Script dicom-info
Script types:
portrule
Categories:
default, discovery, safe
Download: https://svn.nmap.org/nmap/scripts/dicom-info.nse
Script Summary
DICOM service fingerprinter and capability enumerator.
Connects to a DICOM SCP (Service Class Provider) and extracts: * Implementation Class UID and Version Name (software identification) * Supported SOP Classes (storage, query/retrieve, workflow services) * Accepted Transfer Syntaxes per SOP Class * Maximum PDU length * Protocol version * AE Title echo
The Implementation Class UID and Version Name are set by the DICOM software at build time and uniquely identify the vendor and version -- the DICOM equivalent of an HTTP Server header. A fingerprint database maps known UIDs to software names: DCMTK, Orthanc, Horos, dcm4chee, etc.
SOP Class probing reveals what services the target exposes: image storage (CT, MR, US, ...), query/retrieve (C-FIND, C-MOVE, C-GET), modality worklist, MPPS, and storage commitment. Each accepted SOP class is an entry point for further testing with dicom-cfind-ls or dicom-store-fuzzer.
Transfer syntax enumeration reveals encoding capabilities: Implicit/Explicit VR, compressed formats (JPEG, JPEG-LS, JPEG 2000, RLE), and the deprecated Explicit VR Big Endian. Compressed transfer syntaxes exercise additional codec code paths in the target.
This script is non-intrusive -- it only performs A-ASSOCIATE negotiations and does not send any DIMSE commands or patient data.
Requires the dicom.lua library (place in nselib/ or same directory).
Script Arguments
- dicom-info.probe
Probe depth: "basic" (fingerprint only), "standard" (+ common SOP classes), "full" (+ all storage + workflow SOP classes) (default: "standard")
- dicom-info.calling_ae
Calling AE Title (default: "NMAP-INFO")
- dicom-info.max_pdu
Max PDU Length to propose (default: 16384)
- dicom.tls
Force transport for the whole DICOM suite: "true" (DICOM over TLS), "false" (plaintext), or unset to auto-detect (dicom-info only)
- dicom-info.called_ae
Called AE Title (default: "ANY-SCP")
- dicom-info.timeout
Association timeout in seconds (default: 10)
- dicom.called_aet, dicom.calling_aet
See the documentation for the dicom library.
Example Usage
nmap -p 104,11112,4242 --script dicom-info <target>
nmap -p 4242 --script dicom-info \ --script-args 'dicom-info.called_ae=ORTHANC,dicom-info.calling_ae=FINDSCU' <target>
nmap -p 11112 --script dicom-info \ --script-args 'dicom-info.probe=full' <target>
Script Output
PORT STATE SERVICE 4242/tcp open dicom | dicom-info: | Implementation: Orthanc 1.12.4 | Class UID: 1.2.826.0.1.3680043.2.1545.1.2.1.7 | Version: Orthanc | Max PDU: 16384 | Protocol Version: 1 | Accepted SOP Classes (15 of 42 probed): | C-ECHO Verification 1.2.840.10008.1.1 | CT Image Storage 1.2.840.10008.5.1.4.1.1.2 | MR Image Storage 1.2.840.10008.5.1.4.1.1.4 | Secondary Capture Image Storage 1.2.840.10008.5.1.4.1.1.7 | Study Root Q/R - FIND 1.2.840.10008.5.1.4.1.2.2.1 | Study Root Q/R - MOVE 1.2.840.10008.5.1.4.1.2.2.2 | Study Root Q/R - GET 1.2.840.10008.5.1.4.1.2.2.3 | ... | Accepted Transfer Syntaxes: | Implicit VR Little Endian 1.2.840.10008.1.2 | Explicit VR Little Endian 1.2.840.10008.1.2.1 | Security: No TLS (plaintext DICOM association) |_ WARNING: DICOM service accessible without authentication
Requires
Author:
License: Same as Nmap -- See https://nmap.org/book/man-legal.html
action
- action (host, port)
-
MAIN ACTION
Parameters
- host
- port
