httpd-docs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Allan Liska <>
Subject Re: New FAQ: Changing Server: header info.
Date Wed, 26 Jun 2002 02:07:20 GMT
Hello Rich,

Tuesday, June 25, 2002, 3:28:09 PM, you wrote:

RB> In order to do this, you will need to modify the Apache source code and
RB> rebuilt Apache. This is not advised, as it is almost certain not to
RB> provide you with the added security you think that you are gaining. The
RB> exact method of doing this is left as an exercise for the reader, as we
RB> are not keen on helping you do something that is intrinsically a bad
RB> idea.


Otherwise +1.  Good answer, and I agree that recompiling Apache to try
to hide the name of the web server is bad practice anyway.  A script
kiddie is too dumb to figure out how to find out what web server is
running, and a serious attacker is not going to let a little
obfuscation stop progress.


To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message