Re: Hiding Versions

From: Eivind Eklund (eivind@thinksec.no)
Date: 07/09/01


Date: Mon, 9 Jul 2001 00:24:09 +0200
From: Eivind Eklund <eivind@thinksec.no>
To: Jason Burdick <webmaster@yclan.net>

On Fri, Jul 06, 2001 at 05:01:03PM -0400, Jason Burdick wrote:
> Hiding version strings is very pointless. The only use is to let admins be
> a tad bit more lazy in patching so s'kiddies, who only look for version
> strings for exploit purposes, will pass by the box. This doesn't stop
> someone with a clue, so it's a waste of time. Patch the box correctly, and
> you'll have less problems.

I agree that you should patch the box correctly. I do not agree that hiding
verison numbers is useless. When you hide your version number, you make
it less likely that the exploit will work the first time - and if your
service is set up so the first attempt is all the attackers get (e.g,
BIND exploits) then hiding the version number increase real security.
It also increase the likelihood of detection, as a wrong exploit is likely
to be tried first, and thus log an error.

Eivind.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: How do I change the text on a button at run time on a PDA?
    ... Indeed, you can set the strings for the on and off state, but it will ... only show the default off state text when running on a pocketPC. ... By overlaying the two controls and hiding the last pushed button, ... Prev by Date: ...
    (comp.lang.labview)
  • String to file path
    ... I am looking for a function in LabVIEW and it seems to be hiding from me. ... The 3 strings are then concatenated.Can I turn that concatenated string into a filepath? ... It would be really cool if there was a "string to filepath" function, ...
    (comp.lang.labview)
  • Re: Y&R - I cant believe youre all falling for Brads story!
    ... I remember way back when he was marrying Tracy (the first time) and she ... I thought your exact words "Hmm, that was weird, I wonder what he's ... hiding" But nothing ever came of it until now. ... Both of these past hints were consistent clues to the ...
    (rec.arts.tv.soaps.cbs)
  • free to good home
    ... This time It is red felt that I found hiding away. ... It has a small patch od black dribbles on it, ... Southern Florida - land of the hurricanes ...
    (rec.crafts.textiles.quilting)
  • Re: Pictures from today
    ... We didn't see any animals, they must have all been hiding, saw lots of ... I did take a few pictures if you want to have a look ... This is the first time I've seen foxglove! ...
    (uk.people.silversurfers)