Skip to content

Comment on Fingerprinting web applications (Wordpress, Joomla and Mediawiki)parent

Comments

Even though this technique is primitive, how would you say it compares to the techniques used by run-of-the-mill comment spammers to identify and exploit outdated installations? Are most of them stopping at meta generator?

I doubt it's worth doing much more than looking at version comments in the HTML, because the majority of people won't go to the effort of hiding the version.

Joomla, for example doesn't dump their version in the generator field (nor does mediawiki, I believe). Only wordpress like to do that.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.