Skip to main content

Module os_hint

Module os_hint 

Source
Expand description

A best guess at a host’s operating system, from clues a scan already has, each named with where it came from.

This is not nmap’s -O. That sends deliberately malformed packets and fingerprints how the TCP/IP stack answers, which needs raw sockets (so administrator rights, and Npcap on Windows) and a fingerprint database under nmap’s own licence. The clues here need neither:

  • SMB: a Windows host’s NTLM challenge states its exact version and build before any login (os_hint/smb.rs);
  • SSH banner: OpenSSH usually names the distribution (OpenSSH_9.6p1 Ubuntu-3ubuntu13) or says for_Windows;
  • HTTP Server header: Apache/2.4.58 (Ubuntu), Microsoft-IIS/10.0;
  • open ports: 135 with 445 is Windows’ RPC and file sharing;
  • MAC vendor: an Apple or Raspberry Pi network card;
  • ping TTL: hosts start the TTL at 64 (Linux, macOS, most Unix), 128 (Windows) or 255 (network gear), and a LAN hop barely lowers it.

The strongest clue sets the family; every clue is kept as evidence, so a reader can see both what was concluded and why, including clues that disagree. It’s a hint: a host can run anything behind any of these.

Structs§

OsHint
A best guess at a host’s operating system, and the clues behind it.