|
Masking or anonymizing a Web
Raster to Vector converts
Masking or anonymizing a Web
Fast Find: Easy to find
server involves removing
scanned drawings, maps and
server involves removing
thousands of link partners
identifying details that
raster images (such as BMP,
identifying details that
relevant to your website.
intruders could use to
JPG, TIF, GIF, etc) into
intruders could use to
Direct Add Link Pages: All
detect your OS and Web
vector formats (such as DXF,
detect your OS and Web
the link pages found are
server vendor and version.
HPGL, EMF, etc). You can
server vendor and version.
direct add link page, that
This information, while
scan old plans, archive
This information, while
you can add your link
providing little or no
drawings, or even photos and
providing little or no
directly. Such as
utility to legitimate users,
convert them into useful CAD
utility to legitimate users,
www.a.com/addurl.html,
is often the starting place
data.
is often the starting place
www.b.com/add-link.html
for crackers, blackhat
for crackers, blackhat
hackers and "script
hackers and "script
kiddies". This
kiddies". This
article explores some ways
article explores some ways
you can minimize the risk of
you can minimize the risk of
such detection. Most of the
such detection. Most of the
examples focus on
following examples focus on
Microsoft’s Internet
Microsoft's Internet
Information Server (IIS),
Information Services (IIS)
since it has been most
Web server, since it has
widely lambasted for its
been most widely lambasted
vulnerabilities, but some
for its vulnerabilities, but
Apache detection
some Apache detection
countermeasures are also
countermeasures are also
covered. While IIS users
covered. While IIS users
probably have the most
probably have the most
vested interest here, server
vested interest here, server
anonymization is relevant to
anonymization is relevant to
anyone responsible for
anyone responsible for
administering a Web server.
administering a Web server.
Date: May, 21 2003 Date: May, 26 2005 Date: Dec, 02 2004 Date: Feb, 26 2007 |
|
HackerTrap is the first step
towards protecting your
site!The web today is a
jungle of hackers and
script kiddies trying
to take over any servers
they can. They blast your
site with multiple requests
for several different
applications and check which
get a response - then
exploit known weaknesses of
that application. Even if
you don't run the
application, the error
response provides
information on the webserver
type and version (and that's
a double whammy, because the
standard error response is
ugly if seen by a real
user!).
With HackerTrap
you specify which
applications you DON'T run,
and which directories a user
should NEVER access. It
comes preloaded with the
common directories and file
used by popular scripts to
probe sites. When a hacker
shotguns your site looking
for weaknesses, it hits one
and BAM, he's can't get near
you! If a user makes an
innocent mistake in the URL,
he is not penalized and in
fact, gets an attractive
error page customized by you.
Date: Aug, 09 2006 |