[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Any webservers out there?



Oystein Viggen wrote:

* [Sean Neakums]

AFAIR, they use the "Server:" header in the HTTP response to determine
the OS of the server, rather than fingerprinting the TCP/IP stack.
But I could be wrong.


They use something they call "passive tcp fingerprinting".  I don't know
exactly what that implies.  The Server header is not used for OS
detection, at least not for Linux.



You seem to be right... Netcraft has at least once fingerprinted an apache server running on the Hurd. It was hurd.dyndns.org operated by James Morrison (could not connect to, seems to be down). Netcraft says:

"The site hurd.dyndns.org is running Apache/1.3.19 (Unix) Debian/hurd-i386 on Linux."

So Netcraft sees a Linux Box. I don't think the Server String is reliable for getting the OS. We have to change the IP stack slightly to be recognised ;)







Reply to: