/** * HTTP/2 SETTINGS frame fingerprints for server implementation identification. * * When an HTTP/2 connection is established, the server sends a SETTINGS frame * (RFC 7540 Section 6.5) containing its preferred protocol parameters. Different * HTTP/2 implementations choose distinct default values and orderings for these * settings, creating a reliable passive fingerprint. * * Additionally, idle connection GOAWAY behavior (timeout duration and debug data) * varies across implementations, providing a secondary identification signal. * * SETTINGS frame parameters (RFC 7540 Section 6.5.2): * - HEADER_TABLE_SIZE (0x1) - HPACK dynamic table size * - ENABLE_PUSH (0x2) - Server push enabled (0 or 1) * - MAX_CONCURRENT_STREAMS (0x3) - Max simultaneous streams * - INITIAL_WINDOW_SIZE (0x4) - Flow-control window size * - MAX_FRAME_SIZE (0x5) - Largest frame payload * - MAX_HEADER_LIST_SIZE (0x6) - Max header list size * * References: * - RFC 7540 (HTTP/2) * - https://github.com/AliasIO/wappalyzer * - https://www.blackhat.com/docs/eu-17/materials/eu-17-Shuster-Passive-Fingerprinting-Of-HTTP2-Clients-wp.pdf */ /** HTTP/2 SETTINGS frame signature for a known server implementation. */ export interface H2Signature { /** Server or implementation name */ server: string; /** Expected SETTINGS frame parameters (undefined means the setting is not sent) */ settings: { /** HPACK header table size in bytes */ headerTableSize?: number; /** Whether server push is enabled (0 = disabled, 1 = enabled) */ enablePush?: number; /** Maximum number of concurrent streams */ maxConcurrentStreams?: number; /** Initial flow-control window size in bytes */ initialWindowSize?: number; /** Maximum frame payload size in bytes */ maxFrameSize?: number; /** Maximum header list size in bytes */ maxHeaderListSize?: number; }; /** Idle timeout in seconds before the server sends GOAWAY */ goawayTimeout?: number; /** Expected content of the GOAWAY debug data field */ goawayDebugData?: string; } export declare const H2_SIGNATURES: H2Signature[]; //# sourceMappingURL=h2-signatures.d.ts.map