S4E just found a high top 10 tcp port service scan
medium·Misconfiguration·Updated Dec 16, 2023

HTTP Apache Negotiation Scanner

HTTP Apache Negotiation Scanner

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
186
Times Used
by S4E users
74
Assets Scanned
domains & IPs
87
Vulnerabilities Found
confirmed findings
References
Detail

Checks if the target http server has mod_negotiation enabled. This feature can be leveraged to find hidden resources and spider a web site using fewer requests.

The script works by sending requests for resources like index and home without specifying the extension. If mod_negotiate is enabled (default Apache configuration), the target would reply with content-location header containing target resource (such as index.html) and vary header containing "negotiate" depending on the configuration.

For more information, see:

Solution Advice

Make your HTTP server mod_negotiation parameter disabled.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.