Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Server Signature #33

Open
daryakuritsyna opened this issue Jul 29, 2015 · 0 comments
Open

Server Signature #33

daryakuritsyna opened this issue Jul 29, 2015 · 0 comments

Comments

@daryakuritsyna
Copy link
Member

Your server signature is on. Turning off your server signature is generally a good idea from a security standpoint. Read more on how to turn off server signature and improve your website's security.

By default, the Apache webserver sends HTTP headers with some information about your server version, operating system, modules installed, etc. These informations can be used by hackers in order to exploit vulnerabilities (specially if you are running an older version). These information can be hidden or changed with very basic configurations.
Open Apache’s configuration file (httpd.conf or apache.conf) and search for ServerSignature. If you find it, edit it to:
ServerSignature Off
ServerTokens Prod

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant