<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; os fingerprinting tool</title>
	<atom:link href="http://www.darknet.org.uk/tag/os-fingerprinting-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>p0f &#8211; Advanced Passive OS Fingerprinting Tool</title>
		<link>http://www.darknet.org.uk/2008/10/p0f-advanced-passive-os-fingerprinting-tool/</link>
		<comments>http://www.darknet.org.uk/2008/10/p0f-advanced-passive-os-fingerprinting-tool/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 10:39:11 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[fingerprinting]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[hacking-networks]]></category>
		<category><![CDATA[os detection tool]]></category>
		<category><![CDATA[os fingerprinting tool]]></category>
		<category><![CDATA[os-detection]]></category>
		<category><![CDATA[os-fingerprinting]]></category>
		<category><![CDATA[p0f]]></category>
		<category><![CDATA[passive fingerprinting]]></category>
		<category><![CDATA[passive os fingerprinting]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1134</guid>
		<description><![CDATA[Ah can&#8217;t believe I haven&#8217;t posted about this one before, one of my favourite tools! It was a big breakthrough to have a passive OS-fingerprinting tool after relying on Nmap and Xprobe2 for the longest time. OS fingerprinting is a very important part of a pen-test during the information gathering stage. P0f v2 is a [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah can&#8217;t believe I haven&#8217;t posted about this one before, one of my favourite tools! It was a big breakthrough to have a passive OS-fingerprinting tool after relying on <a href="http://www.darknet.org.uk/2007/12/nmap-port-scanner-450-released-for-download/">Nmap</a> and <a href="http://www.darknet.org.uk/2008/05/xprobe2-active-os-fingerprinting-tool/">Xprobe2</a> for the longest time.</p>
<p><a href="http://www.darknet.org.uk/tag/os-fingerprinting/">OS fingerprinting</a> is a very important part of a pen-test during the information gathering stage.</p>
<p>P0f v2 is a versatile passive OS fingerprinting tool. P0f can identify the operating system on:</p>
<ul>
<li>machines that connect to your box (SYN mode),</li>
<li>machines you connect to (SYN+ACK mode),</li>
<li>
machine you cannot connect to (RST+ mode),</li>
<li>machines whose communications you can observe.</li>
</ul>
<p>P0f can also do many other tricks, and can detect or measure the following:</p>
<ul>
<li>firewall presence, NAT use (useful for policy enforcement),</li>
<li>existence of a load balancer setup,</li>
<li>the distance to the remote system and its uptime,</li>
<li>other guy&#8217;s network hookup (DSL, OC3, avian carriers) and his ISP.</li>
</ul>
<p>All this even when the device in question is behind an overzealous packet firewall, when our <a href="http://www.darknet.org.uk/tag/nmap/">favourite active scanner</a> can&#8217;t do much. P0f does not generate ANY additional network traffic, direct or indirect. No name lookups, no mysterious probes, no ARIN queries, nothing. How? It&#8217;s simple: magic. Find out more <a href="http://lcamtuf.coredump.cx/p0f/README">here</a>. </p>
<p>P0f is quite useful for gathering all kinds of profiling information about your users, customers or attackers (IDS, honeypot, firewall), tech espionage (laugh&#8230;), active or passive policy enforcement (restricting access for certain systems or otherwise handling them differently; or detecting guys with illegal network hookups using masquerade detection), content optimization, pen-testing (especially with SYN+ACK and RST+ACK modes), thru-firewall fingerprinting&#8230; plus all the tasks active fingerprinting is suitable for. And, of course, it has a high coolness factor, even if you are not a sysadmin.</p>
<p>P0f v2 is lightweight, secure and fast enough to be run almost anywhere, hands-free for an extended period of time. </p>
<p>You can donwload p0f v2 here:</p>
<p><a href="http://lcamtuf.coredump.cx/p0f.tgz">p0f.tgz</a><br />
<a href="http://lcamtuf.coredump.cx/p0f-win32.zip">p0f for Windows</a></p>
<p></p>
<p>Or read more <a href="http://lcamtuf.coredump.cx/p0f.shtml">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=p0f+%E2%80%93+Advanced+Passive+OS+Fingerprinting+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1134+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/10/p0f-advanced-passive-os-fingerprinting-tool/&amp;t=p0f+%E2%80%93+Advanced+Passive+OS+Fingerprinting+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/10/p0f-advanced-passive-os-fingerprinting-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/10/p0f-advanced-passive-os-fingerprinting-tool/&amp;title=p0f+%E2%80%93+Advanced+Passive+OS+Fingerprinting+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/10/p0f-advanced-passive-os-fingerprinting-tool/&amp;title=p0f+%E2%80%93+Advanced+Passive+OS+Fingerprinting+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/10/p0f-advanced-passive-os-fingerprinting-tool/&amp;title=p0f+%E2%80%93+Advanced+Passive+OS+Fingerprinting+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/10/p0f-advanced-passive-os-fingerprinting-tool/&amp;title=p0f+%E2%80%93+Advanced+Passive+OS+Fingerprinting+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F10%2Fp0f-advanced-passive-os-fingerprinting-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/10/p0f-advanced-passive-os-fingerprinting-tool/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

