Fingerprinting de tecnologías
Antes de atacar una web o un servicio necesitas saber con qué está construido: qué servidor, qué CMS, qué framework, qué lenguaje, qué versiones y qué WAF hay delante. El fingerprinting responde a eso, y cada respuesta orienta el ataque: un WordPress se ataca distinto que un Spring, y una versión concreta te lleva directo a los CVE conocidos.
Qué identificar
Sección titulada «Qué identificar»- Servidor web (nginx, Apache, IIS) y su versión.
- Lenguaje/framework (PHP/Laravel, Python/Django, Node/Express, .NET, Java/Spring).
- CMS (WordPress, Joomla, Drupal — ver CMS (WordPress, Joomla, Drupal)) y plugins/temas.
- Front-end (React, Angular, Vue), librerías JS y sus versiones.
- WAF/CDN delante (Cloudflare, Akamai, Imperva — ver Evasión de WAF).
- Infra (proveedor cloud, balanceadores, lenguajes de plantilla).
Dónde mira el fingerprinting
Sección titulada «Dónde mira el fingerprinting»cabeceras HTTP: Server, X-Powered-By, X-AspNet-Version, Set-Cookie (PHPSESSID, JSESSIONID...)HTML/JS: meta generator, rutas (/wp-content/, /_next/), nombres de ficheros, comentariosfavicon: su hash identifica tecnologías (favicon hashing)códigos/errores: páginas de error características de cada stackorden de cabeceras, TLS fingerprint (JA3), cookiesHerramientas
Sección titulada «Herramientas»whatweb https://target # tecnologías por fingerprintshttpx -l hosts.txt -tech-detect -title -status-code -serverwappalyzer (extensión / CLI) # stack completonuclei -t http/technologies/ -u https://target # detección masiva# favicon hashing (encontrar la misma tecnología/origen)# Shodan: http.favicon.hash:<hash> (ver recon-shodan)Verificación manual rápida:
curl -sI https://target # cabeceras (Server, X-Powered-By, cookies)curl -s https://target | grep -iE 'generator|wp-content|_next|csrf'De la versión al CVE
Sección titulada «De la versión al CVE»El objetivo real: una vez identificada la versión, cruzas con bases de vulnerabilidades:
searchsploit <producto> <version> # exploits localesnuclei -t cves/ -u https://target # plantillas de CVE# y bases: CVE Details, Exploit-DB, GitHub advisoriesUna versión concreta y desactualizada suele ser el camino más corto a la explotación.
WAF/CDN: saber qué tienes delante
Sección titulada «WAF/CDN: saber qué tienes delante»wafw00f https://target # identifica el WAF (ver web-wafbypass)# un CDN (Cloudflare) también oculta la IP de origen -> buscarla (recon-asn)Para la defensa
Sección titulada «Para la defensa»Reducir la huella: ocultar/normalizar cabeceras de versión (Server, X-Powered-By), quitar meta generator, personalizar páginas de error, mantener todo actualizado (que la versión filtrada no sea vulnerable), y no exponer rutas reveladoras. El fingerprinting no se puede impedir del todo, pero sí dificultar.
Checklist de prueba
Sección titulada «Checklist de prueba»- Cabeceras HTTP (Server, X-Powered-By, cookies de sesión)
- Pistas en HTML/JS (generator, rutas, comentarios)
- whatweb/httpx/wappalyzer sobre el objetivo
- CMS y sus plugins/temas identificados (si aplica)
- Favicon hashing para correlacionar tecnología/origen
- WAF/CDN identificado (wafw00f)
- Versiones cruzadas con CVE (searchsploit/nuclei)
- Decisión de vector según el stack identificado