Implements p0f using 3.0.9b in Docker: http://lcamtuf.coredump.cx/p0f3/#
50K+
Fixes:
1 Sets up p0f to listen in promiscuous mode (-p argument) - otherwise it just listens to the local docker traffic - surely not what you want. Doh.
2 Adds the fingerprint file p0f.fp (-f) to the command line so that the latest fingerprint file is implicitly used with a full path
3 Most critically - Actually finds the correct interface!! All other implementations of this I've seen just look for ^2, i.e. the interface that starts with number 2, however, that could be anything, and depending on how you set up your host and Docker image, again, repeat potentially anything.
So... this prints the default route, finds the interface used for that default route, as it's what all the traffic will be sent on, and then listens on that default route's interface.
Not that magic really, but, reliable and dependable and.. consistently works!
I'm using this on an UNRAID, but it should work on most Linux based platforms. I will try and turn this in to an automated build (i.e. link to GItHub) for full disclosure.
The base is using Alpine at the moment.
Any comments/questions please send over.
Cheers
Content type
Image
Digest
Size
3.6 MB
Last updated
almost 8 years ago
docker pull niavasha/p0f