Apache: Disable response headers
Posted: Fri Feb 19, 2016 11:21 pm
[Problem]
When displaying an empty page or an error, the server exposes the apache/php/ssl versions, like:
[Solution]
Change in vhost (for each site + default):
Change in php.ini:
When displaying an empty page or an error, the server exposes the apache/php/ssl versions, like:
Code: Select all
Server: Apache/2.4.10 (Ubuntu) PHP/5.5.30-1+deb.sury.org~precise+1 OpenSSL/1.0.1
X-Powered-By: PHP/5.5.30-1+deb.sury.org~precise+1
[Solution]
Change in vhost (for each site + default):
Code: Select all
ServerSignature Off
ServerTokens ProductOnly
Code: Select all
expose_php = off