Sign inSign up

niavasha/p0f

By niavasha

•Updated almost 8 years ago

Implements p0f using 3.0.9b in Docker: http://lcamtuf.coredump.cx/p0f3/#

Image
1

50K+

niavasha/p0f repository overview

Fixes:
1 Sets up p0f to listen in promiscuous mode (-p argument) - otherwise it just listens to the local docker traffic - surely not what you want. Doh.
2 Adds the fingerprint file p0f.fp (-f) to the command line so that the latest fingerprint file is implicitly used with a full path
3 Most critically - Actually finds the correct interface!! All other implementations of this I've seen just look for ^2, i.e. the interface that starts with number 2, however, that could be anything, and depending on how you set up your host and Docker image, again, repeat potentially anything.
So... this prints the default route, finds the interface used for that default route, as it's what all the traffic will be sent on, and then listens on that default route's interface.
Not that magic really, but, reliable and dependable and.. consistently works!
I'm using this on an UNRAID, but it should work on most Linux based platforms. I will try and turn this in to an automated build (i.e. link to GItHub) for full disclosure.
The base is using Alpine at the moment.
Any comments/questions please send over.
Cheers

Tag summary

Content type

Image

Digest

Size

3.6 MB

Last updated

almost 8 years ago

docker pull niavasha/p0f