<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; thc-amap</title>
	<atom:link href="http://www.darknet.org.uk/tag/thc-amap/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Mon, 22 Mar 2010 06:54:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>thc-Amap &#8211; Application Protocol Detection &amp; Fingerprinting</title>
		<link>http://www.darknet.org.uk/2008/05/thc-amap-application-protocol-detection-fingerprinting/</link>
		<comments>http://www.darknet.org.uk/2008/05/thc-amap-application-protocol-detection-fingerprinting/#comments</comments>
		<pubDate>Fri, 23 May 2008 08:04:02 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[amap]]></category>
		<category><![CDATA[application detection]]></category>
		<category><![CDATA[application fingerprinting]]></category>
		<category><![CDATA[banner grabber]]></category>
		<category><![CDATA[banner grabbing]]></category>
		<category><![CDATA[fingerprinting]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[protocol detection]]></category>
		<category><![CDATA[thc]]></category>
		<category><![CDATA[thc-amap]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=854</guid>
		<description><![CDATA[thc-Amap (Application MAPper) is another excellent tool more towards banner grabbing and protocol detection than OS-fingerprinting. But from the services running on a machine you can get a good idea of the OS and the purpose of the server.
Amap is a next-generation scanning tool for pentesters. It attempts to identify applications even if they are [...]]]></description>
			<content:encoded><![CDATA[<p>thc-Amap (<strong>A</strong>pplication <strong>MAP</strong>per) is another excellent tool more towards banner grabbing and protocol detection than OS-fingerprinting. But from the services running on a machine you can get a good idea of the OS and the purpose of the server.</p>
<p>Amap is a next-generation scanning tool for pentesters. It attempts to identify applications even if they are running on a different port than normal. It also identifies non-ascii based applications. This is achieved by sending trigger packets, and looking up the responses in a list of response strings.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text";
google_ad_channel ="9647861209";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Without filled databases containing triggers and responses, the tool is worthless, the authors would like you to help fill the database. How to do this? Well, whenever a client application connects to a server, some kind of handshake is exchanged (at least, usually. Syslogd for instance won&#8217;t say nothing, and snmpd without the right community string neither). Anyway, Amap takes the first packet sent back and compares it to a list of signature responses. Really simple, actually. And in reality, it turns out really to be that simple, at least, for most protocols.</p>
<p>Send the initial packets (sent and received) in tcpdump format for all wacko, proprietary and obscure applications. Send them to: amap-dev@thc.org. Please include application name and version.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text";
google_ad_channel ="9647861209";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Currently there are two tools for this purpose: Amap, and <a href="http://www.darknet.org.uk/tag/nmap">nmap</a> &#8211; Both have their strength and weaknesses, as they deploy different techniques. We recommend to use both tools for reliabe identification.</p>
<p>The newer versions of nmap also have a banner grabbing feature.</p>
<p>You can download Amap here:</p>
<p>The source code of Amap: <a href="http://freeworld.thc.org/releases/amap-5.2.tar.gz">amap-5.2.tar.gz</a></p>
<p>The Win32/Cywin binary release: <a href="http://freeworld.thc.org/thc-amap/amap-5.2-win.zip">amap-5.2-win.zip</a></p>
<p>Or read more <a href="http://freeworld.thc.org/thc-amap/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=thc-Amap+%E2%80%93+Application+Protocol+Detection+%26+Fingerprinting+http://bit.ly/AxdC8+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/05/thc-amap-application-protocol-detection-fingerprinting/&amp;title=thc-Amap+%E2%80%93+Application+Protocol+Detection+%26+Fingerprinting" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/05/thc-amap-application-protocol-detection-fingerprinting/&amp;title=thc-Amap+%E2%80%93+Application+Protocol+Detection+%26+Fingerprinting" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/05/thc-amap-application-protocol-detection-fingerprinting/&amp;t=thc-Amap+%E2%80%93+Application+Protocol+Detection+%26+Fingerprinting" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/05/thc-amap-application-protocol-detection-fingerprinting/&amp;title=thc-Amap+%E2%80%93+Application+Protocol+Detection+%26+Fingerprinting" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/05/thc-amap-application-protocol-detection-fingerprinting/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>
