pen-test
[Top] [All Lists]

SinFP 2.06, now works under big-endian architectures

To: pen-test@securityfocus.com
Subject: SinFP 2.06, now works under big-endian architectures
From: "GomoR" <pt@gomor.org>
Date: Thu, 21 Dec 2006 13:28:27 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Thu, 21 Dec 2006 09:24:05 -0700 (MST)
Resent-from: pen-test-return-1078483304@securityfocus.com
Resent-message-id: <20061221162405.EDA70246956@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Hello,
SinFP is a new approach to OS fingerprinting, which bypasses
limitations that nmap has. More info:
http://www.gomor.org/sinfp . SinFP has now 140 signatures.
You can download it via CPAN, or via SourceForge:
https://sourceforge.net/projects/sinfp
Also, two benchmarks versus Nmap have been done:
http://www.phocean.net/index.php/post/2006/12/17/SinFP
http://www.computerdefense.org/?p=173
This new release has been tested under Solaris 8/SPARC,
and Mac OS X/PPC.
Example "advanced" usage:
# sinfp.pl -kai www.heise.de
P1: B00000 F0 W0 O0 M0
P2: B11113 F0x12 W4320 O0204ffff010303000101080affffffff4445414401010402 M1440
P3: B11123 F0x14 W0 O0 M0
IPv4: unknown
##
## Retry in offline active mode:
##
# sinfp.pl -1 -f sinfp4-193.99.144.85.80.pcap -H
P2: B11113 F0x12 W4320 O0204ffff010303000101080affffffff4445414401010402 M1440 IPv4: BH0FH0WH2OH0MH1/P2: Unix: IRIX: 6.5
--
^  ___  ___             http://www.GomoR.org/          <-+
| / __ |__/          Systems & Security Engineer         |
| \__/ |  \     ---[ zsh$ alias psed='perl -pe ' ]---    |
+-->  Net::Frame <=> http://search.cpan.org/~gomor/  <---+

<Prev in Thread] Current Thread [Next in Thread>
  • SinFP 2.06, now works under big-endian architectures, GomoR <=