Nmap Development mailing list archives

Re: [NSE] rpc library; trusted inputs?


From: David Fifield <david () bamsoftware com>
Date: Wed, 21 Apr 2010 18:34:18 -0600

On Sat, Apr 17, 2010 at 04:21:59PM +0100, Djalal Harouni wrote:
2) NSE Scripts:
- better error handling.


I must remind you that some scripts/libs (including these ones) trust
remote inputs!!! 
I have found this thread: http://seclists.org/nmap-dev/2009/q3/210
which is a good start.

Can you explain more in what way external inputs are being trusted? One
specific example is already handled at a high level; control characters
in NSE output are always escaped. I'm sure there are other
possibilities, like a script looping forever. As Solar Designer pointed
out, in case of a bug in liblua it might be possible for network input
to escape the scripting environment. If you've found specific examples,
please share them so they can be fixed.

David Fifield
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: