rapid7 / recog

Pattern recognition for hosts, services, and content
Other
671 stars 199 forks source link

Added SonicOS FP #293

Closed jheysel-r7 closed 4 years ago

jheysel-r7 commented 4 years ago

Description

Added a SNMP fingerprint for SonicOS SonicWALL devices that do not include a hardware model in the snmp.banner. The target that was being tested returnes the following snmp.banner:

SonicWALL SOHO (SonicOS Enhanced 5.9.1.4-4o)

Currently the fingerprinter that almost matches the above expects at least one digit after the hardware product, SOHO, and that digit or set of digits gets asserted as the hw.model.

Because there's no hw.model in the fingerprint seen above, instead of making the hw.model optional (which would mean asserting a null hw.model for the above FP) we've added a second FP that doesn't expect a hw.model.

How Has This Been Tested?

A clear and concise description of your changes were tested. Rake tests run successfully. Deploying to nexpose now

9 scenarios (9 passed)
20 steps (20 passed)
0m1.917s

Checklist: