UDP port scanner is missing SNMP ports
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 76/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- rust
- Domain
- networking, security
Research direction
Start in build.rs and inspect the payload decoding used by the bundled SNMP probe, then run the supplied snmpget and RustScan commands against demo.pysnmp.com. Verify that literal text, escape sequences, and adjacent quoted strings are decoded as described, and that UDP port 161 is detected with the public SNMP service.
Written by the indexing model from the issue text.
Description
Describe the bug
Rustscan cannot find an open SNMP port, while it can be found using NMAP and snmpget.
To Reproduce
-
Confirm that the public SNMP test service responds using SNMPv1 and community
public:snmpget -v1 -c public -t 3 -r 1 \ demo.pysnmp.com 1.3.6.1.2.1.1.1.0Observed:
SNMPv2-MIB::sysDescr.0 = STRING: #SNMP Agent on .NET Standard -
Scan UDP port 161 using Nmap:
sudo nmap -sU -Pn -n -p 161 --reason \ --max-retries 1 --host-timeout 20s demo.pysnmp.comObserved with Nmap 7.95:
PORT STATE SERVICE REASON 161/udp open snmp udp-response ttl 63 -
Scan the same port using an affected RustScan build:
rustscan --no-config --udp -a demo.pysnmp.com -p 161 \ --timeout 3000 --tries 2 --scripts none --accessibleObserved with the affected RustScan 2.4.1 lab build:
Looks like I didn't find any open ports for 128.203.82.143.
Expected behavior
RustScan should generate a valid SNMP payload containing the community string public and detect UDP port 161 when the agent responds.
More generally, payload decoding should preserve literal text, decode escape sequences, and concatenate quoted strings without adding separator whitespace.
Screenshots
Not applicable;
Desktop (please complete the following information):
- OS: Linux/aarch64 for the containerized comparison; macOS/Apple Silicon for an additional host check.
- Browser: Not applicable.
- Version: RustScan 2.4.1 in downstream lab builds; installed host RustScan 2.3.0 also missed the port.
- Nmap: 7.95 for the comparison.
Smartphone (please complete the following information):
- Device: Not applicable.
- OS: Not applicable.
- Browser: Not applicable.
- Version: Not applicable.
Additional context
According to our friend 🤖
The missing detection appears to be caused by a malformed SNMP payload. The server does not respond to that payload, so RustScan reports no open ports.
The parser in build.rs keeps only ASCII hexadecimal digits:
if char == '\' && payload.chars().nth(idx + 1) == Some('x') {
continue;
} else if char.is_ascii_hexdigit() {
tmp_str.push(char);
// Converts each pair of retained hex digits into a byte.
}
However, the bundled SNMP probe contains the literal community string public. The parser retains only b and c, converting the six-character string into the single byte 0xbc.
This produces a 28-byte probe instead of the expected 33 bytes, while its BER header still declares 31 bytes after the two-byte header.
A local build with corrected payload decoding detected port 161 on the same server. The faulty parser is also present in upstream master at the time of reporting.
Other probes containing literal text, including NetBIOS, LDAP, SSDP, memcached, and service location, may be affected as well.
- Dominant language
- Rust
- Stars
- 20.5k
- Forks
- 1.4k
- Avg merge
- 3d 19h
- Merged PRs (30d)
- 16
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from bee-san/RustScan
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
bee-san/RustScan#937 · 1 comment ·
Maintainers usually reply within 2 days
-
Difficulty 4/5 3-5 days Newbie friendliness 38/100
bee-san/RustScan#825 · 7 comments · 1 reaction ·
Maintainers usually reply within 2 days
-
Difficulty 3/5 1-2 days Newbie friendliness 42/100
bee-san/RustScan#822 · 1 reaction ·
Maintainers usually reply within 2 days
-
Difficulty 3/5 1-2 days Newbie friendliness 58/100
bee-san/RustScan#795 · 1 comment · 1 reaction ·
Maintainers usually reply within 2 days
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
bee-san/RustScan#780 · 4 comments ·
Maintainers usually reply within 2 days
All issues in bee-san/RustScan
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
rust-windowing/winit#4731 ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
area:cli bug priority:high
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
Anthropic streamed blocks without a content_block_stop are discardedPossibly taken @Frun1na claimed this today. Opencomponent:sight
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
agentic-os-org/ANOLISA#4622 · 1 comment ·
Maintainers usually reply within 1 day