[an error occurred while processing this directive] [an error occurred while processing this directive][an error occurred while processing this directive] [an error occurred while processing this directive] [an error occurred while processing this directive] [an error occurred while processing this directive] (none) [an error occurred while processing this directive] [an error occurred while processing this directive] [an error occurred while processing this directive] [an error occurred while processing this directive] [an error occurred while processing this directive][an error occurred while processing this directive] [an error occurred while processing this directive][an error occurred while processing this directive] [an error occurred while processing this directive][an error occurred while processing this directive] [an error occurred while processing this directive] [an error occurred while processing this directive] [an error occurred while processing this directive] (none) [an error occurred while processing this directive] [an error occurred while processing this directive] [an error occurred while processing this directive][an error occurred while processing this directive]
 
[an error occurred while processing this directive] [an error occurred while processing this directive]
Skåne Sjælland Linux User Group - http://www.sslug.dk Home   Subscribe   Mail Archive   Forum   Calendar   Search
MhonArc Date: [Date Prev] [Date Index] [Date Next]   Thread: [Date Prev] [Thread Index] [Date Next]   MhonArc
 

Re: [SIKKERHED] Annoncere hvilket OS der køres



> Heikki Levanto <sslug@sslug> writes:
> All in all, this sounds like security by obscurity. A bit of information
> hiding is all right, but nothing should depend on it.
>
Man bör ikke basere sin sikkerhed paa "security through obscurity", men
der er heller ingen grund til at skilte med al informationen! Apache har
en dejlig lille indstilling med deres "ServerTokens" tag - der kan sättes
til kun at sige "Apache", saaledes at man absolut ingen information faar
fra en server.

Det ville väre dejligt hvis man kunne faa samme feature med i SSH og andre
protokoller, der foreskriver detaljeret beskrivelse - hvorfor skal man
fortälle andet end hvilke protokoller man understötter ?

Jo mere arbejde en cracker skal paa for at komme ind i et system, jo bedre!

/Kim



 
Home   Subscribe   Mail Archive   Index   Calendar   Search

 
 
Questions about the web-pages to <www_admin>. Last modified 2005-08-10, 20:47 CEST [an error occurred while processing this directive]
This page is maintained by [an error occurred while processing this directive]MHonArc [an error occurred while processing this directive] # [an error occurred while processing this directive] *