
CVE-1999-0524(ICMP 타임스탬프 노출)를 탐지하기 위한 정찰 도구로, nping 또는 hping3를 통해 타임스탬프 추출을 자동화합니다. 원시 ICMP 타임스탬프를 사람이 읽을 수 있는 원격 시스템 시간으로 변환하여 취약점 검증에 사용합니다.
CVE-1999-0524 취약점(ICMP 타임스탬프 정보 공개)을 탐지하고 시연하기 위한 스크립트 모음입니다.
이 도구들은 조작된 ICMP Type 13(타임스탬프 요청) 패킷을 전송하고 응답을 분석하여 원격 시스템 시간 정보를 추출합니다.
nping(권장) 및 hping3(Bash) 지원ICMP-Timestamp.ps1 — PowerShell (Windows)icmp_timestamp_scanner.sh — Bash (Linux)PATH에 nping(Nmap에서 제공) 필요단일 대상 스캔
.\ICMP-Timestamp.ps1 -Targets "example.com"
여러 대상 스캔 (쉼표로 구분)
.\ICMP-Timestamp.ps1 -Targets "example.com","192.168.1.1","target.domain.com"
파일에서 대상 스캔
.\ICMP-Timestamp.ps1 -TargetFile "targets.txt"
더 빠른 스캔을 위해 ping 테스트 건너뛰기
.\ICMP-Timestamp.ps1 -TargetFile "targets.txt" -SkipPingTest
사용자 지정 타임아웃 (밀리초)
.\ICMP-Timestamp.ps1 -TargetFile "targets.txt" -TimeoutMs 5000
nping 또는 hping3sudo 권한 (ICMP 전송에 필요)실행 가능하게 만들기
chmod +x icmp_timestamp_scanner.sh
단일 대상 스캔
sudo ./icmp_timestamp_scanner.sh -i example.com
여러 대상 스캔 (쉼표로 구분)
sudo ./icmp_timestamp_scanner.sh -l "example.com,192.168.1.1,target.domain.com"
sudo ./icmp_timestamp_scanner.sh -f targets.txt
sudo ./icmp_timestamp_scanner.sh -f targets.txt
ping 테스트 건너뛰기 (더 빠름)
sudo ./icmp_timestamp_scanner.sh -f targets.txt -p
nping 대신 hping3 사용
sudo ./icmp_timestamp_scanner.sh -f targets.txt -t hping3
사용자 지정 타임아웃 (초)
sudo ./icmp_timestamp_scanner.sh -f targets.txt -w 5
##🖨️ 예제 출력
#################################################
# CVE-1999-0524 - Remote Date Disclosure #
# Multi-Target Enhanced Version #
#################################################
Starting scan of 3 targets...
Processing target: example.com
Host is online
[RESULT] VULNERABLE to CVE-1999-0524
Disclosed remote time: 2023-10-15T07:28:28.065Z
Timestamps - Originate: 0, Receive: 26908065, Transmit: 26908065
Processing target: 192.168.1.1
Host is offline or not responding
Processing target: target.domain.com
Host is online
[RESULT] Not vulnerable to CVE-1999-0524
The target is not disclosing system time via ICMP timestamps
Scan completed.