Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create DetectServerNames.bambda #66

Merged
merged 4 commits into from
Apr 15, 2024
Merged
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
51 changes: 51 additions & 0 deletions Filter/Proxy/HTTP/DetectServerNames.bambda
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
/**
* Bambda Script to Detect Specific Server Names in HTTP Response
@author Tur24Tur / BugBountyzip (https://github.com/BugBountyzip)
It identifies if the 'Server' header of the HTTP response contains any of the specified server names.
* Upon detection, responses are highlighted in red and notes are appended, if enabled.
**/

// Convert the list of server names to a set for faster lookup
Set<String> serverNames = new HashSet<>(Arrays.asList(
"awselb", "Kestrel", "Apache", "Nginx", "Microsoft-IIS", "LiteSpeed", "Google Frontend",
"GWS", "openresty", "IBM_HTTP_Server", "AmazonS3", "CloudFront", "AkamaiGHost", "Jetty",
"Tengine", "lighttpd", "AOLserver", "ATS", "Boa", "Caddy", "Cherokee", "Caudium", "Hiawatha",
"GlassFish", "H2O", "httpd", "Jigsaw", "LiteSpeed", "Mongrel", "NCSA HTTPd", "Netscape Enterprise",
"Oracle iPlanet", "Pound", "Resin", "thttpd", "Tornado", "Varnish", "WebObjects", "Xitami",
"Zope", "Werkzeug", "WebSTAR", "WebSEAL", "WebServerX", "WebtoB", "Squid", "Sun Java System Web Server",
"Sun ONE Web Server", "Stronghold", "Zeus Web Server", "Zope", "Roxen", "RapidLogic", "Pramati",
"Phusion Passenger", "Oracle Containers for J2EE", "Oracle-Application-Server-10g", "Oracle-Application-Server-11g",
"Nostromo", "Novell-HTTP-Server", "NaviServer", "MochiWeb", "Microsoft-HTTPAPI", "Mbedthis-Appweb",
"Lotus-Domino", "LiteSpeed", "Kangle", "Joost", "Jino", "IceWarp", "IBM_HTTP_Server", "GoAhead",
"Flywheel", "EdgePrism", "DMS", "Cowboy", "CommuniGatePro", "CompaqHTTPServer", "CERN", "CauchoResin",
"Caddy", "BarracudaHTTP", "BaseHTTP", "AllegroServe", "Abyss", "4D_WebSTAR_S", "4D_WebSTAR_D",
"Yaws", "WDaemon", "Virtuoso", "UserLand", "TUX", "TwistedWeb", "TwistedWeb", "Thin",
"Thttpd", "Tengine", "Swiki", "SurgeLDAP", "Sun-ONE-Web-Server", "Sun-ONE-Application-Server",
"Sucuri/Cloudproxy", "SSWS", "SWS", "SW", "srv", "squid", "Spamfire", "SOMA",
"Snap", "SmugMug", "SME Server", "Smart-4-Hosting", "Sioux", "SilverStream", "Silk", "Siemens Gigaset WLAN Camera", // Additional server namesV2
"Traefik", "HAProxy", "Envoy", "Linkerd", "Istio", "Kong", "tyk", "nginx unit", "OpenLiteSpeed", "Node.js", "IIS Express", "Gunicorn", "uWSGI", "DMS"
));

// Ensure there is a response
if (!requestResponse.hasResponse()) {
return false;
}

boolean foundServerName = false;
boolean enableManualAnnotations = true; // Define this variable

// Get the 'Server' header from the response
String serverHeader = requestResponse.response().headerValue("Server");

// Check if the 'Server' header value is in the set of server names
if (serverHeader != null && serverNames.contains(serverHeader)) {
foundServerName = true;
if (enableManualAnnotations) {
requestResponse.annotations().setHighlightColor(HighlightColor.RED);
requestResponse.annotations().setNotes("Detected '" + serverHeader + "' in 'Server' header");
}
}

return foundServerName;


Loading