httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Brian Behlendorf <>
Date Thu, 27 Jul 1995 23:27:03 GMT
On Thu, 27 Jul 1995, Andrew Wilson wrote:
> 	this is just a thought prompted by Paul Richards.  It'd be kind of
> nice to figure out what OS people are running their server on.

Many would consider this a security hole, and most internet daemons have 
removed this information (i.e. wu-ftpd, sendmail, etc).  The recent spat 
of "Olga" messages made themselves untraceable by specifically going 
through broken IBM VMS mailers who trusted whatever the client told them 
in the HELO message.  I'd consider putting information about extensions 
in there a security hole too, perhaps even worse.  Just a note of 
caution, I wouldn't veto it but I wouldn't +1 it either.

	The Anal Retentive Computerist

--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--  http://www.[hyperreal,organic].com/

View raw message