Forums: Findin Out The Os Of A Machine - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Findin Out The Os Of A Machine

#1 User is offline   Ahmeket 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 101
  • Joined: 15-February 04

Posted 04 June 2005 - 04:54 AM

I was wondering if there are any ways to find out what operating system a machine runs remotely considering it has the needed ports opened.
0

#2 User is offline   tibbar 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 1,423
  • Joined: 14-October 03

Posted 04 June 2005 - 05:56 AM

search for nmap
If you want to read more about my security research, visit Tibbar.org
0

#3 User is offline   seppel18 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 95
  • Joined: 07-October 03

Posted 04 June 2005 - 08:17 AM

look at the ports

139,445,3389 Windoze

22,3306 Linux

Look at the banners:

Microsoft/IIS 5.0 = Windows


Apache/1.3.27 (Unix) (Red-Hat/Linux) mod_ssl/2.8.12 OpenSSL/0.9.6b PHP/4.1.2 = Linux

Try X-Scan 3.2 ,works like nmap, but runs on Windows
0

#4 User is offline   deaz 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 101
  • Joined: 24-September 04

Posted 04 June 2005 - 09:16 AM

Nmap 3.81 Usage: nmap [Scan Type(s)] [Options] <host or net list>
Some Common Scan Types ('*' options require root privileges)
* -sS TCP SYN stealth port scan (default if privileged (root))
-sT TCP connect() port scan (default for unprivileged users)
* -sU UDP port scan
-sP ping scan (Find any reachable machines)
* -sF,-sX,-sN Stealth FIN, Xmas, or Null scan (experts only)
-sV Version scan probes open ports determining service & app names/version
-sR RPC scan (use with other scan types)
Some Common Options (none are required, most can be combined):
* -O Use TCP/IP fingerprinting to guess remote operating system
-p <range> ports to scan. Example range: 1-1024,1080,6666,31337
-F Only scans ports listed in nmap-services
-v Verbose. Its use is recommended. Use twice for greater effect.
-P0 Don't ping hosts (needed to scan www.microsoft.com and others)
* -Ddecoy_host1,decoy2[,...] Hide scan using many decoys
-6 scans via IPv6 rather than IPv4
-T <Paranoid|Sneaky|Polite|Normal|Aggressive|Insane> General timing policy
-n/-R Never do DNS resolution/Always resolve [default: sometimes resolve]
-oN/-oX/-oG <logfile> Output normal/XML/grepable scan logs to <logfile>
-iL <inputfile> Get targets from file; Use '-' for stdin
* -S <your_IP>/-e <devicename> Specify source address or network interface
--interactive Go into interactive mode (then press h for help)
--win_help Windows-specific features
Example: nmap -v -sS -O www.my.com 192.168.0.0/16 '192.88-90.*.*'
SEE THE MAN PAGE FOR MANY MORE OPTIONS, DESCRIPTIONS, AND EXAMPLES
0

#5 User is offline   Pu$u 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 22
  • Joined: 29-December 03

Posted 04 June 2005 - 11:25 AM

seppel18, on Jun 4 2005, 04:17 PM, said:

look at the ports

22,3306 Linux



3306 is not only for Linux
MySQL can be used on Windows, too.
0

#6 User is offline   Ahmeket 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 101
  • Joined: 15-February 04

Posted 05 June 2005 - 02:46 AM

What if they changed the default daemon ports on linux? As I understand the reason to search for port 22 is to see if sshd is running, but that port can easily be changed.
0

#7 User is offline   Terminal 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 536
  • Joined: 21-February 04

Posted 05 June 2005 - 05:57 AM

windows specific:

139 and 445 open then its windows nt ( xp/2k)

only 139 open and sharing is on ( u can visit \\ip ) then its win98 .

if 139 open and no netbios sharing then it can be any 98/2k/xp

3389 open means windows xp or 2000 server as 2k professional do not have terminal services ..




1025 = windows 2k/xp

dunno much abt 2k3
0

#8 User is offline   TedOb1 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 120
  • Joined: 05-October 03

Posted 21 June 2005 - 02:09 PM

many times you can tell using the ping command.

linux ttl = 64

windows ttl = 128

you must subtract 1 for each hop. for me a ping to yahoo has a time to live of 54 wich says it.s *nix.
0

#9 User is offline   whiskah 

  • Sergeant First Class
  • Icon
  • Group: Specialist
  • Posts: 393
  • Joined: 13-February 04

Posted 21 June 2005 - 07:55 PM

xprobe

Quote

Xprobe2 is a remote active operating system fingerprinting tool which uses advanced techniques, some which where first to be introduced with Xprobe2, such as the usage of statistical analysis ('fuzzy logic') to match between probe response(s) to its signature database and others, in order to provide with accurate results regarding the underlying operating system of a probed element(s).

0

#10 User is offline   seppel18 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 95
  • Joined: 07-October 03

Posted 21 June 2005 - 10:23 PM

Port 5000 = XP ;)
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting