
POC de CVE-1999-0524
╔══════════════════════════════════════════════════════════════════╗
║ ██╗ ██████╗███╗ ███╗██████╗ ████████╗███████╗ ║
║ ██║██╔════╝████╗ ████║██╔══██╗ ██╔══╝██╔════╝ ║
║ ██║██║ ██╔████╔██║██████╔╝ ██║ ███████╗ ║
║ ██║██║ ██║╚██╔╝██║██╔═══╝ ██║ ╚════██║ ║
║ ██║╚██████╗██║ ╚═╝ ██║██║ ██║ ███████║ ║
║ ╚═╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═╝ ╚══════╝ ║
╠══════════════════════════════════════════════════════════════════╣
║ CVE-1999-0524 · ICMP Timestamp Request/Reply Scanner ║
║ Author : Muhamad Bion Tadavi — VPSI ║
║ Org : Vantage Point Security — Authorized Use Only ║
╚══════════════════════════════════════════════════════════════════╝
Escáner de sellos de tiempo ICMP rápido y multihilo, con salida hexadecimal codificada por colores y análisis detallado de sellos de tiempo.
Detecta hosts vulnerables a CVE-1999-0524 (divulgación de información de sello de tiempo ICMP) mediante el envío de paquetes ICMP Tipo 13 (Timestamp Request). Los hosts que responden con ICMP Tipo 14 (Timestamp Reply) se marcan como vulnerables — filtran su reloj interno del sistema, lo que facilita el fingerprinting del dispositivo y el encadenamiento de ataques basados en tiempo.
Creado con cero dependencias externas: solo biblioteca estándar de Python.
| Campo | Valor |
|---|---|
| CVE ID | CVE-1999-0524 |
| CWE | CWE-200 — Exposición de información sensible |
| CVSS v3 | 0.0 (Bajo) |
| Tipo | Divulgación de información |
| Protocolo | ICMP Tipo 13 / Tipo 14 |
| Afectados | Cisco IOS, Cisco ASA, Linux, Windows (según la configuración) |
Attacker Target
│ │
│──── ICMP Type 13 (Timestamp Request) ──▶│
│ │ [host processes request]
│◀─── ICMP Type 14 (Timestamp Reply) ─────│
│ │
Reply contains three 32-bit timestamp fields (ms since midnight UTC):
├── Originate Timestamp (set by requester — often 0)
├── Receive Timestamp ◀── server clock leaked here
└── Transmit Timestamp ◀── server clock leaked here
| Característica | Detalle |
|---|---|
| Escaneo multihilo | Sondas paralelas configurables (predeterminado: 30 hilos) |
| Entrada flexible | IP única · Separadas por comas · Rango CIDR · Archivo (-t / -f) |
| Hex codificado por colores | Cabecera IP · Cabecera ICMP · Byte de tipo · Sellos de tiempo: cada uno con un color único |
| Decodificación de sellos de tiempo | Milisegundos sin procesar decodificados a HH:MM:SS.mmm UTC |
| Evidencia hexadecimal en el resumen | Hex coloreado + leyenda impresos por cada host vulnerable en el resumen final |
Volcado hexadecimal completo (-v) | Columnas de offset + hex + ASCII para cada respuesta |
Barra de progreso (-v) | Barra de progreso en vivo que se muestra solo en el modo verboso |
| Tabla de resumen | Tabla ordenada de hosts vulnerables con TTL, RTT y hora del servidor |
| Cero dependencias | Solo biblioteca estándar de Python: no requiere pip install |
python3 --version # must be 3.8+
git clone https://github.com/<your-username>/CVE-1999-0524-ICMP-Timestamp-Scanner.git
cd CVE-1999-0524-ICMP-Timestamp-Scanner
chmod +x icmp_timestamp_scan.py
sudo python3 icmp_timestamp_scan.py [OPTIONS]
Options:
-t, --target IP, comma-separated IPs, or CIDR (terminal input)
-f, --file Path to file with one IP/CIDR per line
--timeout SECS Seconds to wait per host (default: 2.0)
--threads N Concurrent threads (default: 30)
-v, --verbose Show progress bar + full hex dump per host
-h, --help Show help
| Modo | Comportamiento |
|---|---|
Predeterminado (sin -v) | Los resultados se imprimen de inmediato a medida que responde cada host: hex coloreado + sellos de tiempo por host y, después, el resumen |
Verboso (-v) | Barra de progreso en vivo durante el escaneo; luego, volcado hexadecimal completo por host y, por último, el resumen |
# Single host
sudo python3 icmp_timestamp_scan.py -t 192.168.1.1
# Multiple hosts
sudo python3 icmp_timestamp_scan.py -t 192.168.1.1,192.168.1.2,192.168.1.3
# CIDR subnet sweep
sudo python3 icmp_timestamp_scan.py -t 192.168.1.0/24
# From file
sudo python3 icmp_timestamp_scan.py -f hosts.txt
# Verbose — progress bar + full hex dump
sudo python3 icmp_timestamp_scan.py -f hosts.txt -v
# Fast wide scan
sudo python3 icmp_timestamp_scan.py -t 10.0.0.0/16 --threads 100 --timeout 1
hosts.txt# One IP or CIDR per line. Lines starting with # are ignored.
192.168.1.1
192.168.1.2
192.168.1.3
10.0.0.1
10.0.0.2
10.0.0.0/24
-v) [*] Targets : 4 hosts
[*] Timeout : 2.0s | Threads: 30
[*] Started : 2026-07-14 06:37:25 UTC
[*] Probe : ICMP Type 13 (Timestamp Request)
[*] Expect : ICMP Type 14 (Timestamp Reply) from vulnerable hosts
╔══ VULNERABLE ══════════════════════════════════════════╗
║ Host : 192.168.1.1
║ ICMP Type : 14 — Timestamp Reply (sent Type 13)
║ TTL : 59
║ RTT : 1.84 ms
║ ── Timestamps (ms since midnight UTC) ──────────────
║ Originate : 0 ms → 00:00:00.000 (not set)
║ Receive : 22,974,518 ms → 06:22:54.518 UTC
║ Transmit : 22,974,518 ms → 06:22:54.518 UTC ← server time
║ ── Raw Response (hex) ──────────────────────────────
║ 45 48 00 28 14 76 00 00 3b 01 2d 93 c0 a8 01 01 c0 a8 01 64 0e 00 f9 15 ...
║ Legend: ██=IP header ██=ICMP header ██=ICMP type14 ██=timestamps
╚════════════════════════════════════════════════════════╝
[-] 192.168.1.2 no response (filtered or not vulnerable)
╔══ VULNERABLE ══════════════════════════════════════════╗
║ Host : 192.168.1.3
║ TTL : 59 | RTT : 2.11 ms
║ Transmit : 22,977,926 ms → 06:22:57.926 UTC ← server time
╚════════════════════════════════════════════════════════╝
══════════════════════════════════════════════════════════════════
SCAN SUMMARY
══════════════════════════════════════════════════════════════════
Scanner time : 2026-07-14 13:37:25 WIB (06:37:25 UTC)
Total probed : 4
Vulnerable : 2
No response : 2
Errors : 0