exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

remote.html

remote.html
Posted Oct 26, 1999
Authored by pho

Pho's alternate remote OS detection techinques page has been updated. Includes information on ICMP techniques, ARP techniques, IP techniques, and UDP techniques.

tags | paper, remote, udp
SHA-256 | 8ad58add858120309dfa20fecd05c30e086888dd27674d03eb1a7771daeb0615

remote.html

Change Mirror Download
<!DOCTYPE HTML PUBLIC "html.dtd">
<HTML>

<HEAD>
<TITLE>[pho] - OS Detection</TITLE>
</HEAD>

<BODY BGCOLOR="BLACK" VLINK="WHITE" TEXT="WHITE" LINK="WHITE" ALINK="WHITE">

<CENTER>
<!-- err, whole page table bit. afterthoughts are ugly. -->
<TABLE BORDER="0"><TR><TD>
<!-- /pagetable -->
<IMG SRC="http://pho.2600.org.au/mermaid.gif" ALT="Mermaid Image"><BR>
<!-- pagetable -->
</TD><TD>
<!-- /pagetable-->
<CENTER>
<H3>OS Detection</H3>
</CENTER>

<CENTER>
<TABLE WIDTH="100%" CELLSPACING="0" BORDER="0" CELLPADDING="0">
<TR>
<TD BGCOLOR="WHITE" COLSPAN="2">&nbsp;</TD>
</TR>
</TABLE>
</CENTER>

<BR>

OS detection has had a pretty sad history. It used to be that you
could just <I>telnet targethost</I> and read the login banner. As network
administrators have wisened, however, stealth methods have evolved to match.
Queso, and later <A HREF="http://www.insecure.org/nmap/">nmap</A> pioneered
TCP header-flag based OS detection, but now there are some viable
alternatives with (at least for the time being) superior stealth...

<P>

<UL>
<LI><A HREF="http://pho.2600.org.au/icmp.html">ICMP techniques</A>
<LI><A HREF="http://pho.2600.org.au/arp.html">ARP techniques</A>
<LI><A HREF="http://pho.2600.org.au/ip.html">IP techniques</A>
<LI><A HREF="http://pho.2600.org.au/udp.html">UDP techniques</A>
</UL>

<BR>

<I>Note: Not all of these methods have been tested, some are no more
than theoretical. They'll all be tested soon enough. Although I have
developed these techniques independantly of others, it is quite likely
that others discovered them first. No public release of papers or
tools on these techniques has been made ,at least that I am aware of.</I>

<P>

I want to create a program to automate the use of these techniques, however
I lack the time at present. If you would like to program something, go
right ahead -- I'll post the source here with credit. Otherwise, we're
talking middle to late 2000 for something usable to appear.

<P><BR>

<B>Other 'Common' Methods of OS Detection</B><BR>
<UL>
<LI>FTP SYST command</LI> - "SYST" will return information about the server.
<LI>HTTP HEAD command</LI> - The "HEAD" command will return HTTP headers
only, which sometimes contain the server architecture/os as well as the http
daemon version. The more regular "GET" command returns the page requested,
also.
</UL>

<BR>

<CENTER>
<TABLE WIDTH="100%" CELLSPACING="0" BORDER="0" CELLPADDING="0">
<TR>
<TD BGCOLOR="WHITE" COLSPAN="2">&nbsp;</TD>
</TR>
</TABLE>
<BR>
[ <A HREF="http://pho.2600.org.au/">back home</A> ] [ <A HREF="mailto:photon@2600.org.au">email</A> ]
</CENTER>

<!-- pagetable -->
</TD></TR>
</TABLE>
<!-- /pagetable -->
</CENTER>

</BODY>
</HTML>
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close