4 ms·
p0f: TCP Packet Fingerprinting
- anfractuosity 4y agoI assume p0f doesn't do TCP timestamp clock skew fingerprinting out of curiosity too? Curious if there are any OSS tools for that.
- nibbleshifter 4y agonmap reports clock skew.
- anfractuosity 4y agoDo you mean via this script - https://svn.nmap.org/nmap/scripts/clock-skew.nse https://svn.nmap.org/nmap/scripts/clock-skew.nse , if so it looks like that's extracting time values from protocols above TCP such as HTTP etc? Please correct me, if I misunderstood what you meant. This was the type of technique I was thinking of - https://murdoch.is/talks/eurobsdcon07hotornot.pdf https://murdoch.is/talks/eurobsdcon07hotornot.pdf
- gsich 4y agoOn Linux TCP timestamps are random.
- nykolasz 4y agoGreat tool, but not maintained anymore, unfortunatelly.
- dilawar 4y agoToo bad it doesn't work on Windows out of thr box without cygwin/msys trickery. The lippcap doesnt have an open source alternative on windows. winpcap is almost dead and npcap is not free to use.
- therearwindow 4y agoYou can try this one: https://github.com/Nisitay/scapy-p0f https://github.com/Nisitay/scapy-p0f
- account-5 4y agoHow would this fair now against encryption? Being that's it's from 2014.
- nickphx 4y agoIt looks at tcp header values, not packet data.
- nibbleshifter 4y agoIf you update the fingerprints, it will still work fine. Application layer or session layer stuff like encryption is irrelevant, the fingerprints are largely based on differences at the transport layer and below. You can also do some nice fingerprinting at the TLS layer based on stuff like what ciphers are offered, the order of them, etc.
- lossolo 4y agoI remember when I was in college and we were doing work about passive OS fingerprinting and we used p0f, Vista was a new OS back then and we fingerprinted it successfully before p0f got its own signatures, it was so cool. It was around 15 years ago, my god time flies so fast.
- jeffbee 4y agoIt’s still great for that exact purpose. Knowing that your SMTP peer is running Windows XP is the strongest spam fighting signal that has ever existed.
- binkHN 4y agoI use this. It works, but it's dated and doesn't work consistently enough that it should be relied upon in any capacity.
- dilawar 4y agoinconsistency is due to missing fingerprints?
- viraptor 4y agoNot OP but: Linux with TTL modified to look like Windows+1 to avoid tethering prevention gets actively proxied by an enterprise security/nat appliance. What fingerprint do you expect to see and what would you want to learn from it? That kind of thing.
- iszomer 4y agoiirc, one of lcamtuf's works. His book Silence on the Wire is still one of my favorite reads of all time.
- bediger4000 4y agoThis is p0f 3.09b. Does anybody know of updated fingerprint files? The fingerprint file dates to 2014, well before Windows 10, and about Linux kernel 3.12. There's lots of things it just doesn't identify.
- tedunangst 4y agoThe openbsd pf.os file is occasionally updated as practically required. http://cvsweb.openbsd.org/src/etc/pf.os http://cvsweb.openbsd.org/src/etc/pf.os
- bArray 4y agoIs there a UDP equivalent to passively monitor and fingerprint? I'm guessing not, but would be interested to hear if there is.
- gerdesj 4y ago"Copyright (C) 2000-2014 by Michal Zalewski" 2014
- princes 4y agoPliss packet data
- princes 4y agoPlis packet data