panos-scanner
panos-scanner copied to clipboard
How to get panos verion without etag
When i surf the pan web, i can't find etag in header. But got "Expires: Thu, 19 Nov 1981 08:52:00 GMT" and "Strict-Transport-Security: max-age=31536000", can i get version via js or other web pages?
Hello, Unfortunatly since our publication of this tool, Palo Alto is now stripping the Etag responses. This tool will only work on legacy versions. And as you can see in the version-table.txt file, the returned ETag was equivalent to dates of release of the software that doesn't seem to be related to "Expires: Thu, 19 Nov 1981 08:52:00 GMT" So to my understanding, no you can't get the version with the etag reply.
a new version of the code will be released soon. Some URIs still have the etag enabled, and will enable version detection. Working on identifiying 2-3 years of back log of versions. PR will be done soon
expect
@k4nfr3 any luck with your update and are you able to share your methodology on identifying the back versions? Happy to help.
Yes it's done. I need to send pr. The time consuming work is the fingerprinting of a lot of versions
I'll send pr tonight. Mostly as it is high topic after today's CVE announcement