File: ajp-headers.nse

package info (click to toggle)
nmap 6.47-3%2Bdeb8u2
  • links: PTS, VCS
  • area: main
  • in suites: jessie
  • size: 44,788 kB
  • ctags: 25,108
  • sloc: ansic: 89,741; cpp: 62,412; sh: 19,492; python: 17,323; xml: 11,413; perl: 2,529; makefile: 2,503; yacc: 608; lex: 469; asm: 372; java: 45
file content (48 lines) | stat: -rw-r--r-- 1,378 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
local ajp = require "ajp"
local shortport = require "shortport"
local stdnse = require "stdnse"

description = [[
Performs a HEAD or GET request against either the root directory or any
optional directory of an Apache JServ Protocol server and returns the server response headers.
]]

---
-- @usage
-- nmap -p 8009 <ip> --script ajp-headers
--
-- @output
-- PORT     STATE SERVICE
-- 8009/tcp open  ajp13
-- | ajp-headers:
-- |   X-Powered-By: JSP/2.2
-- |   Set-Cookie: JSESSIONID=goTHax+8ktEcZsBldANHBAuf.undefined; Path=/helloworld
-- |   Content-Type: text/html;charset=ISO-8859-1
-- |_  Content-Length: 149
--
-- @args ajp-headers.path The path to request, such as <code>/index.php</code>. Default <code>/</code>.


portrule = shortport.port_or_service(8009, 'ajp13', 'tcp')

author = "Patrik Karlsson"
license = "Same as Nmap--See http://nmap.org/book/man-legal.html"
categories = {"discovery", "safe"}

local arg_path   = stdnse.get_script_args(SCRIPT_NAME .. '.path') or "/"

local function fail(err) return ("\n  ERROR: %s"):format(err or "") end

action = function(host, port)
  local method
  local helper = ajp.Helper:new(host, port)
  helper:connect()

  local status, response = helper:get(arg_path)
  helper:close()

  if ( not(status) ) then
    return fail("Failed to retrieve server headers")
  end
  return stdnse.format_output(true, response.rawheaders)
end