漏洞名称:可通过HTTP获取远端WWW服务信息
-
Description
REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The HTTP/WWW service is running." -
解决办法:
- NSFOCUS建议您采取以下措施以降低威胁:
- 改变您的HTTP服务器的缺省banner。
- 讲人话就是:你的服务地址暴露了一些服务相关的信息,比如:“你的服务正在运行中”,屏蔽掉相关敏感信息就行。
漏洞官方描述:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0633