hakoriginfinder: Find Origin Hosts Behind Reverse Proxies

Summary
hakoriginfinder compares responses from supplied IP addresses with a target hostname to help identify an origin host behind a reverse proxy. It is a Go command-line tool for authorized security testing and network reconnaissance.
At a glance
- Language
- Go
- Stars
- 1.1k
- Forks
- 141
- Added to OSRepos
- March 26, 2026
- Last analyzed
- October 3, 2026
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Overview
hakoriginfinder tests whether IP addresses may host the origin server behind a reverse proxy. It requests a baseline response from a hostname, then sends requests to the supplied IPs with the original host in the Host header and compares response similarity using Levenshtein distance.
It is intended for security practitioners investigating their own infrastructure or conducting authorized assessments. A match is a lead for further verification, not proof that an IP is the origin.
Key Features
- Reads candidate IP addresses from standard input.
- Uses a specified hostname or URL as the baseline.
- Tests HTTP and HTTPS ports 80 and 443 by default, with configurable ports.
- Sets the original host in requests to candidate IP addresses.
- Scores response similarity with the Levenshtein algorithm and a configurable threshold.
- Supports concurrent requests, with a default of 32 threads.
- Prints a match status, tested URL, and distance score for each result.
Use Cases
- A penetration tester can check authorized candidate IP ranges for an application protected by a reverse proxy or WAF.
- A security team can investigate whether a publicly reachable origin server may be bypassing its intended proxy controls.
- An infrastructure operator can validate that known backend addresses return the expected site response when addressed with the production hostname.
- A researcher can triage candidate hosts during scoped web reconnaissance, then manually verify any reported matches.
Project Facts
- Language: Go
- Stars: 1.1k
- Forks: 141
- Archived: No
Getting Started
Install with Go:
go install github.com/hakluke/hakoriginfinder@latest
Provide candidate IPs on standard input and set the target hostname with -h. See the README for options and examples.
Considerations
- Use only against systems you own or are explicitly authorized to assess. Identifying an origin can undermine proxy or WAF protections.
- Response similarity is heuristic: dynamic pages, redirects, error pages, and differing content can affect results. Validate findings independently.
- Candidate IPs must be supplied by the user. The tool does not discover address ranges itself.
- The README documents HTTP and HTTPS requests, default ports, a similarity threshold, and a thread count; plan for network access and potentially many requests when scanning large input lists.
- No license is specified in the provided repository metadata.
Source repository
Open the original repository on GitHub.
19 counted GitHub visits
Related repositories
Similar repositories that may be relevant next.

e2a: Email API for Applications and AI Agents
September 29, 2026
e2a provides an email API and relay for applications and AI agents. It supports transactional sending, inbound mailboxes, and agent replies, with optional human review and hosted or Docker-based deployment.

router: Route AI Requests to the Best Model
September 28, 2026
weave-os/router is a Go proxy that routes AI requests across configured model providers, while accepting Anthropic, OpenAI, and Gemini API formats. It suits developers who want model choice and routing behind one endpoint, including agent and coding-tool users.

ksail: Create and Operate Kubernetes Clusters
September 27, 2026
KSail is a Go-based toolkit for creating and operating Kubernetes clusters across local, nested, and cloud providers. It brings provisioning, GitOps, secrets, cluster operations, and AI interfaces into one tool, for developers and platform teams who want a unified workflow.

Memoh: Give AI Agents Dedicated Cloud Computers
September 26, 2026
Memoh is a multi-agent platform that gives each agent an isolated, always-on workspace with a desktop, browser, network access, and long-term memory. Use your own API keys or host agents such as Claude Code and Codex, either in Memoh Cloud or on your own infrastructure.