Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Nmap Development: RE: OS fingerprints and virtualization

RE: OS fingerprints and virtualization

From: Dario Ciccarone (dciccaro) <dciccaro_at_cisco.com>
Date: Thu, 15 Nov 2007 10:39:23 -0500

AFAIK, *bridging* on VMWare just does that - bridging from virtual
adapter to real. Shouldn't modify anything about L2 - the MAC addresses
will certainly look funny ;)

Submit the sigs, and on the description add "OS X running on VMWare ESX
a.b(c)"

Dario
 

> -----Original Message-----
> From: nmap-dev-bounces_at_insecure.org
> [mailto:nmap-dev-bounces_at_insecure.org] On Behalf Of Thomas Buchanan
> Sent: Thursday, November 15, 2007 10:31 AM
> To: nmap-dev_at_insecure.org
> Subject: OS fingerprints and virtualization
>
> I've been doing some testing with 4.23RC1, specifically against guest
> systems inside VMWare Workstation. I've been prompted a
> couple of times
> about submitting OS fingerprints, but I wondered if the virtualization
> could have an impact on the fingerprinting process. Could the VMWare
> network driver alter the network packets such that the OS
> fingerprint is
> changed? What about virtual system under qemu, connected via tun/tap
> drivers? Has anybody compared OS network signatures from virtualized
> systems to bare metal installations?
>
> Sorry about all the questions, but I'd rather not submit these
> fingerprints if they don't accurately reflect the true OS
> network stack.
>
> Thanks,
>
> Thomas
>
> _______________________________________________
> Sent through the nmap-dev mailing list
> http://cgi.insecure.org/mailman/listinfo/nmap-dev
> Archived at http://SecLists.Org
>

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org
Received on Nov 15 2007

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]