How to hide the Apache version and OS information to security scan?

In Ubuntu edit the following file
sudo vim /etc/apache2/conf-enabled/security.conf

Change ServerTokens OS to ServerTokens Prod 

then change ServerSignature On to ServerSignature Off

Restart the apache2 :

sudo service apache2 restart


In CentOS and RedHat edit the following file:

 vim /etc/httpd/conf/httpd.conf

Change ServerTokens OS to ServerTokens ProductOnly 

then change ServerSignature On to ServerSignature Off

Restart the apache2 

Comments

Popular posts from this blog

ACTION_FAILED:OU_INVALID: Solution for GoogleApps bulk user upload issue, username@domainname.com:ACTION_FAILED:OU_INVALID. This error is because you have not specified the Org Unit Path properly.

Email Notification in Koha! How to configure Email Notification in Koha 20.11 with postfix?

Moodle OAuth 2. This account is pending email confirmation! Solved