]
&lt;br&gt;&lt;br&gt;o Nmap now reports scan start and end times for individual hosts
&lt;br&gt;&amp;nbsp; within a larger scan. The information is added to the XML host
&lt;br&gt;&amp;nbsp; element like so: [host starttime=&amp;quot;1198292349&amp;quot; endtime=&amp;quot;1198292370&amp;quot;]
&lt;br&gt;&amp;nbsp; (but of course with angle brackets rather than square ones). &amp;nbsp;It is
&lt;br&gt;&amp;nbsp; also printed in normal output if -d or &amp;quot;-v -v&amp;quot; are
&lt;br&gt;&amp;nbsp; specified. [Brandon, Kris, Fyodor]
&lt;br&gt;&lt;br&gt;o &amp;quot;make uninstaltion returns. [Michael]
&lt;br&gt;&lt;br&gt;o Nmap now understands the RFC 4007 percent syntax for IPv6 Zone IDs.
&lt;br&gt;&amp;nbsp; On Windows, this ID has to be a numeric index. &amp;nbsp;On Linux and some
&lt;br&gt;&amp;nbsp; other OS's, this ID can instead be an interface name. &amp;nbsp;Some examples
&lt;br&gt;&amp;nbsp; of this syntax:
&lt;br&gt;&amp;nbsp; &amp;nbsp; fe80::20f:b0ff:fec6:15af%2
&lt;br&gt;&amp;nbsp; &amp;nbsp; fe80::20f:b0ff:fec6:15af%eth0
&lt;br&gt;&amp;nbsp; [Kris]
&lt;br&gt;&lt;br&gt;o The Zenmap installer and uninstaller are more careful about escaping
&lt;br&gt;&amp;nbsp; filenames and dealing with an installation root (DESTDIR). [David]
&lt;br&gt;&lt;br&gt;o Since assert() calls are used for various security-related tests,
&lt;br&gt;&amp;nbsp; their safety is now ensured by keeping NDEBUG undefined throughout
&lt;br&gt;&amp;nbsp; Nmap, Nbase and Nsock. [Kris]
&lt;br&gt;&lt;br&gt;o Fix a couple bugs in the way the Nmap build system checked for an
&lt;br&gt;&amp;nbsp; existing LUA library. &amp;nbsp;A bashism caused one test to fail on system
&lt;br&gt;&amp;nbsp; which don't use bash as /bin/sh, and another bug fixed --with-liblua
&lt;br&gt;&amp;nbsp; configure option for specifying your own liblua. [Daniel
&lt;br&gt;&amp;nbsp; Roethlisberger]
&lt;br&gt;&lt;br&gt;o The NSE nmap.registry.args table is now available, albeit empty,
&lt;br&gt;&amp;nbsp; when --script-args isn't used. &amp;nbsp;Now scripts don't need to check if
&lt;br&gt;&amp;nbsp; it's nil before attempting to index it. [Kris]
&lt;br&gt;&lt;br&gt;o Changed SSLv2-support.nse so that it only enumerates the list of
&lt;br&gt;&amp;nbsp; available ciphers with a verbosity level of at least two or with
&lt;br&gt;&amp;nbsp; debugging enabled. [Kris]
&lt;br&gt;&lt;br&gt;o Replaced kibuvDetection.nse with version detection match lines which
&lt;br&gt;&amp;nbsp; work better than the script. [Kris, Brandon]
&lt;br&gt;&lt;br&gt;o Removed mswindowsShell.nse as there is a version detection NULL
&lt;br&gt;&amp;nbsp; probe match which does the same thing. [Brandon, Fyodor, Kris]
&lt;br&gt;&lt;br&gt;o Updated IANA assignment IP list for random IP (-iR)
&lt;br&gt;&amp;nbsp; generation. [Kris]
&lt;br&gt;&lt;br&gt;Nmap 4.62 [2008-5-3]
&lt;br&gt;&lt;br&gt;o Added a new --min-rate option that allows specifying a minimum rate
&lt;br&gt;&amp;nbsp; at which to send packets. This allows you to override Nmap's
&lt;br&gt;&amp;nbsp; congestion control algorithms and request that Nmap try to keep at
&lt;br&gt;&amp;nbsp; least the rate you specify. &amp;nbsp;The rate is given in packets per
&lt;br&gt;&amp;nbsp; second. Read more in the Nmap man page
&lt;br&gt;&amp;nbsp; (&lt;a href=&quot;http://nmap.org/book/man-performance.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/man-performance.html&lt;/a&gt;) [David]
&lt;br&gt;&lt;br&gt;o Create /nmap/macosx directory in SVN with files necessary to build
&lt;br&gt;&amp;nbsp; binary Mac OS X Nmap/Zenmap packages. &amp;nbsp;We are trying to create
&lt;br&gt;&amp;nbsp; binary installer packages which are as useful and easy to use as the
&lt;br&gt;&amp;nbsp; Windows installer. &amp;nbsp;This has involved a lot of work by David. &amp;nbsp;We
&lt;br&gt;&amp;nbsp; aren't quite yet distributing the results on the Nmap download page,
&lt;br&gt;&amp;nbsp; but testing our beta versions is useful. &amp;nbsp;You can find the latest
&lt;br&gt;&amp;nbsp; universal (PPC and Intel) binary test version by looking at David
&lt;br&gt;&amp;nbsp; Fifield's posts at &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q2/author.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q2/author.html&lt;/a&gt;.
&lt;br&gt;&amp;nbsp; You can also read /nmap/macosx/README in svn for more info.
&lt;br&gt;&lt;br&gt;o Nmap 2008 Summer of Code students have began working (though full
&lt;br&gt;&amp;nbsp; time doesn't start until late May). &amp;nbsp;Learn about the winners and
&lt;br&gt;&amp;nbsp; their projects at &lt;a href=&quot;http://seclists.org/nmap-dev/2008/q2/0132.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q2/0132.html&lt;/a&gt;&amp;nbsp;.
&lt;br&gt;&lt;br&gt;o Brandon added/modified a whole bunch of version detection signatures
&lt;br&gt;&amp;nbsp; based on systems discovered when scanning UCSD's network.
&lt;br&gt;&lt;br&gt;o Reformat Nmap COPYING file (e.g. remove C comment markers, reduce
&lt;br&gt;&amp;nbsp; line length) during Nmap windows build so that it looks much better
&lt;br&gt;&amp;nbsp; when presented by the Windows executable (NSIS) installer. &amp;nbsp;Thanks
&lt;br&gt;&amp;nbsp; to Jah for the patch, which was modified slightly by Fyodor.
&lt;br&gt;&lt;br&gt;o Added NSE Datafiles library which reads and parses Nmap's nmap-*
&lt;br&gt;&amp;nbsp; data files for scripts. &amp;nbsp;The functions (parse_protocols(),
&lt;br&gt;&amp;nbsp; parse_rpc() and parse_services()) return tables with numbers
&lt;br&gt;&amp;nbsp; (e.g. port numbers) indexing names (e.g. service names). &amp;nbsp;The
&lt;br&gt;&amp;nbsp; rpcinfo.nse script was also updated to use this library. [Kris]
&lt;br&gt;&lt;br&gt;o Fixed a bug in the nbase random number generator (and the way it
&lt;br&gt;&amp;nbsp; interacted with Nmap and MS Windows) which caused duplicates in some
&lt;br&gt;&amp;nbsp; instances. &amp;nbsp;Thanks to Jah for reporting the problem and working with
&lt;br&gt;&amp;nbsp; Brandon Enright, Fyodor and Kris to fix it.
&lt;br&gt;&lt;br&gt;o It turns out that hours contain 60 minutes, not 24. &amp;nbsp;Fixed a scan
&lt;br&gt;&amp;nbsp; status message which was rolling over the hours column
&lt;br&gt;&amp;nbsp; prematurely. [David]
&lt;br&gt;&lt;br&gt;o Added scripting options to Zenmap profile editor and command wizard
&lt;br&gt;&amp;nbsp; to make use of NSE. [David]
&lt;br&gt;&lt;br&gt;o Zenmap now prints an exception message rather than segfaulting when
&lt;br&gt;&amp;nbsp; it can't open a display (such as when trying to connect to an X
&lt;br&gt;&amp;nbsp; server as an unauthorized user). Thanks to Aaron Leininger for the
&lt;br&gt;&amp;nbsp; initial report and Guilherme Polo for suggesting the fix.
