Want everyone on your software team to learn this? Free 14-day trial.

Train my team

The first thing an attacker will try to figure out is what web server you are running, and the language it is written in. Many web servers describe this information in HTTP headers, which is great advertising for the web server vendor, but bad news for you.

HTTP response from Apache 1.3.23
HTTP
Server: Apache/1.3.23
Accept-Ranges: bytes
Content-Length: 196
Connection: close
Content-Type: text/html
HTTP response from Microsoft IIS 5.0
HTTP
Server: Microsoft-IIS/5.0
Content-Type: text/html
Accept-Ranges: bytes
ETag: "b0aac0542e25c31"
Content-Length: 7369