Dailydave mailing list archives

Re: how to remotely fingerprint 2k3 SP0 vs SP1 ?


From: "Hamid . K" <elite_netbios () yahoo com>
Date: Mon, 6 Jun 2005 15:54:50 -0700 (PDT)

Thanks for usefull hint.

I did some excersises ( using Hping and manualy
comparing resaults )but as first try was still boring
and disappointing , to do it manually.
Later I came accross "RING" provided az PoC and still
playing with. btw any new tool based on RING
methodology ?

aside RTT technique , is there any other reliable
technique ? 
consider both Daveless and Daved staff ;p

Hamid

--- Tod Beardsley <todb () planb-security net> wrote:

Hamid . K wrote:
is there anyway to remotely guess SP version of
running host ?

Specific to Dave's stuff, or just in general? In the
latter case,
yes. Just use TCP RTT timing.

-tod




                
__________________________________ 
Discover Yahoo! 
Use Yahoo! to plan a weekend, have fun online and more. Check it out! 
http://discover.yahoo.com/
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: