Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default Apache 2.2. security issue? Raw index shows system details.

    We just updated to Apache 2.2. and now the raw index listing shows all sorts of server details that we would rather not have displayed, example (see the bottom):

    -------------------------------
    Index of /wc/mov

    * Parent Directory
    * My cool movies/
    * My cool Menus/
    * _Go_To_Main_Menu.html

    Apache/2.2.6 (Unix) mod_ssl/2.2.6 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www.domainextra.com Port 80
    -------------------------------

    Any way to obscure these details?


    By the way, the customer says that he used to get a much nicer looking index page, e.g. with icons rather than bullets, so I guess my question is, is there any way to set parameters for this?

  2. #2
    Member
    Join Date
    Oct 2005
    Posts
    125

    Default

    They can be obscured in mod_security.

  3. #3
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default

    Quote Originally Posted by Serra View Post
    They can be obscured in mod_security.
    Thanks. This is very good news, but how? Can you point me to a page or offer an example? This would be very much appreciated!

  4. #4
    cPanel Staff
    Join Date
    Mar 2007
    Posts
    113

    Default

    Change ServerSignature to Off in httpd.conf or add a line with "ServerTokens Min"

    Then run "/usr/local/cpanel/bin/apache_conf_distiller --update --main" to preserve the change and "/scripts/restartsrv_httpd" to restart Apache.

  5. #5
    Member
    Join Date
    Nov 2004
    Location
    Earth
    Posts
    151

    Default

    Great.. thanks for the info. I was just trying to figure this out.

    One thing..does
    /scripts/buildhttpdconf
    need to be run too?


    Quote Originally Posted by jdlightsey View Post
    Change ServerSignature to Off in httpd.conf or add a line with "ServerTokens Min"

    Then run "/usr/local/cpanel/bin/apache_conf_distiller --update --main" to preserve the change and "/scripts/restartsrv_httpd" to restart Apache.

  6. #6
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default

    Quote Originally Posted by jdlightsey View Post
    Change ServerSignature to Off in httpd.conf or add a line with "ServerTokens Min"

    Then run "/usr/local/cpanel/bin/apache_conf_distiller --update --main" to preserve the change and "/scripts/restartsrv_httpd" to restart Apache.
    Hey thanks! I should have geeked this one out myself. I had ServerSignature set to off before, but of course I recently upgraded to Apache 2.2. so this feature was set back on.

    However, I did not know about the apache_conf_distiller --update --main thing. So I guess this just locks the basic features in place? Without locking anything else out? Hmmmm, interesting.

Similar Threads & Tags
Similar threads

  1. Using cpanel, then why the page shows the index of /?
    By Spring0105 in forum New User Questions
    Replies: 1
    Last Post: 12-12-2009, 08:43 PM
  2. Raw Log download shows this:
    By t9clkclnr in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-09-2007, 11:46 AM
  3. Security issue? netstat -ntu shows blank line in output
    By jols in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 04-01-2007, 08:11 PM
  4. Horde / Security TMP or Apache Issue?
    By claudio in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-03-2004, 08:45 AM
  5. Apache Security issue, A hacker have access to my server!!
    By emeric21 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-09-2003, 05:46 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube