For a description of this category, see intrusive NSE category in the Nmap documentation.
Scripts
- afp-brute
Performs password guessing against Apple Filing Protocol (AFP).
- afp-path-vuln
Detects the Mac OS X AFP directory traversal vulnerability, CVE-2010-0533.
- ajp-brute
Performs brute force passwords auditing against the Apache JServ protocol. The Apache JServ Protocol is commonly used by web servers to communicate with back-end Java application server containers.
- backorifice-brute
Performs brute force password auditing against the BackOrifice service. The
backorifice-brute.portsscript argument is mandatory (it specifies ports to run the script against).- broadcast-avahi-dos
Attempts to discover hosts in the local network using the DNS Service Discovery protocol and sends a NULL UDP packet to each host to test if it is vulnerable to the Avahi NULL UDP packet denial of service (CVE-2011-1002).
- cassandra-brute
Performs brute force password auditing against the Cassandra database.
- cics-enum
CICS transaction ID enumerator for IBM mainframes. This script is based on mainframe_brute by Dominic White (https://github.com/sensepost/mainframe_brute). However, this script doesn't rely on any third party libraries or tools and instead uses the NSE TN3270 library which emulates a TN3270 screen in lua.
- cics-user-brute
CICS User ID brute forcing script for the CESL login screen.
- cics-user-enum
CICS User ID enumeration script for the CESL/CESN Login screen.
- citrix-brute-xml
Attempts to guess valid credentials for the Citrix PN Web Agent XML Service. The XML service authenticates against the local Windows server or the Active Directory.
- cvs-brute
Performs brute force password auditing against CVS pserver authentication.
- cvs-brute-repository
Attempts to guess the name of the CVS repositories hosted on the remote server. With knowledge of the correct repository name, usernames and passwords can be guessed.
- deluge-rpc-brute
Performs brute force password auditing against the DelugeRPC daemon.
- distcc-cve2004-2687
Detects and exploits a remote code execution vulnerability in the distributed compiler daemon distcc. The vulnerability was disclosed in 2002, but is still present in modern implementation due to poor configuration of the service.
- dns-brute
Attempts to enumerate DNS hostnames by brute force guessing of common subdomains. With the
dns-brute.srvargument, dns-brute will also try to enumerate common DNS SRV records.- dns-cache-snoop
Performs DNS cache snooping against a DNS server.
- dns-fuzz
Launches a DNS fuzzing attack against DNS servers.
- dns-ip6-arpa-scan
Performs a quick reverse DNS lookup of an IPv6 network using a technique which analyzes DNS server response codes to dramatically reduce the number of queries needed to enumerate large networks.
- dns-nsec-enum
Enumerates DNS names using the DNSSEC NSEC-walking technique.
- dns-nsec3-enum
Tries to enumerate domain names from the DNS server that supports DNSSEC NSEC3 records.
- dns-random-srcport
Checks a DNS server for the predictable-port recursion vulnerability. Predictable source ports can make a DNS server vulnerable to cache poisoning attacks (see CVE-2008-1447).
- dns-random-txid
Checks a DNS server for the predictable-TXID DNS recursion vulnerability. Predictable TXID values can make a DNS server vulnerable to cache poisoning attacks (see CVE-2008-1447).
- dns-update
Attempts to perform a dynamic DNS update without authentication.
- dns-zone-transfer
Requests a zone transfer (AXFR) from a DNS server.
- domcon-brute
Performs brute force password auditing against the Lotus Domino Console.
- domcon-cmd
Runs a console command on the Lotus Domino Console using the given authentication credentials (see also: domcon-brute)
- domino-enum-users
Attempts to discover valid IBM Lotus Domino users and download their ID files by exploiting the CVE-2006-5835 vulnerability.
- dpap-brute
Performs brute force password auditing against an iPhoto Library.
- drda-brute
Performs password guessing against databases supporting the IBM DB2 protocol such as Informix, DB2 and Derby
- firewall-bypass
Detects a vulnerability in netfilter and other firewalls that use helpers to dynamically open ports for protocols such as ftp and sip.
- ftp-brute
Performs brute force password auditing against FTP servers.
- ftp-libopie
Checks if an FTPd is prone to CVE-2010-1938 (OPIE off-by-one stack overflow), a vulnerability discovered by Maksymilian Arciemowicz and Adam "pi3" Zabrocki. See the advisory at https://nmap.org/r/fbsd-sa-opie. Be advised that, if launched against a vulnerable host, this script will crash the FTPd.
- ftp-proftpd-backdoor
Tests for the presence of the ProFTPD 1.3.3c backdoor reported as BID 45150. This script attempts to exploit the backdoor using the innocuous
idcommand by default, but that can be changed with theftp-proftpd-backdoor.cmdscript argument.- ftp-vsftpd-backdoor
Tests for the presence of the vsFTPd 2.3.4 backdoor reported on 2011-07-04 (CVE-2011-2523). This script attempts to exploit the backdoor using the innocuous
idcommand by default, but that can be changed with theexploit.cmdorftp-vsftpd-backdoor.cmdscript arguments.- ftp-vuln-cve2010-4221
Checks for a stack-based buffer overflow in the ProFTPD server, version between 1.3.2rc3 and 1.3.3b. By sending a large number of TELNET_IAC escape sequence, the proftpd process miscalculates the buffer length, and a remote attacker will be able to corrupt the stack and execute arbitrary code within the context of the proftpd process (CVE-2010-4221). Authentication is not required to exploit this vulnerability.
- hartip-info
This NSE script is used to send a HART-IP packet to a HART device that has TCP 5094 open. The script will establish Session with HART device, then Read Unique Identifier and Read Long Tag packets are sent to parse the required HART device information. Read Sub-Device Identity Summary packet with Sub-Device index 00 01 is sent to request information on Sub-Device, if any available. If the response code differs from 0 (success), the error code is passed as Sub-Device Information. Otherwise, the required Sub-Device information is parsed from response packet.
- http-awstatstotals-exec
Exploits a remote code execution vulnerability in Awstats Totals 1.0 up to 1.14 and possibly other products based on it (CVE: 2008-3922).
- http-axis2-dir-traversal
Exploits a directory traversal vulnerability in Apache Axis2 version 1.4.1 by sending a specially crafted request to the parameter
xsd(BID 40343). By default it will try to retrieve the configuration file of the Axis2 service'/conf/axis2.xml'using the path'/axis2/services/'to return the username and password of the admin account.- http-barracuda-dir-traversal
Attempts to retrieve the configuration settings from a Barracuda Networks Spam & Virus Firewall device using the directory traversal vulnerability described at http://seclists.org/fulldisclosure/2010/Oct/119.
- http-brute
Performs brute force password auditing against http basic, digest and ntlm authentication.
- http-chrono
Measures the time a website takes to deliver a web page and returns the maximum, minimum and average time it took to fetch a page.
- http-config-backup
Checks for backups and swap files of common content management system and web server configuration files.
- http-csrf
This script detects Cross Site Request Forgeries (CSRF) vulnerabilities.
- http-default-accounts
Tests for access with default credentials used by a variety of web applications and devices. It detects applications by matching web responses of known paths and launching a login routine using default credentials when found.
- http-devframework
- http-dombased-xss
It looks for places where attacker-controlled information in the DOM may be used to affect JavaScript execution in certain ways. The attack is explained here: http://www.webappsec.org/projects/articles/071105.shtml
- http-domino-enum-passwords
Attempts to enumerate the hashed Domino Internet Passwords that are (by default) accessible by all authenticated users. This script can also download any Domino ID Files attached to the Person document. Passwords are presented in a form suitable for running in John the Ripper.
- http-drupal-enum
Enumerates the installed Drupal modules/themes by using a list of known modules and themes.
- http-drupal-enum-users
Enumerates Drupal users by exploiting an information disclosure vulnerability in Views, Drupal's most popular module.
- http-enum
Enumerates directories used by popular web applications and servers.
- http-errors
This script crawls through the website and returns any error pages.
- http-exif-spider
Spiders a site's images looking for interesting exif data embedded in .jpg files. Displays the make and model of the camera, the date the photo was taken, and the embedded geotag information.
- http-feed
This script crawls through the website to find any rss or atom feeds.
- http-fileupload-exploiter
Exploits insecure file upload forms in web applications using various techniques like changing the Content-type header or creating valid image files containing the payload in the comment.
- http-form-brute
Performs brute force password auditing against http form-based authentication.
- http-form-fuzzer
Performs a simple form fuzzing against forms found on websites. Tries strings and numbers of increasing length and attempts to determine if the fuzzing was successful.
- http-iis-short-name-brute
Attempts to brute force the 8.3 filenames (commonly known as short names) of files and directories in the root folder of vulnerable IIS servers. This script is an implementation of the PoC "iis shortname scanner".
- http-iis-webdav-vuln
Checks for a vulnerability in IIS 5.1/6.0 that allows arbitrary users to access secured WebDAV folders by searching for a password-protected folder and attempting to access it. This vulnerability was patched in Microsoft Security Bulletin MS09-020, https://nmap.org/r/ms09-020.
- http-joomla-brute
Performs brute force password auditing against Joomla web CMS installations.
- http-litespeed-sourcecode-download
Exploits a null-byte poisoning vulnerability in Litespeed Web Servers 4.0.x before 4.0.15 to retrieve the target script's source code by sending a HTTP request with a null byte followed by a .txt file extension (CVE-2010-2333).
- http-majordomo2-dir-traversal
Exploits a directory traversal vulnerability existing in Majordomo2 to retrieve remote files. (CVE-2011-0049).
- http-open-redirect
Spiders a website and attempts to identify open redirects. Open redirects are handlers which commonly take a URL as a parameter and responds with a HTTP redirect (3XX) to the target. Risks of open redirects are described at http://cwe.mitre.org/data/definitions/601.html.
- http-passwd
Checks if a web server is vulnerable to directory traversal by attempting to retrieve
/etc/passwdor\boot.ini.- http-phpself-xss
Crawls a web server and attempts to find PHP files vulnerable to reflected cross site scripting via the variable
$_SERVER["PHP_SELF"].- http-proxy-brute
Performs brute force password guessing against HTTP proxy servers.
- http-put
Uploads a local file to a remote web server using the HTTP PUT method. You must specify the filename and URL path with NSE arguments.
- http-rfi-spider
Crawls webservers in search of RFI (remote file inclusion) vulnerabilities. It tests every form field it finds and every parameter of a URL containing a query.
- http-shellshock
Attempts to exploit the "shellshock" vulnerability (CVE-2014-6271 and CVE-2014-7169) in web applications.
- http-sitemap-generator
Spiders a web server and displays its directory structure along with number and types of files in each folder. Note that files listed as having an 'Other' extension are ones that have no extension or that are a root document.
- http-slowloris
Tests a web server for vulnerability to the Slowloris DoS attack by launching a Slowloris attack.
- http-sql-injection
Spiders an HTTP server looking for URLs containing queries vulnerable to an SQL injection attack. It also extracts forms from found websites and tries to identify fields that are vulnerable.
- http-stored-xss
Unfiltered '>' (greater than sign). An indication of potential XSS vulnerability.
- http-unsafe-output-escaping
Spiders a website and attempts to identify output escaping problems where content is reflected back to the user. This script locates all parameters, ?x=foo&y=bar and checks if the values are reflected on the page. If they are indeed reflected, the script will try to insert ghz>hzx"zxc'xcv and check which (if any) characters were reflected back onto the page without proper html escaping. This is an indication of potential XSS vulnerability.
- http-userdir-enum
Attempts to enumerate valid usernames on web servers running with the mod_userdir module or similar enabled.
