Apache Headers

Posted on 2004-11-06
Last Modified: 2010-03-04
How do I remove response headers from Apache? I tried using mod_headers, and did:

Header remove Server

With no luck, so I tried:

Header set Server "Hiding"

Again, no luck. I want to be able to change these headers, because for example, Google returns:

Response Headers -

X-TR: 1
Cache-Control: private
Content-Type: text/html
Server: GWS/2.1
Date: Sun, 07 Nov 2004 05:33:57 GMT
Content-Length: 2325

Which is minimal information, helping in avoid attacks against a server.

I am using Apache2, I am also using mod_security to modify Server but that is all that I can seem to modify/remove...I tried to set Headers within the actual PHP files, but still no luck.

My current headers after trying for the last 5 hours:

Date: Sun, 07 Nov 2004 05:36:09 GMT
Server: Mine
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: private
Keep-Alive: timeout=15, max=74
Content-Type: text/html; charset=ISO-8859-1
Connection: Keep-Alive
Transfer-Encoding: chunked

How can I turn off Keep-Alive and Connection headers? Modify the content-type header to remove the charset?
Question by:drakkarnoir
    LVL 48

    Accepted Solution

    You can turn off Keep-Alive by setting
    KeepAlive Off
    This will remove the Keep-Alive -header, but the Connection is changed to closed.

    But why do you want to change Content-Type. This is needed by each browser to determin how to display the pagecorrectly.

    Those information about Keep-Alive, Connection and Content-Type do not expose any information about your server, but removing/changing parts will break/slow down browsers.
    LVL 48

    Expert Comment

    very hard to say if the hints I provided helped or not as there was no feedback at all and no other comments have been made.

    Featured Post

    Why You Should Analyze Threat Actor TTPs

    After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

    Join & Write a Comment

    If you've heard about htaccess and it sounds like it does what you want, but you're not sure how it works... well, you're in the right place. Read on. Some Basics #1. It's a file and its filename is .htaccess (yes, with a dot in the front). #…
    In Solr 4.0 it is possible to atomically (or partially) update individual fields in a document. This article will show the operations possible for atomic updating as well as setting up your Solr instance to be able to perform the actions. One major …
    Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
    This video is in connection to the article "The case of a missing mobile phone (". It will help one to understand clearly the steps to track a lost android phone.

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now