
POC of CVE-1999-0524
╔══════════════════════════════════════════════════════════════════╗
║ ██╗ ██████╗███╗ ███╗██████╗ ████████╗███████╗ ║
║ ██║██╔════╝████╗ ████║██╔══██╗ ██╔══╝██╔════╝ ║
║ ██║██║ ██╔████╔██║██████╔╝ ██║ ███████╗ ║
║ ██║██║ ██║╚██╔╝██║██╔═══╝ ██║ ╚════██║ ║
║ ██║╚██████╗██║ ╚═╝ ██║██║ ██║ ███████║ ║
║ ╚═╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═╝ ╚══════╝ ║
╠══════════════════════════════════════════════════════════════════╣
║ CVE-1999-0524 · ICMP Timestamp Request/Reply Scanner ║
║ Author : Muhamad Bion Tadavi — VPSI ║
║ Org : Vantage Point Security — Authorized Use Only ║
╚══════════════════════════════════════════════════════════════════╝
Fast, multi-threaded ICMP Timestamp scanner with color-coded hex output and detailed timestamp analysis.
Detects hosts vulnerable to CVE-1999-0524 (ICMP Timestamp Information Disclosure) by sending ICMP Type 13 (Timestamp Request) packets. Hosts that reply with ICMP Type 14 (Timestamp Reply) are flagged as vulnerable — they leak their internal system clock, which aids device fingerprinting and time-based attack chaining.
Built with zero external dependencies — pure Python stdlib.
| Field | Value |
|---|---|
| CVE ID | CVE-1999-0524 |
| CWE | CWE-200 — Exposure of Sensitive Information |
| CVSS v3 | 0.0 (Low) |
| Type | Information Disclosure |
| Protocol | ICMP Type 13 / Type 14 |
| Affected | Cisco IOS, Cisco ASA, Linux, Windows (config-dependent) |
Attacker Target
│ │
│──── ICMP Type 13 (Timestamp Request) ──▶│
│ │ [host processes request]
│◀─── ICMP Type 14 (Timestamp Reply) ─────│
│ │
Reply contains three 32-bit timestamp fields (ms since midnight UTC):
├── Originate Timestamp (set by requester — often 0)
├── Receive Timestamp ◀── server clock leaked here
└── Transmit Timestamp ◀── server clock leaked here
| Feature | Detail |
|---|---|
| Multi-threaded scanning | Configurable parallel probes (default: 30 threads) |
| Flexible input | Single IP · Comma-separated · CIDR range · File (-t / -f) |
| Color-coded hex | IP header · ICMP header · Type byte · Timestamps — each uniquely colored |
| Timestamp decode | Raw milliseconds decoded to HH:MM:SS.mmm UTC |
| Hex evidence in summary | Colored hex + legend printed per vuln host in final summary |
Full hex dump (-v) | Offset + hex + ASCII columns for each response |
Progress bar (-v) | Live progress bar displayed only in verbose mode |
| Summary table | Sorted vulnerable host table with TTL, RTT, and server time |
| Zero dependencies | Pure Python stdlib — no pip install required |
python3 --version # must be 3.8+
git clone https://github.com/<your-username>/CVE-1999-0524-ICMP-Timestamp-Scanner.git
cd CVE-1999-0524-ICMP-Timestamp-Scanner
chmod +x icmp_timestamp_scan.py
sudo python3 icmp_timestamp_scan.py [OPTIONS]
Options:
-t, --target IP, comma-separated IPs, or CIDR (terminal input)
-f, --file Path to file with one IP/CIDR per line
--timeout SECS Seconds to wait per host (default: 2.0)
--threads N Concurrent threads (default: 30)
-v, --verbose Show progress bar + full hex dump per host
-h, --help Show help
| Mode | Behavior |
|---|---|
Default (no -v) | Results printed immediately as each host responds — colored hex + timestamps per host, then summary |
Verbose (-v) | Live progress bar during scan, then full hex dump per host, then summary |
# Single host
sudo python3 icmp_timestamp_scan.py -t 192.168.1.1
# Multiple hosts
sudo python3 icmp_timestamp_scan.py -t 192.168.1.1,192.168.1.2,192.168.1.3
# CIDR subnet sweep
sudo python3 icmp_timestamp_scan.py -t 192.168.1.0/24
# From file
sudo python3 icmp_timestamp_scan.py -f hosts.txt
# Verbose — progress bar + full hex dump
sudo python3 icmp_timestamp_scan.py -f hosts.txt -v
# Fast wide scan
sudo python3 icmp_timestamp_scan.py -t 10.0.0.0/16 --threads 100 --timeout 1
hosts.txt Format# One IP or CIDR per line. Lines starting with # are ignored.
192.168.1.1
192.168.1.2
192.168.1.3
10.0.0.1
10.0.0.2
10.0.0.0/24
-v) [*] Targets : 4 hosts
[*] Timeout : 2.0s | Threads: 30
[*] Started : 2026-07-14 06:37:25 UTC
[*] Probe : ICMP Type 13 (Timestamp Request)
[*] Expect : ICMP Type 14 (Timestamp Reply) from vulnerable hosts
╔══ VULNERABLE ══════════════════════════════════════════╗
║ Host : 192.168.1.1
║ ICMP Type : 14 — Timestamp Reply (sent Type 13)
║ TTL : 59
║ RTT : 1.84 ms
║ ── Timestamps (ms since midnight UTC) ──────────────
║ Originate : 0 ms → 00:00:00.000 (not set)
║ Receive : 22,974,518 ms → 06:22:54.518 UTC
║ Transmit : 22,974,518 ms → 06:22:54.518 UTC ← server time
║ ── Raw Response (hex) ──────────────────────────────
║ 45 48 00 28 14 76 00 00 3b 01 2d 93 c0 a8 01 01 c0 a8 01 64 0e 00 f9 15 ...
║ Legend: ██=IP header ██=ICMP header ██=ICMP type14 ██=timestamps
╚════════════════════════════════════════════════════════╝
[-] 192.168.1.2 no response (filtered or not vulnerable)
╔══ VULNERABLE ══════════════════════════════════════════╗
║ Host : 192.168.1.3
║ TTL : 59 | RTT : 2.11 ms
║ Transmit : 22,977,926 ms → 06:22:57.926 UTC ← server time
╚════════════════════════════════════════════════════════╝
══════════════════════════════════════════════════════════════════
SCAN SUMMARY
══════════════════════════════════════════════════════════════════
Scanner time : 2026-07-14 13:37:25 WIB (06:37:25 UTC)
Total probed : 4
Vulnerable : 2
No response : 2
Errors : 0
┌─ VULNERABLE HOSTS ────────────────────────────────────────────┐
│ Host TTL RTT Server Time (UTC) Transmit ms │
├───────────────────────────────────────────────────────────────┤
│ 192.168.1.1 59 1.8ms 06:22:54.518 UTC 22,974,518 │
│ 192.168.1.3 59 2.1ms 06:22:57.926 UTC 22,977,926 │
└───────────────────────────────────────────────────────────────┘
── Hex Evidence ─────────────────────────────────────────────
[192.168.1.1] TTL=59 RTT=1.84ms Server→ 06:22:54.518 UTC
45 48 00 28 14 76 00 00 3b 01 2d 93 c0 a8 01 01 c0 a8 01 64 0e 00 f9 15 ...
Legend: ██=IP header ██=ICMP header ██=ICMP type14 ██=timestamps
[192.168.1.3] TTL=59 RTT=2.11ms Server→ 06:22:57.926 UTC
45 48 00 28 1a c3 00 00 3b 01 27 46 c0 a8 01 03 c0 a8 01 64 0e 00 f3 7e ...
Legend: ██=IP header ██=ICMP header ██=ICMP type14 ██=timestamps