Quantcast
Viewing all articles
Browse latest Browse all 1881

Default iis message 40* is break security

Is returning the standard iis message from 400 family errors a vulnerability issue like headers?

My reasoning:
I'm not returning the headers, but the iis 404 error is different from apache, so an attacker would know that the server is an iis.


Viewing all articles
Browse latest Browse all 1881

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>