This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Category:OWASP Favicon Database Project"

From OWASP
Jump to: navigation, search
(Results)
(Related)
Line 44: Line 44:
 
= Related  =
 
= Related  =
  
Original scripts and files can be found at [http://kost.com.hr/favicon.php http://kost.com.hr/favicon.php].
+
* Original scripts and files can be found at [http://kost.com.hr/favicon.php http://kost.com.hr/favicon.php]
 +
* Nmap favicon poster project can be found at [http://nmap.org/favicon/]
  
 
==== Project Identification  ====
 
==== Project Identification  ====

Revision as of 20:44, 9 June 2011

Main

Idea is to have software enumerated via favicon.ico. How to do that? Take hash (in our case MD5) of favicon.ico and compare it against the known database. This project is about the favicon database itself and process in how to get the database of most frequent ones by crawling internet.

Vlatko Kosturjak initially wrote .nse script for nmap to perform enumeration of software via favicon.ico. He has noticed that there is very small database of existing MD5 fingerprints of favicon.ico and also most of the current md5 fingerprinting implementations have only web server enumeration, he have added also some popular CMS, wikis, etc. He added some of them manually, but it's boring process. Fyodor suggested that we should do internet wide scan and gather the statistics and MD5 fingerprints of most usual favicons.ico and document them.

Pages in category "OWASP Favicon Database Project"

The following 3 pages are in this category, out of 3 total.