[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
yo soy un hombre con QueSO (fwd)
---------- Forwarded message ----------
Date: Thu, 20 Aug 1998 09:40:22 -0700
From: Don Marti <dmarti@electriclichen.com>
To: svlug@svlug.org
Subject: [svlug] yo soy un hombre con QueSO
Attention Linux users:
Somebody posted a link to http://members.tripod.com/~hzo/osi_counter/
-- an operating system counting page that seems to show a lot of Linux
systems on the net. So I checked on the method they were using to
identify the OS, and found a program called QueSO, (short for "Que
Sistema Operativo?")
QueSO is fun. I got it, compiled it, and installed it here. (It's
GPL.) AFAIK it works by sending bad packets to a host and seeing what
it does under conditions unspecified by the RFCs. (Normally it needs
to be run as root, but I'm using sudo and alias; also the -d for debug
flag so I can see how many packets it has to send.)
$ queso svlug.org
Starting 140.174.70.41:7503 -> 209.81.8.243:80
IN #0 : 80->7503 S:363379DD A:5A2A20AB W:7FE0 U:0000 F: SYN ACK
IN #1 : 80->7504 S:00000000 A:00000000 W:0000 U:0000 F: RST
IN #3 : 80->7506 S:00000000 A:00000000 W:0000 U:0000 F: RST
IN #4 : 80->7507 S:0D60EF1B A:5A2A20AB W:7FE0 U:0000 F: SYN FIN ACK
IN #6 : 80->7509 S:B3DA0E6E A:5A2A20AB W:7FE0 U:0000 F: SYN ACK XXX YYY
* Linux 2.0.xx
$ queso www.ibm.com
Starting 140.174.70.41:12858 -> 204.146.18.33:80
IN #0 : 80->12858 S:54AF6ADA A:79621BCC W:FFFF U:0000 F: SYN ACK
IN #1 : 80->12859 S:00000000 A:00000000 W:0000 U:0000 F: RST
IN #6 : 80->12864 S:FA6F3B10 A:79621BCC W:FFFF U:0000 F: SYN ACK
* IBM AIX 4
$ queso www.sun.com
Starting 140.174.70.41:4681 -> 192.9.24.116:80
IN #0 : 80->4681 S:018F509D A:444E7E55 W:2398 U:0000 F: SYN ACK
* Firewalled Solaris 2.x
The following machine was once identified as running Apache, but is
now saying "Server: Undisclosed/0.0" in its HTTP headers. What does
QueSO say?
$ queso egg.microsoft.com
Starting 140.174.70.41:29845 -> 131.107.1.4:80
IN #0 : 80->29845 S:08ED8DE9 A:6696F052 W:7FE0 U:0000 F: SYN ACK
IN #1 : 80->29846 S:00000000 A:00000000 W:0000 U:0000 F: RST
IN #3 : 80->29848 S:00000000 A:00000000 W:0000 U:0000 F: RST
IN #4 : 80->29849 S:487AA7D0 A:6696F052 W:7FE0 U:0000 F: SYN FIN ACK
IN #6 : 80->29851 S:AF918E7A A:6696F052 W:7FE0 U:0000 F: SYN ACK XXX YYY
* Linux 2.0.xx
BTW, if QueSO works, Tom Abate was right to say that the Committee for
the Moral Defense of Microsoft is running Linux:
$ queso www.moral-defense.org
Starting 140.174.70.41:10303 -> 209.64.240.31:80
IN #0 : 80->10303 S:7A75FC21 A:5AA25BF5 W:7FE0 U:0000 F: SYN ACK
IN #1 : 80->10304 S:00000000 A:00000000 W:0000 U:0000 F: RST
IN #3 : 80->10306 S:00000000 A:00000000 W:0000 U:0000 F: RST
IN #4 : 80->10307 S:90A700E8 A:5AA25BF5 W:7FE0 U:0000 F: SYN FIN ACK
IN #6 : 80->10309 S:6BBDA71D A:5AA25BF5 W:7FE0 U:0000 F: SYN ACK XXX YYY
* Linux 2.0.xx
--
Don Marti Electric Lichen L.L.C.
whois DM683 -rwxr--r-- Harrison Street
dmarti@electriclichen.com San Francisco, California USA