logo
Apache Lounge
Webmasters

 

About Forum Index Downloads Search Register Log in RSS X


Keep Server Online

If you find the Apache Lounge, the downloads and overall help useful, please express your satisfaction with a donation.

or

Bitcoin

A donation makes a contribution towards the costs, the time and effort that's going in this site and building.

Thank You! Steffen

Your donations will help to keep this site alive and well, and continuing building binaries. Apache Lounge is not sponsored.
Post new topic   Forum Index -> Apache View previous topic :: View next topic
Reply to topic   Topic: Disabling server info into response header
Author
mishravik



Joined: 25 Oct 2013
Posts: 3

PostPosted: Tue 04 Mar '14 16:42    Post subject: Disabling server info into response header Reply with quote

We are trying to disable server info into response header.

Header unset Server
Header set Server "unknown"

It is not working.

We have installed "Apache 2.4.6-x86 server" on Win 2008 R2 Standard server (64-Bit).
Back to top
jraute



Joined: 13 Sep 2013
Posts: 188
Location: Rheinland, Germany

PostPosted: Tue 04 Mar '14 19:04    Post subject: Reply with quote

Normally you would use:

ServerTokens Prod
ServerSignature Off

"ServerTokens Prod" would give "Apache" as response and nothing else. But maybe it works to have "ServerTokens Off" as well to get really nothing.

Give it a try.
Back to top
glsmith
Moderator


Joined: 16 Oct 2007
Posts: 2268
Location: Sun Diego, USA

PostPosted: Tue 04 Mar '14 20:35    Post subject: Reply with quote

There is no "Off" choice. There was a big discussion a few years ago when "Off" was going to be added and it was felt there was no need.

The question is, why do you need to turn this info off? Are you trying to hide that you are running Apache for security reasons? Security through obscurity has been shown to be no security at all over many years. It may also be of detriment, people scanning servers for vulnerability will hit you with everything under the sun for all the different servers.

You still have options however. mod_security can remove it with SecServerSignature as well as mod_bikeshed.
Back to top
jraute



Joined: 13 Sep 2013
Posts: 188
Location: Rheinland, Germany

PostPosted: Tue 04 Mar '14 21:01    Post subject: Reply with quote

Thanks for the update, i was remembering that disussion. Smile
Back to top


Reply to topic   Topic: Disabling server info into response header View previous topic :: View next topic
Post new topic   Forum Index -> Apache