logo
Apache Lounge
Webmasters

 

About Forum Index Downloads Search Register Log in RSS X


Keep Server Online

If you find the Apache Lounge, the downloads and overall help useful, please express your satisfaction with a donation.

or

Bitcoin

A donation makes a contribution towards the costs, the time and effort that's going in this site and building.

Thank You! Steffen

Your donations will help to keep this site alive and well, and continuing building binaries. Apache Lounge is not sponsored.
Post new topic   Forum Index -> Apache View previous topic :: View next topic
Reply to topic   Topic: ServerTokens Ignored in 2.2.6?
Author
VoodooMill



Joined: 11 Jan 2007
Posts: 60

PostPosted: Tue 04 Dec '07 1:21    Post subject: ServerTokens Ignored in 2.2.6? Reply with quote

Hey there,

Has anyone noticed in 2.2.6 that ServerTokens are ignored?

I suppose it's not the end of the world, but I really would like to keep that information from being seen.

EDIT: Actually, nevermind. I guess the full token is displayed in the services panel even though ServerTokens Prod is configured. The info did not display over the web.
Back to top
glsmith
Moderator


Joined: 16 Oct 2007
Posts: 2268
Location: Sun Diego, USA

PostPosted: Tue 04 Dec '07 1:36    Post subject: Reply with quote

Just an FYI for this thread, you can change tokens/signature to read

"Yourkshire/2.2.2.2 (DOS5) mod_this/2.2.2.2 mod_that/2.2.2.2"

anything you want it to say using the mod_security directive

SecServerSignature "Yourkshire/2.2.2.2 (DOS5) mod_this/2.2.2.2 mod_that/2.2.2.2"


As far as hiding tokens, if they want to know what it is your running, they can find out without looking at the sig line. Hiding tokens may slow them down a wee widdle bit ..... maybe.
Back to top


Reply to topic   Topic: ServerTokens Ignored in 2.2.6? View previous topic :: View next topic
Post new topic   Forum Index -> Apache