Re: Hiding NATs with PF

From: Greg Hennessy (me_at_privacy.org)
Date: 09/28/05


Date: Wed, 28 Sep 2005 14:45:51 +0100

On Wed, 28 Sep 2005 03:01:55 +0100, Max Bolingbroke
<batterseapower{no@spam}hotmail.com> wrote:

>This has covered the two main bases: TTL monitoring and statistical
>analysis of IP IDs. However, I'm still going to be vunerable to passive
>OS fingerprinting.

What are you protecting yourself against exactly ?

> Are there any further ways I can have PF munge my
>outgoing packets so look like they all come from the same flavour of TCP
>stack?

You mean a http://lcamtuf.coredump.cx/p0f-help/
response looking something like ?

UNKNOWN [65535:56:1:64:M1438,N,W3,N,N,T,S,E:P:?:?] (up: 8454 hrs) ->
213.134.128.25:80 (link: unknown-1478)

-- 
"Access to a waiting list is not access to health care"


Relevant Pages

  • [Full-Disclosure] Re: [tool] the new p0f 2.0.1 is now out
    ... Question concerning the the POF, how can we setup a IDS to detect a POF ... > even if the device is behind a fascist packet firewall. ... plus all the tasks active fingerprinting is suitable ...
    (Full-Disclosure)
  • Re: Fingerprinting IDS sensors?
    ... Typically an IDS would be running in completely passive mode and thus ... I can't think of any way of fingerprinting the last snort IDS I ... It should be easy to fingerprint an IPS by seeing what kind of attacks ... You may need access to a range of different IPS systems to ...
    (Focus-IDS)
  • [tool] p0f 2.0.4 is out
    ... - Official SYN+ACK fingerprinting support, ... More information, links to related or derived projects, and last but not ... Test Your IDS ...
    (Focus-IDS)
  • Re: Network IDS
    ... >> is not about protecting systems. ... > to protect a single server/system with an NIDS sensor. ... > someone deploying a sensor to detect network traffic based attacks. ... My view (as an ex-IDS vendor employee) is that the IDS isn't actively ...
    (Focus-IDS)
  • Re: Hiding NATs with PF
    ... On 2005-09-28, Max Bolingbroke wrote: ... > This has covered the two main bases: TTL monitoring and statistical ... > analysis of IP IDs. ... > outgoing packets so look like they all come from the same flavour of TCP ...
    (comp.unix.bsd.openbsd.misc)