RE: Re: [tool] the new p0f 2.0.1 is now out

"Parker, Jeff (MSE)" <[email protected]>
Newsgroups gmane.comp.security.full-disclosure,gmane.comp.security.honeypots,gmane.comp.security.penetration,gmane.comp.security.ids,gmane.comp.security.incidents,gmane.comp.security.bugtraq
Message-ID <A486476CDD336846B0A4FA6691413388026AF7@mseexp01.americas.cpqcorp.net>
Umer,

Running p0f does not necessarily offer a stimulus/response test.

Regarding detecting a machine with p0f installed/running, you may have
better success simply trying to detect for any network adapter in
promiscuous mode.  And there's tons of info available on that...

HTH,
-jeff parker

-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of thetic
Sent: Thursday, September 04, 2003 2:20 PM
To: Michal Zalewski; [email protected];
[email protected]; [email protected];
[email protected]
Cc: [email protected]; [email protected];
[email protected]
Subject: [Full-Disclosure] Re: [tool] the new p0f 2.0.1 is now out


Question concerning the the POF, how can we setup a IDS to detect a POF
scan.

umer

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.