Ukukhishwa kwesithwebuli sokuphepha senethiwekhi i-Nmap 7.90

Ngaphezu konyaka kusukela kokugcina kwethulwe ukukhishwa kwesithwebuli sokuphepha senethiwekhi imephu 7.90, eklanyelwe ukwenza ukuhlolwa kwenethiwekhi nokuhlonza amasevisi enethiwekhi asebenzayo. Ingxenye kufakiwe Imibhalo emi-3 emisha ye-NSE yokuhlinzeka ngokuzenzakalelayo kwezenzo ezahlukahlukene nge-Nmap. Kungezwe amasiginesha amasha angaphezu kuka-1200 ukuze kuhlonzwe izinhlelo zenethiwekhi namasistimu okusebenza.

Phakathi kwezinguquko ku-Nmap 7.90:

  • Iphrojekthi isishintshile isuka ekusebenziseni ilayisensi ye-GPLv2 eshintshiwe yaya ku- I-Nmap Public Source License, engashintshile ngokuyisisekelo futhi futhi esekelwe ku-GPLv2, kodwa yakheke kangcono futhi inikezwe ulimi olucacile. Umehluko ovela ku-GPLv2 uhlanganisa ukwengezwa kokuhlukile okumbalwa kanye nemibandela, njengokukwazi ukusebenzisa ikhodi ye-Nmap emikhiqizweni engaphansi kwamalayisense okungewona awe-GPL ngemva kokuthola imvume kumbhali, kanye nesidingo selayisense ehlukene yokuhlinzekwa nokusetshenziswa kwe-nmap ngokuphathelene nobunikazi. imikhiqizo.
  • Izihlonzi zezinhlelo zokusebenza nezinguqulo zesevisi ezingaphezu kuka-800 zengeziwe, futhi usayizi ophelele wesizindalwazi sezihlonzi usufinyelele amarekhodi ayi-11878. Ukutholwa okwengeziwe kwe-MySQL 8.x, i-Microsoft SQL Server 2019, i-MariaDB, i-Crate.io i-CrateDB kanye nokufakwa kwe-PostreSQL ku-Docker. Ukunemba okuthuthukisiwe kokutholwa kwenguqulo ye-MS SQL. Inani lezivumelwano ezichaziwe linyukile lisuka ku-1193 laya ku-1237, okuhlanganisa ukwesekwa okwengeziwe kwezivumelwano zomsindo we-airmedia,
    banner-ivu, control-m, insteon-plm, pi-hole-stats kanye
    ums-webviewer.

  • Cishe izihlonzi zesistimu yokusebenza ezingu-400 zengeziwe, i-330 ye-IPv4 kanye ne-67 ye-IPv6, okuhlanganisa izihlonzi ze-iOS 12/13, i-macOS Catalina ne-Mojave, Linux 5.4 ne-FreeBSD 13. Inani lezinguqulo ze-OS ezikhonjiwe linyuselwe ku-5678.
  • Imitapo yolwazi emisha yengeziwe ku-Nmap Scripting Engine (NSE), eklanyelwe ukuhlinzeka ngokuzenzakalelayo kwezenzo ezihlukahlukene nge-Nmap: veza ngemisebenzi yokucubungula okukhiphayo nokufometha kwezintambo, kanye ne-dicom ngokusetshenziswa kwephrothokholi ye-DICOM esetshenziselwa ukugcina nokudlulisa izithombe zezokwelapha. .
  • Kwengezwe okusha Imibhalo ye-NSE:
    • i-dicom-brute yokukhetha izihlonzi ze-AET (Isihloko Sebhizinisi Lokusebenza) kumaseva I-DICOM (Ukufanekisa Kwedijithali Nokuxhumana Kwezokwelapha);
    • i-dicom-ping ukuthola amaseva e-DICOM nokunquma ukuxhumana kusetshenziswa izihlonzi ze-AET;
    • uptime-agent-info ukuqoqa ulwazi lwesistimu kuma-ejenti e-Idera Uptime Infrastructure Monitor.
  • Kwengezwe izicelo zokuhlolwa kwe-UDP ezintsha ezingu-23 (Ukulayishwa kwe-UDP, imibuzo eqondene nephrothokholi eholela ekuphenduleni esikhundleni sokuziba iphakethe le-UDP) edalelwe injini yokuskena yenethiwekhi ye-Rapid7 InsightVM futhi ivumele ukunemba okungeziwe ekuhlonzeni izinsiza ezihlukahlukene ze-UDP.
  • Kwengezwe izicelo ze-UDP zokunquma i-STUN (Session Traversal Utilities for NAT) kanye ne-GPRS Tunnel Protocol (GTP).
  • Inketho eyengeziwe "--discovery-ignore-rst" ukuze uzibe izimpendulo ze-TCP RST uma kunqunywa impilo yomsingathi oqondiwe (kusiza uma izindonga zomlilo noma amasistimu okuhlolwa kwethrafikhi. esikhundleni Amaphakethe e-RST okunqanyulwa kokuxhumeka).
  • Inketho eyengeziwe "--ssl-servername" ukuze uguqule inani legama lomethuleli ku-TLS SNI.
  • Kwengezwe amandla okusebenzisa inketho ethi "--resume" ukuqalisa kabusha amaseshini okuskena e-IPv6 aphazamisekile.
  • Insiza ye-nmap-update, eyathuthukiswa ukuze kuhlelwe ukubuyekezwa kolwazi lwezihlonzi nemibhalo ye-NSE, isusiwe, kodwa ingqalasizinda yalezi zenzo ayikadalwa.

Ezinsukwini ezimbalwa ezedlule kwakukhona futhi eshicilelwe ukukhululwa I-Npcap 1.0, imitapo yolwazi yokuthwebula amaphakethe nokushintshwa endaweni yesikhulumi seWindows, ithuthukiswe njengokuthatha indawo I-Winpcap nokusebenzisa i-Windows API yesimanje NDIS 6 LWF. Inguqulo 1.0 iletha ekupheleni kweminyaka eyisikhombisa yentuthuko futhi iphawula ukuzinza kwe-Npcap kanye nokulungela kwayo ukusetshenziswa kabanzi. Umtapo wezincwadi we-Npcap, uma uqhathaniswa neWinPcap, ubonisa ukusebenza okuphezulu, ukuphepha nokwethembeka, kuhambisana ngokugcwele Windows 10 futhi isekela izici eziningi ezithuthukile njengemodi eluhlaza, edinga amalungelo omlawuli ukuze isebenze, kusetshenziswa i-ASLR ne-DEP ukuze kuvikelwe, kuthwebule futhi kufakwe amaphakheji esikhundleni. i-loopback interface, ehambisana ne-Libpcap ne-WinPcap APIs.

Source: opennet.ru

Engeza amazwana