Technology Fingerprinting
Before attacking a web app or service you need to know what it’s built with: which server, which CMS, which framework, which language, which versions, and which WAF sits in front. Fingerprinting answers that, and each answer steers the attack: a WordPress is attacked differently than a Spring, and a specific version leads you straight to the known CVEs.
What to identify
Section titled “What to identify”- Web server (nginx, Apache, IIS) and its version.
- Language/framework (PHP/Laravel, Python/Django, Node/Express, .NET, Java/Spring).
- CMS (WordPress, Joomla, Drupal — see CMS (WordPress, Joomla, Drupal)) and plugins/themes.
- Front-end (React, Angular, Vue), JS libraries and their versions.
- WAF/CDN in front (Cloudflare, Akamai, Imperva — see WAF Bypass).
- Infra (cloud provider, load balancers, template languages).
Where fingerprinting looks
Section titled “Where fingerprinting looks”HTTP headers: Server, X-Powered-By, X-AspNet-Version, Set-Cookie (PHPSESSID, JSESSIONID...)HTML/JS: meta generator, paths (/wp-content/, /_next/), file names, commentsfavicon: its hash identifies technologies (favicon hashing)codes/errors: error pages characteristic of each stackheader order, TLS fingerprint (JA3), cookieswhatweb https://target # technologies by fingerprinthttpx -l hosts.txt -tech-detect -title -status-code -serverwappalyzer (extension / CLI) # full stacknuclei -t http/technologies/ -u https://target # mass detection# favicon hashing (find the same technology/origin)# Shodan: http.favicon.hash:<hash> (see recon-shodan)Quick manual verification:
curl -sI https://target # headers (Server, X-Powered-By, cookies)curl -s https://target | grep -iE 'generator|wp-content|_next|csrf'From version to CVE
Section titled “From version to CVE”The real goal: once the version is identified, cross-reference vulnerability databases:
searchsploit <product> <version> # local exploitsnuclei -t cves/ -u https://target # CVE templates# and databases: CVE Details, Exploit-DB, GitHub advisoriesA specific, outdated version is usually the shortest road to exploitation.
WAF/CDN: knowing what’s in front
Section titled “WAF/CDN: knowing what’s in front”wafw00f https://target # identifies the WAF (see web-wafbypass)# a CDN (Cloudflare) also hides the origin IP -> find it (recon-asn)For the defense
Section titled “For the defense”Reduce the footprint: hide/normalize version headers (Server, X-Powered-By), remove meta generator, customize error pages, keep everything updated (so the leaked version isn’t vulnerable), and don’t expose revealing paths. Fingerprinting can’t be fully prevented, but it can be made harder.
Testing checklist
Section titled “Testing checklist”- HTTP headers (Server, X-Powered-By, session cookies)
- HTML/JS clues (generator, paths, comments)
- whatweb/httpx/wappalyzer on the target
- CMS and its plugins/themes identified (if applicable)
- Favicon hashing to correlate technology/origin
- WAF/CDN identified (wafw00f)
- Versions cross-referenced with CVEs (searchsploit/nuclei)
- Vector decision based on the identified stack