Apache ServerTokens and ServerSignatures
From apache2.conf:
Code:
# Clipped
ServerRoot "/etc/apache2"
ServerName "localhost"
ServerSignature Off
ServerTokens Prod
# Clipped
Being printed on error pages:
Code:
Apache/2.2.11 (Ubuntu) DAV/2 SVN/1.5.4 mod_fastcgi/2.4.6 Phusion_Passenger/2.2.4 mod_ssl/2.2.11 OpenSSL/0.9.8g mod_chroot/0.5 mod_perl/2.0.4 Perl/v5.10.0 Server at redmine.blade.local Port 443
Its not working as it should. Why could be the reason?
[EDIT]:
Modified conf.d/security and commented the overridden settings there.
Re: Apache ServerTokens and ServerSignatures
have you reloaded/restarted apache?
Re: Apache ServerTokens and ServerSignatures
Quote:
Originally Posted by
shoaibi
From apache2.conf:
Code:
# Clipped
ServerRoot "/etc/apache2"
ServerName "localhost"
ServerSignature Off
ServerTokens Prod
# Clipped
Being printed on error pages:
Code:
Apache/2.2.11 (Ubuntu) DAV/2 SVN/1.5.4 mod_fastcgi/2.4.6 Phusion_Passenger/2.2.4 mod_ssl/2.2.11 OpenSSL/0.9.8g mod_chroot/0.5 mod_perl/2.0.4 Perl/v5.10.0 Server at redmine.blade.local Port 443
Its not working as it should. Why could be the reason?
[EDIT]:
Modified conf.d/security and commented the overridden settings there.
Thanks, that had me scratching my head for a while!
Re: Apache ServerTokens and ServerSignatures
I found my ServerToken in /etc/apache2/conf.d/security (ubuntu precise with apache port)
Changing/adding values to httpd.conf or apache.conf had no effect here.
Seems signatures are controlled by the ServerTokens directive since 2.0.2 or so as well.
Use nmap -A your.ip.address after reloading to ensure your edits are in fact giving you the desired effect.
:)