EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesEasy

A cybersecurity consultant is advising a small business on hardening their public-facing web server to prevent information leakage. The previous penetration test identified that the server's HTTP response headers (e.g., 'Server', 'X-Powered-By') were revealing specific software versions and technologies. Which of the following is the most effective countermeasure to address this specific issue?

  1. AModifying web server configuration to remove or obfuscate banners
  2. BImplementing an Intrusion Prevention System (IPS)
  3. CEncrypting all web traffic with HTTPS
  4. DDisabling ICMP echo requests
Show answer & explanation

Correct answer: A. Modifying web server configuration to remove or obfuscate banners

Modifying web server configuration to remove or obfuscate HTTP response headers like 'Server' and 'X-Powered-By' directly prevents the leakage of specific software versions and technologies, addressing the identified issue effectively.

Why the other options are wrong

  • B. An IPS can detect and block attacks but doesn't inherently modify server response headers to hide information.
  • C. Encrypting traffic with HTTPS protects the content of communication but does not inherently remove or obfuscate server banners in the headers themselves.
  • D. Disabling ICMP echo requests prevents ping responses but does not affect HTTP header information leakage.

Service Banner Grabbing Countermeasures

Techniques to prevent network services (e.g., web servers, FTP, SSH) from revealing their software type and version in response to connection attempts, thereby reducing the attack surface.

  • Obfuscates or removes identifying headers.
  • Applies to various protocols (HTTP, FTP, SSH).
  • Reduces information available to attackers for targeted exploits.

Memory trick: Don't show your hand, hide the server's brand.

More Reconnaissance Techniques questions