Most (all?) web servers stick their names in a header. I've never heard that that is controversial from a security POV. Also, .NET apps are incredibly recognisable from a quick glance of the source code (__doPostBack and VIEWSTATE are two easy tells). Again, most popular web app frameworks leave some hints in the source that makes it fairly easy to figure out what they are (utf8=✓ in rails).