hackwither_

reap / rules / templates

Server response header discloses backend/edge software

mcp-tmpl-server-header-fingerprint ASI09 Human-Agent Trust Exploitation severity: info

What it detects

Server header (excluding known CDN/edge tokens) or any X-Powered-By header identifying backend/origin software. ASI09. Go probe despite the tmpl in its ID — the name predates the JSON template format.

Flags a Server header (excluding known CDN/edge tokens: cloudflare, envoy, nginx, cloudfront, varnish, akamai, fastly) or any X-Powered-By header identifying backend/origin software. Go probe despite the tmpl in its ID (name predates the later template format).

applies to MCP endpoints

Example finding

INFO  mcp-tmpl-server-header-fingerprint  MEDIUM CONFIDENCE
Server response header discloses backend/edge software
The response includes a Server or X-Powered-By header identifying backend software that appears to be the origin application, not a CDN/edge layer (which is already surfaced separately in the target fingerprint's Edge line). Not a vulnerability by itself, but useful fingerprinting context worth trimming in production.
Evidence  POST /mcp → 200

from a scan of reap-range, bad target

Fix

Suppress or genericize identifying response headers in production deployments where they name the origin application.

On reap-range

insecure targetbad/mcp (Server: Werkzeug/3.0 Python/3.12.3) · Info
correct targetgood/mcp sends no Server header

Run only this check

reap -t https://your-host/mcp --authorized --include mcp-tmpl-server-header-fingerprint

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.