&lt;br&gt;&lt;br&gt;o Now ports in the &amp;quot;unfiltered&amp;quot; state can be selected for attention by
&lt;br&gt;&amp;nbsp; NSE scripts. [Kris]
&lt;br&gt;&lt;br&gt;o Nbase random number generation system now avoids having a high-bit
&lt;br&gt;&amp;nbsp; of zero in every other byte on Windows due to Windows having such a
&lt;br&gt;&amp;nbsp; low RAND_MAX. [Jah]
&lt;br&gt;&lt;br&gt;o Added release dates for each Nmap version to this CHANGELOG going
&lt;br&gt;&amp;nbsp; back to Nmap 3.00 (July 31, 2002). &amp;nbsp;Dates are in MM/DD/YY format.
&lt;br&gt;&amp;nbsp; If someone wants to track down dates for the last 22% of the file
&lt;br&gt;&amp;nbsp; (pre-3.00), you are welcome to do so and send a patch. &amp;nbsp;Searching
&lt;br&gt;&amp;nbsp; Google for the version number and site:seclists.org seems to work
&lt;br&gt;&amp;nbsp; well. [Fyodor]
&lt;br&gt;&lt;br&gt;o Nmap RPM builds now use the versions of libdnet, libpcap, libpcre,
&lt;br&gt;&amp;nbsp; and liblua included with Nmap rather than whatever happens to be
&lt;br&gt;&amp;nbsp; installed on the build system. [David]
&lt;br&gt;&lt;br&gt;o Zenmap can now be installed in and run in directories with a space
&lt;br&gt;&amp;nbsp; in the name. [David]
&lt;br&gt;&lt;br&gt;o Fixed an assertion failure (&amp;quot;Target.cc:396: void
&lt;br&gt;&amp;nbsp; Target::stopTimeOutClock(const timeval*): Assertion
&lt;br&gt;&amp;nbsp; 'htn.toclock_running == true' failed.&amp;quot;)caused when a host had NSE
&lt;br&gt;&amp;nbsp; scripts in multiple runlevels. &amp;nbsp;This also fixes --host-timeout
&lt;br&gt;&amp;nbsp; behavior in NSE. [Kris]
&lt;br&gt;&lt;br&gt;o Reduce the maximum number of socket descriptors which Nmap is
&lt;br&gt;&amp;nbsp; allowed to open concurrently. &amp;nbsp;This resoles a bug which could cause
&lt;br&gt;&amp;nbsp; &amp;quot;Too many open files&amp;quot; error on Mac OS X when not running as
&lt;br&gt;&amp;nbsp; root. [David]
&lt;br&gt;&lt;br&gt;o Canonicalized service names between nmap-service-probes (version
&lt;br&gt;&amp;nbsp; detection DB) and nmap-services (port scanning DB). [Kris]
&lt;br&gt;&lt;br&gt;o Removed the &amp;quot;class&amp;quot; attribute from the tcpsequence element in XML
&lt;br&gt;&amp;nbsp; output. For a long time it had always been &amp;quot;unknown class&amp;quot; because
&lt;br&gt;&amp;nbsp; Nmap doesn't calculate a class anymore. The XML output version has
&lt;br&gt;&amp;nbsp; been increased from 1.01 to 1.02. [David]
&lt;br&gt;&lt;br&gt;o Fixed a bug on Win32 which caused an infinite loop when Nmap
&lt;br&gt;&amp;nbsp; encountered certain broadcast addresses. [Dudi Itzhakov]
&lt;br&gt;&lt;br&gt;o Fix MingW compilation by adding a signal.h include to
&lt;br&gt;&amp;nbsp; main.cc. [Gisle Vanem]
&lt;br&gt;&lt;br&gt;o Fix the test in our build system to determine if liblua is already
&lt;br&gt;&amp;nbsp; available or not. For example, the test needed to link with -lm
&lt;br&gt;&amp;nbsp; since some systems require that. &amp;nbsp;[David].
&lt;br&gt;&lt;br&gt;o Added TIMEVAL_BEFORE and TIMEVAL_AFTER macros to test whether one
&lt;br&gt;&amp;nbsp; timeval is earlier than another while avoiding possible integer
&lt;br&gt;&amp;nbsp; overflows in a naive approach we were using previously. [David]
&lt;br&gt;&lt;br&gt;o Adjusted a bunch of code to avoid compilation warning messages on
&lt;br&gt;&amp;nbsp; some Linux machines. [Andrew J. Bennieston]
&lt;br&gt;&lt;br&gt;o Fixed the NmapArpCache so that it actually works. Previously, Nmap
&lt;br&gt;&amp;nbsp; was always falling back to the system ARP cache. Of course this
&lt;br&gt;&amp;nbsp; raises the question of whether NmapArpCache is needed in the first
&lt;br&gt;&amp;nbsp; place. [Daniel Roethlisberger]
&lt;br&gt;&lt;br&gt;o Fix a Zenmap bug which could cause the error message
&lt;br&gt;&amp;nbsp; &amp;quot;zenmapCore.NmapOptions.OptionNotFound: No option named '' found!&amp;quot;
&lt;br&gt;&amp;nbsp; if you create a new profile without checking any options then try to
&lt;br&gt;&amp;nbsp; edit it. [David]
&lt;br&gt;&lt;br&gt;o Zenmap now shows a more helpful error message when there is an error
&lt;br&gt;&amp;nbsp; in executing Nmap. [David]
&lt;br&gt;&lt;br&gt;o Zenmap now creates the directory ~/.zenmap-etc to store
&lt;br&gt;&amp;nbsp; automatically generated GTK+ and Pango files. They used to go in the
&lt;br&gt;&amp;nbsp; application bundle but that doesn't work on a read-only filesystem
&lt;br&gt;&amp;nbsp; or disk image. This is what Wireshark does (~/.wireshark-etc),
&lt;br&gt;&amp;nbsp; although the directory could be called anything. It doesn't have to
&lt;br&gt;&amp;nbsp; persist across sessions.
&lt;br&gt;&lt;br&gt;o Added a mechanism in Zenmap for including extra executable search
&lt;br&gt;&amp;nbsp; paths on specific platforms, so we can include /usr/local/bin in
&lt;br&gt;&amp;nbsp; PATH on Mac OS X by default and add the Nmap install directory on
&lt;br&gt;&amp;nbsp; Windows. [David]
&lt;br&gt;&lt;br&gt;o We now use --no-strip when building Zenmap Mac OS X packages to
&lt;br&gt;&amp;nbsp; prevent many mysterious warnings which occur when the binary is
&lt;br&gt;&amp;nbsp; stripped. [David]
&lt;br&gt;&lt;br&gt;o When Zenmap invokes Nmap, it now copies the whole environment for
&lt;br&gt;&amp;nbsp; the Nmap invocation rather than just providing $PATH. &amp;nbsp;Windows may
&lt;br&gt;&amp;nbsp; need this to do proper name resolution. [David]
&lt;br&gt;&lt;br&gt;o Corrected uptime parsing and reporting in SNMPsysdesr.nse for an
&lt;br&gt;&amp;nbsp; uptime of less than 46 hours. [Kris]
&lt;br&gt;&lt;br&gt;o Modified the use of CXXFLAGS, CFLAGS, and CPPFLAGS in Nmap build
&lt;br&gt;&amp;nbsp; system to work better when building Mac OS X universal
&lt;br&gt;&amp;nbsp; binaries. [David]
&lt;br&gt;&lt;br&gt;o Added many additional PCRE option flags to the list returned by the
&lt;br&gt;&amp;nbsp; NSE pcre.flags() function. [Kris]
&lt;br&gt;&lt;br&gt;o Changed the NSE function nmap.set_port_state() so that it checks to
&lt;br&gt;&amp;nbsp; see if the requested port is already in the requested state. &amp;nbsp;This
&lt;br&gt;&amp;nbsp; prevents &amp;quot;Duplicate port&amp;quot; messages during the script scan and the
&lt;br&gt;&amp;nbsp; inaccurate &amp;quot;script-set&amp;quot; state reason. [Kris]
&lt;br&gt;&lt;br&gt;o Canonicalize NSE script license text--more than half did not even
&lt;br&gt;&amp;nbsp; spell license correctly. They all still say that they are under
&lt;br&gt;&amp;nbsp; Nmap's license, just with consistent capitalization and spelling,
&lt;br&gt;&amp;nbsp; and now a link to Nmap legal page at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://nmap.org/man/man-legal.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/man/man-legal.html&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;o Updated ripeQuery.nse to not print extraneous whitespace. [Kris]
&lt;br&gt;&lt;br&gt;o Switched telnet brute force password cracking NSE (bruteTelnet.nse)
&lt;br&gt;&amp;nbsp; to vulnerability category so it isn't executed by default. &amp;nbsp;It can
&lt;br&gt;&amp;nbsp; take too long to run. [Eddie]
&lt;br&gt;&lt;br&gt;o NSE status messages now print host name and IP, rather than just the
&lt;br&gt;&amp;nbsp; host name (which was blank when Nmap didn't know it). [Jah]
&lt;br&gt;&lt;br&gt;o Allocate 128 characters for the idle scan ScanProgressMeter
&lt;br&gt;&amp;nbsp; title. Previously it was 32 characters. The &amp;quot;idle scan against &amp;quot; and
&lt;br&gt;&amp;nbsp; the \0 terminator take up 19 characters, leaving only 13, which
&lt;br&gt;&amp;nbsp; isn't enough to represent all IP addresses, let alone host
&lt;br&gt;&amp;nbsp; names. Bug reported by Stephan Fijneman, fixed by David.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Enjoy the release!
&lt;br&gt;-Fyodor
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap-4.68-release-tp18768817p18768817.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18764426</id>
	<title>Lots of Nmap News</title>
	<published>2008-07-31T14:45:38Z</published>
	<updated>2008-07-31T14:45:38Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">Hi All. &amp;nbsp;I feel derelict for failing to post any Nmap news to this
&lt;br&gt;nmap-hackers list in the last four months, but you can rest assured
&lt;br&gt;that we've been busy on the project! &amp;nbsp;For example, there have been
&lt;br&gt;1,181 posts on the nmap-dev list (not all from me) since my March
&lt;br&gt;nmap-hackers announcements. &amp;nbsp;So you can always join that if you want a
&lt;br&gt;constant flood of Nmap news :). &amp;nbsp;There have also been several stable
&lt;br&gt;Nmap releases since that time, great news on the Nmap book project,
&lt;br&gt;web site improvements, Google SoC success stories, and much more!
&lt;br&gt;&lt;br&gt;In this mail, I describe the most important general Nmap and
&lt;br&gt;Insecure.Org news, while the next email will introduce Nmap 4.68 and
&lt;br&gt;125 of its most important enhancements since March.
&lt;br&gt;&lt;br&gt;==Black Hat and Defcon Presentations==
&lt;br&gt;&lt;br&gt;I will be speaking next week in Las Vegas at the Black Hat Briefings
&lt;br&gt;in the first speaking slot (10AM Wednesday the 6th) and then at Defcon
&lt;br&gt;on Friday the 8th (4PM). &amp;nbsp;My talk discusses the results of large-scale
&lt;br&gt;Internet scans I've been conducting, and demonstrates how you can use
&lt;br&gt;the empirical data to make your scans (over the Internet or even
&lt;br&gt;internal) more efficient. &amp;nbsp;I also plan to show off new and
&lt;br&gt;poorly-understand features which can help you bypass firewall
&lt;br&gt;restrictions, reduce scan times, and gather more information about
&lt;br&gt;remote hosts.
&lt;br&gt;&lt;br&gt;Preparing for this presentation required scanning millions of hosts
&lt;br&gt;and got me into minor trouble with my ISP and also with the
&lt;br&gt;U.S. Department of Defense Joint Task Force for Global Network
&lt;br&gt;Operations. &amp;nbsp;Apparently they don't like people scanning their
&lt;br&gt;sensitive military installations. &amp;nbsp;But if they are so sensitive, maybe
&lt;br&gt;they shouldn't be on the Internet in the first place. &amp;nbsp;Anyway, when
&lt;br&gt;you see the new Nmap features this data enables, I hope you'll agree
&lt;br&gt;that it was worth ruffling some feathers :).
&lt;br&gt;&lt;br&gt;==Nmap Network Scanning book==
&lt;br&gt;&lt;br&gt;Most of you know that I've been working for years on a comprehensive
&lt;br&gt;guide to Nmap and network/security scanning. &amp;nbsp;I'm happy to report that
&lt;br&gt;the book is almost done! &amp;nbsp;Here is the marketing blurb:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;quot;From port scanning basics for novices to the type of packet
&lt;br&gt;&amp;nbsp; &amp;nbsp;crafting used by advanced hackers, this book suits all levels of
&lt;br&gt;&amp;nbsp; &amp;nbsp;security and networking professionals. Rather than simply document
&lt;br&gt;&amp;nbsp; &amp;nbsp;what every Nmap option does, Nmap Network Scanning demonstrates how
&lt;br&gt;&amp;nbsp; &amp;nbsp;these features can be applied to solve real world tasks such as
&lt;br&gt;&amp;nbsp; &amp;nbsp;penetration testing, taking network inventory, detecting rogue
&lt;br&gt;&amp;nbsp; &amp;nbsp;wireless access points or open proxies, quashing network worm and
&lt;br&gt;&amp;nbsp; &amp;nbsp;virus outbreaks, and much more. Examples and diagrams show actual
&lt;br&gt;&amp;nbsp; &amp;nbsp;communication on the wire. This book is essential for anyone who
&lt;br&gt;&amp;nbsp; &amp;nbsp;needs to get the most out of Nmap, particularly security auditors
&lt;br&gt;&amp;nbsp; &amp;nbsp;and systems or network administrators.&amp;quot;
&lt;br&gt;&lt;br&gt;I plan to do the official release in mid/late September, but I've
&lt;br&gt;printed up 75 pre-release copies each for Black Hat and Defcon. &amp;nbsp;The
&lt;br&gt;Black Hat copies will be available at the Black Hat Bookstore starting
&lt;br&gt;on Tuesday evening or Wednesday morning. &amp;nbsp;At Defcon the books will be
&lt;br&gt;sold by Bill Pollock at his No Starch Press table in the vendor area
&lt;br&gt;(starting at 10AM Friday). &amp;nbsp;I'm planning to do a signing right after
&lt;br&gt;my Black Hat talk in the bookstore, and right after my Defcon talk in
&lt;br&gt;either the QA room or the No Starch booth. &amp;nbsp;But the trick to get a
&lt;br&gt;book before they sell out will probably be to pick it up _before_ my
&lt;br&gt;talks, and then you can bring the copy to the signing. &amp;nbsp;More than
&lt;br&gt;7,000 people are expected at Defcon, so 75 books may not last long.
&lt;br&gt;&lt;br&gt;You can find a lot more about the book online:
&lt;br&gt;&lt;br&gt;Description and pictures: &lt;a href=&quot;http://nmap.org/book/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Defcon pre-release table of contents: &lt;a href=&quot;http://nmap.org/book/toc.pdf&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/toc.pdf&lt;/a&gt;&lt;br&gt;&lt;br&gt;Acknowledging the dozens of people who helped make this happen:
&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/acknowledgements.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/acknowledgements.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;If you'd like to see a sample chapter, you have plenty to choose from!
&lt;br&gt;About half of the book is already online at:
&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/toc.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/toc.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;==Mac OS X Nmap/Zenmap Installer==
&lt;br&gt;&lt;br&gt;A native Mac OS X installer for Nmap and the Zenmap GUI is now
&lt;br&gt;available from the Nmap download page (&lt;a href=&quot;http://nmap.org/download.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/download.html&lt;/a&gt;).
&lt;br&gt;We plan to create these for each new release now, just as we do with
&lt;br&gt;the Linux RPMs and the Windows installer. &amp;nbsp;Installation is
&lt;br&gt;straightforward, but detailed instructions are available anyway at
&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/inst-macosx.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/inst-macosx.html&lt;/a&gt;&amp;nbsp;. &amp;nbsp;As a universal installer, it
&lt;br&gt;works on both Intel and PPC Macs. It is distributed as a disk image
&lt;br&gt;file (.dmg) containing an mpkg package. &amp;nbsp;OpenSSL is supported, and it
&lt;br&gt;also supports Authorization Services so that Zenmap can run as root.
&lt;br&gt;Thanks to David Fifield for all his hard work in creating this!
&lt;br&gt;&lt;br&gt;==Mailing list RSS Feed Improvements==
&lt;br&gt;&lt;br&gt;The nmap-dev and nmap-hackers mailing list RSS feeds at SecLists.Org
&lt;br&gt;now include message excerpts to make it easier to identify interesting
&lt;br&gt;messages and speed the process of reading through the list. &amp;nbsp;Feeds for
&lt;br&gt;Bugtraq, Full Disclosure, Security Basics, Pen-Test, and all other
&lt;br&gt;mailing lists archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&amp;nbsp;have been similarly
&lt;br&gt;augmented. &amp;nbsp;For details, see
&lt;br&gt;&lt;a href=&quot;http://seclists.org/nmap-dev/2008/q2/0333.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q2/0333.html&lt;/a&gt;&amp;nbsp;.
&lt;br&gt;&lt;br&gt;==Google Summer of Code==
&lt;br&gt;&lt;br&gt;Seven Google-sponsored Summer of Code students are spending the summer
&lt;br&gt;working full time on exciting Nmap projects. &amp;nbsp;The winning students and
&lt;br&gt;their Nmap development projects are showcased at
&lt;br&gt;&lt;a href=&quot;http://seclists.org/nmap-dev/2008/q2/0132.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2008/q2/0132.html&lt;/a&gt;&amp;nbsp;. &amp;nbsp;All of them have
&lt;br&gt;already written code which has been integrated into Nmap, and they
&lt;br&gt;still have several weeks of work left.
&lt;br&gt;&lt;br&gt;==Nmap's 7th Movie==
&lt;br&gt;&lt;br&gt;To end on a fun note, Nmap recently appeared in its seventh movie--the
&lt;br&gt;acclaimed Thai thriller &amp;quot;13: Game of Death&amp;quot;. &amp;nbsp;This movie follows the
&lt;br&gt;story of a man given the chance to complete 13 challenges to win $100
&lt;br&gt;million. Successive challenges become increasingly intense, dangerous,
&lt;br&gt;and illegal. &amp;nbsp;What would you do for $100 million?
&lt;br&gt;&lt;br&gt;I posted a video clip and screenshots yesterday to the Nmap movies
&lt;br&gt;page:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/movies.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/movies.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;==New Nmap Releases==
&lt;br&gt;&lt;br&gt;Nmap has so many new features and improvements that they deserve their
&lt;br&gt;own email. &amp;nbsp;I'll send it shortly!
&lt;br&gt;&lt;br&gt;I look forward to seeing many of you next week at Black Hat and
&lt;br&gt;Defcon!
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Fyodor
&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Lots-of-Nmap-News-tp18764426p18764426.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18592173</id>
	<title>Re: Probelm running Nmap</title>
	<published>2008-07-22T08:35:47Z</published>
	<updated>2008-07-22T08:35:47Z</updated>
	<author>
		<name>adonis28850</name>
	</author>
	<content type="html">&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Neminath wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;I m new to Nmap and to linux rather
&lt;br&gt;have the following problem running Nmap scanner
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;b&gt;nmap -O x.x.x.x &lt;/b&gt;&lt;br&gt;&lt;br&gt;when i run the above command i get the following
&lt;br&gt;&lt;br&gt;Starting Nmap 4.20 ( &lt;a href=&quot;http://insecure.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://insecure.org&lt;/a&gt;&amp;nbsp;) at 2008-07-06 11:46 IST
&lt;br&gt;mass_dns: warning: Unable to open /etc/resolv.conf. Try using --system-dns or specify valid servers with --dns-servers
&lt;br&gt;mass_dns: warning: Unable to determine any DNS servers. Reverse DNS is disabled. Try using --system-dns or specify valid servers with --dns_servers
&lt;br&gt;&lt;b&gt;Note: Host seems down. If it is really up, but blocking our ping probes, try -P0&lt;/b&gt;&lt;br&gt;Nmap finished: 1 IP address (0 hosts up) scanned in 0.171 seconds
&lt;br&gt;&lt;br&gt;whats this message is all about how do i resolve it .
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Neminath
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
target host could be behind a firewall, try option -PO to confirm it
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Probelm-running-Nmap-tp18299355p18592173.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18299355</id>
	<title>Probelm running Nmap</title>
	<published>2008-07-05T23:33:09Z</published>
	<updated>2008-07-05T23:33:09Z</updated>
	<author>
		<name>Neminath</name>
	</author>
	<content type="html">I m new to Nmap and to linux rather
&lt;br&gt;have the following problem running Nmap scanner
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;b&gt;nmap -O x.x.x.x &lt;/b&gt;&lt;br&gt;&lt;br&gt;when i run the above command i get the following
&lt;br&gt;&lt;br&gt;Starting Nmap 4.20 ( &lt;a href=&quot;http://insecure.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://insecure.org&lt;/a&gt;&amp;nbsp;) at 2008-07-06 11:46 IST
&lt;br&gt;mass_dns: warning: Unable to open /etc/resolv.conf. Try using --system-dns or specify valid servers with --dns-servers
&lt;br&gt;mass_dns: warning: Unable to determine any DNS servers. Reverse DNS is disabled. Try using --system-dns or specify valid servers with --dns_servers
&lt;br&gt;Note: Host seems down. If it is really up, but blocking our ping probes, try -P0
&lt;br&gt;Nmap finished: 1 IP address (0 hosts up) scanned in 0.171 seconds
&lt;br&gt;&lt;br&gt;whats this message is all about how do i resolve it .
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Neminath
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Probelm-running-Nmap-tp18299355p18299355.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18209260</id>
	<title>lf: computer virus</title>
	<published>2008-06-30T22:03:57Z</published>
	<updated>2008-06-30T22:03:57Z</updated>
	<author>
		<name>unstop</name>
	</author>
	<content type="html">anyone who has nice computer virus that i can use? work in a bank would like give goodbye gift to stupid management. work under techsup department. can save file in best places.</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/lf%3A-computer-virus-tp18209260p18209260.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17770365</id>
	<title>Port scan from two machine</title>
	<published>2008-06-10T22:32:19Z</published>
	<updated>2008-06-10T22:32:19Z</updated>
	<author>
		<name>atevewr</name>
	</author>
	<content type="html">Hi everybody, m looking forward if somebody can answer my two queries
&lt;br&gt;1&amp;gt;
&lt;br&gt;if i scan my own computer from nmap (ofcourse not possible in windows) , will i get the ports from lo or local loopback also or just the ports from my ethernet card , the destination i have specified is the ip address of the computer itself.
&lt;br&gt;&lt;br&gt;2&amp;gt;
&lt;br&gt;same way if i try to scan the same computer from other computer on network, i am getting different results, 
&lt;br&gt;Details
&lt;br&gt;m/c 1: CentOS
&lt;br&gt;m/c 2: Backtrack Live iso
&lt;br&gt;&lt;br&gt;wen i scanned for the centOS, from both, itself &amp; Backtrack, i m getting different results,
&lt;br&gt;while backtrack is showing port 38292(landesk) open, CentOS is showing much more ports
&lt;br&gt;22
&lt;br&gt;111
&lt;br&gt;627
&lt;br&gt;5555
&lt;br&gt;5900
&lt;br&gt;11111
&lt;br&gt;16851
&lt;br&gt;&lt;br&gt;Both machines are on different subnets with inter subnet ping blocked, but i dont think so that should create a problem, as i m doing a syn scan on both.
&lt;br&gt;&lt;br&gt;Plz tell me what is the problem, Thanks in advance.</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Port-scan-from-two-machine-tp17770365p17770365.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17297539</id>
	<title>i need a helping hand ....contact me</title>
	<published>2008-05-17T16:20:58Z</published>
	<updated>2008-05-17T16:20:58Z</updated>
	<author>
		<name>niyi</name>
	</author>
	<content type="html">hello,i need someone to teach me how to host and how to hack a website,i have so much dollars to spend on these project,contact me on messenger on yahoo...these is my id ...punpinman@yahoo.com</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/different-results-using-diff-dest-host-tp13442727p17297539.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17080100</id>
	<title>R&amp;D Information</title>
	<published>2008-05-06T03:40:27Z</published>
	<updated>2008-05-06T03:40:27Z</updated>
	<author>
		<name>securityprofile</name>
	</author>
	<content type="html">does anyone know of a good site to seek security professionals to help develop new security products ?</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/R-D-Information-tp17080100p17080100.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-16825625</id>
	<title>Re: Problem to scan</title>
	<published>2008-04-22T12:37:23Z</published>
	<updated>2008-04-22T12:37:23Z</updated>
	<author>
		<name>Cr4sh</name>
	</author>
	<content type="html">Are you sure your using eth4 as your adaptor?
&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;fullmax wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Hi, 
&lt;br&gt;I have a problem while it's either a host or an iP adress.
&lt;br&gt;I executed the following command : nmap Ip_Adress or host. 
&lt;br&gt;It doesn't work, after executign command there is written : 
&lt;br&gt;&lt;br&gt;Copyright (c) 2006 Microsoft Corporation. All rigths reserved.
&lt;br&gt;&lt;br&gt;nmap 192.168.0.137
&lt;br&gt;&lt;br&gt;Starting Nmap 4.60 ( &lt;a href=&quot;http://insecure.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://insecure.org&lt;/a&gt;&amp;nbsp;) at 2008-03-26 23:36 Paris, Madrid
&lt;br&gt;dnet: Failed to open device eth4
&lt;br&gt;QUITTING!
&lt;br&gt;&lt;br&gt;C:\&amp;gt;
&lt;br&gt;&lt;br&gt;Could somebody help me or exlain me what's the problem.
&lt;br&gt;Thanks
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Problem-to-scan-tp16318099p16825625.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-16318099</id>
	<title>Problem to scan</title>
	<published>2008-03-26T15:39:12Z</published>
	<updated>2008-03-26T15:39:12Z</updated>
	<author>
		<name>fullmax</name>
	</author>
	<content type="html">Hi, 
&lt;br&gt;I have a problem while it's either a host or an iP adress.
&lt;br&gt;I executed the following command : nmap Ip_Adress or host. 
&lt;br&gt;It doesn't work, after executign command there is written : 
&lt;br&gt;&lt;br&gt;Copyright (c) 2006 Microsoft Corporation. All rigths reserved.
&lt;br&gt;&lt;br&gt;nmap 192.168.0.137
&lt;br&gt;&lt;br&gt;Starting Nmap 4.60 ( &lt;a href=&quot;http://insecure.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://insecure.org&lt;/a&gt;&amp;nbsp;) at 2008-03-26 23:36 Paris, Madrid
&lt;br&gt;dnet: Failed to open device eth4
&lt;br&gt;QUITTING!
&lt;br&gt;&lt;br&gt;C:\&amp;gt;
&lt;br&gt;&lt;br&gt;Could somebody help me or exlain me what's the problem.
&lt;br&gt;Thanks</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Problem-to-scan-tp16318099p16318099.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-16269454</id>
	<title>Nmap accepting applications for Summer of Code developers</title>
	<published>2008-03-24T21:04:25Z</published>
	<updated>2008-03-24T21:04:25Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">It may have taken me four months to send this year's first
&lt;br&gt;nmap-hackers mail, but the second only took me four hours. &amp;nbsp;I want to
&lt;br&gt;let you all know that Nmap has been accepted for the fourth year
&lt;br&gt;running to participate in the Google Summer of Code program. &amp;nbsp;This
&lt;br&gt;generous and innovative program provides $4,500 stipends to hundreds
&lt;br&gt;of university students to create or enhance open source software.
&lt;br&gt;Applications are only accepted for one week, until Monday, March 31.
&lt;br&gt;&lt;br&gt;If you are a college student in any country, I'd strongly encourage
&lt;br&gt;you to apply for Nmap SoC. &amp;nbsp;There aren't many opportunities available
&lt;br&gt;to get paid to work on free software of your choice, and this is one
&lt;br&gt;of them. &amp;nbsp;The last three years have been great! &amp;nbsp;Even if you aren't a
&lt;br&gt;student, perhaps you have a talented friend or relative who might be
&lt;br&gt;interested. &amp;nbsp;This program is a great benefit to Nmap, and the benefit
&lt;br&gt;is proportional to the quality of applicants we get. &amp;nbsp;So please spread
&lt;br&gt;the word! &amp;nbsp;Some SoC students have turned into long-term Nmap
&lt;br&gt;developers and are still writing great new code. &amp;nbsp;Several have become
&lt;br&gt;SoC mentors to guide new Nmap SoC students.
&lt;br&gt;&lt;br&gt;Summer of code successes in recent years have lead to the 2nd
&lt;br&gt;Generation OS detection system, the Zenmap GUI, the runtime
&lt;br&gt;interaction feature which tells you how soon your scan is likely to
&lt;br&gt;finish, and much more. &amp;nbsp;Here are more Nmap SoC success stories:
&lt;br&gt;&lt;br&gt;2007: &lt;a href=&quot;http://seclists.org/nmap-dev/2007/q4/0024.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2007/q4/0024.html&lt;/a&gt;&lt;br&gt;2006: &lt;a href=&quot;http://seclists.org/nmap-dev/2007/q1/0235.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/nmap-dev/2007/q1/0235.html&lt;/a&gt;&lt;br&gt;2005: &lt;a href=&quot;http://slashdot.org/comments.pl?sid=183143&amp;cid=15133184&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://slashdot.org/comments.pl?sid=183143&amp;cid=15133184&lt;/a&gt;&lt;br&gt;&lt;br&gt;If you or someone you know are interested, you can send them to the
&lt;br&gt;Nmap 2008 project ideas page at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/GoogleGrants.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/GoogleGrants.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;And you can learn more about the program in general at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://code.google.com/soc/2008/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/soc/2008/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Since you can apply for more than one project, I'd like to mention
&lt;br&gt;some other security projects which were accepted, along with their
&lt;br&gt;ideas pages:
&lt;br&gt;&lt;br&gt;OSVDB: The Open Source Vulnerability Database:
&lt;br&gt;&lt;a href=&quot;http://osvdb.org/blog/?p=231&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://osvdb.org/blog/?p=231&lt;/a&gt;&lt;br&gt;&lt;br&gt;OSSIM: Open Source Security Information Management:
&lt;br&gt;&lt;a href=&quot;http://www.ossim.net/dokuwiki/doku.php?id=ideas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ossim.net/dokuwiki/doku.php?id=ideas&lt;/a&gt;&lt;br&gt;&lt;br&gt;The Electronic Frontier Foundation/Tor Project:
&lt;br&gt;&lt;a href=&quot;https://www.torproject.org/volunteer.html.en#Projects&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.torproject.org/volunteer.html.en#Projects&lt;/a&gt;&lt;br&gt;&lt;br&gt;Freenet Project:
&lt;br&gt;&lt;a href=&quot;http://wiki.freenetproject.org/SummerOfCode2008&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://wiki.freenetproject.org/SummerOfCode2008&lt;/a&gt;&lt;br&gt;&lt;br&gt;So please get those applications in by Monday, or help spread the
&lt;br&gt;word!
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Fyodor
&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap-accepting-applications-for-Summer-of-Code-developers-tp16269454p16269454.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-16260908</id>
	<title>Nmap 4.60 and new movies page</title>
	<published>2008-03-24T13:39:15Z</published>
	<updated>2008-03-24T13:39:15Z</updated>
	<author>
		<name>Fyodor</name>
	</author>
	<content type="html">Hi everyone. &amp;nbsp;This is the first nmap-hackers message of the year, but
&lt;br&gt;we haven't been slacking. &amp;nbsp;The nmap-dev list has more than 500 posts
&lt;br&gt;so far this quarter, and we've made many great improvements to Nmap
&lt;br&gt;during the period.
&lt;br&gt;&lt;br&gt;Nmap-hackers is reserved for the most important Nmap news, but that
&lt;br&gt;won't prevent me from starting out this message with something
&lt;br&gt;frivolous :). &amp;nbsp;I recently learned that Nmap was in not just one, but
&lt;br&gt;two major motion pictures last year! &amp;nbsp;In addition to the known Bourne
&lt;br&gt;Ultimatum appearance, I now have screen shots of Nmap being used in
&lt;br&gt;Die Hard 4: Live Free or Die Hard. &amp;nbsp;I've posted them to the new Nmap
&lt;br&gt;movies page:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/movies.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/movies.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Nmap has become quite the movie star! &amp;nbsp;Who knows where it will show up
&lt;br&gt;in 2008.
&lt;br&gt;&lt;br&gt;The other exciting news I have for you is that Nmap 4.60 has been
&lt;br&gt;released. &amp;nbsp;The changelog (&lt;a href=&quot;http://nmap.org/changelog.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/changelog.html&lt;/a&gt;) notes more
&lt;br&gt;than 60 important changes since 4.50. &amp;nbsp;This includes a new and shorter
&lt;br&gt;URL (nmap.org rather than insecure.org/nmap/), massive OS detection and
&lt;br&gt;version detection signature updates, many new Nmap Scripting Engine
&lt;br&gt;scripts, bug fixes, performance optimization, and more. &amp;nbsp;It is
&lt;br&gt;available now from the download page:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/download.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/download.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Don't hesitate to let us know on nmap-dev if you find any problems.
&lt;br&gt;Here is the detailed list of changes since 4.50:
&lt;br&gt;&lt;br&gt;4.60
&lt;br&gt;&lt;br&gt;o Nmap has moved. &amp;nbsp;Everything at &lt;a href=&quot;http://insecure.org/nmap/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://insecure.org/nmap/&lt;/a&gt;&amp;nbsp;can now be
&lt;br&gt;&amp;nbsp; found at &lt;a href=&quot;http://nmap.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org&lt;/a&gt;&amp;nbsp;. &amp;nbsp;That should save your fingers from a
&lt;br&gt;&amp;nbsp; little bit of typing. &amp;nbsp;Even though transparent redirectors are in
&lt;br&gt;&amp;nbsp; place for the old URLs, please update your links and bookmarks. And
&lt;br&gt;&amp;nbsp; if you don't have a link to Nmap on your web site, now is a good
&lt;br&gt;&amp;nbsp; time to add one :).
&lt;br&gt;&lt;br&gt;o All of your OS detection fingerprints up until March 10, 2008 have
&lt;br&gt;&amp;nbsp; now been integrated by David. &amp;nbsp;The second generation database has
&lt;br&gt;&amp;nbsp; grown from 1,085 fingerprints representing 421 operating
&lt;br&gt;&amp;nbsp; systems/devices, to 1,304 fingerprints representing 478 systems.
&lt;br&gt;&amp;nbsp; That is an increase of more than 20%. &amp;nbsp;New fingerprints were added
&lt;br&gt;&amp;nbsp; for Mac OS X Tiger, iPod Touch, the La Fonera WAP, FreeBSD 7.0,
&lt;br&gt;&amp;nbsp; Linux 2.6.24, Windows 2008, Vista, OpenBSD 4.2, and of course
&lt;br&gt;&amp;nbsp; hundreds of broadband routers, VoIP phones, printers, some crazy
&lt;br&gt;&amp;nbsp; oscilloscope, etc. &amp;nbsp;We get a ton of new fingerprint submissions, but
&lt;br&gt;&amp;nbsp; not as many corrections. &amp;nbsp;Please remember to visit
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://nmap.org/submit/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/submit/&lt;/a&gt;&amp;nbsp;if Nmap gives you bad results, whether they
&lt;br&gt;&amp;nbsp; are completely wrong or just a slight mistake (like Nmap says Linux
&lt;br&gt;&amp;nbsp; 2.6.20-2.6.23, but you're running 2.6.24). &amp;nbsp;Of course you need to be
&lt;br&gt;&amp;nbsp; certain you know exactly what is running on the target before you do
&lt;br&gt;&amp;nbsp; this.
&lt;br&gt;&lt;br&gt;o All of your service fingerprints and corrections submitted until
&lt;br&gt;&amp;nbsp; January 14, 2008 have now been integrated by Doug. &amp;nbsp;As usual, he has
&lt;br&gt;&amp;nbsp; documented his adventures at &lt;a href=&quot;http://hcsw.org/blog.pl/33&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://hcsw.org/blog.pl/33&lt;/a&gt;&amp;nbsp;. &amp;nbsp;More than
&lt;br&gt;&amp;nbsp; a hundred signatures were added, growing the database to 4,645
&lt;br&gt;&amp;nbsp; signatures for 457 services. &amp;nbsp;Corrections are welcome for service
&lt;br&gt;&amp;nbsp; detection too -- visit &lt;a href=&quot;http://nmap.org/submit/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/submit/&lt;/a&gt;&amp;nbsp;if you get incorrect results.
&lt;br&gt;&lt;br&gt;o Nmap now saves the target name (if any) specified on the command
&lt;br&gt;&amp;nbsp; line, since this can differ from the reverse DNS results. &amp;nbsp;It can be
&lt;br&gt;&amp;nbsp; particularly important when doing HTTP tests against virtual hosts.
&lt;br&gt;&amp;nbsp; The data can be accessed from target-&amp;gt;TargetName() from Nmap proper
&lt;br&gt;&amp;nbsp; and host.targetname from NSE scripts. &amp;nbsp;The NSE HTTP library now uses
&lt;br&gt;&amp;nbsp; this for the Host header. &amp;nbsp;Thanks to Sven Klemm for adding this
&lt;br&gt;&amp;nbsp; useful feature.
&lt;br&gt;&lt;br&gt;o Added NSE HTTP library which allows scripts to easily fetch URLs
&lt;br&gt;&amp;nbsp; with http.get_url() or create more complex requests with
&lt;br&gt;&amp;nbsp; http.request(). &amp;nbsp;There is also an http.get() function which takes
&lt;br&gt;&amp;nbsp; components (hostname, port, and path) rather than a URL. &amp;nbsp;The
&lt;br&gt;&amp;nbsp; HTTPAuth, robots, and showHTMLTitle NSE scripts have been updated to
&lt;br&gt;&amp;nbsp; use this library. Sven Klemm wrote all of this code.
&lt;br&gt;&lt;br&gt;o Fixed an integer overflow in the DNS caching code that caused nmap
&lt;br&gt;&amp;nbsp; to loop infinitely once it had expunging the cache of older
&lt;br&gt;&amp;nbsp; entries. &amp;nbsp;Thanks to David Moore for the report, and Eddie Bell for
&lt;br&gt;&amp;nbsp; the fix.
&lt;br&gt;&lt;br&gt;o Fixed another integer overflow in the DNS caching code which caused
&lt;br&gt;&amp;nbsp; infinite loops. [David]
&lt;br&gt;&lt;br&gt;o Added IPv6 host support to the RPC scan. &amp;nbsp;Attempting this before
&lt;br&gt;&amp;nbsp; (via -sV) caused a segmentation fault. &amp;nbsp;Thanks to Will Cladek for
&lt;br&gt;&amp;nbsp; the report. [Kris]
&lt;br&gt;&lt;br&gt;o Fixed an event handling bug in NSE that could cause execution of
&lt;br&gt;&amp;nbsp; some in-progress scripts to be excessively delayed. [Marek]
&lt;br&gt;&lt;br&gt;o A new NSE table library (tab.lua) allows scripts to deliver better
&lt;br&gt;&amp;nbsp; formatted output. &amp;nbsp;The Zone transfer script (zoneTrans.nse) has been
&lt;br&gt;&amp;nbsp; updated to use this new facility. [Eddie]
&lt;br&gt;&lt;br&gt;o Rewrote HTTPpasswd.nse to use Sven's excellent HTTP library and to
&lt;br&gt;&amp;nbsp; do some much-needed cleaning up. [Kris]
&lt;br&gt;&lt;br&gt;o Added a new MsSQL version detection probe and a bunch of match lines
&lt;br&gt;&amp;nbsp; developed by Tom Sellers.
&lt;br&gt;&lt;br&gt;o Added a new service detection probe and signatures for the memcached
&lt;br&gt;&amp;nbsp; service [Doug]
&lt;br&gt;&lt;br&gt;o Added new service detection probes and signatures for the Beast
&lt;br&gt;&amp;nbsp; Trojan and Firebird RDBMS. [Brandon Enright]
&lt;br&gt;&lt;br&gt;o Fixed a crash in Zenmap which occurred when attempting to edit or
&lt;br&gt;&amp;nbsp; create a new profile based on an existing one when there wasn't one
&lt;br&gt;&amp;nbsp; selected. &amp;nbsp;The error message was:
&lt;br&gt;&amp;nbsp; &amp;nbsp; 'NoneType' object has no attribute 'toolbar'
&lt;br&gt;&amp;nbsp; Now a new Profile Editor is opened. &amp;nbsp;Thanks to D1N (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=16260908&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;d1n@...&lt;/a&gt;)
&lt;br&gt;&amp;nbsp; for the report. [Kris]
&lt;br&gt;&lt;br&gt;o Fixed another crash in Zenmap which occurred when exiting the
&lt;br&gt;&amp;nbsp; Profile Editor (while editing an existing profile) by clicking the
&lt;br&gt;&amp;nbsp; &amp;quot;X&amp;quot;, then going to edit the same profile again. &amp;nbsp;The error message
&lt;br&gt;&amp;nbsp; was: &amp;quot;No option named '' found!&amp;quot;. &amp;nbsp;Now the same window that appears
&lt;br&gt;&amp;nbsp; when clicking Cancel comes up when clicking &amp;quot;X&amp;quot;. &amp;nbsp;Thanks to David
&lt;br&gt;&amp;nbsp; for reporting this bug. [Kris]
&lt;br&gt;&lt;br&gt;o Another Zenmap bug was fixed: ports consolidated into &amp;quot;extra ports&amp;quot;
&lt;br&gt;&amp;nbsp; groups are now counted and shown in the &amp;quot;Host Details&amp;quot; tab. &amp;nbsp;The
&lt;br&gt;&amp;nbsp; closed, filtered and scanned port counts in this tab didn't contain
&lt;br&gt;&amp;nbsp; this information before so they were usually very inaccurate. [Kris]
&lt;br&gt;&lt;br&gt;o Another Zenmap bug was fixed: the --scan-delay and --max-scan-delay
&lt;br&gt;&amp;nbsp; buttons (&amp;quot;amount of time between probes&amp;quot;) under the Advanced tab in
&lt;br&gt;&amp;nbsp; the Profile Editor were backwards. [Kris]
&lt;br&gt;&lt;br&gt;o Added the UDP Scan (-sU) and IPProto Ping (-PO) to Zenmap's Profile
&lt;br&gt;&amp;nbsp; Editor and Command Wizard. [Kris]
&lt;br&gt;&lt;br&gt;o Reordered the UDP port selection for Traceroute: a closed port is
&lt;br&gt;&amp;nbsp; now chosen before an open one. &amp;nbsp;This is because an open UDP port is
&lt;br&gt;&amp;nbsp; usually due to running version detection (-sV), so a Traceroute
&lt;br&gt;&amp;nbsp; probe wouldn't elicit a response. [Kris]
&lt;br&gt;&lt;br&gt;o Add Famtech Radmin remote control software probe and signatures to
&lt;br&gt;&amp;nbsp; the Nmap version detection DB. [Tom Sellers, Fyodor]
&lt;br&gt;&lt;br&gt;o Add &amp;quot;Conection: Close&amp;quot; header to requests from HTTP NSE scripts so
&lt;br&gt;&amp;nbsp; that they finish faster. [Sven Klemm]
&lt;br&gt;&lt;br&gt;o Update SSLv2-support NSE script to run against more services which
&lt;br&gt;&amp;nbsp; are likely SSL. [Sven Klemm]
&lt;br&gt;&lt;br&gt;o A bunch of service name canonicalization was done in the Nmap
&lt;br&gt;&amp;nbsp; version detection file by Brandon Enright (e.g. capitalizing D-Link
&lt;br&gt;&amp;nbsp; and Netgear consistently).
