2 ms·
In addition to the coffeescript / browserify detection, here are the headers it checks[0]: var frameworks = [ {name: 'express.js', s: "express", h: 'x-po
by sisk 13y ago
In addition to the coffeescript / browserify detection, here are the headers it checks[0]:
var frameworks = [
{name: 'express.js', s: "express", h: 'x-powered-by'},
{name: 'koa.js', s: 'koa', h: 'x-powered-by'},
{name: 'sails.js', s: "sails", h: 'x-powered-by'},
{name: 'ecstatic', s: 'ecstatic', h: 'server'},
{name: 'flatiron', s: 'flatiron', h: 'x-powered-by'}
]
All in all, this should prove relatively inaccurate. A vanilla http server from node sets neither server nor x-powered-by headers. Many frameworks don't set them, either (Walmart's hapi, PayPal's krakenjs, etc).
Fun toy project but if you're really interesting in fingerprinting, check out the OWASP entry on the subject[1].
[0]: https://github.com/dotheyusenode/dotheyusenode/blob/ea23561918ba7ae41b8bc88f25bbf7e777e62359/checkers/headers.js#L3-L9 https://github.com/dotheyusenode/dotheyusenode/blob/ea235619...
[1]: https://www.owasp.org/index.php/Testing_for_Web_Application_Fingerprint_(OWASP-IG-004) https://www.owasp.org/index.php/Testing_for_Web_Application_...
- wlaurance 13y agoYes, it is just a toy project. It is a lot more work to fingerprint successfully. OWASP looks very interesting. Thanks for the link and subsequently the white paper links!