hatRiot / clusterd

application server attack toolkit
MIT License
681 stars 197 forks source link

Add header fingerprints for JBoss #9

Closed hatRiot closed 10 years ago

hatRiot commented 10 years ago

If authentication is enabled on all exposed interfaces for a JBoss instance, we can still pull headers for the version. This isn't always entirely accurate, and I didn't include it for this very reason, but it's a good last resort indication.

Not sure which versions include the version in the header, but it should suffice for all versions 3.x-5.x, at least.