P0F
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
p0f is a passive OS fingerprinting tool. It identifies operating systems of machines connecting to or from your system by analyzing TCP/IP packet characteristics without sending any traffic. Completely passive and stealthy.
BASIC USAGE#
p0f # Listen on default interface p0f -i eth0 # Listen on specific interface p0f -r capture.pcap # Read from pcap file
INTERFACE OPTIONS#
p0f -i eth0 # Specify network interface p0f -i any # Listen on all interfaces p0f -p # Promiscuous mode
FILTERING#
p0f 'host 192.168.1.1' # Filter by host p0f 'port 80' # Filter by port p0f 'src host 192.168.1.1' # Filter by source p0f 'dst port 443' # Filter by destination port p0f 'net 192.168.1.0/24' # Filter by network
OUTPUT OPTIONS#
p0f -o results.log # Log to file p0f -s /tmp/p0f.sock # Create API socket p0f -d # Daemon mode (background) p0f -u nobody # Drop privileges to user
DATABASE OPTIONS#
p0f -f /etc/p0f/p0f.fp # Use custom fingerprint file
QUERY API#
# Query p0f API socket for host info: # Connect to socket and send query # Returns OS, distance, uptime, link type
EXAMPLES#
# Basic passive OS detection p0f -i eth0 # Monitor web traffic only p0f -i eth0 'port 80 or port 443' # Analyze packet capture file p0f -r traffic.pcap -o results.log # Run as daemon with logging p0f -i eth0 -d -o /var/log/p0f.log # Monitor specific subnet p0f -i eth0 'net 10.0.0.0/8' # Monitor SSH connections p0f -i eth0 'port 22' # Promiscuous mode with API socket p0f -i eth0 -p -s /tmp/p0f.sock
FINGERPRINT DETAILS#
# p0f analyzes these TCP/IP fields: # - IP TTL (initial TTL) # - IP don't-fragment flag # - TCP window size # - TCP MSS (Maximum Segment Size) # - TCP window scaling # - TCP options and order # - TCP timestamp # - Quirks (unusual flags, options)
INTERPRETING OUTPUT#
# Output format: # .-[ 192.168.1.100/45678 -> 192.168.1.1/80 (syn) ]- # | client = 192.168.1.100 # | os = Linux 3.x # | dist = 0 # | params = none # | raw_sig = 4:64+0:0:1460:mss*20,7:mss,sok,... # '---- # Fields: # os = Detected operating system # dist = Network distance (hop count) # params = Additional parameters # raw_sig = Raw TCP/IP signature
DETECTABLE FEATURES#
# - Operating system and version # - Network distance (hops) # - Uptime estimation # - Network link type (Ethernet, DSL, VPN, etc.) # - NAT detection # - Load balancer detection # - Application-level fingerprinting (HTTP)
NOTES#
- Completely passive - sends no packets - Cannot be detected by the target - Useful for network monitoring and IDS - Works with live traffic or pcap files - Accuracy depends on fingerprint database - May not identify very new or obscure OS versions - Can be run continuously as a daemon - Pairs well with other recon tools