Hacker News new | ask | show | jobs
by AstralStorm 2639 days ago
How is sending a patch level a vulnerability? It only makes things easier to scan, not to exploit.

(And you shouldn't trust that data anyway.)

1 comments

If every site responded, upon request, with their patch level, a database could easily be created.

Or a scan becomes that much easier to perform on 100,000 endpoints - and then your targeted attacks can begin on only vulnerable systems. 'Exploiters' waste a lot of time trying non-vulnerable systems.

The less information your server exposes to the outside, the better.