CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is analyzing network traffic captured during a reconnaissance phase. They observe several HTTP requests containing a 'User-Agent' header that reveals the operating system and browser version of the client making the request. This is an example of which type of fingerprinting?
- APassive OS Fingerprinting
- BActive Service Fingerprinting
- CActive OS Fingerprinting
- DPassive Network Fingerprinting
Show answer & explanationAnswer & explanation
Correct answer: A. Passive OS Fingerprinting
Passive OS fingerprinting involves analyzing network traffic (like User-Agent headers, TTL values, TCP window sizes) without sending any probes, to infer the operating system of a host.
Why the other options are wrong
- B. Active service fingerprinting involves sending specific probes to a port to identify the service and its version, not the OS from a User-Agent.
- C. Active OS fingerprinting involves sending specially crafted packets to a target to elicit responses that reveal its OS, which is not what's happening here.
- D. Passive network fingerprinting is too broad; 'Passive OS Fingerprinting' is more specific to identifying the operating system.
Passive OS Fingerprinting
The process of identifying a target's operating system by analyzing existing network traffic, such as HTTP User-Agent strings, TCP window sizes, TTL values, and other network stack characteristics, without directly interacting with the target.
- Relies on analyzing existing traffic.
- Does not send probes to the target.
- User-Agent strings are a key indicator.
- Considered a reconnaissance technique.
Memory trick: Passive means you observe, Active means you probe.