隱藏Apache版本號及版本敏感信息

在安裝軟件前,咱們須要隱藏軟件的版本號及版本其餘信息,這樣就大大提升了安全指數。html

只隱藏版本號:apache

咱們在主配置文件裏:httpd.confvim

[root@bqh-119 ~]# curl -i bbs.bqh123.com
HTTP/1.1 200 OK
Date: Tue, 16 Jul 2019 14:45:30 GMT
Server: Apache/2.2.27 (Unix) DAV/2    #不隱藏的狀況下,顯示版本號及版本信息
Last-Modified: Sun, 14 Jul 2019 11:06:54 GMT
ETag: "dff71-16-58da224263365"
Accept-Ranges: bytes
Content-Length: 22
Content-Type: text/html

http://bbs.bqh123.com
[root@bqh-119 ~]# echo -e "ServerTokens Prod\nServerSignature Off" >>/application/apache/conf/httpd.conf
[root@bqh-119 ~]# tail -2 /application/apache/conf/httpd.conf
ServerTokens Prod
ServerSignature Off
[root@bqh-119 ~]# /application/apache/bin/apachectl -t
Syntax OK
[root@bqh-119 ~]# /application/apache/bin/apachectl graceful
[root@bqh-119 ~]# curl -i bbs.bqh123.com
HTTP/1.1 200 OK
Date: Tue, 16 Jul 2019 15:19:04 GMT
Server: Apache                                 #版本號木有了
Last-Modified: Sun, 14 Jul 2019 11:06:54 GMT
ETag: "dff71-16-58da224263365"
Accept-Ranges: bytes
Content-Length: 22
Content-Type: text/html

http://bbs.bqh123.com

隱藏系統及版本信息:安全

編輯源文件中:app

  • vim apache2.2.27/include/ap_release.h
  • vim httpd-2.2.27/os/unix/os.h

能夠把裏面的信息改爲你想要的系統或版本curl

注:是在編譯軟件以前的操做!!!url

相關文章
相關標籤/搜索