[VulnDiscuss] xprobe2 0.1 Release
Ofir Arkin <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
I am pleased to announce the immediate availability of xprobe2 0.1 Release. xprobe2 is an active operating system fingerprinting tool with a different approach to operating system fingerprinting. The tool relies on fuzzy signature matching, probabilistic guesses, simultaneous multiple matches, and a signature database. More information on xprobe2’s technology can be obtained from [1] and [2]. Changes from previous versions: - A lot of new signatures were added - xprobe2 0.1 sends RFC compliant icmp query packets - Support for IP ID = SENT was added (please see [3] for more information) - Added documentation on "how to add your own signatures" - No more “xprobe” in the data portion of the icmp queries - A lot of bug fixes - An extensive Source code cleaning The source code can be obtained from: http://www.sys-security.com/archive/tools/xprobe2/xprobe2-0.1.tar.gz MD5 (xprobe2-0.1.tar.gz) = 91e79394e82d6742532be17670d88427 Yours Ofir Arkin [[email protected]] Founder The Sys-Security Group http://www.sys-security.com PGP CC2C BE53 12C6 C9F2 87B1 B8C6 0DFA CF2D D360 43FA [1] http://www.sys-security.com/html/projects/X.html [2] “xprobe2 - A 'Fuzzy' Approach to Remote Active Operating System Fingerprinting”, Ofir Arkin & Fyodor Yarochkin, August 2002, http://www.sys-security.com/archive/papers/Xprobe2.pdf. [3] Using ICMP queries to fingerprint some networking equipment, Ofir Arkin, April 2003, http://www.sys-security.com/archive/advisories/ofirarkin-2003-02.txt.