Re: Web Server Type



Whilst this is information disclosure, it's not really a huge security
vulnerability. If you remove that header, does it some how protect you
against any sort of malicious attack? Nor really.

An attacker can easily hurl malicious code for every possible attack against
every possible type of webserver against your box using an automated tool,
and no matter whether you remove the banner or not, the attack will still
succeed if your server is vulnerable.

Cheers
Ken

"George Schneider" <georgedschneider@xxxxxxxxxxxxxx> wrote in message
news:47FB1C9E-6E7D-427E-9712-B1AC30604B79@xxxxxxxxxxxxxxxx
I recently had a vulnerbility test conducted on one of web servers and the
recommendation that was made to us that web server server type was
detectable
as Microsoft-IIS/6.0. The conclusion was this is a vulnerabilty. The
recommended solution was to configure the server to use an alternative
name.
Does anyone have any idea how to do this or heard anything like this.


.



Relevant Pages

  • Re: How to Hide the IIS FTP Banner ?
    ... > before starting their attack. ... >>vulnerable server in the first place so it wouldn't make any ... > know, until a vulnerability is discovered and announced, that your server ... You'd have to ask the client authors about that, ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: How to Hide the IIS FTP Banner ?
    ... before starting their attack. ... How do you know that the server is vulnerable or not? ... know, until a vulnerability is discovered and announced, that your server ... Cedar Park TX 78613-1419 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.inetserver.iis.ftp)
  • iDefense Security Advisory
    ... Bufferoverflow in 0verkill Server ... 0verkill is a client-server 2d deathmatch-like game in ASCII art. ... very serious vulnerability and should be taken seriously. ... detect this version of the attack, ...
    (Bugtraq)
  • [Full-Disclosure] iDefense Security Advisory
    ... Bufferoverflow in 0verkill Server ... 0verkill is a client-server 2d deathmatch-like game in ASCII art. ... very serious vulnerability and should be taken seriously. ... detect this version of the attack, ...
    (Full-Disclosure)
  • RE: Views and Correlation in Intrusion Detection
    ... compares those to packets hitting specific ... The ability to integrate IDS data and vulnerability scan ... a db with the info on each server - OS, applications, ... a detection engine that matches the IP and attack sig to the entry in ...
    (Focus-IDS)