Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-1999-0524-POC — POC of CVE-1999-0524 | Kitploit
Tools/GitHubGitHub/biontdv/cve-1999-0524-poc
ReconnaissanceVulnerability AnalysisExploitationInformation GatheringNetwork SecurityPenetration Testing
GitHubbiontdv/cve-1999-0524-poc

CVE-1999-0524-POC

POC of CVE-1999-0524

View Repository
11 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ICMP Timestamp Scanner — CVE-1999-0524

root@kitploit:~
╔══════════════════════════════════════════════════════════════════╗
║  ██╗ ██████╗███╗   ███╗██████╗     ████████╗███████╗           ║
║  ██║██╔════╝████╗ ████║██╔══██╗       ██╔══╝██╔════╝           ║
║  ██║██║     ██╔████╔██║██████╔╝       ██║   ███████╗           ║
║  ██║██║     ██║╚██╔╝██║██╔═══╝        ██║   ╚════██║           ║
║  ██║╚██████╗██║ ╚═╝ ██║██║            ██║   ███████║           ║
║  ╚═╝ ╚═════╝╚═╝     ╚═╝╚═╝            ╚═╝   ╚══════╝           ║
╠══════════════════════════════════════════════════════════════════╣
║   CVE-1999-0524 · ICMP Timestamp Request/Reply Scanner          ║
║   Author  : Muhamad Bion Tadavi — VPSI                          ║
║   Org     : Vantage Point Security — Authorized Use Only        ║
╚══════════════════════════════════════════════════════════════════╝

Python License Root Required Platform Authorized Use

Fast, multi-threaded ICMP Timestamp scanner with color-coded hex output and detailed timestamp analysis.


Overview

Detects hosts vulnerable to CVE-1999-0524 (ICMP Timestamp Information Disclosure) by sending ICMP Type 13 (Timestamp Request) packets. Hosts that reply with ICMP Type 14 (Timestamp Reply) are flagged as vulnerable — they leak their internal system clock, which aids device fingerprinting and time-based attack chaining.

Built with zero external dependencies — pure Python stdlib.


Vulnerability Details

How It Works

root@kitploit:~
Attacker                                  Target
   │                                         │
   │──── ICMP Type 13 (Timestamp Request) ──▶│
   │                                         │  [host processes request]
   │◀─── ICMP Type 14 (Timestamp Reply) ─────│
   │                                         │
   Reply contains three 32-bit timestamp fields (ms since midnight UTC):
      ├── Originate Timestamp  (set by requester — often 0)
      ├── Receive Timestamp    ◀── server clock leaked here
      └── Transmit Timestamp   ◀── server clock leaked here

Impact

  • System time disclosure — leaks internal clock (ms since midnight UTC)
  • Device fingerprinting — TTL + response behavior reveals vendor (Cisco ASA, IOS, etc.)
  • Attack chaining — accurate server time assists in forging time-based tokens, TOTP analysis, or log correlation

Features


Requirements

  • Python 3.8+
  • Root / sudo privileges (required for raw ICMP socket)
  • No external libraries
root@kitploit:~
python3 --version   # must be 3.8+

Installation

root@kitploit:~
git clone https://github.com/<your-username>/CVE-1999-0524-ICMP-Timestamp-Scanner.git
cd CVE-1999-0524-ICMP-Timestamp-Scanner
chmod +x icmp_timestamp_scan.py

Usage

root@kitploit:~
sudo python3 icmp_timestamp_scan.py [OPTIONS]

Options:
  -t, --target    IP, comma-separated IPs, or CIDR  (terminal input)
  -f, --file      Path to file with one IP/CIDR per line
  --timeout SECS  Seconds to wait per host  (default: 2.0)
  --threads N     Concurrent threads        (default: 30)
  -v, --verbose   Show progress bar + full hex dump per host
  -h, --help      Show help

Display Modes

ModeBehavior
Default (no -v)Results printed immediately as each host responds — colored hex + timestamps per host, then summary
Verbose (-v)Live progress bar during scan, then full hex dump per host, then summary

Examples

root@kitploit:~
# Single host
sudo python3 icmp_timestamp_scan.py -t 192.168.1.1

# Multiple hosts
sudo python3 icmp_timestamp_scan.py -t 192.168.1.1,192.168.1.2,192.168.1.3

# CIDR subnet sweep
sudo python3 icmp_timestamp_scan.py -t 192.168.1.0/24

# From file
sudo python3 icmp_timestamp_scan.py -f hosts.txt

# Verbose — progress bar + full hex dump
sudo python3 icmp_timestamp_scan.py -f hosts.txt -v

# Fast wide scan
sudo python3 icmp_timestamp_scan.py -t 10.0.0.0/16 --threads 100 --timeout 1

hosts.txt Format

root@kitploit:~
# One IP or CIDR per line. Lines starting with # are ignored.
192.168.1.1
192.168.1.2
192.168.1.3
10.0.0.1
10.0.0.2
10.0.0.0/24

Sample Output

Default Mode (no -v)

root@kitploit:~
  [*] Targets  : 4 hosts
  [*] Timeout  : 2.0s  |  Threads: 30
  [*] Started  : 2026-07-14 06:37:25 UTC
  [*] Probe    : ICMP Type 13 (Timestamp Request)
  [*] Expect   : ICMP Type 14 (Timestamp Reply) from vulnerable hosts

╔══ VULNERABLE ══════════════════════════════════════════╗
║  Host       : 192.168.1.1
║  ICMP Type  : 14 — Timestamp Reply  (sent Type 13)
║  TTL        : 59
║  RTT        : 1.84 ms
║  ── Timestamps (ms since midnight UTC) ──────────────
║  Originate  :            0 ms  →  00:00:00.000 (not set)
║  Receive    :   22,974,518 ms  →  06:22:54.518 UTC
║  Transmit   :   22,974,518 ms  →  06:22:54.518 UTC  ← server time
║  ── Raw Response (hex) ──────────────────────────────
║  45 48 00 28 14 76 00 00 3b 01 2d 93 c0 a8 01 01 c0 a8 01 64 0e 00 f9 15 ...
║  Legend: ██=IP header  ██=ICMP header  ██=ICMP type14  ██=timestamps
╚════════════════════════════════════════════════════════╝

  [-] 192.168.1.2        no response (filtered or not vulnerable)

╔══ VULNERABLE ══════════════════════════════════════════╗
║  Host       : 192.168.1.3
║  TTL        : 59  |  RTT : 2.11 ms
║  Transmit   :   22,977,926 ms  →  06:22:57.926 UTC  ← server time
╚════════════════════════════════════════════════════════╝

══════════════════════════════════════════════════════════════════
  SCAN SUMMARY
══════════════════════════════════════════════════════════════════
  Scanner time  : 2026-07-14 13:37:25 WIB  (06:37:25 UTC)
  Total probed  : 4
  Vulnerable    : 2
  No response   : 2
  Errors        : 0

  ┌─ VULNERABLE HOSTS ────────────────────────────────────────────┐
  │  Host               TTL      RTT      Server Time (UTC)   Transmit ms │
  ├───────────────────────────────────────────────────────────────┤
  │  192.168.1.1         59    1.8ms   06:22:54.518 UTC    22,974,518  │
  │  192.168.1.3         59    2.1ms   06:22:57.926 UTC    22,977,926  │
  └───────────────────────────────────────────────────────────────┘

  ── Hex Evidence ─────────────────────────────────────────────

  [192.168.1.1]  TTL=59  RTT=1.84ms  Server→ 06:22:54.518 UTC
  45 48 00 28 14 76 00 00 3b 01 2d 93 c0 a8 01 01 c0 a8 01 64 0e 00 f9 15 ...
  Legend: ██=IP header  ██=ICMP header  ██=ICMP type14  ██=timestamps

  [192.168.1.3]  TTL=59  RTT=2.11ms  Server→ 06:22:57.926 UTC
  45 48 00 28 1a c3 00 00 3b 01 27 46 c0 a8 01 03 c0 a8 01 64 0e 00 f3 7e ...
  Legend: ██=IP header  ██=ICMP header  ██=ICMP type14  ██=timestamps

  Impact   : Information Disclosure — server time exposed
  CWE      : CWE-200 Exposure of Sensitive Information
  CVSS v3  : 0.0 (Low) — network access required
  Fix      : Block ICMP type 13 at perimeter ACL/firewall
  Cisco    : access-list <ACL> deny icmp any any 13

Hex Response Anatomy

root@kitploit:~
Byte   Field              Example      Description
─────  ─────────────────  ───────────  ──────────────────────────────────────
 0     IP Version/IHL     45           IPv4, header length = 20 bytes
 1     DSCP/ECN           48
 2-3   Total Length       0028         40 bytes
 4-5   Identification     1476
 6-7   Flags/Fragment     0000
 8     TTL                3b           59 hops
 9     Protocol           01           ICMP
10-11  IP Checksum        2d93
12-15  Source IP          c0a80101     192.168.1.1  ← responding host
16-19  Destination IP     c0a80164     192.168.1.100  ← scanner
──── ICMP header starts at byte 20 ────────────────────────────────────────
20     ICMP Type          0e           14 = Timestamp Reply  ← VULNERABLE
21     ICMP Code          00
22-23  ICMP Checksum      f915
24-25  Identifier         d5bf
26-27  Sequence Number    0001
28-31  Originate TS       00000000     0 ms (requester field, not filled)
32-35  Receive TS         015e9036     22,974,518 ms = 06:22:54 UTC  ← leaked
36-39  Transmit TS        015e9036     22,974,518 ms = 06:22:54 UTC  ← leaked

Remediation

Cisco IOS / IOS XE

root@kitploit:~
ip access-list extended BLOCK-ICMP-TS
 deny icmp any any 13
 deny icmp any any 17
 permit ip any any
!
interface GigabitEthernet0/0
 ip access-group BLOCK-ICMP-TS in

Cisco ASA

root@kitploit:~
access-list OUTSIDE_IN deny icmp any any 13
access-list OUTSIDE_IN deny icmp any any 17
access-group OUTSIDE_IN in interface outside

Linux — iptables

root@kitploit:~
iptables -A INPUT  -p icmp --icmp-type timestamp-request -j DROP
iptables -A OUTPUT -p icmp --icmp-type timestamp-reply   -j DROP

Linux — nftables

root@kitploit:~
nft add rule inet filter input  icmp type timestamp-request drop
nft add rule inet filter output icmp type timestamp-reply   drop

Windows Firewall

root@kitploit:~
netsh advfirewall firewall add rule `
  name="Block ICMP Timestamp Request" `
  protocol=icmpv4:13,any action=block dir=in

References

  • CVE-1999-0524 — NVD
  • RFC 792 — ICMP (Type 13/14 specification)
  • CWE-200 — Exposure of Sensitive Information
  • Nessus Plugin 10114 — ICMP Timestamp Request Remote Date Disclosure

Legal Disclaimer

This tool is intended solely for authorized penetration testing engagements, security research, and educational purposes.
Running this tool against any system without explicit written permission from the system owner is illegal and may violate computer crime laws in your jurisdiction.
The author and Vantage Point Security assume no liability for any misuse of this tool.


Made with ♥ by Muhamad Bion Tadavi — Vantage Point Security (VPSI)

Download Tool
FieldValue
CVE IDCVE-1999-0524
CWECWE-200 — Exposure of Sensitive Information
CVSS v30.0 (Low)
TypeInformation Disclosure
ProtocolICMP Type 13 / Type 14
AffectedCisco IOS, Cisco ASA, Linux, Windows (config-dependent)
FeatureDetail
Multi-threaded scanningConfigurable parallel probes (default: 30 threads)
Flexible inputSingle IP · Comma-separated · CIDR range · File (-t / -f)
Color-coded hexIP header · ICMP header · Type byte · Timestamps — each uniquely colored
Timestamp decodeRaw milliseconds decoded to HH:MM:SS.mmm UTC
Hex evidence in summaryColored hex + legend printed per vuln host in final summary
Full hex dump (-v)Offset + hex + ASCII columns for each response
Progress bar (-v)Live progress bar displayed only in verbose mode
Summary tableSorted vulnerable host table with TTL, RTT, and server time
Zero dependenciesPure Python stdlib — no pip install required