Skip to content

Technology Fingerprinting

Before attacking a web app or service you need to know what it’s built with: which server, which CMS, which framework, which language, which versions, and which WAF sits in front. Fingerprinting answers that, and each answer steers the attack: a WordPress is attacked differently than a Spring, and a specific version leads you straight to the known CVEs.

  • Web server (nginx, Apache, IIS) and its version.
  • Language/framework (PHP/Laravel, Python/Django, Node/Express, .NET, Java/Spring).
  • CMS (WordPress, Joomla, Drupal — see CMS (WordPress, Joomla, Drupal)) and plugins/themes.
  • Front-end (React, Angular, Vue), JS libraries and their versions.
  • WAF/CDN in front (Cloudflare, Akamai, Imperva — see WAF Bypass).
  • Infra (cloud provider, load balancers, template languages).
HTTP headers: Server, X-Powered-By, X-AspNet-Version, Set-Cookie (PHPSESSID, JSESSIONID...)
HTML/JS: meta generator, paths (/wp-content/, /_next/), file names, comments
favicon: its hash identifies technologies (favicon hashing)
codes/errors: error pages characteristic of each stack
header order, TLS fingerprint (JA3), cookies
whatweb https://target # technologies by fingerprint
httpx -l hosts.txt -tech-detect -title -status-code -server
wappalyzer (extension / CLI) # full stack
nuclei -t http/technologies/ -u https://target # mass detection
# favicon hashing (find the same technology/origin)
# Shodan: http.favicon.hash:<hash> (see recon-shodan)

Quick manual verification:

curl -sI https://target # headers (Server, X-Powered-By, cookies)
curl -s https://target | grep -iE 'generator|wp-content|_next|csrf'

The real goal: once the version is identified, cross-reference vulnerability databases:

searchsploit <product> <version> # local exploits
nuclei -t cves/ -u https://target # CVE templates
# and databases: CVE Details, Exploit-DB, GitHub advisories

A specific, outdated version is usually the shortest road to exploitation.

wafw00f https://target # identifies the WAF (see web-wafbypass)
# a CDN (Cloudflare) also hides the origin IP -> find it (recon-asn)

Reduce the footprint: hide/normalize version headers (Server, X-Powered-By), remove meta generator, customize error pages, keep everything updated (so the leaked version isn’t vulnerable), and don’t expose revealing paths. Fingerprinting can’t be fully prevented, but it can be made harder.

  • HTTP headers (Server, X-Powered-By, session cookies)
  • HTML/JS clues (generator, paths, comments)
  • whatweb/httpx/wappalyzer on the target
  • CMS and its plugins/themes identified (if applicable)
  • Favicon hashing to correlate technology/origin
  • WAF/CDN identified (wafw00f)
  • Versions cross-referenced with CVEs (searchsploit/nuclei)
  • Vector decision based on the identified stack