|
|||||||||||
|
Re: Methods for evading Nmap OS Fingerprinting
From: Alex Lambert <alambert(at)quickfire.org>
Date: Sun Mar 09 2003 - 17:18:13 EST David, OpenBSD's "pf" has an interesting option called "scrub" that I don't believe you explored. The URL for the manpage is http://www.openbsd.org/cgi-bin/man.cgi?query=pf.conf&sektion=5&arch=i386&apr opos=0&manpath=OpenBSD+Current and says: "Traffic normalization is used to sanitize packet content in such a way
that there are no ambiguities in packet interpretation on the receiving
side. The normalizer does IP fragment reassembly to prevent attacks
that
confuse intrusion detection systems by sending overlapping IP
fragments."
Some of its options, such as "random-id" could inhibit nmap success. Cheers, apl
--Received on Tue Mar 11 11:53:07 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:33 EDT |
||||||||||
|
|||||||||||