Tuesday, April 22, 2014

Apache fingerprinting with icons directory

Sometimes webservers don't return "Server" header in HTTP response or return fake value. It doesn't increase security in any way and it's clear example of Security through obscurity, however some administrators want to hide this information or even change it to some odd values.

If you are one of them and you're running apache don't forget about default /icons/ alias. Anyone can use it to guess that you're using apache, for example:


Directory content can be different between apache versions, so it also may reveal which version you are using.

For example:

Apache 2.2 (icons/apache_pb.gif):
Apache 2.2

Apache 2.4 (icons/apache_pb.gif):
Apache 2.2

For more differences you can take a look in apache source code repository history:

You can disable this alias in the httpd.conf file, simply comment out the line:
Alias /icons/ "/var/www/icons/"


  1. This comment has been removed by a blog administrator.

  2. This comment has been removed by a blog administrator.

  3. On the other hand, the initial download and set up of a download-based on-line on line casino shopper take time. As with 코인카지노 any download from the internet, the chance of the program containingmalwareexists. That’s why on-line casinos have to offer other kinds of games, corresponding to roulette. Punters who like actual casinos all the time look for this recreation, which additionally makes it in style among iGaming followers.

  4. The RNG determines finish result} of every spherical in an unbiased method. Either way, you'll be able to|you possibly can} put in your spare cash and take some winnings home with on-line casinos with actual cash. Here are a number of} of the options that characterize actual cash on-line casinos. Firstly, the aforementioned RNGs are regularly examined by third-party firms. Yes, plenty of on-line casinos for actual cash take Canadian dollars 온라인카지노 and embrace them throughout the record of accepted currencies.