HTTP-Basma - Fingerprinting Server HTTP-Basma Server Fingerprinting Theme Aurora Midnight Forest Sunset Mono Ocean Nord Dracula Rose Admin Verbosus & Pacto Fingerprints Probe servers and inspect, demangle, and compare their HTTP behavior signatures. This UI talks to the HTTP-Basma fingerprinting REST API. Fingerprint Pacto Demangle Compare DB Match Search Cluster Statistics Recent Status Fetch fingerprints Probe a server and retrieve its verbosus and pacto fingerprints. Hover any ? for parameter details. Server / Domain ? Fang URL ? Port ? SSL / TLS ? Include URL Path ? Follow Redirects ? Detail ? Full Compact Plain Proxy route the probes through an HTTP/SOCKS proxy Type ? None HTTP HTTPS SOCKS4 SOCKS5 Server ? Port ? Username ? Password ? Database match cross-reference the fingerprint against the Majestic Million HTTP-Basma database Search the database ? Match limit ? Save to database store this fingerprint & tag it Save result to database ? Tags ? Auto-resolve tags ? Fetch fingerprints Reset Verbosus → Pacto Convert a list of verbosus fingerprints into their pacto equivalents. Up to 50 entries per request. Verbosus fingerprints - one per line Upload .txt Clear 1 0 lines Resolve pacto Reset Demangle verbosus Reconstruct every probe component encoded in a verbosus fingerprint. Up to 50 per request. Results come with two views: Cards for the field-by-field breakdown, and Graph for a proportional byte-layout ruler plus a fingerprint → probe → field tree. Detail ? Compact Full Verbosus fingerprints - one per line Upload .txt Clear 1 0 lines Demangle Reset Compare verbosus pairs Compare a pair of verbosus fingerprints per line, separated by :. Up to 100 pairs per request. Pairs - one per line, format fp1:fp2 Upload .txt Clear 1 0 pairs Compare Reset Database match Search the Majestic Million HTTP-Basma database for servers that share a given fingerprint. Choose the fingerprint type, paste the fingerprint, and set how many matches to return. Type ? Verbosus Pacto Limit ? Fingerprint ? Enter a fingerprint Search database Reset Database search Search the live HTTP-Basma database by column. Pick what to search for, fill in the query, and run it. The total number of matches is always reported. Search by ? P1 response-headers fingerprint Server / domain Pacto fingerprint Verbosus fingerprint Tags Limit ? 0 – 1000 P1 response-headers fingerprint ? 8 hex characters Server / domain ? Match ? Contains Exact Starts with Ends with Pacto fingerprint ? 32 hex characters, starts with 02 Verbosus fingerprint ? Match ? Contains Exact Starts with Ends with Up to 76 hex characters Tags ? Combine ? All tags (AND) Any tag (OR) Search Reset By tags By structural distance Cluster by tags Group the database servers that match your tags by their verbosus fingerprint. Each cluster is one unique fingerprint shared by a set of servers, a quick way to see which infrastructure a campaign reuses. Tags ? Match ? All tags (AND) Any tag (OR) Max clusters ? 0 = no limit Max servers / cluster ? 0 = no limit Cluster by tags Get all unique tags Reset Cluster by structural distance Group verbosus fingerprints that are structurally close - a weighted count of differing demangled fields, per probe, so a status-code change can count differently from a reason-phrase change. Paste or upload the fingerprints; each group is a set that is all mutually at the same distance. Verbosus fingerprints ? 1 Upload .txt 0 fingerprints · up to 1000 Granularity ? Field (weighted leaves) Probe (probes that differ) Return ? Indices Fingerprints Response ? JSON (in browser) ZIP download Weights & algorithm settings Per-field-type weights (each differing leaf adds its weight) and per-probe multipliers. Defaults come from the admin panel - adjust them for this run. The algorithm caps below are set in the admin panel. Status code Reason phrase Content-Length Content-Encoding Allow header len Allow header hash HSTS (sts) Keep-Alive Close HTTP version Per-probe multipliers p1 p2 p3 p4 p5 p6f p6l p7a Max clique degeneracy ? 20 Min group size 2 Cluster by distance Reset Database statistics A periodic snapshot of the HTTP-Basma database: fingerprint distributions, ports, tags, SSL usage, and dead-probe counts. The snapshot is collected automatically on a schedule; the timestamp below shows when it was last refreshed. Recent submissions The most recently fingerprinted servers from the HTTP-Basma database. This list refreshes automatically about every 120 seconds. Refresh Server status Check that the HTTP-Basma server is reachable. Check status A product of Netomize Updates Blog Paper Feedback FAQ Privacy Project Admin