Well sat down and finally played with p0fv3...
DAMN that is fast! Reminds me how pathetically slow Satori is since I wander the .xml file EVERY packet that goes through instead of reading it in once, hashing it and doing a look up on that hash. Not sure how easy it will be, but after seeing how fast p0fv3 is (and prads in the past) just reminds me how much time I'm killing do to how I do lookups!
Anyway, back to p0fv3. Ran a 7 year old pcap file through it, there were about 7-10 devices that it didn't know. Mostly Netware 5 and 6 boxes, a few others that I don't know and would like to, and then a few XP ones that may have been because of the SP they were at or other services. Anyway, sent them on.
Very nice nice program as always mz!
Monday, February 13, 2012
Monday, February 6, 2012
Passive Aggressive Pwnage
15 min fire talk at Schmoocon 2012, mentions Satori in DHCP fingerprinting, which I was happy to see, missed the greater use of it, but at least it was mentioned!
Audio on this sucks, but was worth my 15 mins to listen to and get a few new ideas.
Thanks for the mention of Satori John!
Audio on this sucks, but was worth my 15 mins to listen to and get a few new ideas.
Thanks for the mention of Satori John!
Friday, January 27, 2012
NetSlueth
It was posted to the fingerbank discussion list in the past week on the Alpha version of NetSlueth. I'd tagged it to go back and look at, and unlike most of the time I tag things for follow up I did it in less than 6 months!
I guess it was just 2 days ago, wow, not sure I've ever gotten back that quick.
Anyway, partial info from the list:
"I basically used tshark for low level processing, allowing me to focus on the logic of the analysis. It needs ALOT more work, including improving my sloppy coding skills. It requires a full installation of Wireshark and .Net Framework or later on the machine. I'm going to make it fully mono compatible shortly."
By using tshark he took a lot of the headache out of coding underlying pieces that I've dealt with in Satori. Anyway, I ran some initial pcap files I had around through it and it seemed to do quite nicely on identifying the OS running on them. I didn't have any luck with a live capture, but I didn't dig around very long on trying to figure out why either!
I need to dig into it more and see what all protocols they are utilizing, but if you need another little tool, this one may be worth looking at!
I guess it was just 2 days ago, wow, not sure I've ever gotten back that quick.
Anyway, partial info from the list:
"I basically used tshark for low level processing, allowing me to focus on the logic of the analysis. It needs ALOT more work, including improving my sloppy coding skills. It requires a full installation of Wireshark and .Net Framework or later on the machine. I'm going to make it fully mono compatible shortly."
By using tshark he took a lot of the headache out of coding underlying pieces that I've dealt with in Satori. Anyway, I ran some initial pcap files I had around through it and it seemed to do quite nicely on identifying the OS running on them. I didn't have any luck with a live capture, but I didn't dig around very long on trying to figure out why either!
I need to dig into it more and see what all protocols they are utilizing, but if you need another little tool, this one may be worth looking at!
Thursday, January 12, 2012
Fingerprint Editor 1.00.08
Jeff recompiled his fingerprint editor for us with the latest .xml files from my fingerprint database!
Tuesday, January 10, 2012
p0f v3
And I though MZ gave up on p0f after no updates to v2 in years. I guess I'm proven wrong....
== What's new ==
Version 3 is a complete rewrite, bringing you much improved SYN and SYN+ACK fingerprinting capabilities, auto-calibrated uptime measurements, completely redone databases and signatures, new API design, IPv6 support (who knows, maybe it even works?), stateful traffic inspection with thorough cross-correlation of collected data, application-level fingerprinting modules (for HTTP now, more to come),
and a lot more.
----
On my list to test in the near future and provide some new fingerprints. Assuming time permits and how well it works (I have no doubts well, but...), I will look at what it is doing and see if I can incorporate new stuff/ideas into a newer tcp plugin for Satori.
== What's new ==
Version 3 is a complete rewrite, bringing you much improved SYN and SYN+ACK fingerprinting capabilities, auto-calibrated uptime measurements, completely redone databases and signatures, new API design, IPv6 support (who knows, maybe it even works?), stateful traffic inspection with thorough cross-correlation of collected data, application-level fingerprinting modules (for HTTP now, more to come),
and a lot more.
----
On my list to test in the near future and provide some new fingerprints. Assuming time permits and how well it works (I have no doubts well, but...), I will look at what it is doing and see if I can incorporate new stuff/ideas into a newer tcp plugin for Satori.
Saturday, November 5, 2011
Using Machine Learnign Techniques for Advanced Passive Operating System Fingerprinting
Ok, guess I'm about a year out on this, but....
Anytime someone mentions your work in their master thesis, it is a nice thing to mention it and post a link!
His thesis can be found here.
He covers a lot of the same ground initially I did it my paper on OS Fingerprinting, but also covers a few tools and newer techniques that were not around back in 2005 or whenever it was that I wrote my paper on this subject. This is only in regards to the start of the paper, giving a quick overview of fingerprinting techniques and tools, he then dives deeply into other things that go well beyond what I've covered previously. I guess it is a master thesis,so it better!
He does bring up a good point/issue with passive fingerprinting and ipsec. Which since I'm working on a final project for school right now discussing network security and ipsec, it may be worth me looking into this a bit more!
Anytime someone mentions your work in their master thesis, it is a nice thing to mention it and post a link!
His thesis can be found here.
He covers a lot of the same ground initially I did it my paper on OS Fingerprinting, but also covers a few tools and newer techniques that were not around back in 2005 or whenever it was that I wrote my paper on this subject. This is only in regards to the start of the paper, giving a quick overview of fingerprinting techniques and tools, he then dives deeply into other things that go well beyond what I've covered previously. I guess it is a master thesis,so it better!
He does bring up a good point/issue with passive fingerprinting and ipsec. Which since I'm working on a final project for school right now discussing network security and ipsec, it may be worth me looking into this a bit more!
DLink cloud managed solutions - offer dhcp fingerprinting in basic option
I don't have a lot of details here, I've been sitting on a lot of "Os fingerprinting" notices the past 6 months, been so busy with work and school I haven't posted much, but have some time to catch up this weekend.
Anyway, DLink has a cloud based solution that does DHCP OS Fingerprinting, more are more every day seem to finally be catching on on how to use this!
One of many articles can be found here.
Anyway, DLink has a cloud based solution that does DHCP OS Fingerprinting, more are more every day seem to finally be catching on on how to use this!
One of many articles can be found here.
OS fingerprinting with IPv6
I was sad to see they didn't go into DHCPv6 at all in this, but the author goes into IPv4 with IPv6 fingerprinting, some of what still works, some possible new stuff.
He did this for his GIAC Gold, maybe I should have used my DHCP presentation for Blackhat and got a Gold Cert on one of the many GIAC certs I hold. Oh well.
Check out the paper here.
He did this for his GIAC Gold, maybe I should have used my DHCP presentation for Blackhat and got a Gold Cert on one of the many GIAC certs I hold. Oh well.
Check out the paper here.
ArubaOS 6.0.1.0 adds DHCP fingerprinting
They are using their own DB, but now the ArubaOS supports doing DHCP fingerprinting of devices on the network. You can find the writeup here
It is good to see more products doing this!
My original introduction to them doing this was this blog post:
http://airheads.arubanetworks.com/vBulletin/showthread.php?p=11211
There haven't been a lot of things published on this, but it is something new they've added recently.
It is good to see more products doing this!
My original introduction to them doing this was this blog post:
http://airheads.arubanetworks.com/vBulletin/showthread.php?p=11211
There haven't been a lot of things published on this, but it is something new they've added recently.
Fingerbank presentation at Defcon 19
Ok, I knew Oliver did a presentation fingerbank, but didn't realize it was recorded.
It can be found here.
I did find it interesting that he said he was introducing fingerbank when we did that back in 2007, but it did die off and they brought it back!
Anyway, check it out if you want.
It can be found here.
I did find it interesting that he said he was introducing fingerbank when we did that back in 2007, but it did die off and they brought it back!
Anyway, check it out if you want.
Subscribe to:
Posts (Atom)