Skip to main content

HTTP Headers

Comments

4 comments

  • robb3369
    For Apache: Go into WHM, under Apache Config and set the Server Signature to "Off" For Joomla: Edit source or use this extension: /http://extensions.joomla.org/extensions/site-management/browsers-a-web-standards/12736 For PHP: Add the following in the php.ini: expose_php = off
    0
  • fidividi
    [quote="robb3369, post: 1596741">For Apache: Go into WHM, under Apache Config and set the Server Signature to "Off" For PHP: Add the following in the php.ini: expose_php = off
    Hi Rob, I applied your recommended changes (for PHP and Apache). Only PHP expose_php was on, and I changed to off. Apache signature option was off already. Yet, nothing changed, I still see PHP version, and ofcourse apache details.... [COLOR="silver">- - - Updated - - - PHP expose_php worked on another server. But didn't on the main one. And apart from Apache, what about nginx for instance? Anyway to disable the version and information with that?
    0
  • fidividi
    For anyone else having the same issue, as far as Apache, you also need to change to "Product Only" under "Server Tokens" in "Home "Service Configuration "Apache Configuration"
    0
  • cPanelMichael
    Hello :) I just wanted to note that while hiding the version of Joomla might make it less of a target, it's important to ensure the latest versions of the software are used. Taking the time to ensure your customers use the latest versions of PHP scripts like Joomla will go a long way in helping to reduce the likelihood of an exploited account. Thank you.
    0

Please sign in to leave a comment.