Started by rotation, January 03, 2013, 05:13:39 PM

Got it from here:

nmap is the standard tool whilst p0f can identify OS by examining captured packets.
Is nmap also capable of packet capturing?

Btw.: Apparently p0f has been rewritten. Does anybody know if there is an official Repo with the newest version?



To scan for remote OS version we use option -O. Example:

nmap -sS -O

You can add --osscan-guess command if you want nmap to guess remote OS system.

nmap -O --osscan-guess

If you want to capture ...use WireShark.

It's not made for package capture. You should use Wireshark (it's really cool, esp tshark ;) )
And, if you _must_ use nmap have a look at I recall you could do it with a nmap script.
