1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172
| ❯ whatweb -v $ip:8080 WhatWeb report for http://192.168.60.238:8080 Status : 403 Forbidden Title : <None> IP : 192.168.60.238 Country : RESERVED, ZZ
Summary : Cookies[JSESSIONID.e6f0a594], HTTPServer[Jetty(10.0.13)], HttpOnly[JSESSIONID.e6f0a594], Jenkins[2.401.2], Jetty[10.0.13], Meta-Refresh-Redirect[/login?from=%2F], Script, UncommonHeaders[x-content-type-options,x-hudson,x-jenkins,x-jenkins-session]
Detected Plugins: [ Cookies ] Display the names of cookies in the HTTP headers. The values are not returned to save on space.
String : JSESSIONID.e6f0a594
[ HTTPServer ] HTTP server header string. This plugin also attempts to identify the operating system from the server header.
String : Jetty(10.0.13) (from server string)
[ HttpOnly ] If the HttpOnly flag is included in the HTTP set-cookie response header and the browser supports it then the cookie cannot be accessed through client side script - More Info: http://en.wikipedia.org/wiki/HTTP_cookie
String : JSESSIONID.e6f0a594
[ Jenkins ] Jenkins is an application that monitors executions of repeated jobs, such as building a software project or jobs run by cron.
Version : 2.401.2 Google Dorks: (1) Website : http://jenkins-ci.org/
[ Jetty ] Jetty is a pure Java application server. Jetty provides an HTTP server, HTTP client, and javax.servlet container.
Version : 10.0.13 Google Dorks: (1) Website : http://jetty.codehaus.org/jetty/
[ Meta-Refresh-Redirect ] Meta refresh tag is a deprecated URL element that can be used to optionally wait x seconds before reloading the current page or loading a new page. More info: https://secure.wikimedia.org/wikipedia/en/wiki/Meta_refresh
String : /login?from=%2F
[ Script ] This plugin detects instances of script HTML elements and returns the script language/type.
[ UncommonHeaders ] Uncommon HTTP server headers. The blacklist includes all the standard headers and many non standard but common ones. Interesting but fairly common headers should have their own plugins, eg. x-powered-by, server and x-aspnet-version. Info about headers can be found at www.http-stats.com
String : x-content-type-options,x-hudson,x-jenkins,x-jenkins-session (from headers)
HTTP Headers: HTTP/1.1 403 Forbidden Date: Fri, 14 Mar 2025 03:27:52 GMT Connection: close X-Content-Type-Options: nosniff Set-Cookie: JSESSIONID.e6f0a594=node01wvd9qgontwmz1sdotihw47u340.node0; Path=/; HttpOnly Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Type: text/html;charset=utf-8 X-Hudson: 1.395 X-Jenkins: 2.401.2 X-Jenkins-Session: 03c1a8ff Content-Length: 541 Server: Jetty(10.0.13)
WhatWeb report for http://192.168.60.238:8080/login?from=%2F Status : 200 OK Title : Sign in [Jenkins] IP : 192.168.60.238 Country : RESERVED, ZZ
Summary : Cookies[JSESSIONID.e6f0a594], HTML5, HTTPServer[Jetty(10.0.13)], HttpOnly[JSESSIONID.e6f0a594], Jenkins[2.401.2], Jetty[10.0.13], PasswordField[j_password], UncommonHeaders[x-content-type-options,x-hudson,x-jenkins,x-jenkins-session,x-instance-identity], X-Frame-Options[sameorigin]
Detected Plugins: [ Cookies ] Display the names of cookies in the HTTP headers. The values are not returned to save on space.
String : JSESSIONID.e6f0a594
[ HTML5 ] HTML version 5, detected by the doctype declaration
[ HTTPServer ] HTTP server header string. This plugin also attempts to identify the operating system from the server header.
String : Jetty(10.0.13) (from server string)
[ HttpOnly ] If the HttpOnly flag is included in the HTTP set-cookie response header and the browser supports it then the cookie cannot be accessed through client side script - More Info: http://en.wikipedia.org/wiki/HTTP_cookie
String : JSESSIONID.e6f0a594
[ Jenkins ] Jenkins is an application that monitors executions of repeated jobs, such as building a software project or jobs run by cron.
Version : 2.401.2 Google Dorks: (1) Website : http://jenkins-ci.org/
[ Jetty ] Jetty is a pure Java application server. Jetty provides an HTTP server, HTTP client, and javax.servlet container.
Version : 10.0.13 Google Dorks: (1) Website : http://jetty.codehaus.org/jetty/
[ PasswordField ] find password fields
String : j_password (from field name)
[ UncommonHeaders ] Uncommon HTTP server headers. The blacklist includes all the standard headers and many non standard but common ones. Interesting but fairly common headers should have their own plugins, eg. x-powered-by, server and x-aspnet-version. Info about headers can be found at www.http-stats.com
String : x-content-type-options,x-hudson,x-jenkins,x-jenkins-session,x-instance-identity (from headers)
[ X-Frame-Options ] This plugin retrieves the X-Frame-Options value from the HTTP header. - More Info: http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29. aspx
String : sameorigin
HTTP Headers: HTTP/1.1 200 OK Date: Fri, 14 Mar 2025 03:27:58 GMT Connection: close X-Content-Type-Options: nosniff Content-Type: text/html;charset=utf-8 Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: no-cache,no-store,must-revalidate X-Hudson: 1.395 X-Jenkins: 2.401.2 X-Jenkins-Session: 03c1a8ff X-Frame-Options: sameorigin Content-Encoding: gzip X-Instance-Identity: MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6qPbkwm/Lq2Osr70fsrpPlgwoNsgKcKdY3a8uJNrwzkzMNoB3pz1PKWqV5OItojSxVg1dkcf0dhS5OLv5Y4SpCPCioP/nfF0odo9GXMrrAvp4GCEhjDcU4tauk8DAv/pBiyxy5gpoJv9Ay1iVLOBZw2uoDAcFZgheAcN+gTeGEWoFvJ2+ED2dkWstmGvI5TnH2Uax9BkJmp7SBi5+08mkJeWXgWi15o8ul09okcJQTJNNgEIHHzTLhArCLloJ7GoaILCPaZuurUl9BEw1eMkNBijL9DVqyo+a7zxhWgFVXlwBEJC+KN8T1fCUzeqjaJgQgEVzKOrQb3Dnp1evpKwXwIDAQAB Set-Cookie: JSESSIONID.e6f0a594=node01aoao12kzvc5w1gkfplpibbq7g1.node0; Path=/; HttpOnly Content-Length: 706 Server: Jetty(10.0.13)
|