Script dicom-info

Script types: portrule
Categories: default, discovery, safe
Download: https://svn.nmap.org/nmap/scripts/dicom-info.nse

Script Summary

DICOM service fingerprinter and capability enumerator.

Connects to a DICOM SCP (Service Class Provider) and extracts: * Implementation Class UID and Version Name (software identification) * Supported SOP Classes (storage, query/retrieve, workflow services) * Accepted Transfer Syntaxes per SOP Class * Maximum PDU length * Protocol version * AE Title echo

The Implementation Class UID and Version Name are set by the DICOM software at build time and uniquely identify the vendor and version -- the DICOM equivalent of an HTTP Server header. A fingerprint database maps known UIDs to software names: DCMTK, Orthanc, Horos, dcm4chee, etc.

SOP Class probing reveals what services the target exposes: image storage (CT, MR, US, ...), query/retrieve (C-FIND, C-MOVE, C-GET), modality worklist, MPPS, and storage commitment. Each accepted SOP class is an entry point for further testing with dicom-cfind-ls or dicom-store-fuzzer.

Transfer syntax enumeration reveals encoding capabilities: Implicit/Explicit VR, compressed formats (JPEG, JPEG-LS, JPEG 2000, RLE), and the deprecated Explicit VR Big Endian. Compressed transfer syntaxes exercise additional codec code paths in the target.

This script is non-intrusive -- it only performs A-ASSOCIATE negotiations and does not send any DIMSE commands or patient data.

Requires the dicom.lua library (place in nselib/ or same directory).

Script Arguments

dicom-info.probe

Probe depth: "basic" (fingerprint only), "standard" (+ common SOP classes), "full" (+ all storage + workflow SOP classes) (default: "standard")

dicom-info.calling_ae

Calling AE Title (default: "NMAP-INFO")

dicom-info.max_pdu

Max PDU Length to propose (default: 16384)

dicom.tls

Force transport for the whole DICOM suite: "true" (DICOM over TLS), "false" (plaintext), or unset to auto-detect (dicom-info only)

dicom-info.called_ae

Called AE Title (default: "ANY-SCP")

dicom-info.timeout

Association timeout in seconds (default: 10)

dicom.called_aet, dicom.calling_aet

See the documentation for the dicom library.

Example Usage

  • nmap -p 104,11112,4242 --script dicom-info <target>
    
  • nmap -p 4242 --script dicom-info \
      --script-args 'dicom-info.called_ae=ORTHANC,dicom-info.calling_ae=FINDSCU' <target>
    
  • nmap -p 11112 --script dicom-info \
      --script-args 'dicom-info.probe=full' <target>
    

Script Output

PORT     STATE SERVICE
4242/tcp open  dicom
| dicom-info:
|   Implementation: Orthanc 1.12.4
|     Class UID: 1.2.826.0.1.3680043.2.1545.1.2.1.7
|     Version: Orthanc
|   Max PDU: 16384
|   Protocol Version: 1
|   Accepted SOP Classes (15 of 42 probed):
|     C-ECHO Verification                                 1.2.840.10008.1.1
|     CT Image Storage                                    1.2.840.10008.5.1.4.1.1.2
|     MR Image Storage                                    1.2.840.10008.5.1.4.1.1.4
|     Secondary Capture Image Storage                     1.2.840.10008.5.1.4.1.1.7
|     Study Root Q/R - FIND                               1.2.840.10008.5.1.4.1.2.2.1
|     Study Root Q/R - MOVE                               1.2.840.10008.5.1.4.1.2.2.2
|     Study Root Q/R - GET                                1.2.840.10008.5.1.4.1.2.2.3
|     ...
|   Accepted Transfer Syntaxes:
|     Implicit VR Little Endian                           1.2.840.10008.1.2
|     Explicit VR Little Endian                           1.2.840.10008.1.2.1
|   Security: No TLS (plaintext DICOM association)
|_  WARNING: DICOM service accessible without authentication

Requires


Author:

  • Paulino Calderon <paulino@calderonpale.com>

License: Same as Nmap -- See https://nmap.org/book/man-legal.html

action

action (host, port)

MAIN ACTION

Parameters

host
 
port