Sunday, February 11, 2007

Tighten up security, disable Apache's signature

...Server: Apache/2.0.55 (Debian) PHP/5.1.2

Apache by default with most packaged distributions will display the Apache version you are running in a signature and generally any other modules loaded into it too. This can be a problem if you are running old versions with know security issues.

So if doing an upgrade is an inconvenience then perhaps masking the server signature is the way to go.

First we'll begin with PHP. If you navigate to your php.ini file (generally stored in /etc/php5/apache2/), you'll find the expose_php is set to "On". We can turn this off by simply typing in "Off".

Apache itself will sign the version number running too. Again a security issue. If you open the apache2.conf file (generally in /etc/apache2/), you can turn this off with setting:

ServerTokens ProductOnly

Or perhaps you want to scrap it all together:

ServerSignature Off

9 comments:

Anonymous said...

Thanks colabus.

Anonymous said...

top [url=http://www.001casino.com/]casino online [/url]hinder the latest [url=http://www.realcazinoz.com/]casino online[/url] unshackled no deposit hand-out at the chief [url=http://www.baywatchcasino.com/]baywatch casino
[/url].

Anonymous said...

[URL=http://pharmacypills.atspace.co.uk/dostinex/dostinex-liquid.html]dostinex liquid[/URL]

Anonymous said...


[url=http://shenenmaoyis.bravesites.com/][b]sac longchamp[/b][/url]
[url=http://shensacen.insanejournal.com/][b]sac longchamp[/b][/url]
[url=http://shensacen.xanga.com/770580508/sacs-%C3%A0-main-designer-pour-dames/][b]sac longchamp[/b][/url]
[url=http://shensacen.yolasite.com/][b]sac longchamp[/b][/url]
[url=http://shenenmaoyi.livejournal.com/][b]sac longchamp[/b][/url]

Anonymous said...

top [url=http://www.001casino.com/]casino[/url] hinder the latest [url=http://www.realcazinoz.com/]casino bonus[/url] manumitted no consign reward at the foremost [url=http://www.baywatchcasino.com/]casino
[/url].

Anonymous said...

Did you [url=http://www.onlinecasinos.gd]slots[/url] about that you can wing it devaluate Depart bad Villa momentarily from your mobile? We be effort with a inimitability motorized casino at geste's disposal in the licensed disconsolateness of iPhone, iPad, Android, Blackberry, Windows 7 and Smartphone users. Present your gaming with you and be a title-holder [url=http://www.adultsrus.us]adults toys[/url] wherever you go.

Anonymous said...

We [url=http://www.nodepositbonus.gd]no deposit[/url] be subjected to a rotund library of absolutely unsolicited casino games as a replacement for you to sport opportunely here in your browser. Whether you appetite to practice a table recreation plan or even-handed sample out a few new slots once playing on the side of unfeigned in dough, we possess you covered. These are the exact verbatim at the same time games that you can engage at real online casinos and you can with them all representing free.

Anonymous said...

Hello. And Bye.

erection pills said...

Hi there! I just wanted to ask if you ever have any issues with hackers? My last blog (wordpress) was hacked and I ended up losing many months of hard work due to no back up. Do you have any methods to stop hackers?