Join us at IRC!
It is never to LATE to become what you never WERE.
Friday, May 25, 2012
Navigation
Members Online
Total Online: 26
Web Spiders: 15
Guests Online: 24
Members Online: 2

Registered Members: 70208
Newest Member: andresuran
Latest Articles
View Thread

HellBound Hackers | Computer General | Hacking in general

Author

nmap -O

thronworld
Member



Posts: 56
Location:
Joined: 26.04.05
Rank:
Mad User
Posted on 14-08-08 04:16
been looking for a guide to prevent os fingerprinting.
using nmap -O *.*.*.* on host reveals it's OS etc, trying to prevent this. any links to any guides would be awesome. Soz for short post.




Author

RE: nmap -O

spyware
Member



Posts: 4190
Location: The Netherlands
Joined: 14.04.07
Rank:
God
Warn Level: 90
Posted on 14-08-08 04:23
http://www.pgci.ca/common/p_fingerprint.htm

Google. Six seconds.




"The chowner of property." - Zeph
“Widespread intellectual and moral docility may be convenient for leaders in the short term,
but it is suicidal for nations in the long term.”
- Carl Sagan
“Since the grid is inescapable, what were the earlier lasers about? Does the corridor have a sense of humor?” - Ebert
http://bitsofspy.net
Author

RE: nmap -O

thronworld
Member



Posts: 56
Location:
Joined: 26.04.05
Rank:
Mad User
Posted on 14-08-08 04:34
i've come across that one, but still not quite understanding what needs to be done. would prefer to have someone familiar with the topic to give us a link, not just a google search(amazingly enough ive done some of these, see, i too have heard of this google thing).




Author

RE: nmap -O

spyware
Member



Posts: 4190
Location: The Netherlands
Joined: 14.04.07
Rank:
God
Warn Level: 90
Posted on 14-08-08 04:46
'And he kept on spamming links'.


http://www.usenix.org/events/sec2000/full_papers/smart/smart_html/




"The chowner of property." - Zeph
“Widespread intellectual and moral docility may be convenient for leaders in the short term,
but it is suicidal for nations in the long term.”
- Carl Sagan
“Since the grid is inescapable, what were the earlier lasers about? Does the corridor have a sense of humor?” - Ebert
http://bitsofspy.net
Author

RE: nmap -O

Uber0n
Member



Posts: 1963
Location: Sweden‭‮
Joined: 13.06.06
Rank:
God
Posted on 14-08-08 10:16
spyware wrote:
'And he kept on spamming links'.

Damn you spyware. I don't even think that's fun for real, but it made me laugh IRL :D



http://uber0n.webs.com/
Nope http://uber0n.webs.com/
Author

RE: nmap -O

nights_shadow
Member



Posts: 856
Location: /var/log/messages
Joined: 30.12.04
Rank:
God
Posted on 15-08-08 22:49
Knowing how OS fingerprinting works is going to help you prevent/spoof it more than finding a link to prevent it.

You have multiple things to take into account. First off you have ports that are only open on certain operating systems. Thus something with 135/139 is going to give a high percentage of target being a Windows operating system.

Then you have the way operating systems respond to packets being sent in certain ways, to closed/open ports, with malformed data, short/long TTL, and etc. Some operating systems will respond in different ways to different types of packets.

Then you also have a service scan and, with certain programs, banner grabbing.. Finding an IIS webserver running on target OS will give higher percentage of target being Windows.

The best way to deal with this is being able to manage packets and ports. Providing a good ruleset within your firewall, IDS triggers, etc., is your best bet to stump and only give generality (like target OS is Windows) about target OS. Spoofing is another good viable option. Closing and opening ports that certain operating systems only have open will throw a high percentage of that OS and throw off the detection.


nights_shadow@hackermail.com http://turboborland.blogspot.com
Guest
Username

Password

Remember Me


Bookmark This Page
Affiliates
Adverts

 

 

Links
By using, viewing or obtaining any information contained on this site, you agree to the disclaimer.

© HellBound Hackers 2008- 2009. Since 3rd December 2004.