view mod_version_spoofed/README.md @ 6319:04c3273cb81f

mod_auth_cyrus: Add empty 'profile' table to SASL handler objects This is for compatibility with Prosody's built-in util.sasl objects. A SASL profile table usually includes methods supported by the backend, which can be used by SASL mechanism handlers to perform operations (such as testing the password). It also optionally contains a 'cb' field with channel binding method handlers. The Cyrus backend doesn't support channel binding, and doesn't have the same concept of auth backend methods (it handles all that internally, and Prosody has no insight or control over it). Thus, we create an empty profile which informs Prosody that the SASL handler does not support any of the auth or channel binding methods. Some features will not work, but they didn't work anyway. This just makes it explicit. This fixes a traceback in mod_sasl2_fast, which expected SASL handlers to always contain a 'profile' field.
author Matthew Wild <mwild1@gmail.com>
date Thu, 04 Sep 2025 10:14:46 +0100
parents 0bd63c52bbed
children
line wrap: on
line source

---
summary: Server version spoofer
...

This module is a fork of the built-in mod_version that adds spoofing options. Please do not use this module to mess with services that provide statistics and information. Instead, contact the hosts of such services and request blacklisting.

# Configuration

  Name                   Description                                           Type      Default value
  ---------------------- --------------------------------------------------- -------- ---------------
  server\_name           the reported name of the server software            string   "Prosody"
  server\_version        the reported version of the server software         string   `prosody.version`
  server\_platform       the reported platform of the server software        string   nil

This replaces mod_version, so you must disable mod_version when enabling or the modules might conflict. Unconfigured, this module acts the same as mod_version.

As a tip if you want complete spoofing, you should use the `name` option under your VirtualHost and components to hide mentions of Prosody.

Compatibility
=============

  version   note
  --------- ---------------------------------------------------------------------------
  13        Should work
  0.12      Works