Marketplace:

 
Active-Venture.com: Cheap hosting for ecommerce and small business
Buy cheap domain registration with free domain search and forwarding services
Cheap domain registration: Register domain name and domain search services at affordable price

 

   

Identifying Your System?

next up previous contents index

Note that, for example, a HTTP server on port 80 identifying itself as:

  $ httptype togaware.com
  Apache/1.3.29 (Debian GNU/Linux) PHP/4.3.3


or a SSH server on port 22 identifying itself as:

  $ telnet togaware.com 22
  Trying 150.229.8.170...
  Connected to togaware.com.
  Escape character is '^]'.
  SSH-1.99-OpenSSH_3.6.1p2 Debian 1:3.6.1p2-10


is not really a security risk. Serious attacks will attempt all know vulnerabilities of the port, irrespective of what is running behind the port. Thus this is not regarded as sensitive information. On the other-hand, hiding the banner loses a lot for inter-operation.

Indeed, software should advertise its version number to aid debugging in all kinds of circumstances. If there's a security flaw then the flaw should be fixed instead of trying to hide it.


Copyright (c) 1995-2004

 

      

Marketplace:
Facts: " Perfection is achieved not when you have nothing more to add, but when you have nothing left to take away.   "  

Tuesday 22 May 2012 05:43:13 1337665393