Quote:
Another possible use is for social engineering. Lets say that you are
scanning your target company and Nmap reports a 'Datavoice TxPORT
PRISM 3000 T1 CSU/DSU 6.22/2.06'. The hacker might now call up the
target pretending to be 'Datavoice support' and discuss some issues
about their PRISM 3000. "We are going to announce a security hole
soon, but first we want all our current customers to install the patch
-- I just mailed it to you ..." Some naive administrators might
assume that only an authorized engineer from Datavoice would know so
much about their CSU/DSU.
http://www.insecure.org/nmap/nmap-fingerprinting-article.html