Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
HTTP-Basma — In the realm of cybersecurity, accurately identifying and characterizing web servers is crucial for threat detection, vulnerability assessment, and network mapping. We introduce HTTP-Basma, a novel active fingerprinting algorithm that unveils unique server profiles through a multi-layered approach. | Kitploit
उपकरण/GitHubGitHub/netomize/http-basma
ReconnaissanceNetwork MappingVulnerability AnalysisInformation GatheringWeb SecurityMalware AnalysisCommand and ControlThreat IntelligenceRed Teaming
GitHubnetomize/http-basma

HTTP-Basma

रिपॉजिटरी देखें
20 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
वेबसाइट

विवरण

In the realm of cybersecurity, accurately identifying and characterizing web servers is crucial for threat detection, vulnerability assessment, and network mapping. We introduce HTTP-Basma, a novel active fingerprinting algorithm that unveils unique server profiles through a multi-layered approach.

साझा करें
HTTP-Basma Logo

अनुकूली फिंगरप्रिंटिंग: ग्रैन्युलर सर्वर विभेदीकरण के लिए HTTP-Basma का बहु-चरणीय प्रोबिंग

HTTP-Basma https://httpbasma.netomize.ca/ पर लाइव है

परिचय

साइबर सुरक्षा के क्षेत्र में, खतरे का पता लगाने, भेद्यता मूल्यांकन और नेटवर्क मैपिंग के लिए वेब सर्वरों की सटीक पहचान और लक्षण वर्णन महत्वपूर्ण है। हम HTTP-Basma प्रस्तुत करते हैं, एक नवीन सक्रिय फिंगरप्रिंटिंग एल्गोरिदम जो बहु-स्तरीय दृष्टिकोण के माध्यम से अद्वितीय सर्वर प्रोफाइल को उजागर करता है, जिससे इस चुनौती का समाधान होता है।

मुख्य विशेषताएं: तैयार किए गए अनुरोध, प्रकट करने वाले प्रतिक्रियाएँ: HTTP-Basma 8 सावधानीपूर्वक डिज़ाइन किए गए HTTP प्रोब भेजता है, जो सर्वर कॉन्फ़िगरेशन को दर्शाने वाली विशिष्ट प्रतिक्रियाएँ उत्पन्न करता है। बहुमुखी प्रतिभा के लिए दोहरी हैशिंग। एल्गोरिदम दो हैश उत्पन्न करता है:

  • एक 38-बाइट फ़ज़ी हैश, "verbosus", जो प्रतिवर्तीता प्रदान करता है
  • एक 16-बाइट वन-वे हैश, "pacto", जो verbosus से व्युत्पन्न होता है, गोपनीयता और सुरक्षा बढ़ाता है

क्लस्टरिंग और हंटिंग: ये हैश सर्वर क्लस्टरिंग, अद्वितीय और समान सर्वरों की पहचान, और बढ़े हुए विश्वास के साथ दुर्भावनापूर्ण अभिनेताओं की खोज को सशक्त बनाते हैं।

विस्तार के लिए मॉड्यूलर डिज़ाइन: एल्गोरिदम की वास्तुकला नए हैशिंग वेरिएंट के जोड़ने को बढ़ावा देती है, सहयोग और अनुकूलनशीलता को प्रोत्साहित करती है।

इस पेपर में, हम पहले HTTP फिंगरप्रिंटिंग पर उल्लेखनीय मौजूदा कार्य का सर्वेक्षण करते हैं और फिर एल्गोरिदम की कार्यक्षमता, डिज़ाइन, वास्तुकला और परिणामों का पता लगाते हैं। इसके अतिरिक्त, हम शीर्ष 1 मिलियन Majestic वेबसाइटों को स्कैन करने से आकर्षक निष्कर्ष प्रस्तुत करेंगे, जिसमें विभिन्न मैलवेयर परिवारों के C&C HTTP सर्वरों की पहचान और क्लस्टरिंग शामिल है।


HTTP-Basma के एल्गोरिदम का मुख्य विचार सर्वर से अलग-अलग प्रतिक्रियाएँ प्राप्त करने के लिए अलग-अलग आवश्यकताओं के साथ 8 विशेष रूप से तैयार किए गए HTTP अनुरोध भेजने पर केंद्रित है। एक बार सर्वर प्रतिक्रिया प्राप्त होने के बाद, HTTP स्थिति रेखा को सभी तत्वों के लिए शल्य चिकित्सा की तरह विच्छेदित किया जाता है और इष्टतम रूप से एन्कोड किया जाता है। इसके अतिरिक्त, सर्वर प्रतिक्रिया से चुनिंदा हेडर को भी एन्कोडिंग के लिए जाँचा जाता है।

यह जो अनुरोध भेजता है वे इस प्रकार के हैं:

  1. P1 - GET Normal - मान्य अनुरोध
  2. P2 - GET अमान्य HTTP संस्करण अनुरोध
  3. P3 - GET रैंडम संसाधन अनुरोध
  4. P4 - रैंडम क्रिया अनुरोध
  5. P5 - get लोअरकेस क्रिया
  6. P6 - GET अनुरोध - Accept-Encoding - पूर्ण
  7. P7 - GET अनुरोध - Accept-Encoding - कम
  8. P8 - OPTIONS अनुरोध

प्रत्येक अनुरोध के बाद, सर्वर की प्रतिक्रिया का विश्लेषण विशिष्ट हेडर और उनके मान निकालने के लिए किया जाता है। यह निकाला गया डेटा आगे की प्रक्रिया से गुजरता है, जिसमें विच्छेदन और एन्कोडिंग शामिल है, ताकि एक प्रतिवर्ती फिंगरप्रिंट उत्पन्न हो सके।

एल्गोरिदम कैसे काम करता है, इसके पूर्ण तकनीकी विवरण संलग्न पेपर में हैं।

यह मॉड्यूलर डिज़ाइन दर्शन प्रत्येक अनुरोध फिंगरप्रिंट को एक बिल्डिंग ब्लॉक के रूप में मानता है, जो सुरुचिपूर्ण रीफैक्टरिंग की अनुमति देता है, जिसमें किसी भी अनुरोध के फिंगरप्रिंट को जोड़ने और घटाने की संभावना है।

फिंगरप्रिंट के नमूने:

CobaltStrike

root@kitploit:~
  - verbosus fp: 011420958a0014514bd5221420958a221420958a221420958a2200001420958a22000000001f
  - pacto fp: 02464ae8b7d86f82c9918e2c2b9d6b91
  - note: false-positive rate (72/986,910)

Havoc

root@kitploit:~
  - verbosus fp: 01142494d60914514bd522142494d6221420958a701420958a220000140e04922032c37f1609
  - pacto fp: 020769322f3d94ac2f258ddf5ce08502
  - note-1: false-positive rate 0
  - note-2: tevedadav.site/43.209.165.126:443 (TLS)
    - sample-(sha-256): 9aa1dec8dd12f8adc7fc1274e1958f3613450109ee8b4ec6442a0fcf06df0972

BruteRatel

root@kitploit:~
  - verbosus fp: 01140a85e40014512f3612140a85e422140a85e422140a85e4220000140a85e4220000000001
  - pacto fp: 0207292309a7a7e798e417d69df5f2a5
  - note: false-positive rate (73/986,910)

Google

root@kitploit:~
  - verbosus fp: 01140a85e4001320958a22142494d62214254c5e2214254c5e22080014254c5e220000000000
  - pacto fp: 0202be780e1eaae0eaa6184e20c909b6
  - note: false-positive rate (4/986,910)

YouTube

root@kitploit:~
  - verbosus fp: 01140a85e4011320958a22142494d67214254c5e2214254c5e22080014254c5e220000000000
  - pacto fp: 02cc5be6d05192e17de041538508bc22
  - note: false-positive rate (38/986,910)

X

root@kitploit:~
  - verbosus fp: 01140a85e40914514bd522140a85e4721420958a701420958a220800140a85e4720000001609
  - pacto fp: 0221b4e46bbd0e5c037f5a852ca3fdc0
  - note: false-positive rate (6/986,910)

HTTP-Basma टूल

HTTP-Basma एक C++ टूल है जिसे मैंने इस एल्गोरिदम की व्यावहारिकता और व्यवहार्यता प्रदर्शित करने के लिए विकसित किया है। यह सभी HTTP सॉकेट इंटरैक्शन के लिए Chilkat की लाइब्रेरी का लाभ उठाता है और लाइब्रेरी के भीतर अन्य सहायक कक्षाओं का उपयोग करता है। इसके अतिरिक्त, टूल में एक डिमैंगलर सुविधा शामिल है जो verbosus फ़ज़ी-हैश को विच्छेदित और उलट सकती है, एक व्यापक JSON ऑब्जेक्ट आउटपुट करती है, और एक तुलनित्र फ़ंक्शन जो दो verbosus फिंगरप्रिंट के बीच अंतर आउटपुट करता है।

