Files
nuclei-templates/http/technologies/winstone-detect.yaml
2025-11-19 08:06:43 +00:00

40 lines
1.1 KiB
YAML

id: winstone-detect
info:
name: Winstone Servlet Engine
author: Shivam Kamboj
severity: info
description: |
Detected servers running the Winstone Servlet Engine via the Server or X-Powered-By headers.
metadata:
max-request: 1
shodan-query: http.component:"winstone servlet container"
tags: tech,winstone,discovery
http:
- method: GET
path:
- "{{BaseURL}}"
matchers-condition: or
matchers:
- type: regex
part: header
regex:
- '(?i)Server:\s*Winstone Servlet Engine\s*v?[0-9.]+'
- '(?i)Winstone/[0-9.]+'
- type: regex
part: header
regex:
- '(?i)X-Powered-By:\s*Servlet/[0-9.]+\s*\(Winstone/[0-9.]+\)'
extractors:
- type: regex
name: winstone_version
part: header
group: 0
regex:
- '(?i)Winstone(?: Servlet Engine)?\s*v?[0-9.]+'
- '(?i)Winstone/[0-9.]+'
# digest: 4a0a00473045022100d2069a351e91c103dfeb76a3efda6eb2a1fb41210c1f6a2c8a51c72b5c089d88022007c4b5ed83af61d8ec2237c5e32a0bd7f42e1567e1a5f0c68d0db03e7cdeeeba:922c64590222798bb761d5b6d8e72950