Mike Frantzen write: "Passive operating system fingerprinting was just
committed to PF which exposes the source host's OS to the filter
language. Powerful policy enforcement is now possible such as
redirecting all older windows boxes to a web site telling them to
upgrade. Or blocking all windows boxes from connecting to mail servers
(damn worms). A writeup can be found at http://www.w4g.org/fingerprinting.html. Please help contribute to the
OS fingerprint database by going to http://lcamtuf.coredump.cx/p0f-help/
and typing in your OS description if it does not recognize your OS."