Solved

Unable to determine version of windows running using NMAP TCP/ip fingerprint.

Posted on 2014-10-06
2
371 Views
Last Modified: 2014-10-10
Hi and thank you in advance,

I am having trouble identifying which version of windows an host is running.  I have been reading NMAP articles on TCP/IP fingerprinting and still have an issue determining the version of windows running.  Please help decipher the TCP/IP finger print.  I was looking at the following line, WIN(W1=1%W2=3F%W3=4%W4=4%W5=10%W6=200), and was thinking that the fingerprint points to Windows 2000.  

TCP/IP Fingerprint Below:
SCAN(V=6.47%E=4%D=10/6%OT=21%CT=1%CU=%PV=N%G=Y%TM=5432AF37%P=i686-pc-windows-windows)
SEQ(CI=I%II=I)
OPS(O1=%O2=%O3=%O4=%O5=%O6=)
WIN(W1=1%W2=3F%W3=4%W4=4%W5=10%W6=200)
ECN(R=Y%DF=N%TG=20%W=3%O=%CC=N%Q=)
T1(R=Y%DF=N%TG=20%S=Z%A=O%F=R%RD=0%Q=)
T2(R=Y%DF=N%TG=20%W=80%S=Z%A=O%F=R%O=%RD=0%Q=)
T3(R=OS:Y%DF=N%TG=20%W=100%S=Z%A=O%F=R%O=%RD=0%Q=)
T4(R=Y%DF=N%TG=20%W=400%S=A%A=OS:Z%F=R%O=%RD=0%Q=)
T5(R=Y%DF=N%TG=20%W=7A69%S=Z%A=O%F=R%O=%RD=0%Q=)
T6(R=Y%DF=N%TG=20%W=8000%S=A%A=Z%F=R%O=%RD=0%Q=)
T7(R=Y%DF=N%TG=20%W=FFFF%S=Z%A=O%F=R%O=%RD=0%Q=)
U1(R=N)
IE(R=Y%DFI=N%TG=20%CD=S)
0
Comment
Question by:cesemj
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 13

Accepted Solution

by:
Gabriel Clifton earned 500 total points
ID: 40364008
Try this site for further explanation: http://nmap.org/nmap-fingerprinting-old.html
0
 

Author Comment

by:cesemj
ID: 40364080
reviewing now. - thanks.
0

Featured Post

Ready to get started with anonymous questions?

It's easy! Check out this step-by-step guide for asking an anonymous question on Experts Exchange.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article shows how to use a free utility called 'Parkdale' to easily test the performance and benchmark any Hard Drive(s) installed in your computer. We also look at RAM Disks and their speed comparisons.
Sometimes clients can lose connectivity with the Lotus Notes Domino Server, but there's not always an obvious answer as to why it happens.   Read this article to follow one of the first experiences I had with Lotus Notes on a client's machine, my…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Suggested Courses

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question