[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Apache Headers

Posted on 2004-11-06
3
Medium Priority
?
259 Views
Last Modified: 2010-03-04
How do I remove response headers from Apache? I tried using mod_headers, and did:

Header remove Server

With no luck, so I tried:

Header set Server "Hiding"

Again, no luck. I want to be able to change these headers, because for example, Google returns:

Response Headers - http://www.google.com/

X-TR: 1
Cache-Control: private
Content-Type: text/html
Server: GWS/2.1
Date: Sun, 07 Nov 2004 05:33:57 GMT
Content-Length: 2325

Which is minimal information, helping in avoid attacks against a server.

I am using Apache2, I am also using mod_security to modify Server but that is all that I can seem to modify/remove...I tried to set Headers within the actual PHP files, but still no luck.

My current headers after trying for the last 5 hours:

Date: Sun, 07 Nov 2004 05:36:09 GMT
Server: Mine
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: private
Keep-Alive: timeout=15, max=74
Content-Type: text/html; charset=ISO-8859-1
Connection: Keep-Alive
Transfer-Encoding: chunked

How can I turn off Keep-Alive and Connection headers? Modify the content-type header to remove the charset?
0
Comment
Question by:drakkarnoir
  • 2
2 Comments
 
LVL 48

Accepted Solution

by:
hernst42 earned 2000 total points
ID: 12516801
You can turn off Keep-Alive by setting
KeepAlive Off
This will remove the Keep-Alive -header, but the Connection is changed to closed.

But why do you want to change Content-Type. This is needed by each browser to determin how to display the pagecorrectly.

Those information about Keep-Alive, Connection and Content-Type do not expose any information about your server, but removing/changing parts will break/slow down browsers.
0
 
LVL 48

Expert Comment

by:hernst42
ID: 12737578
very hard to say if the hints I provided helped or not as there was no feedback at all and no other comments have been made.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If your site has a few sections that need to be secure when data is transmitted between the server and local computer, such as a /order/ section for ordering or /customer/ which contains customer data, etc it would of course be recommended to secure…
In Solr 4.0 it is possible to atomically (or partially) update individual fields in a document. This article will show the operations possible for atomic updating as well as setting up your Solr instance to be able to perform the actions. One major …
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…
Suggested Courses
Course of the Month19 days, 14 hours left to enroll

873 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question