View Issue Details

IDProjectCategoryView StatusLast Update
0007084Kali LinuxKali Websites & Docspublic2021-03-10 07:46
ReporterDragonSpider111 Assigned Torhertzog  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionwon't fix 
Summary0007084: Server Information Disclosure
Description

Server Information disclosure:
below information is publically disclosed.
Apache/2.4.10 (Debian) Server at http.kali.org Port 443

Steps To Reproduce

Visit: https://http.kali.org/kali/pool/main/d/dj-database-url/

You will see server apache and its version below files.

Additional Information

Server version and name can be risky to disclose publically, because any pro hacker can try to gain access after knowing this server information.

Attached Files
kali info.JPG (107,038 bytes)   
kali info.JPG (107,038 bytes)   

Activities

Michu

Michu

2021-03-09 19:21

reporter   ~0014300

in my opinion you should go to apache website and report to them not kali team and from kali 2.0 apache in ALL versions showed version of this server so you should report apache team

kali-bugreport

kali-bugreport

2021-03-09 20:46

reporter   ~0014301

because any pro hacker can try to gain access after knowing this server information

Any "pro hacker" won't rely on such information at all :-)

Note that "Security through obscurity" is never working, hiding the version doesn't provide any benefit / additional security.

DragonSpider111

DragonSpider111

2021-03-10 00:41

reporter   ~0014304

@Michu Great, I will try to report it to apache Thank you for the response.

@kali-bugreport I think you didn't notice my full comment in additional information section, i have mentioned any pro hacker can "TRY" to gain access, It does not mean pro hacker will rely on only this small information.

rhertzog

rhertzog

2021-03-10 07:46

administrator   ~0014306

Please don't annoy the apache developers, there's a configuration knob to turn off the display of the version information. But honestly, it's not that important of an issue. Security through obscurity doesn't buy much.

Issue History

Date Modified Username Field Change
2021-03-09 18:22 DragonSpider111 New Issue
2021-03-09 18:22 DragonSpider111 File Added: kali info.JPG
2021-03-09 19:21 Michu Note Added: 0014300
2021-03-09 20:46 kali-bugreport Note Added: 0014301
2021-03-10 00:41 DragonSpider111 Note Added: 0014304
2021-03-10 07:46 rhertzog Assigned To => rhertzog
2021-03-10 07:46 rhertzog Status new => closed
2021-03-10 07:46 rhertzog Resolution open => won't fix
2021-03-10 07:46 rhertzog Note Added: 0014306