Тёмный

Apache Secure Tutorial: Hide HTTP Header and Disable Directory Listing 

dotsway
Подписаться 4,5 тыс.
Просмотров 17 тыс.
50% 1

This is one of the basic secuirty hardening and first steps, by default server will show the OS information and Apache version in the footer whenever a page not found or any other requests replies.
One of the first steps when you start securing your Apache server is to disable the directory browsing, you don't want anyone to browse your file and know the structure.
Other Apache Hardening Tutorials:
1- Secure Apache Web Server - Use SSLScan and Disable Ciphers:
goo.gl/mb7pYz
2- Apache Secure Tutorial: Hide HTTP Header and Disable Directory Listing:
goo.gl/VqcLrG
3- Apache Hardening Tutorial: Disable HTTP Trace / Cross Site Method
goo.gl/KJnbDS
Disable Server Response Header
vi /etc/httpd/conf/httpd.conf
Add
ServerTokens Prod
Save
Restart Apache
service httpd restart "RHEL/CentOS 6 and earlier versions"
systemctl restart httpd "RHEL/CentOS 7 and earlier versions"
Disable Apache Trailing Footer
vi /etc/httpd/conf/httpd.conf
Add
ServerSignature Off
Save
Restart Apache
service httpd restart "RHEL/CentOS 6 and earlier versions"
systemctl restart httpd "RHEL/CentOS 7 and earlier versions"
n this example i will disable browsing for /var/www/html/dotsway folder.
vi /etc/httpd/conf/httpd.com
Add below to the directory part
Options -Indexes
Save
Restart Apache
service httpd restart
OR
systemctl restart httpd

Хобби

Опубликовано:

 

1 июн 2017

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 7   
@mackocour
@mackocour 7 лет назад
The Apache Series is so far my favourite, very useful information, thanks for sharing
@dotsway
@dotsway 7 лет назад
Thanks :) i will be posting more soon, maybe after i will start ethical hacking series.
@brianmaita7394
@brianmaita7394 Год назад
Man you just saved me, I owe you a beer.
@brightantony7833
@brightantony7833 6 лет назад
Is this possible to restrict a specific requests, for example i have to restrict url ends with wsdl.
@hatesoulslayer6005
@hatesoulslayer6005 10 месяцев назад
does this works with subdirectories?
@yeswanthreddy3480
@yeswanthreddy3480 6 лет назад
How can i disable a specific file in the folder
@dotsway
@dotsway 6 лет назад
You can either use mod_rewrite to restrict specific words or you can add something similar to the htaccess or the httpd.conf Order Allow,Deny Deny from all
Далее
Why are you not creating anything in c++ ?
14:46
Просмотров 8 тыс.
The Worlds Most Powerfull Batteries !
00:48
Просмотров 11 млн
Learning Apache Using A  Minimal httpd configuration
10:38
Docker Compose in 12 Minutes
12:00
Просмотров 1,2 млн
Introduction to tmux
11:43
Просмотров 299 тыс.
What is a SAS SSD?
12:08
Просмотров 11 тыс.
Getting started with Ansible 02 - SSH Overview & Setup
28:51
How to install xampp on centos 7 with easy step
11:34
Просмотров 2,2 тыс.
WHY DOES SHE HAVE A REWARD? #youtubecreatorawards
0:41
Жиза..
0:36
Просмотров 1,8 млн
Яжемать в скейт парке !
0:24
Просмотров 915 тыс.