&lt;br&gt;&lt;br&gt;o Upgraded the shipped LibPCRE from version 7.4 to 7.6. [Kris]
&lt;br&gt;&lt;br&gt;o Updated to latest (as of 3/15) autoconf config.sub/config.guess
&lt;br&gt;&amp;nbsp; files from &lt;a href=&quot;http://cvs.savannah.gnu.org/viewvc/config/?root=config&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cvs.savannah.gnu.org/viewvc/config/?root=config&lt;/a&gt;&amp;nbsp;.
&lt;br&gt;&lt;br&gt;o We now escape newlines, carriage returns, and tabs (\n\r\t) in XML
&lt;br&gt;&amp;nbsp; output. &amp;nbsp;While those are allowed in XML attributes, they get
&lt;br&gt;&amp;nbsp; normalized which can make formatting the output difficult for
&lt;br&gt;&amp;nbsp; applications which parse Nmap XML. [Joao Medeiros, David, Fyodor]
&lt;br&gt;&lt;br&gt;o The Zenmap man page is now installed on Unix when &amp;quot;make install&amp;quot; is
&lt;br&gt;&amp;nbsp; run. &amp;nbsp;This was supposed to work before, but didn't. [Kris]
&lt;br&gt;&lt;br&gt;o Fixed a man page bug related to our DocBook to Nroff translation
&lt;br&gt;&amp;nbsp; software producing incorrect Nroff output. &amp;nbsp;The man page no longer
&lt;br&gt;&amp;nbsp; uses the &amp;quot;.nse&amp;quot; string which was being confused with the Nroff
&lt;br&gt;&amp;nbsp; no-space mode command. [Fyodor]
&lt;br&gt;&lt;br&gt;o Fixed a bug in which some NSE error messages were improperly escaped
&lt;br&gt;&amp;nbsp; so that a message including &amp;quot;c:\nmap&amp;quot; would end up with a newline
&lt;br&gt;&amp;nbsp; between &amp;quot;c:&amp;quot; and &amp;quot;map&amp;quot;.
&lt;br&gt;&lt;br&gt;o Updated IANA assignment IP list for random IP (-iR)
&lt;br&gt;&amp;nbsp; generation. [Kris]
&lt;br&gt;&lt;br&gt;o The DocBook XML source code to the Nmap Scripting Engine docs
&lt;br&gt;&amp;nbsp; (&lt;a href=&quot;http://nmap.org/nse/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/nse/&lt;/a&gt;) is now in SVN under docs/scripting.xml .
&lt;br&gt;&lt;br&gt;4.53
&lt;br&gt;&lt;br&gt;o Impoved Windows executable installer by making uninstall wor. [Rob Nicholls]
&lt;br&gt;&lt;br&gt;o The Nmap Scripting Engine (NSE) now supports run-time interaction
&lt;br&gt;&amp;nbsp; and the Nmap --host-timeout option. [Doug]
&lt;br&gt;&lt;br&gt;o Added nmap.fetchfile() function for scripts so they can easily find
&lt;br&gt;&amp;nbsp; Nmap's nmap-* data files (such as the OS/version detection DBs, port
&lt;br&gt;&amp;nbsp; number mapping, etc.) [Kris]
&lt;br&gt;&lt;br&gt;o Updated rpcinfo.nse to use nmap.fetchfile() to read from nmap-rpc
&lt;br&gt;&amp;nbsp; instead of having a huge table of RPC numbers. &amp;nbsp;This reduced the
&lt;br&gt;&amp;nbsp; script's size by nearly 75%. [Kris]
&lt;br&gt;&lt;br&gt;o Fixed multiple NSE scripts that weren't always properly closing their
&lt;br&gt;&amp;nbsp; sockets. &amp;nbsp;The error message was:
&lt;br&gt;&amp;nbsp; &amp;quot;bad argument #1 to 'close' (nsock expected, got no value)&amp;quot; [Kris]
&lt;br&gt;&lt;br&gt;o Added a new version detection probe for the Trend Micro OfficeScan
&lt;br&gt;&amp;nbsp; product line. [Tom Sellers, Doug]
&lt;br&gt;&lt;br&gt;4.51BETA
&lt;br&gt;&lt;br&gt;o We now have a detailed Zenmap Guide at &lt;a href=&quot;http://nmap.org/zenmapguide/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/zenmapguide/&lt;/a&gt;&amp;nbsp;.
&lt;br&gt;&amp;nbsp; Thanks to David for writing it.
&lt;br&gt;&lt;br&gt;o Added rpcinfo.nse script, which contacts a listening RPC portmapper
&lt;br&gt;&amp;nbsp; and reports the listening services and port information (like
&lt;br&gt;&amp;nbsp; rpcinfo -p does). &amp;nbsp;The script was written by Sven Klemm. &amp;nbsp;Fyodor
&lt;br&gt;&amp;nbsp; then enhanced the RPC number list with all of the entries from
&lt;br&gt;&amp;nbsp; nmap-rpc.
&lt;br&gt;&lt;br&gt;o Added a new NSE script (MySQLinfo) which prints MySQL server information
&lt;br&gt;&amp;nbsp; such as the protocol and version numbers, status, thread id, capabilities,
&lt;br&gt;&amp;nbsp; and password salt. [Kris]
&lt;br&gt;&lt;br&gt;o Nmap's output options (-oA, -oX, etc.) now support strftime()-like
&lt;br&gt;&amp;nbsp; conversions in the filename. &amp;nbsp;%H, %M, %S, %m, %d, %y, and %Y are
&lt;br&gt;&amp;nbsp; all the same as in strftime(). &amp;nbsp;%T is the same as %H%M%S, %R is the
&lt;br&gt;&amp;nbsp; same as %H%M, and %D is the same as %m%d%y. &amp;nbsp;A % followed by any
&lt;br&gt;&amp;nbsp; other character just yields that character (%% yields a %). &amp;nbsp;This
&lt;br&gt;&amp;nbsp; means that &amp;quot;-oX 'scan-%T-%D.xml'&amp;quot; uses an XML file in the form of
&lt;br&gt;&amp;nbsp; &amp;quot;scan-144840-121307.xml&amp;quot;. [Kris]
&lt;br&gt;&lt;br&gt;o Fixed Winpcap installer to install the right version of Packet.dll
&lt;br&gt;&amp;nbsp; on Windows Vista. [Fyodor]
&lt;br&gt;&lt;br&gt;o Fixed our Winpcap installer so that it waits for a Winpcap uninstall
&lt;br&gt;&amp;nbsp; (if needed) to complete before trying to install the new Winpcap.
&lt;br&gt;&amp;nbsp; [Jah]
&lt;br&gt;&lt;br&gt;o Fix a bunch of warning/error messages which contained an extra
&lt;br&gt;&amp;nbsp; newline. [Brandon Enright]
&lt;br&gt;&lt;br&gt;o Fixed an error when attempting to scan localhost as an unprivileged
&lt;br&gt;&amp;nbsp; user on Windows (nmap --unprivileged localhost). The error was:
&lt;br&gt;&amp;nbsp; &amp;nbsp;&amp;quot;Skipping SYN Stealth Scan against localhost (127.0.0.1) because
&lt;br&gt;&amp;nbsp; &amp;nbsp; Windows does not support scanning your own machine (localhost) this
&lt;br&gt;&amp;nbsp; &amp;nbsp; way.&amp;quot;
&lt;br&gt;&amp;nbsp; Now connect scan is used instead of SYN scan. [David]
&lt;br&gt;&lt;br&gt;o Fixed a bug that prevented the --resume option from working on
&lt;br&gt;&amp;nbsp; Windows. The error message was:
&lt;br&gt;&amp;nbsp; ..\utils.cc(996): CreateFileMapping(), file 'testresume', length 103,
&lt;br&gt;&amp;nbsp; mflags 000 00006: The parameter is incorrect.(87)
&lt;br&gt;&amp;nbsp; [Fixed by David, reported by Rob Nicholls]
&lt;br&gt;&lt;br&gt;o Zenmap's new web page (&lt;a href=&quot;http://nmap.org/zenmap/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/zenmap/&lt;/a&gt;) is now shown in the
&lt;br&gt;&amp;nbsp; Zenmap about dialogue.
