5 ms·
Test if a URL uses Node.js
- hayksaakian 13y agoIf you can't tell if airbnb uses node, I'm note sure it works at all.
- camus2 13y agoI guess it's just checking for some header,like express has a special header... by the way, framework authors, please refrain from doing stuffs like that. The framework i use is nobody's business but mine.
- mihok 13y agoExactly the same sentiment, making me put in extra effort to hide underlying technology seems ridiculous to me.
- scorcher 13y agoYeh, just looks at the header; node activity detected Found x-powered-by: Express header in response
- skyebook 13y ago+1, its the most horrible form of advertising. And also, yes.. it checks headers (just threw up an Express project and got this: http://i.imgur.com/xpyfv0C.png http://i.imgur.com/xpyfv0C.png)
- mattgreenrocks 13y agoIt's also dangerous and irresponsible from a security standpoint. Not advocating security by obscurity, but advertising it doesn't help.
- wlaurance 13y agoI'm not sure what they are using to serve up their site, other than nginx. But they do have this header, "X-Hi-Human: The AIRBNB SRE team added this header. Come work with us! Email dave+header@airbnb.com"
- meritt 13y agoAirBNB is Ruby/RoR and Java.
- laumars 13y agoPretty pointless since all this does is check the x-powered-by HTTP response header (which can be turned off[1]). If this captured other web frameworks as well (eg PHP also outputs to x-powered-by in it's default config) then this might be a little less pointless - but even then, most production sites should have those information leaks sealed anyway (you don't actually improve security, but at least it slows the attacker down a little as you're not spoon-feeding them information about your server build) [1] http://stackoverflow.com/questions/5867199/cant-get-rid-of-header-x-powered-byexpress http://stackoverflow.com/questions/5867199/cant-get-rid-of-h...
- avree 13y agoDoes node even have an x-powered-by response header by default? I thought you need a framework (like Express.js) and then to not have turned off the header.
- wlaurance 13y agoIt checks x-powered-by and Server in some cases. https://github.com/dotheyusenode/dotheyusenode/blob/master/checkers/headers.js#L3 https://github.com/dotheyusenode/dotheyusenode/blob/master/c... It also tries to read through the Javascript served up to see if it uses browserify. https://github.com/dotheyusenode/dotheyusenode/blob/master/checkers/needsjs/browserify.js#L1 https://github.com/dotheyusenode/dotheyusenode/blob/master/c... But yes it is a glorified `curl -I www.foo.com | grep -i 'x-powered-by` UI
- laumars 13y agoTechnically it's more like "curl -i" rather than "-I" since it does a GET request rather than a HEAD request. Which is a good thing as the former is more accurate. There are rare occasions when a web server might be sending wrong headers which get overwritten with the correct headers from the executing code (I think one of OVH's portals suffered from this issue - though that may have since been fixed) You probably might want to stick "-s" in there too; silence the transfer statistics which curl (annoyingly) adds when output is piped / redirected.
- panarky 13y agonodejs.org "Maybe, but we cannot tell"
- wlaurance 13y agoHaha yeah, for anything static not served up by a framework that leaks headers it doesn't really do very well :)
- dylanpyle 13y agoJust a heads up, there's already a handful of private staging/demo server URLs @ http://dotheyusenode.herokuapp.com/cache http://dotheyusenode.herokuapp.com/cache - you may want to reconsider exposing that for the publicly available instance.
- pornel 13y agoI hoped for something smarter, like testing quirks/bugs in the node's HTTP server.
- wlaurance 13y agoPut in a PR! Currently, it is easy to do things with the Request object. Any ideas on what quirks/bugs to look into?
- sisk 13y agoIn addition to the coffeescript / browserify detection, here are the headers it checks[0]: var frameworks = [ {name: 'express.js', s: "express", h: 'x-powered-by'}, {name: 'koa.js', s: 'koa', h: 'x-powered-by'}, {name: 'sails.js', s: "sails", h: 'x-powered-by'}, {name: 'ecstatic', s: 'ecstatic', h: 'server'}, {name: 'flatiron', s: 'flatiron', h: 'x-powered-by'} ] All in all, this should prove relatively inaccurate. A vanilla http server from node sets neither server nor x-powered-by headers. Many frameworks don't set them, either (Walmart's hapi, PayPal's krakenjs, etc). Fun toy project but if you're really interesting in fingerprinting, check out the OWASP entry on the subject[1]. [0]: https://github.com/dotheyusenode/dotheyusenode/blob/ea23561918ba7ae41b8bc88f25bbf7e777e62359/checkers/headers.js#L3-L9 https://github.com/dotheyusenode/dotheyusenode/blob/ea235619... [1]: https://www.owasp.org/index.php/Testing_for_Web_Application_Fingerprint_(OWASP-IG-004) https://www.owasp.org/index.php/Testing_for_Web_Application_...
- wlaurance 13y agoYes, it is just a toy project. It is a lot more work to fingerprint successfully. OWASP looks very interesting. Thanks for the link and subsequently the white paper links!
- deleted 13y ago[deleted]
- ebbv 13y ago"Maybe but we cannot tell." I win!
- Gurrewe 13y agoDoes anyone know if Node.js has any "easter egg" like PHP < 5.5 has? You can simply add ?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 to the URI of most PHP-sites and the server will respond with the PHP-credits [0]. [0]: http://thepiratebay.se/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 http://thepiratebay.se/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C1...
- randunel 13y ago"Maybe, but we cannot tell". Great script, I could build in in node.js in 10 seconds :D
- ninjakeyboard 13y agoIf your server is detected, that's a security vulnerability. You should never be able to identify the underlying technology of your stack or you open yourself to attack on any known vulnerabilities where as if your stack is unknown, then the vectors for attack are much less obvious.
- vivekn 13y agoWhat if you don't set the "Server" header?