Snort mailing list archives

Snort OS Fingerprint Scan Detectino


From: yasir al-ibrahem <alibrahem.yasir () gmail com>
Date: Thu, 3 Nov 2016 22:06:20 -0500

Hello,

I'm using NMAP to detect the OS type and version of another machine that
hosts snort.

Snort is able to detect the ICMP tests, but that doesn't clearly indicate
that an OS fingerprinting attack is taking place.

I'm wondering if snort has such a specific alert. and if there's any
specific configuration for OS fingerprint detection.

Appreciate your help.

Regards,

*Yasir Saad Al-Ibrahem+1-312-428-0301*
------------------------------------------------------------------------------
Developer Access Program for Intel Xeon Phi Processors
Access to Intel Xeon Phi processor-based developer platforms.
With one year of Intel Parallel Studio XE.
Training and support from Colfax.
Order your platform today. http://sdm.link/xeonphi
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: