I guess it's just checking for some header,like express has a special header... by the way, framework authors, please refrain from doing stuffs like that. The framework i use is nobody's business but mine.
It's also dangerous and irresponsible from a security standpoint. Not advocating security by obscurity, but advertising it doesn't help.
Exactly the same sentiment, making me put in extra effort to hide underlying technology seems ridiculous to me.
Yeh, just looks at the header; node activity detected
Found x-powered-by: Express header in response
I'm not sure what they are using to serve up their site, other than nginx. But they do have this header, "X-Hi-Human: The AIRBNB SRE team added this header. Come work with us! Email dave+header@airbnb.com"