Security Cloak : How to fool Passive OS Scanner


Written by Pavs on July 23rd, 2007


Security Cloak is designed to protect against TCP/IP stack fingerprinting and computer identification/information leakage via timestamp and window options by modifying relevant registry keys. The settings used are based on the results of SYN packet analysis by p0f. While the OS reported by other OS detection scanners were not identical to those of p0f, testing against Nmap, xprobe2, queso and cheops showed that they were unable to identify the correct operating system/version after Security Cloak settings had been applied.

Note that in order to properly emulate some Operating Systems, the MTU must be changed. While most of these require the MTU to be 1500 (the default for most network connections),depending on your network connection, this could degrade/interfere with your connectivity, so be sure to check your current MTU before applying these changes. It is recommended that you save all the original key values before using this program in the event that your computer responds negatively to the changes.
Source: http://www.securiteam.com/tools/5MP052KI0A.html

Windows Binary: http://www.craigheffner.com/security/

Security Cloak in Action:

security-cloak

security-cloak2

I am preety sure I am not running Sega Dreamcast 3.0 .

On a Seperate note. Not Using Security Cloak but trying some modification I changed my server banner into this: (netcraft hasn’t been updated yet as of this writing)

 untitled

Cheers,

pavs



2 Responses to “Security Cloak : How to fool Passive OS Scanner

  • how to cloak ip

    May 29th, 2008 12:20

    [...] fingerprinting and computer identification/information leakage via timestamp and window options byhttp://www.linuxhaxor.net/2007/07/23/security-cloak-how-to-fool-passive-os-scanner/IP BlockerThis library enables developers to easily add functionality from the IP Blocker toolkit [...]

  • fingerprint scanner

    May 31st, 2008 05:56

    [...] by modifying relevant registry keys. The settings used are based on the results of SYN packet analyshttp://www.linuxhaxor.net/2007/07/23/security-cloak-how-to-fool-passive-os-scanner/Review: DigitalPersona U.are.U Personal fingerprint scanner.Review of the DigitalPersona U.are.U [...]


Subscribe without commenting


Leave a Reply

Note: Any comments are permitted only because the site owner is letting you post, and any comments will be removed for any reason at the absolute discretion of the site owner.