Raised This Month: $51 Target: $400
 12% 

Security leak at alliedmods web site


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
addons_zz
Veteran Member
Join Date: Aug 2015
Location: Dreams, zz
Old 10-28-2015 , 11:06   Security leak at alliedmods web site
Reply With Quote #1

Security leak at alliedmods web site

Quote:
Service Temporarily Unavailable

The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later.

Apache/XXXX (Unix) ... More server Info lead... Server at forums.alliedmods.net Port XXX
Quote:
Not Found

The requested URL /laksdjflçaksd was not found on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.

Apache/XXXX (Unix) ... More server Info lead... Server at forums.alliedmods.net Port XXX
The server should not display to the public its softwares version as each know version has its know security leaks.

Then as it is, it let this web site more reliable for attacks.

It is just a configuration at Apache. Here there is a tutorial about that:

http://www.tecmint.com/apache-security-tips/
__________________
Plugin: Sublime Text - ITE , Galileo
Multi-Mod: Manager / Plugin / Server

Support me on Patreon, Ko-fi, Liberapay or Open Collective

Last edited by addons_zz; 12-22-2015 at 19:09. Reason: Here there is a tutorial about that
addons_zz is offline
asherkin
SourceMod Developer
Join Date: Aug 2009
Location: OnGameFrame()
Old 10-28-2015 , 17:55   Re: Security leak at alliedmods web site
Reply With Quote #2

This is not an issue.
__________________
asherkin is offline
addons_zz
Veteran Member
Join Date: Aug 2015
Location: Dreams, zz
Old 10-28-2015 , 21:08   Re: Security leak at alliedmods web site
Reply With Quote #3

Well well, the security tips says it could be a security leak.

Quote:
In above picture, you can see that Apache is showing its version with the OS installed in your server. This can be a major security threat to your web server as well as your Linux box too. To prevent Apache to not to display these information to the world, we need to make some changes in Apache main configuration file.
Of course, it is not an functionality issue.

But will be so bad this site stop releasing unnecessary information about it self.

I mean, change this:



Into this:

Last edited by addons_zz; 10-28-2015 at 21:10.
addons_zz is offline
devilicioux
Veteran Member
Join Date: Jun 2013
Location: Delhi,India
Old 10-29-2015 , 04:10   Re: Security leak at alliedmods web site
Reply With Quote #4

He's right.. publically displaying up versions of softwares used makes it easy for hackers as well as script kiddies to just directly search for exploits and vulnerabilities to that specific version and fire the hell out of website..
__________________
You keep bringing ANTICHRISTUS down .. He will rise again and kick asses !

#RespectList ANTICHRISTUS fysiks Bugsy

Most Common Errors You Can Encounter Every Now and Then
devilicioux is offline
shavit
AlliedModders Donor
Join Date: Dec 2011
Location: Israel
Old 10-29-2015 , 07:03   Re: Security leak at alliedmods web site
Reply With Quote #5

nginx masterrace
__________________
retired
shavit is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 08:19.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode