Tuesday, February 16, 2016

Remove Apache server info from web page header

If you are using Ubuntu or Debian
Edit file  /etc/apache2/conf-enabled/security.conf

Change “ServerTokens OS” to “ServerTokens Prod”

and
Change “ServerSignature On” to “ServerSignature Off”

Restart apache.

If you are using CentOS, RHEL or fedora
Edit file /etc/httpd/conf/httpd.conf

Change “ServerTokens OS” to “ServerTokens Prod”
and
Change “ServerSignature On” to “ServerSignature Off”

Restart apache. 

If there are no entries of these lines, add both lines in the file.
Restart apache

Apache remove php version info from the web page header


Edit your php.ini and set following attribute.

expose_php = off
Restart apache.