Nmap Development mailing list archives

OS detection problem


From: "sara fink" <sara.fink () gmail com>
Date: Mon, 19 May 2008 14:34:35 +0300

Yesterday I ran nmap -sS -O -p 1-1024 some ip and nmap -sT -O -p
1-1024 the same ip. It was detected as Juniper networks router junos
5.5R12


Today I ran the same search on the same ip and now I get this:

No exact OS matches for host (If you know what OS is running on it,
see http://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=4.60%D=5/19%OT=179%CT=1%CU=35349%PV=N%DS=1%G=Y%TM=48315DBC%P=i686
OS:-pc-linux-gnu)SEQ(SP=100%GCD=1%ISR=10C%TI=I%II=I%SS=S%TS=7)SEQ(SP=104%GC
OS:D=1%ISR=10A%TI=I%II=I%SS=S%TS=7)SEQ(SP=102%GCD=1%ISR=10B%TI=I%II=I%SS=S%
OS:TS=7)SEQ(SP=107%GCD=1%ISR=10B%TI=I%II=I%SS=S%TS=7)SEQ(SP=103%GCD=1%ISR=1
OS:02%TI=I%II=I%SS=S%TS=7)OPS(O1=M1142NW0NNT11%O2=M1142NW0NNT11%O3=M1142NW0
OS:NNT11%O4=M1142NW0NNT11%O5=M1142NW0NNT11%O6=M1142NNT11)WIN(W1=4074%W2=407
OS:4%W3=4074%W4=4074%W5=4074%W6=403D)ECN(R=Y%DF=N%T=3E%W=4000%O=M1142NW0%CC
OS:=N%Q=)T1(R=Y%DF=N%T=3E%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=Y%DF=N%T=3E%W=4
OS:03D%S=O%A=S+%F=AS%O=M1142NW0NNT11%RD=0%Q=)T4(R=Y%DF=N%T=3E%W=0%S=A%A=Z%F
OS:=R%O=%RD=0%Q=)T5(R=Y%DF=N%T=3E%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=N%
OS:T=3E%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=N%T=3E%W=0%S=Z%A=S%F=AR%O=%RD=
OS:0%Q=)U1(R=Y%DF=Y%T=FD%TOS=0%IPL=38%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUL=
OS:G%RUD=G)IE(R=Y%DFI=S%T=FD%TOSI=Z%CD=S%SI=S%DLI=S)

Uptime: 340.978 days (since Wed Jun 13 14:32:25 2007)
Network Distance: 1 hop


I must mention that the uptime is exactly as I got yesterday.

Can someone confirm if juniper junos 5.5R12 is correct?

If someone is interested in the ip, please contact me in private.
Regards

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org


Current thread: