UDP port scanner is missing SNMP ports
I maintainer di solito rispondono entro 2 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 76/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- rust
- Ambito
- networking, security
Direzione di ricerca
Inizia da build.rs e ispeziona la decodifica del payload utilizzata dal probe SNMP incluso, quindi esegui i comandi snmpget e RustScan forniti contro demo.pysnmp.com. Verifica che il testo letterale, le sequenze di escape e le stringhe tra virgolette adiacenti vengano decodificati come descritto e che la porta UDP 161 venga rilevata con il servizio SNMP pubblico.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Describe the bug
Rustscan cannot find an open SNMP port, while it can be found using NMAP and snmpget.
To Reproduce
-
Confirm that the public SNMP test service responds using SNMPv1 and community
public:snmpget -v1 -c public -t 3 -r 1 \ demo.pysnmp.com 1.3.6.1.2.1.1.1.0Observed:
SNMPv2-MIB::sysDescr.0 = STRING: #SNMP Agent on .NET Standard -
Scan UDP port 161 using Nmap:
sudo nmap -sU -Pn -n -p 161 --reason \ --max-retries 1 --host-timeout 20s demo.pysnmp.comObserved with Nmap 7.95:
PORT STATE SERVICE REASON 161/udp open snmp udp-response ttl 63 -
Scan the same port using an affected RustScan build:
rustscan --no-config --udp -a demo.pysnmp.com -p 161 \ --timeout 3000 --tries 2 --scripts none --accessibleObserved with the affected RustScan 2.4.1 lab build:
Looks like I didn't find any open ports for 128.203.82.143.
Expected behavior
RustScan should generate a valid SNMP payload containing the community string public and detect UDP port 161 when the agent responds.
More generally, payload decoding should preserve literal text, decode escape sequences, and concatenate quoted strings without adding separator whitespace.
Screenshots
Not applicable;
Desktop (please complete the following information):
- OS: Linux/aarch64 for the containerized comparison; macOS/Apple Silicon for an additional host check.
- Browser: Not applicable.
- Version: RustScan 2.4.1 in downstream lab builds; installed host RustScan 2.3.0 also missed the port.
- Nmap: 7.95 for the comparison.
Smartphone (please complete the following information):
- Device: Not applicable.
- OS: Not applicable.
- Browser: Not applicable.
- Version: Not applicable.
Additional context
According to our friend 🤖
The missing detection appears to be caused by a malformed SNMP payload. The server does not respond to that payload, so RustScan reports no open ports.
The parser in build.rs keeps only ASCII hexadecimal digits:
if char == '\' && payload.chars().nth(idx + 1) == Some('x') {
continue;
} else if char.is_ascii_hexdigit() {
tmp_str.push(char);
// Converts each pair of retained hex digits into a byte.
}
However, the bundled SNMP probe contains the literal community string public. The parser retains only b and c, converting the six-character string into the single byte 0xbc.
This produces a 28-byte probe instead of the expected 33 bytes, while its BER header still declares 31 bytes after the two-byte header.
A local build with corrected payload decoding detected port 161 on the same server. The faulty parser is also present in upstream master at the time of reporting.
Other probes containing literal text, including NetBIOS, LDAP, SSDP, memcached, and service location, may be affected as well.
- Lingua principale
- Rust
- Stelle
- 20.5k
- Fork
- 1.4k
- Merge medio
- 3g 19h
- PR unite (30g)
- 16
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di bee-san/RustScan
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
bee-san/RustScan#937 · 1 commento ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
bee-san/RustScan#825 · 7 commenti · 1 reazione ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 42/100
bee-san/RustScan#822 · 1 reazione ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 58/100
bee-san/RustScan#795 · 1 commento · 1 reazione ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
bee-san/RustScan#780 · 4 commenti ·
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di bee-san/RustScan
Issue simili
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
zcashlabs/thus-spoke-zakura#153 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 79/100
topgrade-rs/topgrade#2395 ·
I maintainer di solito rispondono entro 1 giorno
-
app bug windows-os
Difficoltà 2/5 1-3 ore Idoneità per principianti 67/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
matrix-org/matrix-rust-sdk#7217 ·
I maintainer di solito rispondono entro 1 giorno
-
Improve sublime text syntaxApertaeditor good first issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
funnyboy-roks/inq#54 ·