fingerserver
Description
Fingerprint is a self-hosted anonymity verification service written in Go. It is a TLS/HTTP echo server that analyzes every incoming connection and shows visitors exactly what information about them is observable from the network: browser User-Agent, TLS fingerprint (JA3/JA4), raw TCP/IP parameters of the first SYN packet and IP geolocation.
The project is intended for privacy research, proxy/VPN quality checks and testing how strongly a client's identity leaks through the network stack. The web panel is a single page that displays all collected data in separate sections, each with its own refresh button.
Modules used
Local modules (via replace in go.mod):
- data - generated with go-bindata. Embeds web panel assets (HTML, CSS, JS, fonts) as gzipped data into the binary
- ip2location - reader of IP2Location binary databases (.BIN): binary search over IPv4/IPv6 ranges, returns country, region, city, ISP, coordinates and other fields. Includes a uint128 subpackage for 128-bit integer arithmetic for IPv6
- useragent - regex User-Agent parser (based on mileusna/useragent): extracts browser, OS, device type and bot flags
External dependencies:
- github.com/wi1dcard/fingerproxy v1.2.3 - TLS fingerprinting proxy: intercepts the raw ClientHello record into request metadata, computes JA3/JA4, provides a uTLS proxy server
- github.com/dreadl0ck/tlsx v1.0.3 - low-level TLS ClientHello parsing: deserializes the raw record into structured fields
- github.com/refraction-networking/utls v1.8.1 - uTLS, a TLS stack for client fingerprint analysis; provides a dicttls dictionary with human-readable names of ciphers, extensions, groups and signature algorithms
- github.com/google/gopacket v1.1.19 - packet capture and decoding: pcap (libpcap) live capture, BPF filters, IPv4/TCP layer decoding
Indirect dependencies: prometheus/client_golang (metrics, pulled in via fingerproxy), klauspost/compress, andybalholm/brotli, golang.org/x/{crypto,net,sys,text}, google.golang.org/protobuf.
Technologies
- Go 1.24 - the whole server
- libpcap / gopacket - real-time packet capture and IPv4/TCP decoding
- uTLS / fingerproxy / tlsx - TLS ClientHello interception and JA3/JA4 computation
- IP2Location BIN - binary geolocation database
- go-bindata - embedding web assets into the binary
- Bootstrap 5, jQuery - panel UI
- Leaflet 1.7.1 + OpenStreetMap - geolocation map
- ua-parser-js - client-side User-Agent parsing
- TLS 1.0-1.3 - the service works with all TLS versions; cipher suites and record versions serve as reference data for fingerprint analysis
- License GNU AGPL v3 (Affero GPL)