In Apache you can restrict the information that it reveals about itself setting ServerTokens to Prod for example, and it will give only Apache when you telnet to it. But in case of an error page it will present the version number along with it (I know you can redirect this error, but still). Does Nessus check for this when it finds an Apache webserver but cannot check for version? Rick
This archive was generated by hypermail 2b30 : Fri Mar 07 2003 - 14:49:51 PST