[dokuwiki] Re: HTML header, generator and keywords

  • From: Andreas Gohr <andi@xxxxxxxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Sat, 7 Apr 2007 09:39:51 +0200

On Sat, 7 Apr 2007 00:36:16 +0200
Guy Brand <gb@xxxxxxxxxxxxxxxxx> wrote:

> On 06 April at 10:31, Sebastian Pipping wrote:
> 
> > == Generator ==
> > DukuWiki adds a generator line to the HTML header
> > that reveals the version of DokuWiki used.
> > The problem I see here is that an attacker could
> > use this information to break into the site using
> > a technique only working for this version.
> 
>   I don't think hiding php version, apache version, OS version,
>   SSL version, SSH version, whatever version, DokuWiki version
>   has anything to do with computer security.

I agree, that's security by obscurity and that has never worked. But if
you really want to hide the version, just delete the VERSION file from
you DokuWiki directory.

Andi

-- 
http://www.splitbrain.org
-- 
DokuWiki mailing list - more info at
http://wiki.splitbrain.org/wiki:mailinglist

Other related posts: