Is returning the standard iis message from 400 family errors a vulnerability issue like headers?
My reasoning:
I'm not returning the headers, but the iis 404 error is different from apache, so an attacker would know that the server is an iis.
Is returning the standard iis message from 400 family errors a vulnerability issue like headers?
My reasoning:
I'm not returning the headers, but the iis 404 error is different from apache, so an attacker would know that the server is an iis.