Remote OS detection via TCP/IP Stack FingerPrinting
This paper discusses how to glean precious information about a host by querying its TCP/IP stack. I first present some of the "classical" methods of determining host OS which do not involve stack fingerprinting. Then I describe the current "state of the art" in stack fingerprinting tools. Next comes a description of many techniques for causing the remote host to leak information about itself. Finally I detail my (nmap)implementation of this, followed by a snapshot gained from nmap which discloses what OS is running on many popular Internet sites.
647 views
Post new comment