Skip to content

fix(build): decode literal text in UDP payload probes - #938

Open
kydallaboutlearning wants to merge 4 commits into
bee-san:masterfrom
kydallaboutlearning:fix/udp-payload-decode-933
Open

kydallaboutlearning wants to merge 4 commits into
bee-san:masterfrom
kydallaboutlearning:fix/udp-payload-decode-933

Conversation

@kydallaboutlearning

Copy link
Copy Markdown

SNMP agents never answered RustScan's port-161 probe because the nmap-payloads decoder in build.rs kept only ASCII hex digits: the literal public community string collapsed to the single byte 0xbc, producing a 28-byte probe instead of 33 (and NetBIOS/LDAP/SSDP probes with literal text were mangled the same way).

This rewrites the decoder to Nmap's C-style escape format: \xNN and single-char escapes decode, every other character contributes its literal bytes, and multi-line quoted segments concatenate with no separators (honoring \" escapes). Also passes the block text to the decoder from its opening quote (previously the first quote was pre-stripped, breaking segment pairing), and strips CR line endings so CRLF checkouts parse identically to LF ones.

Verified end-to-end through the generated payload map:

  • SNMP public-walk probe for port 161 is now the exact 33-byte BER packet
  • SSDP probe for port 1900 decodes escapes + literal text across both segments

Gate (matches just test): cargo test all green, cargo clippy -- --deny warnings + cargo clippy --tests -- --deny warnings clean, cargo fmt --check clean, cargo doc clean.

Closes #933

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

UDP port scanner is missing SNMP ports

1 participant