Page 1 of 1

Remove product version from non-authenticated page

Posted: Thu Jan 29, 2015 7:35 pm
by eloyd
I just realized, at the bottom of my Nagios Log Server page, prior to logging in, is displayed the current version of NLS. This is not within best IT security practices, as it provides an intruder with potential information specific to that version of NLS that could be used as an attack vector.

I recommend moving the "Nagios Log Server • 2015R1.1 • Check for updates" to an authenticated page.

The same would apply to NNA as well, but I'm not going to double post.

Re: Remove product version from non-authenticated page

Posted: Fri Jan 30, 2015 11:26 am
by scottwilkerson
Agreed, I'm going to work to get this removed for all products...

Thanks Eric.