From: Alexander S. [ML] <mai...@al...> - 2004-06-29 18:45:29
|
m wrote: > Maybe not in normal way but I have users who want to knows as much as > possible. So when in html code are this entries they have easiest way > to find which software are running bottom, and when there will be > found some security important bug - they have full version number, > date when "system" was updated and if it is susceptible to hack it. > So I want to hide as many as possible - of course this will not avoid > "fingerprint" of system - names of variables, whole scheme etc. > But they must known exacly this system to know what they can do bad. > 90% are teens which has too much free time. If they have enough time, then they can easily read the source code and look for changed behavior and know the version. But you dont need to know the version in order to exploit a bug: you can just try to run the exploit. Hiding those CVS special strings does not increase the security at all. Kind regards, Alexander |