Call trans opt: receveid. 9-18-99 14:32:31 REC:log>
WARNING: carrier anomaly
Trace program: running
> Welcome
38.107.191.99
16.03.2010 - 16:15 (15:15 GMT)
5orry, you have... NO MAIL.
Fingerprinting: The Complete Documentation
- This category contains 19 Tools
- The last tool was added on 2007-02-12 (YYYY-MM-DD)
- Use the Source Lucie!!! >:)
Amap -v4.8
Published on 2005-02-04 - by plasmoid, ©TheHackersChoice.
Amap is a next-generation scanning tool, it identifies applications and services even if they are not listening on the default port by creating a bogus-communication. Amap has a growning database of know applications also including non-ASCII based applications and even enterprise services.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/amap-4.8.tar.gz
- Home: http://www.thc.org/
- License: GNU General Public License
- MD5SUM: db6f6aa06afc6aeea7c7e0c594c73b69
- Platform(s): Unix
Disco -v1.2
Published on 2003-04-07 - by Preston Wood, ©Preston Wood.
Disco is a passive IP discovery and fingerprinting utility designed to sit on segments distributed throughout a network to discover unique IP's on the network. In addition to IP discovery disco has the ability to passively fingerprint TCP SYN packets using techniques detailed in a whitepaper from Lance Spitzner. The intention is for disco to discover IP's on the network, fingerprint the packet if necessary, and load into the Gherkin Scan Manager database for targeted host scans.
- Changelog: http://www.altmode.com/disco/changelog.txt
- Download: http://tools.l0t3k.net/FingerPrinting/disco-1.2.tar.gz
- Home: http://www.altmode.com/
- License: GNU General Public License
- MD5SUM: c5cd6e0c865550dc7f354ef132b2a7c5
- Platform(s): Linux, BSD
FingerPrintFucker -
Published on - by |CyRaX| and FuSyS, ©The Packets Knighs.
FingerPrintFucker is an lkm for linux that changes the tcp/ip stack in order to emulate other os'es against tcp/ip fingerprinting. The package contains the lkm and a parser for the nmap file that let you choose directly the os you want. (of course.. it doesn't work with all the os'es :). This is a new version that fixes a remot denial of service. The module still has some problems. Don't use it on servers!
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/bsdfpf.tar.gz
- Home: http://www.pkcrew.org/
- License:
- MD5SUM: ffa476c1388600f039deafe4e6e6c959
- Platform(s): Linux
Fuzzy Fingerprint -v0.8
Published on 2003-10-25 - by Plasmoid, ©The Hackers Choice.
Fuzzy fingerprinting (ffp) is a technique that extends common man-in-the-middle attacks by generating fingerprints that closely look like the target's public key fingerprint.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/ffp-0.0.8.tar.gz
- Home: http://www.thc.org/
- License:
- MD5SUM: ddcb6acaaf579c4219268812e49b285a
- Platform(s):
IP Personality -
Published on 2002-08-18 - by Carl-Daniel Hailfinger, ©Carl-Daniel Hailfinger.
The IP Personality project is a patch to the Linux kernels that adds netfilter features: it enables the emulation of other OSes at the network level, thus fooling remote OS detection tools such as nmap that rely on network fingerprinting.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/ippersonality-20020427-2.4.18.tar.gz
- Home: http://ippersonality.sourceforge.net/
- License: GNU General Public License
- MD5SUM: 130d967c5640ae2ed6870c258cbc219d
- Platform(s): Linux
iQ -
Published on - by Elie aka Lupin Bursztein, ©Elie aka Lupin Bursztein.
iQ uses ICMP flaw implementation to identify the remote OS. By crafting several packets, it creates an OS signature and compares it to its data-base.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/iQ.tar.gz
- Home: http://www.bursztein.net/
- License: GNU General Public License
- MD5SUM: a5abc58411833e58d39edad3fab09f45
- Platform(s):
Libsf -v0.01b
Published on - by packetfactory, packetfactory.
Libsf is a stack fingerprinting library.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/libsf-beta-0.01.tar.gz
- Home: http://www.packetfactory.net/
- License:
- MD5SUM: 817252d404e6064b98c5bcf2f73cba03
- Platform(s): Linux
Linux DISTribution FingerPrint -v0.1.4
Published on - by Scut, TESO Security Group.