&lt;br&gt;&lt;br&gt;o On Windows, paths beginning with \ are now considered absolute when
&lt;br&gt;&amp;nbsp; used with the --script option. jah (jah(a)zadkiel.plus.com) suggested
&lt;br&gt;&amp;nbsp; this. [David]
&lt;br&gt;&lt;br&gt;o Zenmap no longer double-spaces its output (by inadvertently
&lt;br&gt;&amp;nbsp; duplicating newlines) when viewing scan results that were saved to a
&lt;br&gt;&amp;nbsp; file. [Joao Medeiros]
&lt;br&gt;&lt;br&gt;o Upgraded the shipped LibPCRE from version 7.2 to 7.4. [Kris]
&lt;br&gt;&lt;br&gt;o Fixed Zenmap crash that occurred when selecting Help from the Compar
&lt;br&gt;&lt;br&gt;&lt;br&gt;Enjoy!
&lt;br&gt;Fyodor
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Sent through the nmap-hackers mailing list
&lt;br&gt;&lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&lt;/a&gt;&lt;br&gt;Archived at &lt;a href=&quot;http://seclists.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Nmap-4.60-and-new-movies-page-tp16260908p16260908.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-16112064</id>
	<title>Using nmap on a firewall</title>
	<published>2008-03-17T18:06:35Z</published>
	<updated>2008-03-17T18:06:35Z</updated>
	<author>
		<name>russo</name>
	</author>
	<content type="html">Hi
&lt;br&gt;&lt;br&gt;I have a firewall but I'm not responsable for it.
&lt;br&gt;I tryied nessus it sometimes gave me some information and other time no information, So I tryied nmap to scan it tryied some commands 
&lt;br&gt;&lt;br&gt;I got this 
&lt;br&gt;&lt;br&gt;&amp;nbsp;nmap -P0 -vv -sA -ff -r -n 195.XX.XX.XX
&lt;br&gt;&lt;br&gt;Starting Nmap 4.11 ( &lt;a href=&quot;http://www.insecure.org/nmap/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.insecure.org/nmap/&lt;/a&gt;&amp;nbsp;) at 2008-03-17 23:27 WET
&lt;br&gt;Initiating ACK Scan against 195.XX.XX.XX [1680 ports] at 23:27
&lt;br&gt;ACK Scan Timing: About 16.46% done; ETC: 23:30 (0:02:32 remaining)
&lt;br&gt;The ACK Scan took 54.32s to scan 1680 total ports.
&lt;br&gt;Host 195.XX.XX.XX appears to be up ... good.
&lt;br&gt;Interesting ports on 195.XX.XX.XX:
&lt;br&gt;Not shown: 1679 filtered ports
&lt;br&gt;PORT &amp;nbsp; &amp;nbsp; STATE &amp;nbsp; &amp;nbsp; &amp;nbsp;SERVICE
&lt;br&gt;1723/tcp UNfiltered pptp
&lt;br&gt;&lt;br&gt;Nmap finished: 1 IP address (1 host up) scanned in 54.338 seconds
&lt;br&gt;&lt;br&gt;&lt;br&gt;then I did this scan 
&lt;br&gt;&amp;nbsp;nmap -P0 -vv -sS -ff -r -n -p 1-65535 195.XX.XX.XX
&lt;br&gt;&lt;br&gt;Starting Nmap 4.11 ( &lt;a href=&quot;http://www.insecure.org/nmap/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.insecure.org/nmap/&lt;/a&gt;&amp;nbsp;) at 2008-03-18 00:44 WET
&lt;br&gt;Initiating SYN Stealth Scan against 195.XX.XX.XX [65535 ports] at 00:44
&lt;br&gt;SYN Stealth Scan Timing: About 0.42% done; ETC: 02:43 (1:58:12 remaining)
&lt;br&gt;SYN Stealth Scan Timing: About 3.02% done; ETC: 01:17 (0:32:10 remaining)
&lt;br&gt;SYN Stealth Scan Timing: About 5.66% done; ETC: 01:10 (0:25:01 remaining)
&lt;br&gt;SYN Stealth Scan Timing: About 9.37% done; ETC: 01:07 (0:21:18 remaining)
&lt;br&gt;SYN Stealth Scan Timing: About 27.15% done; ETC: 01:04 (0:14:56 remaining)
&lt;br&gt;The SYN Stealth Scan took 1161.75s to scan 65535 total ports.
&lt;br&gt;Host 195.XX.XX.XX appears to be up ... good.
&lt;br&gt;All 65535 scanned ports on 195.XX.XX.XX are filtered
&lt;br&gt;&lt;br&gt;Nmap finished: 1 IP address (1 host up) scanned in 1161.813 seconds
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Raw packets sent: 262136 (8.388MB) | Rcvd: 4 (234B)
&lt;br&gt;&lt;br&gt;&lt;br&gt;But I know that there are more ports open 
&lt;br&gt;&lt;br&gt;What is the best command to see which ports are open?'
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Using-nmap-on-a-firewall-tp16112064p16112064.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-16053643</id>
	<title>Google Summer of code 2008</title>
	<published>2008-03-14T13:07:45Z</published>
	<updated>2008-03-16T14:19:00Z</updated>
	<author>
		<name>zwanderer</name>
	</author>
	<content type="html">hi to all nmappers &lt;img class='smiley' src='http://old.nabble.com/images/smiley/smiley_grin.gif' /&gt;,

Saw Nmap's participation in GSoc 2007.Found that real good and worth indulging in &lt;img class='smiley' src='http://old.nabble.com/images/smiley/smiley_evil.gif' /&gt;

Now that I want to submit a modification in the Nmap modules, i face a communication problem-

I access internet from my College's internet LAN, where the access to IRC is blocked. 

&lt;b&gt;1. Is there an alternate method to communicate with nmap enthusiasts ? Something like an IRC proxy would help.. 

2. What all programming languages / IDEs are required to be comfortable with in order to proceed for the projects.

3. Will the ideas be strictly provided by the core nmap team, or students can also propose their own ideas.&lt;/b&gt;


thanks&lt;img class='smiley' src='http://old.nabble.com/images/smiley/smiley_grin.gif' /&gt;

-anirudh sharma
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Google-Summer-of-code-2008-tp16053643p16053643.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-15728261</id>
	<title>nmap won't save with -oN</title>
	<published>2008-02-27T18:23:53Z</published>
	<updated>2008-02-27T18:23:53Z</updated>
	<author>
		<name>Magikus</name>
	</author>
	<content type="html">i can't seem to save with nmap using -oN random.txt &amp;nbsp;I look in my folder and it is not there..... any ideas???</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nmap-won%27t-save-with--oN-tp15728261p15728261.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-15262501</id>
	<title>vulnerable host</title>
	<published>2008-02-03T21:43:20Z</published>
	<updated>2008-02-03T21:43:20Z</updated>
	<author>
		<name>honey</name>
	</author>
	<content type="html">hello,
&lt;br&gt;i need to inform that i have discovered a very vulnerable linux system with public IP of 203.129.220.203. i have tried many system attcks attempts like ssh,telnet and ftp login etc. and the results have been fruitful.this is also vulnerable to buffer overflow,brute force and other system level attacks.
&lt;br&gt;TRY IT OUT.
&lt;br&gt;as for me i am again going to hack system</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/vulnerable-host-tp15262501p15262501.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-15231858</id>
	<title>need help with /usr/local/bin/nmap</title>
	<published>2008-02-01T10:47:59Z</published>
	<updated>2008-02-01T10:47:59Z</updated>
	<author>
		<name>Emkayu</name>
	</author>
	<content type="html">hey guys, i'm kinda a n00b at this kinda stuff, i've just installed nmap 4.53 on OS X tiger(10.4.11) with terminal, and it works, as in if i enter /usr/local/bin/nmap, nmap will run, but why can't i just enter nmap? is there anyway i can bind /usr/local/bin/nmap to if i just type nmap? please tell me full instructions as i kinda suck at using CLi</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/need-help-with--usr-local-bin-nmap-tp15231858p15231858.html" />
</entry>

</feed>
