Telecom Tidbits
Jared's Network and Security Blog
  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links

Hardening the Apache Webserver

September 15, 2021 Jared Hall Internet Security, WordPress

One thing that should be done for those hosting their own Apache Webservers is to remove any unneeded information from Apache Error responses:

Apache/2.4.48 (Ubuntu) Server at example.com Port 443

In the standard setup for Apache, Apache reveals it’s version number as well as the underlying O/S that it is running on. Why make it so easy for hackers? Make them work to get that information.

Add this to the end of your /etc/apache2/apache2.conf file:

ServerTokens Prod
ServerSignature Off

That’s all there is to it. If you are hosted on somebody else’s Apache, ask, no DEMAND, that they do it.

« Numb to it all » Give it a REST: Serious WordPress Bugs

Tools & Downloads

Download Center

Categories

Good Reads (PDF)

Recent Posts

  • PayPal Woes and Degenerative AI
  • A Pathetic Defense of Julian Assange
  • Damned if you do. Damned if you don’t.
  • ProtonMail? Not Worth an Electron!
  • Give it a REST: Serious WordPress Bugs
$
Select Payment Method
Personal Info

Donation Total: $20.00

↑

  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links
Temporal Based Intelligence © 2017