← All cheat sheets

P0F

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

p0f is a passive OS fingerprinting tool. It identifies operating
systems of machines connecting to or from your system by analyzing
TCP/IP packet characteristics without sending any traffic.
Completely passive and stealthy.

BASIC USAGE#

p0f                              # Listen on default interface
p0f -i eth0                      # Listen on specific interface
p0f -r capture.pcap              # Read from pcap file

INTERFACE OPTIONS#

p0f -i eth0                      # Specify network interface
p0f -i any                       # Listen on all interfaces
p0f -p                           # Promiscuous mode

FILTERING#

p0f 'host 192.168.1.1'          # Filter by host
p0f 'port 80'                   # Filter by port
p0f 'src host 192.168.1.1'      # Filter by source
p0f 'dst port 443'              # Filter by destination port
p0f 'net 192.168.1.0/24'        # Filter by network

OUTPUT OPTIONS#

p0f -o results.log               # Log to file
p0f -s /tmp/p0f.sock             # Create API socket
p0f -d                           # Daemon mode (background)
p0f -u nobody                    # Drop privileges to user

DATABASE OPTIONS#

p0f -f /etc/p0f/p0f.fp          # Use custom fingerprint file

QUERY API#

# Query p0f API socket for host info:
# Connect to socket and send query
# Returns OS, distance, uptime, link type

EXAMPLES#

# Basic passive OS detection
p0f -i eth0

# Monitor web traffic only
p0f -i eth0 'port 80 or port 443'

# Analyze packet capture file
p0f -r traffic.pcap -o results.log

# Run as daemon with logging
p0f -i eth0 -d -o /var/log/p0f.log

# Monitor specific subnet
p0f -i eth0 'net 10.0.0.0/8'

# Monitor SSH connections
p0f -i eth0 'port 22'

# Promiscuous mode with API socket
p0f -i eth0 -p -s /tmp/p0f.sock

FINGERPRINT DETAILS#

# p0f analyzes these TCP/IP fields:
# - IP TTL (initial TTL)
# - IP don't-fragment flag
# - TCP window size
# - TCP MSS (Maximum Segment Size)
# - TCP window scaling
# - TCP options and order
# - TCP timestamp
# - Quirks (unusual flags, options)

INTERPRETING OUTPUT#

# Output format:
# .-[ 192.168.1.100/45678 -> 192.168.1.1/80 (syn) ]-
# | client   = 192.168.1.100
# | os       = Linux 3.x
# | dist     = 0
# | params   = none
# | raw_sig  = 4:64+0:0:1460:mss*20,7:mss,sok,...
# '----

# Fields:
# os     = Detected operating system
# dist   = Network distance (hop count)
# params = Additional parameters
# raw_sig = Raw TCP/IP signature

DETECTABLE FEATURES#

# - Operating system and version
# - Network distance (hops)
# - Uptime estimation
# - Network link type (Ethernet, DSL, VPN, etc.)
# - NAT detection
# - Load balancer detection
# - Application-level fingerprinting (HTTP)

NOTES#

- Completely passive - sends no packets
- Cannot be detected by the target
- Useful for network monitoring and IDS
- Works with live traffic or pcap files
- Accuracy depends on fingerprint database
- May not identify very new or obscure OS versions
- Can be run continuously as a daemon
- Pairs well with other recon tools