[Snort-users] Fwd: How to detect OS with Snort?

Jason Haar Jason_Haar at ...15306...
Tue May 8 21:53:44 EDT 2012

Can you interpret this ruling as you must use non-invasive techniques?
If that is the case, try p0f - running on the same interface as snort.
Showing its ages these days, but it will do what you want for ipv4 at least



Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +1 408 481 8171
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1

More information about the Snort-users mailing list