Skip to content

Commit

Permalink
x.509 related updates (#357)
Browse files Browse the repository at this point in the history
* x.509 related updates

* add VMware/Win Media Player

* Add CPE for Amazon S3

* Update Netscaler

* akamai and google improvements
  • Loading branch information
tsellers-r7 authored May 7, 2021
1 parent d3464ec commit fbf46dd
Show file tree
Hide file tree
Showing 14 changed files with 176 additions and 15 deletions.
13 changes: 13 additions & 0 deletions cpe-remap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@ mappings:
vendor: alpinelinux
products:
linux: alpine_linux
amazon:
products:
s3: web_services_simple_storage_service
apache:
products:
httpd: http_server
Expand Down Expand Up @@ -71,6 +74,9 @@ mappings:
big-ip_ltm: big-ip_local_traffic_manager
fedora_project:
vendor: fedoraproject
google:
products:
google_web_services: web_server
hp:
products:
ilo: integrated_lights_out
Expand All @@ -95,6 +101,9 @@ mappings:
junos_os: junos
kibana:
vendor: elasticsearch
kubernetes:
products:
nginx_ingress_controller: ingress-nginx
kodi:
products:
media_server: kodi
Expand Down Expand Up @@ -201,6 +210,10 @@ mappings:
desktop: tightvnc
tor_project:
vendor: torproject
traefik_labs:
vendor: containous
products:
traefik_proxy: traefik
twistedmatrix:
products:
twisted_web: twistedweb
Expand Down
2 changes: 2 additions & 0 deletions identifiers/hw_family.txt
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,9 @@ My Book
NE
NPort
NetVanta
Netscaler
Network Audio
Network Security Appliance
Network Video Door Station
Optra
Orbi
Expand Down
2 changes: 2 additions & 0 deletions identifiers/hw_product.txt
Original file line number Diff line number Diff line change
Expand Up @@ -210,9 +210,11 @@ NPort
NetScreen
NetVR
Netbox
Netscaler Gateway
Network Camera
Network Gateway
Network Node
Network Security Appliance
Nexus 1000V
Nexus Player
OfficeConnect Switch
Expand Down
1 change: 1 addition & 0 deletions identifiers/os_product.txt
Original file line number Diff line number Diff line change
Expand Up @@ -157,6 +157,7 @@ NetScaler Gateway
NetScaler SDX Gateway
NetVanta
NetWare
Netscaler Gateway Firmware
Network Gateway
Network Scanner
Network Storage Router
Expand Down
4 changes: 4 additions & 0 deletions identifiers/service_family.txt
Original file line number Diff line number Diff line change
Expand Up @@ -95,6 +95,7 @@ JetDirect
Jetty
Joom!Fish
Knot
Kubernetes
ListManager
Lotus Domino
Lotus Expeditor
Expand Down Expand Up @@ -128,6 +129,7 @@ NetWare Enterprise Web Server
NetWare HTTP Server
NetWare HTTP Stack
NetWeaver
Netscaler
Network Printer Manager
Niagara
OpenAdStream
Expand Down Expand Up @@ -188,6 +190,7 @@ TippingPoint
Tivoli
Tomcat
Tornado
Traefik
Twisted
Twisted Web
UPnP
Expand All @@ -208,6 +211,7 @@ VoiP Gateway
WS_FTP
WeOnlyDo
Web PN Server
Web Services
WebGUI
WebLogic
WebServer
Expand Down
6 changes: 6 additions & 0 deletions identifiers/service_product.txt
Original file line number Diff line number Diff line change
Expand Up @@ -228,6 +228,7 @@ Kestrel web server
Kibana
Kiwi Syslog
Knot DNS
Kubernetes
LDAP Agent for eDirectory
LDAP Server
LLBServer
Expand Down Expand Up @@ -280,6 +281,7 @@ Multicraft
Munin
MySQL
MySQL Proxy
NGINX Ingress Controller
NNTP
NQ
NTMail
Expand Down Expand Up @@ -308,6 +310,7 @@ NetWeaver Application Server
NetWeaver Application Server Java
NetWeaver Internet Communication Manager
NetWeaver Web AS
Netscaler
Network Monitor
Network Printer Manager
Nexpose
Expand Down Expand Up @@ -464,6 +467,7 @@ Tivoli Storage Manager
Tomcat
Tor
Tornado
Traefik Proxy
Twisted FTPD
Twisted Web
Twonky Media Server
Expand All @@ -481,6 +485,7 @@ VShell
Varnish
Vault
VcXsrv
View
Vignette
Virtual Directory Server
Virtual Environment
Expand Down Expand Up @@ -513,6 +518,7 @@ WinRoute
WinSSHD
WinWebMail
Windows CE Web Server
Windows Media Player
Windows Media Server
Wing FTP Server
Work Server
Expand Down
1 change: 1 addition & 0 deletions identifiers/vendor.txt
Original file line number Diff line number Diff line change
Expand Up @@ -695,6 +695,7 @@ Tokutek
Tor Project
TornadoWeb
Toshiba
Traefik Labs
Treck
Tridium
Troy
Expand Down
2 changes: 2 additions & 0 deletions xml/favicons.xml
Original file line number Diff line number Diff line change
Expand Up @@ -1065,7 +1065,9 @@
<param pos="0" name="os.vendor" value="SonicWall"/>
<param pos="0" name="os.device" value="Firewall"/>
<param pos="0" name="os.family" value="SonicOS"/>
<param pos="0" name="os.product" value="SonicOS"/>
<param pos="0" name="os.certainty" value="0.5"/>
<param pos="0" name="os.cpe23" value="cpe:/o:sonicwall:sonicos:-"/>
</fingerprint>

<fingerprint pattern="^e4fd990b4b8a5d61bd5ddb98cdfc7190$">
Expand Down
2 changes: 2 additions & 0 deletions xml/html_title.xml
Original file line number Diff line number Diff line change
Expand Up @@ -338,6 +338,8 @@
<param pos="0" name="os.vendor" value="SonicWall"/>
<param pos="0" name="os.device" value="Firewall"/>
<param pos="0" name="os.family" value="SonicOS"/>
<param pos="0" name="os.product" value="SonicOS"/>
<param pos="0" name="os.cpe23" value="cpe:/o:sonicwall:sonicos:-"/>
</fingerprint>

<fingerprint pattern="^(.*).nbsp;-.nbsp;Synology.nbsp;DiskStation$">
Expand Down
15 changes: 11 additions & 4 deletions xml/http_servers.xml
Original file line number Diff line number Diff line change
Expand Up @@ -1870,7 +1870,7 @@
<param pos="0" name="service.family" value="SSL-VPN"/>
<param pos="0" name="os.vendor" value="SonicWall"/>
<param pos="0" name="os.device" value="VPN"/>
<param pos="0" name="os.family" value="SSL-VPN"/>
<param pos="0" name="os.family" value="SonicOS"/>
<param pos="0" name="os.product" value="SonicOS"/>
<param pos="0" name="os.cpe23" value="cpe:/o:sonicwall:sonicos:-"/>
<param pos="0" name="hw.vendor" value="SonicWall"/>
Expand Down Expand Up @@ -2958,30 +2958,35 @@

<!-- Service provider equipment (CDNs, etc) -->

<fingerprint pattern="^AkamaiGHost$">
<fingerprint pattern="^(?:Akamai)?GHost$">
<description>Akamai Global Host</description>
<example>AkamaiGHost</example>
<example>GHost</example>
<param pos="0" name="service.vendor" value="Akamai"/>
<param pos="0" name="service.product" value="GHost"/>
<param pos="0" name="os.vendor" value="Akamai"/>
<param pos="0" name="os.family" value="Linux"/>
<param pos="0" name="os.device" value="Web Proxy"/>
</fingerprint>

<!-- Banner used for many Google services such as search, Gmail, etc. -->

<fingerprint pattern="^gws$">
<description>Google Web Services</description>
<example>gws</example>
<param pos="0" name="service.vendor" value="Google"/>
<param pos="0" name="service.product" value="Google Web Services"/>
<param pos="0" name="service.family" value="Google Web Server"/>
<param pos="0" name="service.product" value="Google Web Services"/>
<param pos="0" name="service.cpe23" value="cpe:/a:google:web_server:-"/>
</fingerprint>

<fingerprint pattern="^GFE/((?:\d+\.)*\d+)$">
<description>Google Front End for apps running on Google services.</description>
<example>GFE/1.3</example>
<example>GFE/1</example>
<param pos="0" name="service.vendor" value="Google"/>
<param pos="0" name="service.product" value="Google Front End"/>
<param pos="0" name="service.family" value="Google Web Server"/>
<param pos="0" name="service.product" value="Google Front End"/>
<param pos="1" name="service.version"/>
</fingerprint>

Expand All @@ -3004,7 +3009,9 @@
<description>Amazon S3 (Simple Cloud Storage Service)</description>
<example>AmazonS3</example>
<param pos="0" name="service.vendor" value="Amazon"/>
<param pos="0" name="service.family" value="Web Services"/>
<param pos="0" name="service.product" value="S3"/>
<param pos="0" name="service.cpe23" value="cpe:/a:amazon:web_services_simple_storage_service:-"/>
</fingerprint>

<fingerprint pattern="^Amazon SimpleDB$">
Expand Down
3 changes: 3 additions & 0 deletions xml/http_wwwauth.xml
Original file line number Diff line number Diff line change
Expand Up @@ -203,6 +203,9 @@
<description>Kubernetes master nodes</description>
<example>Basic realm="kubernetes-master"</example>
<param pos="0" name="service.vendor" value="Kubernetes"/>
<param pos="0" name="service.family" value="Kubernetes"/>
<param pos="0" name="service.product" value="Kubernetes"/>
<param pos="0" name="service.cpe23" value="cpe:/a:kubernetes:kubernetes:-"/>
</fingerprint>

<fingerprint pattern="(?i)^(?:Basic|Digest) realm=&quot;RUIJIE(?:-CPE)?&quot;.*$">
Expand Down
3 changes: 3 additions & 0 deletions xml/snmp_sysdescr.xml
Original file line number Diff line number Diff line change
Expand Up @@ -6167,6 +6167,7 @@ Copyright (c) 1995-2005 by Cisco Systems
<param pos="0" name="os.vendor" value="SonicWall"/>
<param pos="0" name="os.device" value="Firewall"/>
<param pos="0" name="os.product" value="SonicOS"/>
<param pos="0" name="hw.vendor" value="SonicWall"/>
<param pos="1" name="hw.product"/>
<param pos="2" name="hw.model"/>
<param pos="3" name="os.version"/>
Expand All @@ -6180,6 +6181,7 @@ Copyright (c) 1995-2005 by Cisco Systems
<param pos="0" name="os.vendor" value="SonicWall"/>
<param pos="0" name="os.device" value="Firewall"/>
<param pos="0" name="os.product" value="SonicOS"/>
<param pos="0" name="hw.vendor" value="SonicWall"/>
<param pos="1" name="hw.product"/>
<param pos="2" name="os.version"/>
<param pos="0" name="os.cpe23" value="cpe:/o:sonicwall:sonicos:{os.version}"/>
Expand All @@ -6199,6 +6201,7 @@ Copyright (c) 1995-2005 by Cisco Systems
<param pos="0" name="os.device" value="Firewall"/>
<param pos="0" name="os.product" value="SonicOS"/>
<param pos="0" name="os.cpe23" value="cpe:/o:sonicwall:sonicos:-"/>
<param pos="0" name="hw.vendor" value="SonicWall"/>
<param pos="1" name="hw.family"/>
<param pos="2" name="hw.product"/>
</fingerprint>
Expand Down
20 changes: 20 additions & 0 deletions xml/x509_issuers.xml
Original file line number Diff line number Diff line change
Expand Up @@ -174,4 +174,24 @@
<param pos="0" name="hw.device" value="NAS"/>
</fingerprint>

<fingerprint pattern="^CN=default(?: [A-Z]+)?,OU=NS Internal,O=Citrix ANG,L=San Jose,ST=California,C=US$">
<description>Citrix Netscaler (later renamed to Citrix ADC)</description>
<example>CN=default,OU=NS Internal,O=Citrix ANG,L=San Jose,ST=California,C=US</example>
<example>CN=default UYENMB,OU=NS Internal,O=Citrix ANG,L=San Jose,ST=California,C=US</example>
<param pos="0" name="service.vendor" value="Citrix"/>
<param pos="0" name="service.family" value="Netscaler"/>
<param pos="0" name="service.product" value="Netscaler"/>
<param pos="0" name="service.device" value="Network Management Device"/>
<param pos="0" name="service.cpe23" value="cpe:/a:citrix:netscaler:-"/>
<param pos="0" name="os.vendor" value="Citrix"/>
<param pos="0" name="os.family" value="Netscaler"/>
<param pos="0" name="os.product" value="Netscaler Gateway Firmware"/>
<param pos="0" name="os.device" value="Network Management Device"/>
<param pos="0" name="os.cpe23" value="cpe:/o:citrix:netscaler_gateway_firmware:-"/>
<param pos="0" name="hw.vendor" value="Citrix"/>
<param pos="0" name="hw.family" value="Netscaler"/>
<param pos="0" name="hw.product" value="Netscaler Gateway"/>
<param pos="0" name="hw.device" value="Network Management Device"/>
</fingerprint>

</fingerprints>
Loading

0 comments on commit fbf46dd

Please sign in to comment.