httprecon project
advanced web server fingerprinting
"Marc Ruef developed a new tool to make fingerprinting of web servers much easier. While using different test cases the hard requirements of such an identification can be met much better and more precise." - Martin Rutishauser, OneConsult GmbH, Director Training and Research
Test: get_existing (GET / HTTP/1.1)
Fingerprint: vary-order

Set of request-header fields that fully determines if a cache is permitted to use the response.

ImplementationVary-order
1AOLserver 3.4.2Accept-Encoding
2AOLserver 4.0.10Accept-Encoding
3Apache 1.3.33*
4Apache 1.3.33Accept-Encoding
5Apache 1.3.33negotiate,accept-language,accept-charset
6Apache 1.3.34Accept-Encoding
7Apache 1.3.34Accept-Encoding,User-Agent
8Apache 1.3.37*
9Apache 1.3.37Host
10Apache 2.0.46Accept-Encoding
11Apache 2.0.52Accept-Encoding,User-Agent
12Apache 2.0.54Accept-Encoding
13Apache 2.0.54negotiate,accept-language
14Apache 2.0.55Accept-Encoding
15Apache 2.0.63User-Agent,Accept-Encoding
16Apache 2.2.11Accept-Encoding
17Apache 2.2.2Accept-Encoding
18Apache 2.2.2Accept-Encoding,Cookie
19Apache 2.2.3Accept-Encoding
20Apache 2.2.4Accept-Encoding,Cookie,User-Agent
21Apache 2.2.4User-Agent
22Apache 2.2.6Cookie,User-Agent,Accept-Language
23Apache 2.3.0Accept-Encoding
24BaseHTTPServer 0.3Host
25Compaq HTTP Server 9.9negotiate,accept-language
26IBM HTTP Server 6.1.0.19*
27Lotus Domino Go Webserver 4.6.2.5*
28Microsoft IIS 6.0Accept-Encoding
29Microsoft IIS 6.0Accept-Encoding,User-Agent
30Mongrel 1.0Accept-Encoding
31Netscape Enterprise Server 3.5.1Accept-language
32Oracle Application Server 10g 10.1.2.0.0negotiate
33Oracle Application Server 10g 10.1.2.2.0Host
34Roxen 4.5.145*
35Zeus 4.3Accept-Encoding
36Zope 2.10.4Accept-Encoding
37Zope 2.7.5*
38Zope 2.7.6Cookie
39Zope 2.8.4Accept-Encoding
40Zope 2.8.6Accept-Encoding
41Zope 2.9.6Accept-Encoding
42Zope 2.9.6Accept-Encoding,Accept-Language,User-Agent
43Zope 2.9.7Accept-Encoding,Accept-Language
44Zope 2.9.8Accept-Encoding,Accept-Language,User-Agent
45and-httpd 0.99.11Accept-Encoding
46lighttpd 1.4.18Accept-Encoding,Cookie
47lighttpd 1.4.19Accept-Encoding,User-Agent
48nginx 0.5.33Accept-Encoding
49nginx 0.6.20Accept-Language

[back] [upload] [top]