Project

General

Profile

Actions

Feature #14444

open

Aliases options for custom OS fingerprints?

Added by Jonathan Lee over 1 year ago. Updated over 1 year ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Aliases / Tables
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default

Description

Idea for new feature, is there a way to add some custom fingerprints? I was able to find one manually but how can I add it? Maybe just for what we use on the network? Example: 200 machines that use the same Windows 11 OS and a system admin adds in that fingerprint for an ACL to pass traffic for only Windows 11. With such options the firewall in theory can block and distinguish between different Operating Systems. Take for example Docker containers with the new bleeding edge container of Kali's pentesting OS, something like that can data marshal the NIC card on a machine. Docker for one does not have the same fingerprints as the primary OS so in theory the firewall would know what traffic to allow and what to stop at an OS level even with the newest Docker containers. It is harder to spoof a custom fingerprint as the invasive actor would not know what is in use, and to just add that in would give users that full security tool back, Thus, Aliases options for OS fingerprints.

running: p0f -i (intrface)

Outputs this example of what would be used with OS aliases: 4:63+1:0:1460:65228,7:mss,nop,ws,sok,ts: :0
this is freeBSD 13.12 on Hypervisor V

The database just needs some updated signatures, the software still works great so the tool and features already built in should work great still.
How can I just add in the signatures I need as an Aliases and link them to the access control lists?


Files

versionsig.PNG (29.2 KB) versionsig.PNG Example of finding a OS fingerprint Jonathan Lee, 06/02/2023 02:56 PM
Sigdatabase.txt (36 KB) Sigdatabase.txt p0f current database with 23.05 Jonathan Lee, 06/02/2023 02:56 PM
image001.png (177 KB) image001.png Docker Signature Debian container Jonathan Lee, 06/02/2023 08:47 PM
docker fingerprinting.docx (3.51 MB) docker fingerprinting.docx Docker's Kali Container Fingerprint How to guide Jonathan Lee, 06/02/2023 11:27 PM
kalisig9.PNG (447 KB) kalisig9.PNG Fingerprinted Jonathan Lee, 06/02/2023 11:28 PM
Kali10.PNG (263 KB) Kali10.PNG Kali Fingerprint Jonathan Lee, 06/02/2023 11:43 PM
docker fingerprinting.docx (3.72 MB) docker fingerprinting.docx update to how to guide Jonathan Lee, 06/02/2023 11:44 PM
Actions

Also available in: Atom PDF