Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-1999-0524-POC — POC of CVE-1999-0524 | Kitploit
Tools/GitHubGitHub/biontdv/cve-1999-0524-poc
ReconnaissanceVulnerability AnalysisExploitationInformation GatheringNetwork SecurityPenetration Testing
GitHubbiontdv/cve-1999-0524-poc

CVE-1999-0524-POC

POC of CVE-1999-0524

View Repository
152 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ICMP Timestamp Scanner — CVE-1999-0524

╔══════════════════════════════════════════════════════════════════╗
║  ██╗ ██████╗███╗   ███╗██████╗     ████████╗███████╗           ║
║  ██║██╔════╝████╗ ████║██╔══██╗       ██╔══╝██╔════╝           ║
║  ██║██║     ██╔████╔██║██████╔╝       ██║   ███████╗           ║
║  ██║██║     ██║╚██╔╝██║██╔═══╝        ██║   ╚════██║           ║
║  ██║╚██████╗██║ ╚═╝ ██║██║            ██║   ███████║           ║
║  ╚═╝ ╚═════╝╚═╝     ╚═╝╚═╝            ╚═╝   ╚══════╝           ║
╠══════════════════════════════════════════════════════════════════╣
║   CVE-1999-0524 · ICMP Timestamp Request/Reply Scanner          ║
║   Author  : Muhamad Bion Tadavi — VPSI                          ║
║   Org     : Vantage Point Security — Authorized Use Only        ║
╚══════════════════════════════════════════════════════════════════╝

Python License Root Required Platform Authorized Use

Fast, multi-threaded ICMP Timestamp scanner with color-coded hex output and detailed timestamp analysis.


Overview

Detects hosts vulnerable to CVE-1999-0524 (ICMP Timestamp Information Disclosure) by sending ICMP Type 13 (Timestamp Request) packets. Hosts that reply with ICMP Type 14 (Timestamp Reply) are flagged as vulnerable — they leak their internal system clock, which aids device fingerprinting and time-based attack chaining.

Built with zero external dependencies — pure Python stdlib.


Vulnerability Details

FieldValue
CVE IDCVE-1999-0524
CWECWE-200 — Exposure of Sensitive Information
CVSS v30.0 (Low)
TypeInformation Disclosure
ProtocolICMP Type 13 / Type 14
AffectedCisco IOS, Cisco ASA, Linux, Windows (config-dependent)

How It Works

Attacker                                  Target
   │                                         │
   │──── ICMP Type 13 (Timestamp Request) ──▶│
   │                                         │  [host processes request]
   │◀─── ICMP Type 14 (Timestamp Reply) ─────│
   │                                         │
   Reply contains three 32-bit timestamp fields (ms since midnight UTC):
      ├── Originate Timestamp  (set by requester — often 0)
      ├── Receive Timestamp    ◀── server clock leaked here
      └── Transmit Timestamp   ◀── server clock leaked here

Impact

  • System time disclosure — leaks internal clock (ms since midnight UTC)
  • Device fingerprinting — TTL + response behavior reveals vendor (Cisco ASA, IOS, etc.)
  • Attack chaining — accurate server time assists in forging time-based tokens, TOTP analysis, or log correlation

Features

FeatureDetail
Multi-threaded scanningConfigurable parallel probes (default: 30 threads)
Flexible inputSingle IP · Comma-separated · CIDR range · File (-t / -f)
Color-coded hexIP header · ICMP header · Type byte · Timestamps — each uniquely colored
Timestamp decodeRaw milliseconds decoded to HH:MM:SS.mmm UTC
Hex evidence in summaryColored hex + legend printed per vuln host in final summary
Full hex dump (-v)Offset + hex + ASCII columns for each response
Progress bar (-v)Live progress bar displayed only in verbose mode
Summary tableSorted vulnerable host table with TTL, RTT, and server time
Zero dependenciesPure Python stdlib — no pip install required

Requirements

  • Python 3.8+
  • Root / sudo privileges (required for raw ICMP socket)
  • No external libraries
python3 --version   # must be 3.8+

Installation

git clone https://github.com/<your-username>/CVE-1999-0524-ICMP-Timestamp-Scanner.git
cd CVE-1999-0524-ICMP-Timestamp-Scanner
chmod +x icmp_timestamp_scan.py

Usage

sudo python3 icmp_timestamp_scan.py [OPTIONS]

Options:
  -t, --target    IP, comma-separated IPs, or CIDR  (terminal input)
  -f, --file      Path to file with one IP/CIDR per line
  --timeout SECS  Seconds to wait per host  (default: 2.0)
  --threads N     Concurrent threads        (default: 30)
  -v, --verbose   Show progress bar + full hex dump per host
  -h, --help      Show help

Display Modes

ModeBehavior
Default (no -v)Results printed immediately as each host responds — colored hex + timestamps per host, then summary
Verbose (-v)Live progress bar during scan, then full hex dump per host, then summary

Examples

# Single host
sudo python3 icmp_timestamp_scan.py -t 192.168.1.1

# Multiple hosts
sudo python3 icmp_timestamp_scan.py -t 192.168.1.1,192.168.1.2,192.168.1.3

# CIDR subnet sweep
sudo python3 icmp_timestamp_scan.py -t 192.168.1.0/24

# From file
sudo python3 icmp_timestamp_scan.py -f hosts.txt

# Verbose — progress bar + full hex dump
sudo python3 icmp_timestamp_scan.py -f hosts.txt -v

# Fast wide scan
sudo python3 icmp_timestamp_scan.py -t 10.0.0.0/16 --threads 100 --timeout 1

hosts.txt Format

# One IP or CIDR per line. Lines starting with # are ignored.
192.168.1.1
192.168.1.2
192.168.1.3
10.0.0.1
10.0.0.2
10.0.0.0/24

Sample Output

Default Mode (no -v)

  [*] Targets  : 4 hosts
  [*] Timeout  : 2.0s  |  Threads: 30
  [*] Started  : 2026-07-14 06:37:25 UTC
  [*] Probe    : ICMP Type 13 (Timestamp Request)
  [*] Expect   : ICMP Type 14 (Timestamp Reply) from vulnerable hosts

╔══ VULNERABLE ══════════════════════════════════════════╗
║  Host       : 192.168.1.1
║  ICMP Type  : 14 — Timestamp Reply  (sent Type 13)
║  TTL        : 59
║  RTT        : 1.84 ms
║  ── Timestamps (ms since midnight UTC) ──────────────
║  Originate  :            0 ms  →  00:00:00.000 (not set)
║  Receive    :   22,974,518 ms  →  06:22:54.518 UTC
║  Transmit   :   22,974,518 ms  →  06:22:54.518 UTC  ← server time
║  ── Raw Response (hex) ──────────────────────────────
║  45 48 00 28 14 76 00 00 3b 01 2d 93 c0 a8 01 01 c0 a8 01 64 0e 00 f9 15 ...
║  Legend: ██=IP header  ██=ICMP header  ██=ICMP type14  ██=timestamps
╚════════════════════════════════════════════════════════╝

  [-] 192.168.1.2        no response (filtered or not vulnerable)

╔══ VULNERABLE ══════════════════════════════════════════╗
║  Host       : 192.168.1.3
║  TTL        : 59  |  RTT : 2.11 ms
║  Transmit   :   22,977,926 ms  →  06:22:57.926 UTC  ← server time
╚════════════════════════════════════════════════════════╝

══════════════════════════════════════════════════════════════════
  SCAN SUMMARY
══════════════════════════════════════════════════════════════════
  Scanner time  : 2026-07-14 13:37:25 WIB  (06:37:25 UTC)
  Total probed  : 4
  Vulnerable    : 2
  No response   : 2
  Errors        : 0

  ┌─ VULNERABLE HOSTS ────────────────────────────────────────────┐
  │  Host               TTL      RTT      Server Time (UTC)   Transmit ms │
  ├───────────────────────────────────────────────────────────────┤
  │  192.168.1.1         59    1.8ms   06:22:54.518 UTC    22,974,518  │
  │  192.168.1.3         59    2.1ms   06:22:57.926 UTC    22,977,926  │
  └───────────────────────────────────────────────────────────────┘

  ── Hex Evidence ─────────────────────────────────────────────

  [192.168.1.1]  TTL=59  RTT=1.84ms  Server→ 06:22:54.518 UTC
  45 48 00 28 14 76 00 00 3b 01 2d 93 c0 a8 01 01 c0 a8 01 64 0e 00 f9 15 ...
  Legend: ██=IP header  ██=ICMP header  ██=ICMP type14  ██=timestamps

  [192.168.1.3]  TTL=59  RTT=2.11ms  Server→ 06:22:57.926 UTC
  45 48 00 28 1a c3 00 00 3b 01 27 46 c0 a8 01 03 c0 a8 01 64 0e 00 f3 7e ...
  Legend: ██=IP header  ██=ICMP header  ██=ICMP type14  ██=timestamps
Download Tool