Archive for category Fingerprinting
Telnet Fingerprinting
Posted by Mourad Ben Lakhoua in Fingerprinting, Operating System on August 21, 2009
In some cases we fail to find the real information regarding a host on the network. NMAP can be a good scanner but it also can fail to give us the real OS version. Passive fingerprinting is another good way but now a day changing the OS fingerprint is very common by network/system administrators,To solve this problem and find host finger print there is many ways but we can try the following:
Download telnetrecon and make sure that the telnet port is open (TCP23), after running the application we start the negotiation with the targeted machine so for example if the machine is Microsoft Windows XP it will respond as follow:
ÿý%ÿûÿûÿý’ÿýÿýÿû
Those characters will be translated to their ASCII representation which is easier to analyze and compare them. This will generate the following fingerprint string:
255-253-37-255-251-255-251-255-253-92-39-255-253-255-253-255-251
3. Telnet specification can be found in RFC 854. Explanation response is described as follows:
255 – IAC data byte
253 – DO Code
37 – Authentication option (RFC 2941)
255 – and another IAC-byte
251 – Code WILL
This is a good approach for identifying a host remotely you can try it on your LAB.
make sure you subscribe to my RSS feed!
-
You are currently browsing the archives for the Fingerprinting category.
SUBSCRIBE
Blogroll
- BH Consulting's Security Watch Blog
- Cedric Pernet – Computer Security, Forensics, Malware, Cybercrime
- Chris Hoff Blog
- Infosec Island
- Infosec Ramblings
- Layer8
- Network Security Blog
- Pacific Coast Informer Blog
- RSA Blog And Podcast
- SANS Computer Forensics, Investigation, and Response
- Schneier on Security
- SECURITY DATABASE
- Tekblog
- Telecom, Security,P2P
- The New School of Information Security
- The Roer.com Information Security Blog
- ThreatChaos
Popular Tags
Adobe Anti-virus Arab World Attacks Botnet Cisco Cloud computing Conficker Cybercrime Cybercrime & Hacking cybersecurity Data security DDOS DNS Encryption Ethical Hacking Facebook Google hacking Internet Linux Malicious Web Site Malware Malware Research Microsoft Network security New Tech open source Operating Systems Password recovery patches Pentest Pentesting Security Spam Symantec Update Virtualization Viruses Vulnerabilities & attacks Vulnerabilities Assessment Vulnerability Vulnerability management Web Security Wireless Security
WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.
Lijit Search
Lijit Search


Latest Comments