May 28, 2012, 01:52:02 AM
Welcome,
Guest
. Please
login
or
register
.
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: He-geeks are welcome!
Home
Help
Search
Login
Register
She-geeks Forum
>
Security
>
Computer Security
(Moderators:
swytch
,
justy
) > Topic:
OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMine
Pages:
1
Go Down
« previous
next »
Print
Author
Topic: OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMine (Read 790 times)
0 Members and 1 Guest are viewing this topic.
fraggle
Honored Member
Full Member
Karma: 722
Offline
Posts: 205
OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMine
«
on:
June 21, 2009, 12:26:05 PM »
Quote
I was wondering awhile back how one could go about changing the OS fingerprint of a Windows box to confuse tools like Nmap, P0f, Ettercap and NetworkMiner. I knew there were registry setting you could change in Windows XP/Vista that would let you reconfigure how the TCP/IP stack works, thus changing how the above tools would detect the OS. I wasn't sure what all registry changes to make, but luckily I found Craig Heffner's tool Security Cloak ( sec_cloak.exe ) and by looking at it's source I was able to figure out what to do. The needed IP stack changes were hardcoded into Security Cloak, but for my tool I decided to make it easier to update by allowing the user to add new OS fingerprint profiles as ini files. Yes, I know this is security through obscurity and the attacker can still probably figure out the OS on a box by other means, but I still think it's kind of cool to play with.
http://www.irongeek.com/i.php?page=security/osfuscate-change-your-windows-os-tcp-ip-fingerprint-to-confuse-p0f-networkminer-ettercap-nmap-and-other-os-detection-tools
Logged
>>All the war-propaganda, all the screaming and lies and hatred, comes invariably from people who are not fighting.<<
George Orwell
swytch
GeekTastiC
Administrator
Sr. Member
Karma: 4020
Offline
Posts: 726
"Quis custodiet ipsos custodes?"
Re: OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, Network
«
Reply #1 on:
June 21, 2009, 09:43:57 PM »
Nice..
Logged
The present moment is your only reality...
Pages:
1
Go Up
Print
She-geeks Forum
>
Security
>
Computer Security
(Moderators:
swytch
,
justy
) > Topic:
OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMine
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Myspace, Facebook, Photobucket and other Social Networking
-----------------------------
=> How to see myspace, facebook, and photobucket PRIVATE goodies!
=> Myspace Trackers
=> Myspace Discussion/Help
=> Sites that Scam?
=> Facebook Discussion/Help
=> Social Networking
-----------------------------
Security
-----------------------------
=> Encryption
=> Bypass Windows XP adminstrator password
=> Computer Security
-----------------------------
Operating Systems
-----------------------------
=> Windows
===> Windows Tips, Tricks & Tools
=> Linux
=> Mac
-----------------------------
Hardware
-----------------------------
=> Internal - Motherboards, video cards, RAM, Drives, etc.
=> External - Printers, Scanners, Mice, USB Devices, etc.
-----------------------------
Web Development
-----------------------------
=> HTML/CSS
=> PHP, VB, etc
=> Photoshop, GIMP and Other Editing Software
=> Lets Talk Video
-----------------------------
Game Squad
-----------------------------
=> FB Games
=> Online an PC Games
=> Wii, Xbox, Playstation an More...
-----------------------------
General Category
-----------------------------
=> Underground Handbook - Security
=> Mobile Devices
=> Current Events
=> Software Recomendations
=> she-geek loveline
=> General Discussion
=> get some geek gear
-----------------------------
she-geeks content
-----------------------------
=> Virtualization
=> Browsers
===> Search Engines
Loading...
Custom Search