grsecurity and nmap os deteciton
Posted: Fri Apr 16, 2004 2:53 pm
i have a 2.6.4 kernel with grsecurity
if "echo 1 > /proc/...grsecurity/rand_ip_id"
then nmap will say that is a grsecurity kernel with 1000HZ patch
if "echo 0 > /proc/...grsecurity/rand_ip_id"
then nmap will not detect that it is a grsec kernel
also if "echo 0 > /proc/../tcp_timestamps"
then nmap will also detect a grsec kernel
and this option is exactly to stop os fingerprint and uptime detection!
if "echo 1 > /proc/...grsecurity/rand_ip_id"
then nmap will say that is a grsecurity kernel with 1000HZ patch
if "echo 0 > /proc/...grsecurity/rand_ip_id"
then nmap will not detect that it is a grsec kernel
also if "echo 0 > /proc/../tcp_timestamps"
then nmap will also detect a grsec kernel
and this option is exactly to stop os fingerprint and uptime detection!