All web servers should have a standard build, including standard web content; they should have NTP enabled; and they should not reveal any information relating to the specific web server, such as internal IP addresses or system names.

No devices should reveal error messages to the enduser since the device may leak its type and version, via either the error message or its HTTP headers. Some devices, such as load balancers and firewalls, will perform relatively simple intrusion prevention functions, possibly revealing their presence to an attacker performing various attacks.

