eBay Suspension & PayPal Limited Forums  
Join Today
Register Subscribe
     

Registration is fast, simple and absolutely free so please, join our community today!


Go Back   Home

eBay Suspended & PayPal Limited Forums

eBay Suspended & PayPal Limited Forums (https://www.aspkin.com/forums/)
-   PayPal Talk (https://www.aspkin.com/forums/paypal-talk/)
-   -   MAC address detection by eb/pp.. Possible? (https://www.aspkin.com/forums/paypal-talk/95347-mac-address-detection-eb-pp-possible.html)

PolMart 04-08-2016 12:14 PM

MAC address detection by eb/pp.. Possible?
 
Found an old thread from 2012 that all participants agree this is not possible..

Would like to have an updated input on the matter by members..

Has eb/pp technology/techniques progressed that far so they are today able to detect their users mac address?

ilcarletto 04-08-2016 12:18 PM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by PolMart (Post 761275)
Has eb/pp technology/techniques progressed that far so they are today able to detect their users mac address?

No absolutely no. They can't see your MAC address.

mtproducts 04-08-2016 12:18 PM

Re: MAC address detection by eb/pp.. Possible?
 
Nope not MAC detection, as yet. :) :amen:

iloveghosts 05-24-2018 08:51 AM

Re: MAC address detection by eb/pp.. Possible?
 
Yes. It's possible to get your MAC with following scenarios.

1. Internet Explorer ActiveX
2. Flash & Silverlight
3. Weak Windows Passwords also allows anyone to get your mac address remotely using Powershell Commands. Assume you are using the same password for both PayPal and Windows. If they wanted, they can use your password to get this mac using PowerShell.

iloveghosts 05-24-2018 08:54 AM

Re: MAC address detection by eb/pp.. Possible?
 
I want to add another method. There is another way to get this using Bruteforcing but this requires a lot of computer power.

Lastly, Some advertisers can see your mac address when you log in to manage the router. This depends on your ISP. I do not think they share that info with PayPal. I just talking about possibilities.

yankee 05-24-2018 08:59 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by iloveghosts (Post 921763)
Yes. It's possible to get your MAC with following scenarios.

1. Internet Explorer ActiveX
2. Flash & Silverlight
3. Weak Windows Passwords also allows anyone to get your mac address remotely using Powershell Commands. Assume you are using the same password for both PayPal and Windows. If they wanted, they can use your password to get this mac using PowerShell.

Do you work for the government or hide from the government?

aspkin 05-24-2018 10:31 AM

Re: MAC address detection by eb/pp.. Possible?
 
The thing is we access these "WEBSITES" using a web browser. The apps/plugins that were weak before are generally not used anymore because people could learn more about you than what is allowed by your web browser.

Your web browser protects you believe it or not. Now if you use a web app or mobile app, those are not web browsers.. those generally give a lot more information about you away.

Currently, unless you purposely give away permission, mac address is not given away by your web browser.

iloveghosts 05-24-2018 11:04 AM

Re: MAC address detection by eb/pp.. Possible?
 
:attention:
Quote:

Originally Posted by aspkin (Post 921800)
The thing is we access these "WEBSITES" using a web browser. The apps/plugins that were weak before are generally not used anymore because people could learn more about you than what is allowed by your web browser.

Your web browser protects you believe it or not. Now if you use a web app or mobile app, those are not web browsers.. those generally give a lot more information about you away.

Currently, unless you purposely give away permission, mac address is not given away by your web browser.

I know that these plugins not enabled by default, but some people tend to click on it and enable on some sites and there are flash exploits that begin sold by Zerodium to companies.

I know one exploit being used by Iovation, that they use flash and inject DLL into your system and that DLL gather everything from hard drive to mac.

iloveghosts 05-24-2018 11:05 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by yankee (Post 921767)
Do you work for the government or hide from the government?


I have a PhD in browser fingerprinting.

nate 05-24-2018 11:08 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by iloveghosts (Post 921821)
I have a PhD in browser fingerprinting.

What was you old username? MLADen?

He wrote more elegantly than you do though.

iloveghosts 05-24-2018 11:10 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by nate (Post 921823)
What was you old username? MLADen?

He wrote more elegantly than you do though.

I do not remember it either.

nate 05-24-2018 11:14 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by iloveghosts (Post 921825)
I do not remember it either.

That was a joke... He's the one who created the Canvas Fingerprint Chrome addon.

You said you had a PHD in browser fingerprinting....

iloveghosts 05-24-2018 11:22 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by nate (Post 921827)
That was a joke... He's the one who created the Canvas Fingerprint Chrome addon.

You said you had a PHD in browser fingerprinting....

That addon produces ⊗⊗⊗⊗ canvas fingerprint that easily can be analyzed and mark as ⊗⊗⊗⊗.

I did not make any add-ons, but most canvas add-ons are produced ⊗⊗⊗⊗ canvas which not looks real to analytic systems.

aspkin 05-24-2018 11:41 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by iloveghosts (Post 921820)
:attention:

I know that these plugins not enabled by default, but some people tend to click on it and enable on some sites and there are flash exploits that begin sold by Zerodium to companies.

I know one exploit being used by Iovation, that they use flash and inject DLL into your system and that DLL gather everything from hard drive to mac.

It's good that we tell people not to do that not only in eBay Stealth but throughout this forum. This is a non issue.

BiN4RY 05-24-2018 01:19 PM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by iloveghosts (Post 921763)
1. Internet Explorer ActiveX

ActiveX is more or less dead at this point, so this is not something to be worried about.

Quote:

Originally Posted by iloveghosts (Post 921763)
2. Flash & Silverlight

No, you cannot get MAC address from either of these.

Quote:

Originally Posted by iloveghosts (Post 921763)
3. Weak Windows Passwords also allows anyone to get your mac address remotely using Powershell Commands. Assume you are using the same password for both PayPal and Windows. If they wanted, they can use your password to get this mac using PowerShell.

This is also a nonissue. Knowing your user password is only one of a hundred steps needed for someone to maliciously access your terminal remotely.


People need to understand that MAC address is a link layer address. This is a network layer lower than the IP layer, and no web applications running exclusively on the IP layer and above can see anything below it under normal circumstances.

iloveghosts 05-24-2018 01:46 PM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by BiN4RY (Post 921868)
ActiveX is more or less dead at this point, so this is not something to be worried about.



No, you cannot get MAC address from either of these.



This is also a nonissue. Knowing your user password is only one of a hundred steps needed for someone to maliciously access your terminal remotely.


People need to understand that MAC address is a link layer address. This is a network layer lower than the IP layer, and no web applications running exclusively on the IP layer and above can see anything below it under normal circumstances.

You need to understand that you have to go into School. There are many Flash & Silverlight tricks to get your mac address, hard drive id, as well as there, are zero-day exploits that can escape browser sandbox and do anything.

[1] http://consideredharmful.info/papers...%20Monster.pdf

This [1] article shows how they use Flash and Silverlight to access Mac


[2] https://krebsonsecurity.com/

Brian Krebs everyday post news about Flash, Silverlight exploits. You can follow him.

iloveghosts 05-24-2018 01:51 PM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by BiN4RY (Post 921868)
ActiveX is more or less dead at this point, so this is not something to be worried about.



No, you cannot get MAC address from either of these.



This is also a nonissue. Knowing your user password is only one of a hundred steps needed for someone to maliciously access your terminal remotely.


People need to understand that MAC address is a link layer address. This is a network layer lower than the IP layer, and no web applications running exclusively on the IP layer and above can see anything below it under normal circumstances.

Passwords can get using brute force. Nowadays people brute-force even your card details so it's not surprising.

MAC address is not a big thing. so no software company cares. Nowadays you can view your mac address from xnfiity.com and you may able to see third-party scripts loaded on xnfitiy.com grab and record everything.

iloveghosts 05-24-2018 01:53 PM

Re: MAC address detection by eb/pp.. Possible?
 
I hate when people say no to everyone. Everything is possible, and I posted options that can be used to get this MAC address. I also mentioned that PayPal unlikely do illegal things to get this mac.

dallis 05-24-2018 04:10 PM

Re: MAC address detection by eb/pp.. Possible?
 
I have a PhD in browser fingerprinting.

There's no such degree. Why don't you post your doctoral dissertation. We'd all LOVE to read it. :)

And your diploma too, we'd love to see that "Browser Fingerprinting Doctorate" of yours. :)

To the OP, no, they don't see your MAC address. Otherwise we'd all be toast, wouldn't we?

MM78 05-24-2018 04:16 PM

Re: MAC address detection by eb/pp.. Possible?
 
LOL, Now iloveghosts is on this thread.

BiN4RY 05-25-2018 01:45 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by iloveghosts (Post 921873)
You need to understand that you have to go into School. There are many Flash & Silverlight tricks to get your mac address, hard drive id, as well as there, are zero-day exploits that can escape browser sandbox and do anything.

[1] http://consideredharmful.info/papers...%20Monster.pdf

This [1] article shows how they use Flash and Silverlight to access Mac


[2] https://krebsonsecurity.com/

Brian Krebs everyday post news about Flash, Silverlight exploits. You can follow him.

What this post actually translates to:

"I have absolutely no idea what I'm talking about, so I'm going to pretend to know what I'm saying by berating others and linking a generic paper on some completely unrelated topic, as well as the homepage to some popular security website but not any particular articles".

FYI, a quick ctrl+f on "silverlight" and "MAC" returned literal results on that paper of yours. Good job reading your own sources before even posting it.

Quote:

Originally Posted by iloveghosts (Post 921874)
Passwords can get using brute force. Nowadays people brute-force even your card details so it's not surprising.

lmao no, nobody brute forces CC numbers or passwords across a network. You'll get IP banned after only a few tries, and the number of possible combinations would take you years to even count to.

Quote:

Originally Posted by iloveghosts (Post 921874)
Nowadays you can view your mac address from xnfiity.com and you may able to see third-party scripts loaded on xnfitiy.com grab and record everything.

Hmm, your ISP knows the MAC address of the modem/router they provided for you that forms a direct connection to your house. Yeah I have NO IDEA how they can possibly know the MAC address.

Quote:

Originally Posted by iloveghosts (Post 921875)
I hate when people say no to everyone. Everything is possible, and I posted options that can be used to get this MAC address. I also mentioned that PayPal unlikely do illegal things to get this mac.

Then maybe should step down your ⊗⊗⊗⊗ high horse and stop being so pretentious first? You have absolutely no idea what you're talking about, you're just assuming how technology works. Funny how you're telling others to go back to school :lol:

Before you post anything else purely out of uneducated specualtions, go read about the OSI network models first and learn how the different networking layers work with each other. When you're done, try answering these questions to check your understandings:

Which network layer is the MAC address used in, and why is it needed?

What networking layer would Javascript/Silverlight/Flash reside in, and (roughly speaking) what functionalities do they provide?

How would knowing the user's MAC address be helpful in any way or form for its intended purposes provided by Javascript/Silverlight/Flash? (Hint: it doesn't.)

iloveghosts 05-25-2018 02:10 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by BiN4RY (Post 922004)
What this post actually translates to:

"I have absolutely no idea what I'm talking about, so I'm going to berate others by linking a generic paper on some completely unrelated topic, as well as the homepage to some generic security research website but not any articles".

FYI, a quick ctrl+f on "silverlight" and "MAC" returned literal results on that paper of yours. Good job reading your own sources before even posting it.



lmao no, nobody brute forces CC numbers or passwords across a network. You'll get IP banned after only a few tries.



Hmm, your ISP knows the MAC address of the modem/router they provided for you that forms a direct connection to your house. Yeah I have NO IDEA how they can possibly know the MAC address.



Then maybe should step down your ⊗⊗⊗⊗ high horse and stop being so pretentious first? You have absolutely no idea what you're talking about, you're just assuming how technology works. Funny how you're telling others to go back to school :lol:

Before you post anything else purely out of uneducated specualtions, go read about the OSI network models first and learn how the different networking layers work with each other.



1.https://techcrunch.com/2016/12/05/a-...n-six-seconds/

2. That's why we have proxies to prevent IP ban.

3. Yes, there are countries where you can do Ph.D. in Browser Fingerprinting. I have more degrees than this one.

4. You are lazy, CTRL+F does not work 100% on PDF's.


Windows Registry (SFP) - BLUECAVA
MSIE Product key (SFP) - Iovation ReputationManager
OS & kernel version (Flash) - ThreatMetrix
ActiveX + 6 CLSIDs (JS) - ThreatMetrix
kernel version (Flash) - ThreatMetrix


A part of that researcher paper which describes DLL Injection through Flash/Silverlight :

Nikiforakis et al. found that some vendors (BlueCava and Iovation) attempted
to gain additional information about “deeper” layers of the user’s system. This was achieved through special plugins, which were distributed with (and able to invoke) DLLs that function essentially as native fingerprinting libraries. These libraries have access to a great amount of information about the user’s system, and are able to reveal information belonging to layers “below” the user’s browser – including but not limited to hardware identifiers, machine name, Windows installation date and Digital Product Id, installed system drivers and so forth. While this highly intrusive method requires the
user to “opt-in” at some point (as the plugins have to be installed first), it is possible to bundle them with “desired” software (as has been done with e. g. browser toolbars in the past) and thereby place
them onto a user’s system. Nikiforakis et al. furthermore found that the plugins may attempt to conceal their purpose (by identifying themselves as “identity shields” or similar, which is only technically true), casting this practice in a very questionable light. (cf. Nikiforakis et al. 2013 p. 5) However, the information obtained through these plugins is highly machine-specific (possibly unique) and likely to change frequently and is therefore extremely useful for fingerprinting.



I told everyone this method only works if you click "ALLOW ACCESS TO FLASH OR SILVERLIGHT" otherwise these methods not works.


Your ISP knows MAC address of every device that connected to a router and this includes NetBIOS Name (Your computer name), Computer Model, Running OS too.


If you want to prevent ISP leak, just use extended wifi router. This way ISP can't get your devices MAC's, they only able to get MAC of extended wifi router.


There are browser exploits including VM Escape begin sold by Zerodium to Government's and companies which can be used to infect your system with a virus. So anyone who has access to special exploits can view your mac address and hack into your computer. It's not a big mystery, and man you have no idea what you talking about. The Brian Krebs clearly mentioned on his blog about Flash/Silverlight exploits that were used to infect your computers with a virus and other dozens of proposes. So it's 100% possible to get MAC anyway but PayPal not willing to use Illegal exploits to get this, PayPal only able to get this with your own permission or ISP like Comcast share data with advertising companies then PayPal can use them too.

iloveghosts 05-25-2018 02:20 AM

Re: MAC address detection by eb/pp.. Possible?
 
How would knowing the user's MAC address be helpful in any way or form for its intended purposes provided by Javascript/Silverlight/Flash? (Hint: it doesn't.)

- Flash/Silverlight are only used to Inject DLL into your system, and that DLL can go to a deeper level of your system to get everything from MAC to windows registry. You can't get MAC address solely through Flash/Silverlight, that's why they use some Flash Functionalities to Inject DLL into your system.

- JS has exploits too, Look at recent Intel exploits that gone wild over the web.

https://react-etc.net/entry/exploiti...via-javascript

- https://www.theregister.co.uk/2018/0...vulnerability/


Anyways, DLL gather all info about hardware information, not just MAC and this can be used to track you easily. That's all it about!

iloveghosts 05-25-2018 02:23 AM

Re: MAC address detection by eb/pp.. Possible?
 
I do not think there are still dumb people who do IP ban. They use fingerprinting too because IP's are dynamic and innocent users will have impact from this.

BiN4RY 05-25-2018 02:29 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by iloveghosts (Post 922013)
1.https://techcrunch.com/2016/12/05/a-...n-six-seconds/

2. That's why we have proxies to prevent IP ban.

And what exactly does this have anything to do with a website being able to find your MAC address exactly?

Quote:

Originally Posted by iloveghosts (Post 922013)
3. Yes, there are countries where you can do Ph.D. in Browser Fingerprinting. I have more degrees than this one.

And I'm the king of Nigeria, among with several other thrones in the world.

Quote:

Originally Posted by iloveghosts (Post 922013)
4. You are lazy, CTRL+F does not work 100% on PDF's

That PDF is entirely searchable. You just didn't even bother reading what you linked, as the keywords "MAC" and "silverlight" were simply not mentioned at all.

Quote:

Originally Posted by iloveghosts (Post 922013)
Windows Registry (SFP) - BLUECAVA
MSIE Product key (SFP) - Iovation ReputationManager
OS & kernel version (Flash) - ThreatMetrix
ActiveX + 6 CLSIDs (JS) - ThreatMetrix
kernel version (Flash) - ThreatMetrix

What exactly are these? Googling these exact lines yields nothing.

Quote:

Originally Posted by iloveghosts (Post 922013)
A part of that researcher paper which describes DLL Injection through Flash/Silverlight :

[omitted]

And once again, what does any of this anything to do with your MAC address being seeable by websites under normal circumstances? Security exploits within application frameworks has nothing to do with regular website tracking, and hackers have much better uses for them than trying to figure out what your MAC address is (at the risk of having a zero-day exploit being discovered and patched).

Quote:

Originally Posted by iloveghosts (Post 922016)
I do not think there are still dumb people who do IP ban. They use fingerprinting too because IP's are dynamic and innocent users will have impact from this.

By your logic, you're literally calling every single server host dumb. Banning IPs (usually for an extended period of time) is simply the most straightforward and effective way to mitigate malicious network activities.

The firewall in your very own router in your house even bans remote IPs to mitigate potential attacks such as packet flooding, if it detects such pattern of activity. Are you also calling yourself dumb in this case?

iloveghosts 05-25-2018 02:45 AM

Re: MAC address detection by eb/pp.. Possible?
 
For those who think Canvas Add-ons can fix Canvas Problems, Check this http://kkapsner.github.io/CanvasBloc...ctionTest.html

iloveghosts 05-25-2018 02:53 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by BiN4RY (Post 922018)
And what exactly does this have anything to do with a website being able to find your MAC address exactly?



And I'm the king of Nigeria, among with several other thrones in the world.



That PDF is entirely searchable. You just didn't even bother reading what you linked, as the keywords "MAC" and "silverlight" were simply not mentioned at all.



What exactly are these? Googling these exact lines yields nothing.



And once again, what does any of this anything to do with your MAC address being seeable by websites under normal circumstances? Security exploits within application frameworks has nothing to do with regular website tracking, and hackers have much better uses for them than trying to figure out what your MAC address is (at the risk of having a zero-day exploit being discovered and patched).



By your logic, you're literally calling every single server host dumb. Banning IPs (usually for an extended period of time) is simply the most straightforward and effective way to mitigate malicious network activities.

The firewall in your very own router in your house even bans remote IPs to mitigate potential attacks such as packet flooding, if it detects such pattern of activity. Are you also calling yourself dumb in this case?


I have never seen such an ignorant ever in my life. We live in 21 century with ML solutions. There are ML solutions that detect and block attacks without banning IP's. Machine Learning is powerful, Nowadays people copy your face and voice with machine learning. (Deep⊗⊗⊗⊗).

Keywords MAC and Silverlight not mentioned on that paper, because they used an alternative paragraph to describe the working of that company in lengthy. Do you think researchers use Simple Words to describe everything? It will be not a research paper based on your logic.

Refer :

"are able to reveal information belonging to layers “below” the user’s browser –
including but not limited to hardware identifiers, machine name, Windows installation date and Digital Product Id, installed system drivers and so forth. "



Learn how to read Doctor. Nigerian Prince!

iloveghosts 05-25-2018 03:00 AM

Re: MAC address detection by eb/pp.. Possible?
 
Originally Posted by iloveghosts View Post
Windows Registry (SFP) - BLUECAVA
MSIE Product key (SFP) - Iovation ReputationManager
OS & kernel version (Flash) - ThreatMetrix
ActiveX + 6 CLSIDs (JS) - ThreatMetrix
kernel version (Flash) - ThreatMetrix


What exactly are these? Googling these exact lines yields nothing.


Answer - You are dumb Canadian who does not listen to other people. You clearly can see what are those if you read that paper or you do not understand about Windows or Flash.

These all are trackers, that gets information from a deeper level of your system,

BLUECAVA tracker use SFP to get Windows Registry, and that article described they also inject DLL to get the more deep level of hardware information using Injected DLL.

iovation ReputationManager use SFP to get MSIE Product key, and that article described they also inject DLL to get the more deep level of hardware information using Injected DLL.


ThreatMetrix use Flash to get OS & kernel version, and Real IP (Demo http://browserleaks.com/flash)

iloveghosts 05-25-2018 03:02 AM

Re: MAC address detection by eb/pp.. Possible?
 
And what exactly does this have anything to do with a website being able to find your MAC address exactly?


- you said that card Bruteforcing is impossible, so I provided you sources that make it possible...

BiN4RY 05-25-2018 03:13 AM

Re: MAC address detection by eb/pp.. Possible?
 
At this point, I'm pretty convinced you're just a troll and this isn't worth my time anymore. I'm not sure what exactly you're trying to accomplish here, but good luck to whatever you're trying to do.

PS: still waiting for you to provide concrete proof on how you can get a MAC address through a website by normal means ;)

iloveghosts 05-25-2018 03:16 AM

Re: MAC address detection by eb/pp.. Possible?
 
What does any of this anything to do with your MAC address being seeable by websites under normal circumstances?

This can be used to track you uniquely across users or make tracking your computer easier. Iovation can track you even you change your OS, Browser.

See page 2 :

https://djnvkv0aa8g5w.cloudfront.net...tion-brief.pdf


Cookies are dead, Now people do not need care about Cookies. Honestly, I do not have access to source codes of Commerical Tracking Companies show you demo but you can contact authors of that research paper.

iloveghosts 05-25-2018 03:17 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by BiN4RY (Post 922027)
At this point, I'm pretty convinced you're just a troll and this isn't worth my time anymore. I'm not sure what exactly you're trying to accomplish here, but good luck to whatever you're trying to do.

PS: still waiting for you to provide concrete proof on how you can get a MAC address through a website by normal means ;)

I'm not trolling anyone. I answered TC Question in more detailed. I'm also tired fighting with you!

iloveghosts 05-25-2018 03:30 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by BiN4RY (Post 922027)
At this point, I'm pretty convinced you're just a troll and this isn't worth my time anymore. I'm not sure what exactly you're trying to accomplish here, but good luck to whatever you're trying to do.

PS: still waiting for you to provide concrete proof on how you can get a MAC address through a website by normal means ;)

I actually came to this forum to ask about fixing TCP fingerprint. I still waiting for someone who can help me out.

BiN4RY 05-25-2018 03:54 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by iloveghosts (Post 922032)
I actually came to this forum to ask about fixing TCP fingerprint. I still waiting for someone who can help me out.

TCP fingerprinting is only useful for inferring what the target OS is, since every implementation of the TCP stack uses different parameters for the packet's header.

Why does this bother you in the first place? Websites can get your OS version easily through trivial means, and the target OS inferred through TCP's header parameters serves no usefulness for further tracking purposes.

iloveghosts 05-25-2018 04:01 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by BiN4RY (Post 922036)
TCP fingerprinting is only useful for inferring what the target OS is, since every implementation of the TCP stack uses different parameters for the packet's header.

Why does this bother you in the first place? Websites can get your OS version easily through trivial means, and the target OS inferred through TCP's header parameters serves no usefulness for further tracking purposes.

it bothers me because of TCP OS Mismatch with Browser Reported OS. I want to modify this. I heard this needed to modify in kernel level. PayPal definitely checks this one.

iloveghosts 05-25-2018 04:02 AM

Re: MAC address detection by eb/pp.. Possible?
 
TCP Fingerprint is still useful and is already used by dozens of companies including PayPal.

iloveghosts 05-25-2018 04:03 AM

Re: MAC address detection by eb/pp.. Possible?
 
TCP leaks Time, Language, Connection Type too not just OS.

BiN4RY 05-25-2018 04:09 AM

Re: MAC address detection by eb/pp.. Possible?
 
Quote:

Originally Posted by iloveghosts (Post 922037)
it bothers me because of TCP OS Mismatch with Browser Reported OS. I want to modify this. I heard this needed to modify in kernel level. PayPal definitely checks this one.

You cannot change these parameters, and these inference does not always accurately identify your OS. You're honestly over-complicating things for yourself, and this isn't something you need to worry about.

If it makes you sleep better, use a virtual machine running the same OS as whatever OS you're trying to spoof.

Quote:

Originally Posted by iloveghosts (Post 922039)
TCP leaks Time, Language, Connection Type too not just OS.

Information like system time and language are not part of the TCP header, thus it's not possible for them to be leaked by TCP itself. If this information does get out, some other networking services running above the transport layer leaked it instead.

rsot 05-25-2018 04:23 AM

Re: MAC address detection by eb/pp.. Possible?
 
Very nice IT talk going on back and forth with the lingo :thumb:

iloveghosts 05-25-2018 04:28 AM

Re: MAC address detection by eb/pp.. Possible?
 
Not true. Check this tool witch.valdikss.org.ru as a demo.

Check this article too : https://wiki.mozilla.org/Fingerprinting

"Clock skew measurement exposed by the operating system at the TCP level"


All times are GMT -5. The time now is 12:48 AM.

vBulletin® Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
Ad Management by RedTyger


All times are GMT -5. The time now is 12:48 AM.


Stop the guessing games and learn how you can quickly and easily get back on eBay today!
Read the best selling step-by-step eBay Suspension guide eBay Stealth!
Rotating Residential Proxies? Head to IPBurger for Residential Proxies
vBulletin® Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
Ad Management by RedTyger