fix: remove -O from nmap; OS detection requires root - #36
Merged
Merged
Conversation
nmap hard-codes geteuid()==0 for -O (OS fingerprinting) regardless of Linux file capabilities. Running as non-root uid 1000 always triggers: 'TCP/IP fingerprinting (for OS scan) requires root privileges. QUITTING!' causing the entire nmap scan to abort, losing all service/version data. -O was documented as best-effort; os_guess will be empty string. All other scan data (ports, services, version banners) is unaffected. Test added: test_does_not_use_os_detection_flag asserts -O absent. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
ARP scan finds hosts correctly, but nmap immediately quits:
This aborts the entire nmap run — no port or service data is collected.
Root Cause
nmap's OS detection (
-O) contains a hard-codedgeteuid() == 0check. File capabilities (setcap cap_net_raw+ep) do not affectgeteuid()— it always returns non-zero for uid 1000. No capability-based workaround exists.Fix
Remove
-Ofrom the nmap command. Persystem_config.md, OS detection was already documented as "best-effort".os_guesswill be an empty string; all port and service/version data is unaffected.Test
test_does_not_use_os_detection_flag— asserts-Ois absent and-sVis present in the built command.