Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Four new Telnet fingerprints + Four new DNS fingerprints #252

Merged
merged 4 commits into from Feb 26, 2020
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions xml/dns_versionbind.xml
Original file line number Diff line number Diff line change
Expand Up @@ -722,4 +722,40 @@
<param pos="1" name="service.version"/>
<param pos="2" name="service.version.version"/>
</fingerprint>
<fingerprint pattern="^CleanBrowsing v([^ ]+) - (.*)">
<description>CleanBrowsing DNS Server</description>
<example service.vendor="CleanBrowsing" service.family="CleanBrowsing" service.version="1.5a" service.node="dns-edge-usa-west-sunnyvale-p">CleanBrowsing v1.5a - dns-edge-usa-west-sunnyvale-p</example>
<example service.vendor="CleanBrowsing" service.family="CleanBrowsing" service.version="1.4a" service.node="dns-edge-usa-west-sunnyvale.cleanbrowsing.org">CleanBrowsing v1.4a - dns-edge-usa-west-sunnyvale.cleanbrowsing.org</example>
<param pos="0" name="service.vendor" value="CleanBrowsing"/>
<param pos="0" name="service.family" value="CleanBrowsing"/>
<param pos="0" name="service.product" value="DNS"/>
<param pos="1" name="service.version"/>
<param pos="2" name="service.node"/>
</fingerprint>
<fingerprint pattern="^dnsmasq-pi-hole-(.*)$">
<description>dnsmasq: pi-hole</description>
<example os.vendor="Pi-hole" service.vendor="Thekelleys" service.family="Dnsmasq" service.product="Dnsmasq" os.version="2.80" os.cpe23="cpe:/a:pi-hole:pi-hole:2.80" service.cpe23="cpe:/a:thekelleys:dnsmasq:-">dnsmasq-pi-hole-2.80</example>
<param pos="0" name="os.vendor" value="Pi-hole"/>
<param pos="0" name="service.vendor" value="Thekelleys"/>
<param pos="0" name="service.family" value="Dnsmasq"/>
<param pos="0" name="service.product" value="Dnsmasq"/>
<param pos="1" name="os.version"/>
<param pos="0" name="os.cpe23" value="cpe:/a:pi-hole:pi-hole:{os.version}"/>
<param pos="0" name="service.cpe23" value="cpe:/a:thekelleys:dnsmasq:-"/>
</fingerprint>
<fingerprint pattern="^Q9-[^\-]-(.*)$">
<description>Quad9 Resolver</description>
<example service.vendor="IBM" service.family="Quad9" service.product="DNS" service.version="6.0">Q9-P-6.0</example>
<param pos="0" name="service.vendor" value="IBM"/>
<param pos="0" name="service.family" value="Quad9"/>
<param pos="0" name="service.product" value="DNS"/>
<param pos="1" name="service.version"/>
</fingerprint>
<fingerprint pattern="^keweonDNS v\.(.*)$">
<description>Keweon DNS</description>
<example service.vendor="Keweon" service.product="DNS" service.version="9.63.7201">keweonDNS v.9.63.7201</example>
<param pos="0" name="service.vendor" value="Keweon"/>
<param pos="0" name="service.product" value="DNS"/>
<param pos="1" name="service.version"/>
</fingerprint>
</fingerprints>
52 changes: 52 additions & 0 deletions xml/telnet_banners.xml
Original file line number Diff line number Diff line change
Expand Up @@ -1521,4 +1521,56 @@
<param pos="0" name="os.product" value="ProLiant"/>
<param pos="1" name="os.version"/>
</fingerprint>
<fingerprint pattern="^Power Measurement Ltd. Meter ION ([[:alnum:]]+)">
<!-- Power Measurement Ltd. Meter ION 7330V271 ETH ETH7330V272
Serial#: PB-0204A058-11

login: -->
<description>Power Measurement ION Power Meter</description>
<example _encoding="base64" hw.vendor="Power Measurement Ltd." hw.family="ION" hw.version="7330V271">
UG93ZXIgTWVhc3VyZW1lbnQgTHRkLiBNZXRlciBJT04gNzMzMFYyNzEgRVRIIEVUSDczMzBWMjcyCg1TZ
XJpYWwjOiBQQi0wMjA0QTA1OC0xMQoNCg1sb2dpbjo=
</example>
<param pos="0" name="hw.vendor" value = "Power Measurement Ltd."/>
<param pos="0" name="hw.family" value = "ION"/>
<param pos="1" name="hw.version"/>
</fingerprint>
<fingerprint pattern="^GW25 v([[:digit:]\.]+) - Intelligent Power Meters GPRS Gateway[[:space:]]+Developed by Satelitech">
<!-- GW25 v1.2.1 - Intelligent Power Meters GPRS Gateway
Developed by Satelitech S.A for ESG Dilec
Enter password: -->
<description>Satelitech Power Meter</description>
<example _encoding="base64" hw.vendor="Satelitech" hw.family="GW25" hw.version="1.2.1">
R1cyNSB2MS4yLjEgLSBJbnRlbGxpZ2VudCBQb3dlciBNZXRlcnMgR1BSUyBHYXRld2F5Cg1EZXZlbG9wZ
WQgYnkgU2F0ZWxpdGVjaCBTLkEgZm9yIEVTRyBEaWxlYwoNRW50ZXIgcGFzc3dvcmQ6
</example>
<param pos="0" name="hw.vendor" value = "Satelitech"/>
<param pos="0" name="hw.family" value = "GW25"/>
<param pos="1" name="hw.version"/>
</fingerprint>
<fingerprint pattern="^RDK \(A Yocto Project based Distro\) ([^ ]+) Docsis-Gateway">
<!-- RDK (A Yocto Project based Distro) 2.0 Docsis-Gateway

Docsis-Gateway login: -->
<description>DOCSIS Cable Modem Running RDK</description>
<example _encoding="base64" hw.device="DOCSIS Cable Modem" os.vendor="Yocto" os.product="RDK" os.version="2.0">
UkRLIChBIFlvY3RvIFByb2plY3QgYmFzZWQgRGlzdHJvKSAyLjAgRG9jc2lzLUdhdGV3YXkNCg0NCg1Eb
2NzaXMtR2F0ZXdheSBsb2dpbjo=
</example>
<param pos="0" name="hw.device" value = "DOCSIS Cable Modem"/>
<param pos="0" name="os.vendor" value = "Yocto"/>
<param pos="0" name="os.product" value = "RDK"/>
<param pos="1" name="os.version"/>
</fingerprint>
<fingerprint pattern="^RICOH Maintenance Shell">
<description>a Ricoh device</description>
<!-- RICOH Maintenance Shell.
User access verification.
login:-->
<example _encoding="base64">
UklDT0ggTWFpbnRlbmFuY2UgU2hlbGwuICAgCg1Vc2VyIGFjY2VzcyB2ZXJpZmljYXRpb24uCg1sb2dpbjo=
</example>
<param pos="0" name="os.vendor" value="Ricoh"/>
<param pos="0" name="os.device" value="Printer"/>
</fingerprint>
</fingerprints>