Skip to content

Uwebsockets header constitutes a security issue #363

Answered by ghost
theninthsky asked this question in Q&A
Discussion options

You must be logged in to vote

You already have UWS_HTTPRESPONSE_NO_WRITEMARK to disable this, but you need to build your own binary with it. This software is free and you can do whatever you want with it but by default it does send this header, yes. I want users to keep this header so that's why I have it on by default.

I absolutely see no security issue in telling (roughly) what server is in use. Many, many projects and companies do similar things. Besides, it is not that hard to figure out what tech stack a company use - often times they list all their tech in Careers page, etc.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant
Converted from issue

This discussion was converted from issue #363 on December 09, 2020 03:49.