From owner-freebsd-stable@FreeBSD.ORG Tue Apr 19 18:54:00 2005 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6664516A4CE for ; Tue, 19 Apr 2005 18:54:00 +0000 (GMT) Received: from pandora.afflictions.org (asylum.afflictions.org [64.7.134.90]) by mx1.FreeBSD.org (Postfix) with ESMTP id C847443D1F for ; Tue, 19 Apr 2005 18:53:59 +0000 (GMT) (envelope-from dgerow@afflictions.org) Received: from localhost (localhost [127.0.0.1]) by pandora.afflictions.org (Postfix) with ESMTP id 0AF0D78C62 for ; Tue, 19 Apr 2005 14:55:32 -0400 (EDT) Received: from pandora.afflictions.org ([127.0.0.1]) by localhost (pandora.afflictions.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 22656-07 for ; Tue, 19 Apr 2005 14:55:26 -0400 (EDT) Received: from dementia.afflictions.org (dementia.afflictions.org [172.19.206.56]) by pandora.afflictions.org (Postfix) with ESMTP id 2849C78C35 for ; Tue, 19 Apr 2005 14:55:26 -0400 (EDT) Received: by dementia.afflictions.org (Postfix, from userid 1001) id 6DE0433C60; Tue, 19 Apr 2005 14:53:53 -0400 (EDT) Date: Tue, 19 Apr 2005 14:53:53 -0400 From: Damian Gerow To: freebsd-stable@freebsd.org Message-ID: <20050419185353.GB770@afflictions.org> References: <200504191216.24362.dom@helenmarks.co.uk> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <200504191216.24362.dom@helenmarks.co.uk> X-GPG-Fingerprint: B3D7 D901 A53A 1A99 BFD6 E6DF 9F3B 742B C288 9CC9 User-Agent: Mutt/1.5.9i X-Virus-Scanned: amavisd-new at pandora.afflictions.org Subject: Re: FreeBSD and NMAP X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 19 Apr 2005 18:54:00 -0000 Thus spake Dominic Marks (dom@helenmarks.co.uk) [19/04/05 07:18]: : On Tuesday 19 April 2005 12:11, pck wrote: : > Hi, : > : > How can i hide from nmap that my OS is FreeBSD? Is this possible? : : # sysctl -ad | grep random_id : net.inet.ip.random_id: Assign random ip_id values : # echo 'net.inet.ip.random_id=1' >> /etc/sysctl.conf That doesn't hide the OS. That just makes the IP ID field random. One way to help: echo "net.inet.tcp.drop_synfin=1' >> /etc/sysctl.conf (Note that you need the "options TCP_DROP SYNFIN" line in your kernel config.) Other than that... randomize the packet fingerprint data. I know there's been at least one daemon that did this on Linux, as well as a kernel patch that did the same. But I'd ask: why? You're doing a significant amount of work for very little in return. - Damian