|
1 | 1 | using System;
|
2 |
| -using System.Collections.Generic; |
3 | 2 | using System.Linq;
|
4 |
| -using System.Text; |
5 |
| -using FOCA.ModifiedComponents; |
6 | 3 |
|
7 | 4 | namespace FOCA.Analysis.FingerPrinting
|
8 | 5 | {
|
9 | 6 | [Serializable]
|
10 | 7 | public class DNS : FingerPrinting
|
11 | 8 | {
|
12 | 9 |
|
13 |
| - public override event EventHandler FingerPrintingFinished; // salta cuando se finaliza la conexion y el analisis |
14 |
| - public override event EventHandler FingerPrintingError; // salta cuando se produce un error en la conexion |
| 10 | + public override event EventHandler FingerPrintingFinished; // salta cuando se finaliza la conexion y el analisis |
| 11 | + public override event EventHandler FingerPrintingError; // salta cuando se produce un error en la conexion |
15 | 12 |
|
16 |
| - public DNS() |
17 |
| - { |
18 |
| - } |
| 13 | + public DNS() |
| 14 | + { |
| 15 | + } |
19 | 16 |
|
20 |
| - public DNS(string host) : base(host, 53) { } |
| 17 | + public DNS(string host) : base(host, 53) { } |
21 | 18 |
|
22 |
| - public override void GetVersion() |
| 19 | + public override void GetVersion() |
| 20 | + { |
| 21 | + try |
23 | 22 | {
|
24 |
| - try |
25 |
| - { |
26 |
| - System.Net.IPAddress[] ips = System.Net.Dns.GetHostAddresses(Host); |
| 23 | + System.Net.IPAddress[] ips = System.Net.Dns.GetHostAddresses(Host); |
27 | 24 |
|
28 |
| - if (ips.Length == 0) |
29 |
| - return; |
| 25 | + if (ips.Length == 0) |
| 26 | + return; |
30 | 27 |
|
31 |
| - // Hace la query como 'TXT'. Es mejor hacerla como 'ALL', pero no veo la opción en la lista de QTypes. ¿Quizas ANY? |
32 |
| - Heijden.DNS.Resolver r = new Heijden.DNS.Resolver(ips[0], base.Port); |
33 |
| - r.TimeOut = 1000; |
34 |
| - Heijden.DNS.Response response = r.Query("version.bind", Heijden.DNS.QType.TXT, Heijden.DNS.QClass.CH); |
35 |
| - if (response.RecordsTXT.Length > 0) |
36 |
| - { |
37 |
| - Version = response.RecordsTXT[0].TXT; |
38 |
| - this.os = AnalyzeBanner(Version); |
39 |
| - } |
40 |
| - if (this.FingerPrintingFinished != null) |
41 |
| - FingerPrintingFinished(this, null); |
42 |
| - } |
43 |
| - catch |
| 28 | + Heijden.DNS.Resolver r = new Heijden.DNS.Resolver(ips[0], base.Port); |
| 29 | + r.TimeOut = 10; |
| 30 | + Heijden.DNS.Response response = r.Query("version.bind", Heijden.DNS.QType.TXT, Heijden.DNS.QClass.CH); |
| 31 | + if (response.RecordsTXT.Length > 0) |
44 | 32 | {
|
45 |
| - if (FingerPrintingError != null) |
46 |
| - FingerPrintingError(this, null); |
| 33 | + OperatingSystem.OS os = OperatingSystem.OS.Unknown; |
| 34 | + Version = response.RecordsTXT.SelectMany(p => p.TXT.Where(q => !String.IsNullOrEmpty(q))) |
| 35 | + .FirstOrDefault(p => |
| 36 | + { |
| 37 | + os = AnalyzeBanner(p); |
| 38 | + return os != OperatingSystem.OS.Unknown; |
| 39 | + } |
| 40 | + ); |
| 41 | + |
| 42 | + this.os = os; |
47 | 43 | }
|
| 44 | + if (this.FingerPrintingFinished != null) |
| 45 | + FingerPrintingFinished(this, null); |
| 46 | + } |
| 47 | + catch |
| 48 | + { |
| 49 | + if (FingerPrintingError != null) |
| 50 | + FingerPrintingError(this, null); |
| 51 | + } |
48 | 52 | }
|
49 | 53 |
|
50 |
| - private OperatingSystem.OS AnalyzeBanner(string banner) |
51 |
| - { |
52 |
| - if (this.os != OperatingSystem.OS.Unknown) |
53 |
| - return this.os; // Si ya tiene OS no se re-analiza... |
| 54 | + private OperatingSystem.OS AnalyzeBanner(string banner) |
| 55 | + { |
| 56 | + if (this.os != OperatingSystem.OS.Unknown) |
| 57 | + return this.os; // Si ya tiene OS no se re-analiza... |
54 | 58 |
|
55 |
| - // Familia Windows |
56 |
| - if (banner.ToLower().Contains("win32")) |
57 |
| - return OperatingSystem.OS.Windows; |
58 |
| - else if (banner.ToLower().Contains("macos")) |
59 |
| - return OperatingSystem.OS.MacOS; |
60 |
| - else if (banner.ToLower().Contains("mac os")) |
61 |
| - return OperatingSystem.OS.MacOS; |
62 |
| - // Familia BSD |
63 |
| - else if (banner.ToLower().Contains("freebsd")) |
64 |
| - return OperatingSystem.OS.FreeBSD; |
65 |
| - else if (banner.ToLower().Contains("openbsd")) |
66 |
| - return OperatingSystem.OS.OpenBSD; |
67 |
| - // Familia *nix |
68 |
| - else if (banner.ToLower().Contains("centos")) |
69 |
| - return OperatingSystem.OS.CentOS; |
70 |
| - else if (banner.ToLower().Contains("solaris")) |
71 |
| - return OperatingSystem.OS.Solaris; |
72 |
| - // Familia Linux |
73 |
| - else if (banner.ToLower().Contains("red hat")) |
74 |
| - return OperatingSystem.OS.LinuxRedHat; |
75 |
| - else if (banner.ToLower().Contains("redhat")) |
76 |
| - return OperatingSystem.OS.LinuxRedHat; |
77 |
| - else if (banner.ToLower().Contains("ubuntu")) |
78 |
| - return OperatingSystem.OS.LinuxUbuntu; |
79 |
| - else if (banner.ToLower().Contains("debian")) |
80 |
| - return OperatingSystem.OS.LinuxDebian; |
81 |
| - else if (banner.ToLower().Contains("fedora")) |
82 |
| - return OperatingSystem.OS.LinuxFedora; |
83 |
| - else if (banner.ToLower().Contains("mandrake")) |
84 |
| - return OperatingSystem.OS.LinuxFedora; |
85 |
| - else if (banner.ToLower().Contains("mandriva")) |
86 |
| - return OperatingSystem.OS.LinuxFedora; |
87 |
| - else if (banner.ToLower().Contains("suse")) |
88 |
| - return OperatingSystem.OS.LinuxSuse; |
89 |
| - else if (banner.ToLower().Contains("linux")) |
90 |
| - return OperatingSystem.OS.Linux; |
91 |
| - else if (banner.ToLower().Contains("unix")) |
92 |
| - return OperatingSystem.OS.Linux; |
93 |
| - else |
94 |
| - return OperatingSystem.OS.Unknown; |
95 |
| - } |
| 59 | + // Familia Windows |
| 60 | + if (banner.ToLower().Contains("win32")) |
| 61 | + return OperatingSystem.OS.Windows; |
| 62 | + else if (banner.ToLower().Contains("macos")) |
| 63 | + return OperatingSystem.OS.MacOS; |
| 64 | + else if (banner.ToLower().Contains("mac os")) |
| 65 | + return OperatingSystem.OS.MacOS; |
| 66 | + // Familia BSD |
| 67 | + else if (banner.ToLower().Contains("freebsd")) |
| 68 | + return OperatingSystem.OS.FreeBSD; |
| 69 | + else if (banner.ToLower().Contains("openbsd")) |
| 70 | + return OperatingSystem.OS.OpenBSD; |
| 71 | + // Familia *nix |
| 72 | + else if (banner.ToLower().Contains("centos")) |
| 73 | + return OperatingSystem.OS.CentOS; |
| 74 | + else if (banner.ToLower().Contains("solaris")) |
| 75 | + return OperatingSystem.OS.Solaris; |
| 76 | + // Familia Linux |
| 77 | + else if (banner.ToLower().Contains("red hat")) |
| 78 | + return OperatingSystem.OS.LinuxRedHat; |
| 79 | + else if (banner.ToLower().Contains("redhat")) |
| 80 | + return OperatingSystem.OS.LinuxRedHat; |
| 81 | + else if (banner.ToLower().Contains("ubuntu")) |
| 82 | + return OperatingSystem.OS.LinuxUbuntu; |
| 83 | + else if (banner.ToLower().Contains("debian")) |
| 84 | + return OperatingSystem.OS.LinuxDebian; |
| 85 | + else if (banner.ToLower().Contains("fedora")) |
| 86 | + return OperatingSystem.OS.LinuxFedora; |
| 87 | + else if (banner.ToLower().Contains("mandrake")) |
| 88 | + return OperatingSystem.OS.LinuxFedora; |
| 89 | + else if (banner.ToLower().Contains("mandriva")) |
| 90 | + return OperatingSystem.OS.LinuxFedora; |
| 91 | + else if (banner.ToLower().Contains("suse")) |
| 92 | + return OperatingSystem.OS.LinuxSuse; |
| 93 | + else if (banner.ToLower().Contains("linux")) |
| 94 | + return OperatingSystem.OS.Linux; |
| 95 | + else if (banner.ToLower().Contains("unix")) |
| 96 | + return OperatingSystem.OS.Linux; |
| 97 | + else |
| 98 | + return OperatingSystem.OS.Unknown; |
| 99 | + } |
96 | 100 |
|
97 | 101 | }
|
98 | 102 | }
|
0 commit comments