Logo Background

Httprint – Web Server Analysis Tools

  • By on November 29, 2008 | No Comments

    httprint is a web server fingerprinting tool. It depends on web server characteristics to accurately identify web servers, in spite of the fact that they may have been obfuscated by altering the server banner strings, or by plugins such as mod_security or servermask. httprint can also be used to spot web enabled devices which do not have a server banner string, such as wireless access points, routers, switches, cable modems, etc. httprint use text signature strings and it is very easy to add signatures to the signature database.

    Features
    – Identification of web servers despite the banner string and any other obfuscation. httprint can successfully spot the underlying web servers when their headers are distorted by either patching the binary, by modules such as mod_security.c or by commercial products such as ServerMask.

    – Inventorying of web enabled devices such as printers, routers, switches, wireless access points, etc.

    – Customizable web server signature database. To add new signatures, simply cut and paste the httprint output against unknown servers into the signatures text file.

    – Confidence Ratings. httprint now picks the best matches based on confidence ratings, resulting using a fuzzy logic technique, instead of going by the highest weight.

    – [new] Multi-threaded engine. httprint v301 is a complete re-write, featuring a multi-threaded scanner, to process multiple hosts in parallel. This greatly saves scanning time. *multi-threading is not yet supported in the FreeBSD version.

    – [new] SSL information gathering. httprint now gathers SSL certificate information, which helps you identify expired SSL certificates, ciphers used, certificate issuer, and other such SSL related details.

    – [new] Automatic SSL detection. httprint can detect if a port is SSL enabled or not, and can automatically switch to SSL connections when needed.

    – Automatic traversal of HTTP 301 and 302 redirects. Many servers who have transferred their content to other servers send a default redirect response towards all HTTP requests. httprint now follows the redirection and fingerprints the new server pointed to. This feature is enabled by default and can be turned off, if needed.

    – Ability to import web servers from nmap network scans. httprint can import nmap’s xml output files.

    – Reports in HTML, CSV and XML formats.

    – Available on Linux, Mac OS X, FreeBSD (command line only) and Win32 (command line and GUI).

    Previous
    Next
    » Oracle Apps 11i & Database Cloning
Leave a Comment