
POC von CVE-1999-0524
╔══════════════════════════════════════════════════════════════════╗
║ ██╗ ██████╗███╗ ███╗██████╗ ████████╗███████╗ ║
║ ██║██╔════╝████╗ ████║██╔══██╗ ██╔══╝██╔════╝ ║
║ ██║██║ ██╔████╔██║██████╔╝ ██║ ███████╗ ║
║ ██║██║ ██║╚██╔╝██║██╔═══╝ ██║ ╚════██║ ║
║ ██║╚██████╗██║ ╚═╝ ██║██║ ██║ ███████║ ║
║ ╚═╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═╝ ╚══════╝ ║
╠══════════════════════════════════════════════════════════════════╣
║ CVE-1999-0524 · ICMP Timestamp Request/Reply Scanner ║
║ Author : Muhamad Bion Tadavi — VPSI ║
║ Org : Vantage Point Security — Authorized Use Only ║
╚══════════════════════════════════════════════════════════════════╝
Schneller, multithreaded ICMP-Timestamp-Scanner mit farbcodierten Hex-Ausgaben und detaillierter Zeitstempelanalyse.
Erkennt Hosts, die für CVE-1999-0524 (ICMP-Timestamp-Informationsoffenlegung) anfällig sind, indem ICMP Typ 13 (Timestamp-Anfrage)-Pakete gesendet werden. Hosts, die mit ICMP Typ 14 (Timestamp-Antwort) antworten, werden als anfällig markiert – sie geben ihre interne Systemzeit preis, was die Geräteidentifikation und die zeitbasierte Angriffsverkettung unterstützt.
Erstellt ohne externe Abhängigkeiten – reine Python-Standardbibliothek.
| Feld | Wert |
|---|---|
| CVE-ID | CVE-1999-0524 |
| CWE | CWE-200 – Offenlegung sensibler Informationen |
| CVSS v3 | 0.0 (Niedrig) |
| Typ | Informationsoffenlegung |
| Protokoll | ICMP Typ 13 / Typ 14 |
| Betroffen | Cisco IOS, Cisco ASA, Linux, Windows (konfigurationsabhängig) |
Angreifer Ziel
│ │
│──── ICMP Typ 13 (Timestamp-Anfrage) ───▶│
│ │ [Host verarbeitet Anfrage]
│◀─── ICMP Typ 14 (Timestamp-Antwort) ────│
│ │
Die Antwort enthält drei 32-Bit-Zeitstempelfelder (ms seit Mitternacht UTC):
├── Ursprungs-Zeitstempel (vom Anfrager gesetzt – oft 0)
├── Empfangs-Zeitstempel ◀── Serveruhr hier preisgegeben
└── Sende-Zeitstempel ◀── Serveruhr hier preisgegeben
| Funktion | Detail |
|---|---|
| Multithreaded-Scanning | Konfigurierbare parallele Sonden (Standard: 30 Threads) |
| Flexible Eingabe | Einzel-IP · Kommagetrennt · CIDR-Bereich · Datei (-t / -f) |
| Farbcodiertes Hex | IP-Header · ICMP-Header · Typ-Byte · Zeitstempel – jeweils eigene Farbe |
| Zeitstempel-Dekodierung | Rohe Millisekunden in HH:MM:SS.mmm UTC umgewandelt |
| Hex-Beweis in Zusammenfassung | Farbiges Hex + Legende pro anfälligem Host in der Endzusammenfassung |
Vollständiger Hex-Dump (-v) | Offset + Hex + ASCII-Spalten für jede Antwort |
Fortschrittsbalken (-v) | Live-Fortschrittsbalken nur im ausführlichen Modus |
| Zusammenfassungstabelle | Sortierte Tabelle anfälliger Hosts mit TTL, RTT und Serverzeit |
| Keine Abhängigkeiten | Reine Python-Standardbibliothek – kein pip install erforderlich |
python3 --version # muss 3.8+ sein
git clone https://github.com/<your-username>/CVE-1999-0524-ICMP-Timestamp-Scanner.git
cd CVE-1999-0524-ICMP-Timestamp-Scanner
chmod +x icmp_timestamp_scan.py
sudo python3 icmp_timestamp_scan.py [OPTIONEN]
Optionen:
-t, --target IP, kommagetrennte IPs oder CIDR (Terminaleingabe)
-f, --file Pfad zu Datei mit einer IP/CIDR pro Zeile
--timeout SEKS Sekunden pro Host warten (Standard: 2.0)
--threads N Gleichzeitige Threads (Standard: 30)
-v, --verbose Fortschrittsbalken + vollständigen Hex-Dump pro Host anzeigen
-h, --help Hilfe anzeigen
| Modus | Verhalten |
|---|---|
Standard (kein -v) | Ergebnisse werden sofort ausgegeben, sobald ein Host antwortet – farbiges Hex + Zeitstempel pro Host, dann Zusammenfassung |
Ausführlich (-v) | Live-Fortschrittsbalken während des Scans, dann vollständiger Hex-Dump pro Host, dann Zusammenfassung |
# Einzelner Host
sudo python3 icmp_timestamp_scan.py -t 192.168.1.1
# Mehrere Hosts
sudo python3 icmp_timestamp_scan.py -t 192.168.1.1,192.168.1.2,192.168.1.3
# CIDR-Subnetz-Sweep
sudo python3 icmp_timestamp_scan.py -t 192.168.1.0/24
# Aus Datei
sudo python3 icmp_timestamp_scan.py -f hosts.txt
# Ausführlich – Fortschrittsbalken + vollständiger Hex-Dump
sudo python3 icmp_timestamp_scan.py -f hosts.txt -v
# Schneller weiter Scan
sudo python3 icmp_timestamp_scan.py -t 10.0.0.0/16 --threads 100 --timeout 1
hosts.txt-Format# Eine IP oder CIDR pro Zeile. Zeilen, die mit # beginnen, werden ignoriert.
192.168.1.1
192.168.1.2
192.168.1.3
10.0.0.1
10.0.0.2
10.0.0.0/24
-v) [*] Targets : 4 hosts
[*] Timeout : 2.0s | Threads: 30
[*] Started : 2026-07-14 06:37:25 UTC
[*] Probe : ICMP Type 13 (Timestamp Request)
[*] Expect : ICMP Type 14 (Timestamp Reply) from vulnerable hosts
╔══ VULNERABLE ══════════════════════════════════════════╗
║ Host : 192.168.1.1
║ ICMP Type : 14 — Timestamp Reply (sent Type 13)
║ TTL : 59
║ RTT : 1.84 ms
║ ── Timestamps (ms since midnight UTC) ──────────────
║ Originate : 0 ms → 00:00:00.000 (not set)
║ Receive : 22,974,518 ms → 06:22:54.518 UTC
║ Transmit : 22,974,518 ms → 06:22:54.518 UTC ← server time
║ ── Raw Response (hex) ──────────────────────────────
║ 45 48 00 28 14 76 00 00 3b 01 2d 93 c0 a8 01 01 c0 a8 01 64 0e 00 f9 15 ...
║ Legend: ██=IP header ██=ICMP header ██=ICMP type14 ██=timestamps
╚════════════════════════════════════════════════════════╝
[-] 192.168.1.2 no response (filtered or not vulnerable)
╔══ VULNERABLE ══════════════════════════════════════════╗
║ Host : 192.168.1.3
║ TTL : 59 | RTT : 2.11 ms
║ Transmit : 22,977,926 ms → 06:22:57.926 UTC ← server time
╚════════════════════════════════════════════════════════╝
══════════════════════════════════════════════════════════════════
SCAN SUMMARY
══════════════════════════════════════════════════════════════════
Scanner time : 2026-07-14 13:37:25 WIB (06:37:25 UTC)
Total probed : 4
Vulnerable : 2
No response : 2
Errors : 0
┌─ VULNERABLE HOSTS ────────────────────────────────────────────┐
│ Host TTL RTT Server Time (UTC) Transmit ms │
├───────────────────────────────────────────────────────────────┤
│ 192.168.1.1 59 1.8ms 06:22:54.518 UTC 22,974,518 │
│ 192.168.1.3 59 2.1ms 06:22:57.926 UTC 22,977,926 │
└───────────────────────────────────────────────────────────────┘
── Hex Evidence ─────────────────────────────────────────────