Web Hosting Talk







View Full Version : cracker can get all kinds of server info!


nethosting
07-29-2002, 01:01 AM
I came across this site today and it will tell you everything about a host. It knows when i changed my web server software to another version, and what my longest uptime was, and what my uptime currently is.. lots of stuff :/

Like for instance I looked up dslreports, and it tell me that dslreports didnt start using mod_gzip for apache web server until Feb 21st 2001 and dslreports once used Apache/1.3.12 on Jul 3rd 2002. the site always shows a graph of their uptime, with a max uptime of 144 days.

What my question is. How can I prevent this site from knowing what my uptimes are? I understand that you really cant block apache version from being sent (Without editing httpd file, which i just recently did) and i also blocked headers from being sent. im anonymous with apache.. but how can i block uptime?

i dont have finger service running, nor do i have telnet running.

Shyne
07-29-2002, 01:02 AM
And knowing the uptime helps a hacker how?

ntwaddel
07-29-2002, 01:13 AM
is it http://www.netcraft.com :D

http://uptime.netcraft.com/up/graph/?mode_u=off&mode_w=on&site=www.webspacesolutions.com&submit=Examine

JTY
07-29-2002, 01:27 AM
netcraft knows it by continually checking your server.

ntwaddel
07-29-2002, 01:30 AM
how do they know your uptime though? because when they start monitoring, if your uptime is 100 days, they dont start at 0, they start at 100. Is it some kind of finger or something?

mwatkins
07-29-2002, 01:32 AM
Somebody once gave me the finger. But then I deprecated them.

nethosting
07-29-2002, 01:36 AM
yes netcraft
no to keep crackers away, but everything helps.

yeah, i just did my site (they said no graphs, will start monitoring today) the other day ago,
i went and did my site today, and they new exactly what the uptime was.

wish i knew how they did this..

ntwaddel
07-29-2002, 01:40 AM
how does it help a hacker by knowing how many days your server has been up? :)

ntwaddel
07-29-2002, 01:42 AM
http://cert.uni-stuttgart.de/archive/bugtraq/2001/03/msg00187.html

nethosting
07-29-2002, 03:51 AM
it doesnt help him at all.
it just gives him more info then he needs :)

the less he knows, the better.


thanks for the link, btw

ntwaddel
07-29-2002, 04:00 AM
that link should tell you how to turn it off, and nobody will be able to monitor your uptime now :)

nethosting
07-29-2002, 04:28 PM
yeah i figured it out, thank you again :)