/** * HTTP response header ordering signatures for server identification. * * Different HTTP server implementations emit response headers in a characteristic * order that is determined by the source code, not by any standard. By recording the * order of canonical header names in a response and comparing against known signatures * we can passively fingerprint the server software -- even when the Server header is * stripped or spoofed. * * The hash is computed by joining the lowercased header names with commas and taking * a simple FNV-1a 32-bit hash of the resulting string. * * References: * - https://httprobe.org * - Nmap HTTP fingerprinting engine */ /** A known header-order signature entry. */ export interface HeaderOrderSignature { /** The server software name */ server: string; /** Canonical header names in the order they appear in a typical response */ order: string[]; /** Precomputed SHA-256-based short hash of the joined header order for quick matching */ hash: string; } /** * Compute a deterministic hash from an array of header names. * * The function lowercases every header name, joins them with commas, and returns * the first 16 hex characters of the SHA-256 digest. This gives 64 bits of entropy * which is sufficient for matching against a small dictionary. * * @param headers - Array of header names in observed order * @returns 16-character hex hash string */ export declare function computeHeaderOrderHash(headers: string[]): string; export declare const HEADER_ORDER_SIGNATURES: HeaderOrderSignature[]; //# sourceMappingURL=header-order.d.ts.map