Member-only story
Overview
In this article I would like to summarized the security settings that can be shared for Apache settings and their items.
Example settings:
[root@server vagrant]# cat /etc/httpd/conf.d/security.confServerTokens Prod #version information
Header unset "X-Powered-By"RequestHeader unset Proxy #httpoxy CountermeasureHeader append X-Frame-Options SAMEORIGIN #Clickjacking CountermeasureHeader set X-XSS-Protection "1; mode=block" #XSS Countermeasur
Header set X-Content-Type-Options nosniff TraceEnable Off #XST Countermeasure<Directory /var/www/html>AllowOverride AllOptions -Indexes #Prohibit file list output<IfVersion < 2.3> # Apache 2.2 or earlier countermeasuresServerSignature Off #Hide version informationFileETag MTime Size # ETag inode information Hidden
</IfVersion>
</Directory><Directory "/var/www/cgi-bin">
<IfVersion < 2.3>
ServerSignature Off
FileETag MTime Size
</IfVersion>
</Directory>