@ariadne See also: bargain basement PCI compliance scanning companies. I have a side client where we have as much configured (Apache etc) to strip version numbers from the public responses. Not for security through obscurity, but to hide them from the vendor which doesn't know what those weird "-4ubuntu13" strings are at the end of our MASSIVELY INSECURE SOFTWARE FAIL FAIL FAIL
Edit: just saw what this was was subtooting, and yeah, pretty much what I expected, ugh