TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Show HN: Enter your URL and view CVEs affecting your stack over last 6 months

144 pointsby GiulioSover 5 years ago

11 comments

ComputerGuruover 5 years ago
It’s a pretty poor implementation that is basically matching on the lowest common denominator, by platform rather than by library or framework. An ASP.NET website is fully independent of a WCF vulnerability. They <i>can</i> coexist but definitely don’t have to.<p>Additional suggestion: many times the home page is a link to many different technologies. Crawl all first-level directory indices to see different techs. E.g. we have a xenforo-powered forum at &#x2F;forums, a WordPress blog at &#x2F;blog, a custom ASP.NET CMS at &#x2F;store, a .NET Core web app at &#x2F;foo, etc.<p>The domain index for most companies past a certain age&#x2F;size not dedicated solely to a single app effectively turns into a static html page.
wilsonthewhaleover 5 years ago
My static site running on OpenBSD 6.5 httpd gets identified as Apache ¯\_(ツ)_&#x2F;¯
评论 #20926745 未加载
评论 #20928045 未加载
GiulioSover 5 years ago
Creator here. We built this using Wappalyzer to detect the software given a URL and match it against our database of CVEs and thought it might be a fun little tool.
评论 #20925852 未加载
评论 #20926210 未加载
swileyover 5 years ago
I pointed it at my lighttpd server and all I got was &quot;cannot detect software&quot; or so.
评论 #20923982 未加载
mellosoulsover 5 years ago
This is a nice addendum to the &quot;Let Us Identify Your Stack&quot; style web services tho I guess some of them might already provide this.<p>It does have the somewhat negative effect of making potentially vulnerable websites more visible to lower order hackers (I&#x27;m assuming more proficient ones have automated discovery tools like this anyway).
评论 #20923267 未加载
评论 #20922786 未加载
babuskovover 5 years ago
I tried entering a bunch of major websites. Looks like ibm.com is full of holes that need patching.
r1chover 5 years ago
Looks like it&#x27;s overloaded - HTTP&#x2F;502 on the API here.
评论 #20922908 未加载
not_a_cop75over 5 years ago
Finally, a place that can gather IP addresses and associate them to specific security products to have them hacked later. Just what I&#x27;ve been waiting for.
评论 #20923156 未加载
评论 #20923920 未加载
评论 #20922967 未加载
评论 #20923175 未加载
评论 #20923008 未加载
mrlucaxover 5 years ago
Is there an open source alternative that could be self-hosted and configured to run automated and periodical checks?
评论 #20924916 未加载
评论 #20923232 未加载
jamessteelover 5 years ago
Wasn’t able to detect what software my site use, my server name was disabled.
meesterdudeover 5 years ago
i don&#x27;t need to provide my (potentially vulnerable) production URL to whoever-you-might-be in order to identify the last 6 months of vulnerabilities - I can just google for that.<p>Submitting your site to this is just asking for trouble.
评论 #20922366 未加载
评论 #20922311 未加载
评论 #20922337 未加载
评论 #20922565 未加载
评论 #20926927 未加载