Linux DISTribution FingerPrint, added raw mode to use scanlogs, new fingerprints etc. Send me new fingerprints please ;)
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/ldistfp-0.1.4.tar.gz
- Home:
- License:
- MD5SUM: b346840d28141773178c81fd900b2fad
- Platform(s):
Nmap -v3.70
Published on 2004-08-31 - by Fyodor, www.insecure.org.
Nmap ("Network Mapper") is an open source utility for network exploration or security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (ports) they are offering, what operating system (and OS version) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. Nmap runs on most types of computers, and both console and graphical versions are available. Nmap is free software, available with full source code under the terms of the GNU GPL.
- Changelog: http://www.insecure.org/nmap/data/CHANGELOG
- Download: http://tools.l0t3k.net/Portscanner/nmap-3.70.tgz
- Home: http://www.insecure.org/nmap/
- License: GNU General Public License
- MD5SUM: c886ee052940b6ea90bb6431cb3285ce
- Platform(s): Solaris, Linux, HP-UX, Windows, FreeBSD, OpenBSD, Mac OS X
p0f -v1.8.3
Published on - by Michal Zalewski and William Stearns, ©Bill Stearns.
p0f performs passive OS fingerprinting technique bases on information coming from remote host when it establishes connection to our system. Captured packets contains enough information to determine OS - and, unlike active scanners (nmap, queSO) - it is done without sending anything to this host.
- Changelog: http://www.stearns.org/p0f/ChangeLog
- Download: http://tools.l0t3k.net/FingerPrinting/p0f-1.8.3.tgz
- Home: http://www.stearns.org/
- License: GNU Lesser General Public License
- MD5SUM: 532c58affefef5b4e2f4ce4dba30c33b
- Platform(s): NetBSD, FreeBSD, OpenBSD, Linux 2.0>2.4, Solaris 2.6>2.7, LinuxPPC, Win32.
p0f v2 -v2.0.5
Published on 2004 - by Michal Zalewski, ©Michal Zalewski.
P0f is quite useful for gathering all kinds of profiling information about your users, customers or attackers (IDS, honeypot, firewall), tech espionage (laugh...), active or passive policy enforcement (restricting access for certain systems or otherwise handling them differently; or detecting guys with illegal network hookups using masquerade detection), content optimization, pen-testing (especially with SYN+ACK and RST+ACK modes), thru-firewall fingerprinting... plus all the tasks active fingerprinting is suitable for. And, of course, it has a high coolness factor, even if you are not a sysadmin.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/p0f-2.0.5.tgz
- Home: http://lcamtuf.coredump.cx/p0f.shtml
- License: GNU Lesser General Public License
- MD5SUM: 78235749e8ada6ad2b16b40fe15081f6
- Platform(s):
Queso -v.
Published on - by The Apostols, The Apostols.
Remote O.S. detector. Sends obscure TCP pkts to determine remote OS. Fully configurable. Runs on Linux, Solaris and probably any OS with libpcap support.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/queso-980922.tar.gz
- Home: http://www.apostols.org/projectz
- License: GNU General Public License
- MD5SUM: bb679333867765de866d89d3fcba8a20
- Platform(s): Linux, Solaris.
Siphon -v.666
Published on - by bind, bind.
The Siphon Project is a portable passive network mapping suite. In the latest public version, Siphon passively maps TCP ports and performs passive operating system detection. Through the magic of RFC ambiguity and programmer uniqueness, different machines exhibit telltale characteristics that enable Siphon to make a fairly accurate guess at what operating system is running on machines sending packets out over the wire. The beauty of this method is that our tool does not need to send out a slew of non-RFC compliant packets that trip intrusion detection systems. In fact, we send out no packets at all. Whereas nmap crashes some machines and network hardware when performing its active OS detection tests, Siphon would never crash remote
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/siphon-v.666.tar.gz
- Home: http://siphon.datanerds.net/
- License:
- MD5SUM: 064c63e738235626aeb7820241ce478b
- Platform(s): Unix, Win32
Snacktime -
Published on - by Tod Beardsley, ©Tod Beardsley.
Franck Veysset, Olivier Courtay, and Olivier Heen of Intranode research noticed that one could fairly reliably detect a wide range of operating systems by timing the retransmission timeout lengths of the TCP handshake. Turns out, this is not only a surprisingly reliable, but has the potential to be extremely stealthy. Their proof-of-concept tool, RING, demonstrated this technique, and I reviewed their research for my GCIA Assignment #1, Ring out the old, RING in the new; see these papers for more in-depth analysis on how RTO timing works.Being that I'm a chimp, I'm much better with Perl than I am with C, so I ported the concepts over, and added on some extra passive fingerprinting techniques. The result is Snacktime # a half-open, half-passive OS Fingerprinting tool.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/snacktime.tgz
- Home:
- License: GNU General Public License
- MD5SUM: cbe0db6081b8fb1c0cd46a7f1f3f31a6
- Platform(s):
Sprint -v0.41
Published on - by zillion, ©SafeMode.
Sprint is a simple TCP fingerprinting tool that can be used to remotely identify what operating system a host is running. Next to this functionality sprint has also the ability to calculate uptimes and contains advanced banner grepping functionality. In fact, if you run sprint with the -n switch it will similate netcraft.
- Changelog: http://www.safemode.org/sprint/packages/Changelog
- Download: http://l0t3k.net/tools/FingerPrinting/sprint-0.4.1.tgz
- Home:
- License: GNU General Public License
- MD5SUM: de405c1930c0a92f1b6bffaadbe8fb75
- Platform(s): UNIX
Vmap -v0.6
Published on 2003-08-10 - by , ©The Hacker's Choice.
Vmap stands for version mapper. It allows you to find out the version of a daemon by fingerprinting the features and replys of bogus commands. It's a great addition to the other *map tools.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/vmap-0.6.tar.gz
- Home:
- License:
- MD5SUM: 0bacf8350c52a2fdc37cb80beaece6c2
- Platform(s): Unix
Winfingerprint -v0.5.13
Published on 2004-11-06 - by Kirby Kuehl, ©Kirby Kuehl.
Winfingerprint is a Win32 Host/Network Enumeration Scanner. Winfingerprint is capable of performing SMB, TCP, UDP, ICMP, RPC, and SNMP scans. Using SMB, winfingerprint can enumerate OS, users, groups, SIDs, password policies, services, service packs and hotfixes, NetBIOS shares, transports, sessions, disks, security event log, and time of day in either an NT Domain or Active Directory environment. Winfingerprint-cli is a command line version of winfingerprint and it is currently bundled with each release. As of version 0.5.13, Winfingerprint will utilize WinPcap for TCP SYN scans if it is present, otherwise TCP portscans will be non-blocking connect() based.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/winfingerprint-0.5.13.zip
- Home: http://winfingerprint.sourceforge.net/
- License: GNU General Public License
- MD5SUM: b4a5d02596570a9cc11d380f443dab82
- Platform(s):
Xprobe I -v0.0.2
Published on - by Fyodor Yarochkin and Ofir Arkin, Sys-Security.com.
Xprobe I combines various remote active operating system fingerprinting methods using the ICMP protocol, which were discovered during the "ICMP Usage in Scanning" research project, into a simple, fast, efficient and a powerful way to detect an underlying operating system a targeted host is using.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/xprobe-0.0.2.tar.gz
- Home: http://www.sys-security.com/
- License: GNU General Public License
- MD5SUM: 72761231d7829e0ce4eb8f7db9049405
- Platform(s):
Xprobe II -v2.0.2.2
Published on 2005-02-17 - by Fyodor Yarochkin and Ofir Arkin, Sys-Security.com.
Xprobe2 is an active operating system fingerprinting tool with a different approach to operating system fingerprinting. Xprobe2 rely on fuzzy signature matching, probabilistic guesses, multiple matches simultaneously, and a signature database.
- Changelog:
- Download: http://tools.l0t3k.net/FingerPrinting/xprobe2-0.2.2.tar.gz
- Home: http://www.sys-security.com/
- License: GNU General Public License
- MD5SUM: 8eea1406d035827bb8bfeb0536622e1f
- Platform(s): FreeBSD 4.x, Linux 2.0.x, 2.2.x, 2.4.x, Solaris 2.x, OpenBSD 2.x NetBSD 1.4.x, 1.5.x, IRIX