She-geeks Forum
May 28, 2012, 01:52:02 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: He-geeks are welcome!
 
   Home   Help Search Login Register  
Pages: 1   Go Down
  Print  
Author Topic: OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMine  (Read 790 times)
0 Members and 1 Guest are viewing this topic.
fraggle
Honored Member
Full Member
**********

Karma: 722
Offline Offline

Posts: 205



WWW
« on: June 21, 2009, 12:26:05 PM »

Quote
      I was wondering awhile back how one could go about changing the OS fingerprint of a Windows box to confuse tools like Nmap, P0f, Ettercap and NetworkMiner. I knew there were registry setting you could change in Windows XP/Vista that would let you reconfigure how the TCP/IP stack works, thus changing how the above tools would detect the OS.  I wasn't sure what all registry changes to make, but luckily I found Craig Heffner's tool Security Cloak ( sec_cloak.exe ) and by looking at it's source I was able to figure out what to do.  The needed IP stack changes were hardcoded into Security Cloak, but for my tool I decided to make it easier to update by allowing the user to add new OS fingerprint profiles as ini files. Yes, I know this is security through obscurity and the attacker can still probably figure out the OS on a box by other means, but I still think it's kind of cool to play with.

http://www.irongeek.com/i.php?page=security/osfuscate-change-your-windows-os-tcp-ip-fingerprint-to-confuse-p0f-networkminer-ettercap-nmap-and-other-os-detection-tools
Logged

>>All the war-propaganda, all the screaming and lies and hatred, comes invariably from people who are not fighting.<<

George Orwell
swytch
GeekTastiC
Administrator
Sr. Member
************

Karma: 4020
Offline Offline

Posts: 726


"Quis custodiet ipsos custodes?"


WWW
« Reply #1 on: June 21, 2009, 09:43:57 PM »

Nice..  Cool
Logged

The present moment is your only reality...
Pages: 1   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
.
Custom Search