ध्यान रखें कि टूल के कुछ आउटपुट में थोड़े अलग प्रोब नंबर का उपयोग हो सकता है, लेकिन अंतर्निहित क्रम सुसंगत रहता है: P1->P1, P2->P2, P3->P3, P4->P4, P->P5, P6->P6F, P7->P6L, P8->P7a।

टूल के विकल्प

विस्तार करने के लिए क्लिक करें
root@kitploit:~
Usage:
  HTTP-Basma [OPTION...]

  -d, --domain arg         domains/IPs (you may query multiple domains, comma separated)
  -p, --port arg           port number
  -s, --ssl                does the HTTP connection have to be carried over SSL/TLS?
  -q, --qpath              check domain with url path included (not recommended)
  -w, --redirect           enable/disable HTTP redirects. If disabled/false, only the next redirect is followed,
                           otherwise, all redirects are followed (default: true)
  -t, --ctimeout arg       socket connection timeout value in seconds (default: 1)
  -g, --rtimeout arg       socket read (from the server) timeout value in seconds (default: 1)
  -e, --sleep arg          the duration (in milliseconds) to pause between each request (default: 100)
  -x, --proxy arg          proxy config: <"socks4|socks5|http">,<domain>,<port>,<bool:direct_tls>,<login>,<pass>
                                         all values are comma-separated. <direct_tls> is ignored with a non-HTTP proxy
  -f, --file arg           file with list of domains/IPs (requires "-c/--csv" or "-j/--json")
  -P, --parallel           Scan list of domains passed via the "-f/--file" option in parallel
  -c, --csv                save to csv file; if the option 'n' is not specified, the CSV filename will be auto
                           generated
  -n, --csvfile arg        name of the CSV file
  -j, --json               save to json file; if the option 'l' is not specified, the JSON filename will be auto
                           generated
  -l, --jsonfile arg       name of the JSON file
  -r, --saveh              save request response headers
  -o, --pjson              display fingerprint dissection to the console as a JSON object
  -i, --demangle_json arg  demangle a fingerprint into a detailed json format (you can have more than one, comma
                           separated)
  -u, --demangle_txt arg   output a concise text format of the fingerprint, comma-separated for multiple results
  -C, --compare arg        compare two verbosus fingerprints (comma-separated)
  -a, --pacto arg          obtain the Pacto fingerprint using Verbosus
  -h, --help               print usage	

विस्तृत आउटपुट

किसी दिए गए डोमेन/IP का अनुरोध करते समय, प्रतिक्रिया को CSV या JSON फ़ाइल में सर्वर प्रतिक्रिया हेडर और प्रत्येक प्रोब के अद्वितीय फिंगरप्रिंट के बारे में अत्यधिक जानकारी के साथ सहेजा जा सकता है।

उदाहरण के लिए, सर्वर https://google.com का फिंगरप्रिंट प्राप्त करने और परिणामों को JSON और CSV फ़ाइल में सहेजने के साथ-साथ प्रत्येक प्रोब के HTTP प्रतिक्रिया हेडर को सहेजने के लिए:

root@kitploit:~
HTTPBasma.exe -d https://google.com --json --csv --saveh

फ़ोल्डर Output में, आपको CSV फ़ाइल google_hb_results_2026-05-19_08-35-38_am.csv और JSON फ़ाइल google_hb_results_2026-05-19_08-35-38_am.json मिलेगी।

डिमैंगलर

टूल का डिमैंगलर फ़ंक्शन "-i/--demangle_json" एक verbosus फिंगरप्रिंट लेता है और प्रत्येक प्रोब की विशेषताओं का पुनर्निर्माण करता है, एक व्यापक JSON ऑब्जेक्ट आउटपुट करता है। विशेष रूप से, FNV-1a हैश को उलटने का प्रयास करते समय, डिमैंगलर दो स्थानीय डेटाबेस का उपयोग करता है: अनुमत HTTP विधियों के लिए options.csv और स्थिति-पंक्ति कारण वाक्यांशों के लिए status_line_db.csv। यदि इनमें से कोई भी डेटाबेस फ़ाइल गायब है, तो संबंधित हैश रिवर्सल सुविधा स्वचालित रूप से अक्षम हो जाती है। ये डेटाबेस शीर्ष 1 मिलियन Majestic वेबसाइटों के स्कैन से संकलित किए गए थे।

डोमेन example.com के लिए verbosus के फिंगरप्रिंट का डिमैंगलिंग:

root@kitploit:~
HTTPBasma.exe --demangle_json 01140a85e40014514bd522142494d67214254c5e721420958a22020214254c5e720000001609
डिमैंगलर आउटपुट (विस्तार करने के लिए क्लिक करें)
root@kitploit:~
{
  "type": "verbosus",
  "fp": "01140a85e40014514bd522142494d67214254c5e721420958a22020214254c5e720000001609",
  "p1": {
    "type": "get_normal",
    "fp": "140a85e400",
    "status_line": {
      "http_version": {
        "fp": "14",
        "val_cmt": "HTTP/1.1"
      },
      "status_code": {
        "fp": "0a",
        "val_cmt": "200"
      },
      "http_reason": {
        "fp": "85e4",
        "val_cmt": "OK"
      },
      "sl_reversed_db": {
        "http_version": "HTTP/1.1",
        "status_code": [
          200,
          404,
          403,
          500,
          204,
          999,
          888,
          603
        ],
        "http_reason": "OK"
      }
    },
    "sts_hdr": {
      "fp": "00",
      "cmt": "this header is not used"
    }
  },
  "p2": {
    "type": "get_invalid_ver_nb",
    "fp": "14514bd522",
    "status_line": {
      "http_version": {
        "fp": "14",
        "val_cmt": "HTTP/1.1"
      },
      "status_code": {
        "fp": "51",
        "val_cmt": "505"
      },
      "http_reason": {
        "fp": "4bd5",
        "val_cmt": "HTTP Version Not Supported"
      },
      "sl_reversed_db": {
        "http_version": "HTTP/1.1",
        "status_code": [
          505
        ],
        "http_reason": "HTTP Version Not Supported"
      }
    },
    "cont_len_hdr": {
      "fp": "22",
      "name": "Content-Length",
      "value": ">1",
      "cmt": "content-length/transfer-encoding:chunked header is present with either of the size values: [0,1,>1]"
    },
    "cnx": {
      "ka": false,
      "c": true
    }
  },
  "p3": {
    "type": "get_rnd_resource",
    "fp": "142494d672",
    "status_line": {
      "http_version": {
        "fp": "14",
        "val_cmt": "HTTP/1.1"
      },
      "status_code": {
        "fp": "24",
        "val_cmt": "404"
      },
      "http_reason": {
        "fp": "94d6",
        "val_cmt": "Not Found"
      },
      "sl_reversed_db": {
        "http_version": "HTTP/1.1",
        "status_code": [
          404,
          403,
          501,
          410,
          204,
          400,
          200,
          418
        ],
        "http_reason": "Not Found"
      }
    },
    "cont_len_hdr": {
      "fp": "72",
      "name": "Transfer-Encoding",
      "value": ">1",
      "cmt": "content-length/transfer-encoding:chunked header is present with either of the size values: [0,1,>1]"
    },
    "cnx": {
      "ka": true,
      "c": false
    }
  },
  "p4": {
    "type": "get_rnd_verb",
    "fp": "14254c5e72",
    "status_line": {
      "http_version": {
        "fp": "14",
        "val_cmt": "HTTP/1.1"
      },
      "status_code": {
        "fp": "25",
        "val_cmt": "405"
      },
      "http_reason": {
        "fp": "4c5e",
        "val_cmt": "Method Not Allowed"
      },
      "sl_reversed_db": {
        "http_version": "HTTP/1.1",
        "status_code": [
          405,
          403,
          204,
          418,
          404
        ],
        "http_reason": "Method Not Allowed"
      }
    },
    "cont_len_hdr": {
      "fp": "72",
      "name": "Transfer-Encoding",
      "value": ">1",
      "cmt": "content-length/transfer-encoding:chunked header is present with either of the size values: [0,1,>1]"
    },
    "cnx": {
      "ka": true,
      "c": false
    }
  },
  "p5": {
    "type": "get_lowercase_verb",
    "fp": "1420958a22",
    "status_line": {
      "http_version": {
        "fp": "14",
        "val_cmt": "HTTP/1.1"
      },
      "status_code": {
        "fp": "20",
        "val_cmt": "400"
      },
      "http_reason": {
        "fp": "958a",
        "val_cmt": "Bad Request"
      },
      "sl_reversed_db": {
        "http_version": "HTTP/1.1",
        "status_code": [
          400,
          422,
          405,
          401
        ],
        "http_reason": "Bad Request"
      }
    },
    "cont_len_hdr": {
      "fp": "22",
      "name": "Content-Length",
      "value": ">1",
      "cmt": "content-length/transfer-encoding:chunked header is present with either of the size values: [0,1,>1]"
    },
    "cnx": {
      "ka": false,
      "c": true
    }
  },
  "p6f": {
    "type": "get_accept_encoding_full",
    "fp": "02",
    "cont_enc_hdr": {
      "value": "br",
      "empty_value": false,
      "total_plus": 0
    }
  },
  "p6l": {
    "type": "get_accept_encoding_less",
    "fp": "02",
    "cont_enc_hdr": {
      "value": "br",
      "empty_value": false,
      "total_plus": 0
    }
  },
  "p7a": {
    "type": "options_allow_hdr",
    "fp": "14254c5e72000000",
    "status_line": {
      "http_version": {
        "fp": "14",
        "val_cmt": "HTTP/1.1"
      },
      "status_code": {
        "fp": "25",
        "val_cmt": "405"
      },
      "http_reason": {
        "fp": "4c5e",
        "val_cmt": "Method Not Allowed"
      },
      "sl_reversed_db": {
        "http_version": "HTTP/1.1",
        "status_code": [
          405,
          403,
          204,
          418,
          404
        ],
        "http_reason": "Method Not Allowed"
      }
    },
    "cont_len_hdr": {
      "fp": "72",
      "name": "Transfer-Encoding",
      "value": ">1",
      "cmt": "content-length/transfer-encoding:chunked header is present with either of the size values: [0,1,>1]"
    },
    "allow_hdr": {
      "fp": "000000",
      "cmt": "this header is not used"
    },
    "cnx": {
      "ka": true,
      "c": false
    }
  }
}

ध्यान दें कि "status_code" सरणी में कई HTTP स्थिति कोड हैं। ऐसा इसलिए होता है क्योंकि विभिन्न सर्वर विभिन्न स्थिति कोडों के लिए एक ही कारण वाक्यांश का उपयोग कर सकते हैं, जिसके परिणामस्वरूप समान FNV-1a हैश होते हैं।

तुलनित्र विकल्प

तुलनित्र विकल्प "-C/--compare" दो verbosus फिंगरप्रिंट की तुलना करता है और प्रत्येक प्रोब के प्रमुख घटकों में अंतर प्रिंट करता है।

उदाहरण के लिए, Google और YouTube के लिए निम्नलिखित दो फिंगरप्रिंट की तुलना करना:

root@kitploit:~
HTTPBasma.exe --compare 01140a85e4001320958a22142494d62214254c5e2214254c5e22080014254c5e220000000000,01140a85e4011320958a22142494d67214254c5e2214254c5e22080014254c5e220000000000

इस आउटपुट में परिणाम:

root@kitploit:~
 < FPrnt-1 Vs. FPrnt-2 >

 [ P1 ]
    {Strict-Transport-Security}
      sts header: 00 != 01

 [ P2 ]
 [ P3 ]
    {Content-Length}

      cl_name: 2 != 7

 [ P4 ]
 [ P5 ]
 [ P6F ]
 [ P6L ]
 [ P7a ]

आउटपुट विशेष रूप से P1 प्रोब के हैश घटक में अंतर प्रकट करता है, जहाँ STS हेडर पहले fp में मौजूद है और दूसरे में नहीं। इसके अलावा, प्रोब P3 के लिए दो फिंगरप्रिंट के बीच "Content-Length" का एन्कोडिंग भिन्न है।


रिलीज़

Netomize इस रिपॉजिटरी में सार्वजनिक कोड के संकलित Windows और Linux x64 संस्करण प्रदान करता है। इसके अलावा, majestic 1-million HTTP-Basma fingerprints CSV File - data set पहली रिलीज़ में शामिल है।

उपयोग की गई तृतीय-पक्ष लाइब्रेरीज़

  • Chilkat v11.4.0
  • rang: कंसोल रंग के लिए
  • cxxopts (v3.3.1)

योगदान

पुल अनुरोध और मुद्दों के लिए खुला है। टिप्पणियाँ और सुझाव अत्यधिक सराहनीय हैं।

टूल डाउनलोड करें