LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > General > Server Signature

Reply
 
Thread Tools Display Modes
  #1  
Old 03-18-2007, 06:18 AM
alberto alberto is offline
Member
 
Join Date: Dec 2006
Posts: 14
Default Server Signature

We run e-commerce sites on our servers, so security is always a big concern.

Hence the importance of minimizing the amount of information an attacker can get from our system.

I know it's important for you to get as much exposure as possible for LiteSpeed, but I think it should not be done at the expense of your customers. Finally I ask you:

Is it possible to hide LiteSpeed server signature? Does LiteSpeed offers this option?
Reply With Quote
  #2  
Old 03-18-2007, 11:24 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
First, we think LiteSpeed is the most secure web server out there.
Second, the security by obscure does not really help much, if any help at all.
Reply With Quote
  #3  
Old 03-19-2007, 02:58 AM
alberto alberto is offline
Member
 
Join Date: Dec 2006
Posts: 14
"Second, the security by obscure does not really help much, if any help at all."

That's true, but any security boost is welcome in the e-commerce world.

Signature hiding might be so easy to implement that I can't believe you don't have it...
Reply With Quote
  #4  
Old 03-19-2007, 09:31 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Yeah, it is very easy to implement, we will consider adding it in future release.
Reply With Quote
  #5  
Old 09-11-2007, 05:10 PM
rubyjuice rubyjuice is offline
New Member
 
Join Date: Aug 2007
Posts: 8
Default I'd like to see this also

I trust that Litespeed is as secure as it is fast, but, that's not the point.

Obscurity may not be security, but that doesn't mean it's not a useful tool. Deception is a useful and cheap mechanism to employ. If a vulnerability is ever discovered, it may just help my server "hide" from the casual attacker until the weakness is patched.

Please add it to a future release, especially if it is easy to implement. :P
Reply With Quote
  #6  
Old 09-11-2007, 06:13 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Enterprise edition can completely hide the server signature.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 03:14 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.