JGZimmerle
November 3rd, 2006, 10:55 PM
Hi!
The default configuration of the apache2 package makes apache report detailed information about installed software versions of web-related packages to potential attackers. This could simply be prevented by putting the line
ServerTokens Prod
into the default apache2.conf of the apache2 package.
The default configuration of the apache2 package makes apache report detailed information about installed software versions of web-related packages to potential attackers. This could simply be prevented by putting the line
ServerTokens Prod
into the default apache2.conf of the apache2 package.