data:image/s3,"s3://crabby-images/eec01/eec0181e9ead005a01381c1e0aa621787905c3e7" alt="nmap-dev logo"
Nmap Development Mailing List
Unmoderated technical development forum for debating ideas, patches, and suggestions regarding proposed changes to Nmap and related projects. Subscribe to nmap-dev here.
List Archives
- Jan–Mar
- Apr–Jun
- Jul–Sep
- Oct–Dec
- 2025
- 14
- –
- –
- –
- 2024
- 1
- 12
- 14
- 9
- 2023
- 10
- 26
- 17
- 24
- 2022
- 10
- 12
- 12
- 4
- 2021
- 33
- 14
- 11
- 15
- 2020
- 12
- 39
- 29
- 38
- 2019
- 98
- 44
- 50
- 16
- 2018
- 55
- 54
- 49
- 58
- 2017
- 303
- 199
- 202
- 68
- 2016
- 356
- 269
- 310
- 192
- 2015
- 427
- 375
- 384
- 308
- 2014
- 358
- 571
- 514
- 390
- 2013
- 422
- 534
- 664
- 337
- 2012
- 739
- 993
- 1068
- 533
- 2011
- 1148
- 1302
- 925
- 638
- 2010
- 1248
- 1035
- 916
- 793
- 2009
- 928
- 846
- 1116
- 732
- 2008
- 568
- 911
- 1038
- 809
- 2007
- 305
- 509
- 479
- 832
- 2006
- 410
- 497
- 447
- 326
- 2005
- 175
- 257
- 202
- 251
- 2004
- 173
- 80
- 131
- 178
- 2003
- 58
- 113
- 141
- 91
- 2002
- 58
- 90
- 59
- 77
- 2001
- 18
- 3
- 51
- 46
- 2000
- –
- –
- 77
- 20
Latest Posts
Windows 10/11: Ncat: A message sent on a datagram socket was larger than the internal message buffer ...
Ken Kayser (Feb 20)
*Describe the bug*
When listening to a port with ncat, as soon as a UDP packet is received, I
receive a constant stream of errors with the following text: "Ncat: A
message sent on a datagram socket was larger than the internal message
buffer or some other network limit, or the buffer used to receive a
datagram into was smaller than the datagram itself. ."
*To Reproduce*
1. In either a Windows command line or Powershell I enter...
Reverse DNS (issue #3007)
Matteo Nicoli (Feb 13)
Hi all,
I noticed a cool feature proposal on GitHub (issue 3007 <https://github.com/nmap/nmap/issues/3007>). It basically
suggests a new feature for returning the (complete) list of DNS records obtained ā through reverse DNS lookups ā from
an IP address. If it matches with the map product roadmap, Iād like to start implementing it. Is there some maintainer
who could give me a brief feedback about it?
Cheers,
Matteo
Re: Mail stoppage
Gordon Fyodor Lyon (Feb 12)
Yes, this was my fault. Mail to the Nmap dev list from non-subscribers
goes through moderation to keep out the spam. I regularly go through the
moderation queue to find and approve the "real" messages, but I was a bit
slow this time. We strongly recommend that folks posting to the list first
subscribe to it. This avoids the moderation delay and prevents them from
missing any responses which might only be sent to the list.
Cheers,...
Mail stoppage
Dave Close (Feb 12)
Several messages received today seem to have been stuck on nmap.org for
up to a month. Example (edited for clarity):
Version: 7.94+SVN TypeError: Couldn't find foreign struct converter for 'cairo.Context'
Hendrick Halim (Feb 12)
Version: 7.94+SVN
TypeError: Couldn't find foreign struct converter for 'cairo.Context'
topology tab crash
Genny and Doug Kent (Feb 12)
zenmap crashes when topology tab clicked.
Output message below
Version: 7.94+SVN
TypeError: Couldn't find foreign struct converter for 'cairo.Context'
Doug Kent
PR #2954, Fix out of bounds reads in packet parsing
Domen Puncer Kugler via dev (Feb 12)
Hi,
I've submitted a pull request a few months ago:
https://github.com/nmap/nmap/pull/2954
The PR includes following three commits:
- Fix out of bounds read in HopByHopHeader::validate
- Fix out of bounds read in PacketParser::split
- Add AFL test code for PacketParser
This was found as a part of a short Hackathon at NCC Group.
As far as I can tell, there is no security impact, but it would still be nice
to see this fixed.
Kind regards
High-Priority HTML Parsing script
astrotoki via dev (Feb 12)
Hello,
I noticed that under the high priority script ideas was the need for a library that parses HTML info from sites. I
wrote a script that uses a web crawler and extracts html info from attached pages and accompanying urls within the html
body. Let me know if this is what yall were after?
Thanks!
Ryan LaPierre <Astro>_______________________________________________
Sent through the dev mailing list...
URL Pathfinder
astrotoki via dev (Feb 12)
Hello all!
I just wrote up another script, trying to practice and maybe have some added to the master list for nmap. This script
enumerates possible hidden path extensions on urls. As always, Id love input on it, changes or updates.
Thanks all!
Ryan LaPierre <Astro>_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at https://seclists.org/nmap-dev/
Null Byte Poisoning NSE
astrotoki via dev (Feb 12)
Here is my submission of a script I wrote that should test a site for null byte poisoning vulnerabilities._______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at https://seclists.org/nmap-dev/
Re: First Go
astrotoki via dev (Feb 12)
Here is an updated version with more XSS patterns integrated into it. As well as some clean up!
I also created a separate .lua with just the http crawler function.
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at https://seclists.org/nmap-dev/
First Go
astrotoki via dev (Feb 12)
Hello!,
I just started learning Lua for writing NSEs and had a go at a HTTP crawler that identifies XSS vulnerabilities on
sites. I used Juice-Shop OWASP to confirm it works. (Thats why the source code uses port 3000 in addition to 80) Id
love feedback! Doing my best to learn as much as I can. I attached the http_xss_crawler.nse below!
PS. I had used ChatGPTo1 and Github CoPilot to aid in debugging and syntax issues. The overall code is my...
Re: [PATCH] nping: bind to interface on Linux for IPv4 send-ip
Daniel Miller (Feb 10)
Thanks, Valdik! I reviewed the code and moved the call to
socket_bindtodevice() to ProbeMode::start() so that it will affect all
modes, not just TCP. The change is in r39078.
Dan
High-Priority HTML Parsing script
astrotoki via dev (Jan 28)
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at https://seclists.org/nmap-dev/
Post Quantum hackathon and nmap
Loganaden Velvindron (Dec 09)
Hi Folks,
I'm logan from the cyberstorm.mu team. We have opened several PRs for
nmap to improve support for Post Quantum algorithms:
https://github.com/nmap/nmap/pull/2977
https://github.com/nmap/nmap/pull/2978
https://github.com/nmap/nmap/pull/2987
We are working on other PRs for PQ which we will send in due time.
Feedback is welcome and we are willing to commit time to improve our
PRs.
Kind regards,
Logan
(On behalf of the...
More Lists
Dozens of other network security lists are archived at SecLists.Org.