This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Category:OWASP Favicon Database Project

From OWASP
Revision as of 20:44, 9 June 2011 by Kost (talk | contribs) (Related)

Jump to: navigation, search

Main

Idea is to have software enumerated via favicon.ico. How to do that? Take hash (in our case MD5) of favicon.ico and compare it against the known database. This project is about the favicon database itself and process in how to get the database of most frequent ones by crawling internet.

Vlatko Kosturjak initially wrote .nse script for nmap to perform enumeration of software via favicon.ico. He has noticed that there is very small database of existing MD5 fingerprints of favicon.ico and also most of the current md5 fingerprinting implementations have only web server enumeration, he have added also some popular CMS, wikis, etc. He added some of them manually, but it's boring process. Fyodor suggested that we should do internet wide scan and gather the statistics and MD5 fingerprints of most usual favicons.ico and document them.

Pages in category "OWASP Favicon Database Project"

The following 3 pages are in this category, out of 3 total.